Your IT provider or software vendor might own more of your business than you realize — your passwords, your data, your infrastructure. Here's how to spot it, and how to get your leverage back.
I had a conversation a few months ago with a business owner who wanted to switch IT providers. The relationship had soured — slow response times, no proactive communication, just a monthly invoice showing up without much to show for it. Totally reasonable to want a change.
The problem? Her current IT provider had never given her the admin credentials to her own systems. Every password, every configuration, every bit of documentation lived in their system. When she asked for it, they stalled. Then they quoted her an "offboarding fee" of several thousand dollars to hand over what was rightfully hers.
That's vendor lock-in. And it's not a rare story.
After 30+ years in this business, I've seen every flavor of it. Some of it is deliberate — vendors and providers who engineer lock-in on purpose because customers who can't leave don't leave. Some of it is just negligence that happens to benefit the vendor. But the result is the same: you're stuck, and you're paying a premium for the privilege.
This post is about learning to see lock-in before it traps you — and about what to do if you're already in too deep.
This is the most common form we see with small businesses, and it's particularly insidious because it often develops gradually over years of a working relationship.
Here's how it typically happens. You hire an IT person or small IT company to manage your systems. They set everything up. They know the passwords. They handle the renewals. They're the ones who registered your domain, set up your email, and configured your server. For a while, this is convenient — you don't have to think about any of it.
But over time, all of that knowledge and access has concentrated in their hands. And they may or may not be documenting it in a way that you can actually access. Then one day you want to switch providers, or they raise their rates 40%, or they just stop being responsive — and you realize you have no idea how to run your own systems without them.
Specific red flags to watch for:
If you're evaluating a transition, our post on how to survive an IT provider switch walks through exactly what you should demand during handoff — and the red flags that signal a provider isn't acting in good faith.
Software vendor lock-in works differently, but it can be just as costly. The basic mechanic: your data lives in a proprietary format or system, and getting it out is either impossible, extremely painful, or by design expensive enough that most customers give up and stay.
Classic examples small businesses run into:
Accounting and ERP software. You spend years entering data into a system. Then you want to switch to something better or cheaper. But your data is locked in a proprietary database format. You can export some things, but your years of transaction history, customer records, and custom reports? Good luck. Many businesses end up running the old system in parallel for years because full migration is too painful, effectively paying twice.
Industry-specific platforms. Dental software, property management software, point-of-sale systems, legal case management — these vertical-specific tools are often the worst offenders. They know their customers don't have time to migrate, so they price accordingly. We've seen contracts with 3-year auto-renewals, significant price increases built in after year one, and genuinely hostile data export policies.
Cloud storage and collaboration tools. This one's subtle. If your entire workflow is built around one platform's specific features — say, a cloud platform whose collaboration tools don't have any equivalents elsewhere — you're locked in even if your data is technically portable. The switching cost isn't just data migration; it's retraining everyone and rebuilding processes.
Hardware tied to subscription services. Some vendors sell you hardware at a low upfront cost, but the hardware only works with their cloud subscription. Cancel the subscription and the device becomes useless. We see this with certain security cameras, smart locks, and even some networking equipment.
Vendor lock-in costs you in ways that are easy to miss because they don't show up as a line item on an invoice.
Above-market pricing. When you can't leave, you lose negotiating power. Providers and vendors who know you're stuck quote higher rates for renewals, add-on services, and support. We've seen locked-in customers paying 40-60% more than the market rate for services they could get elsewhere if they were free to switch.
Offboarding fees and ransom.effective. The scenario I opened with — the business owner hit with a surprise "offboarding fee" — is not unusual. We've seen providers charge thousands of dollars to hand over documentation, credentials, and configurations that the customer already paid to have created. Some call it an administrative fee. We call it what it is.
Opportunity cost. If you can't switch to a better solution because the switching cost is too high, you're stuck with an inferior product. Your competitors who aren't locked in can adopt better tools faster. Over time, that gap compounds.
Negotiation paralysis. Even if a provider or vendor never actually charges you a punitive exit fee, the mere existence of lock-in changes every negotiation. You bring less leverage to every conversation because both sides know you have fewer options. That power imbalance shows up in every contract renewal.
Add it up over five or ten years, and "thousands" is probably an understatement for most small businesses. We've seen it hit six figures when you account for above-market rates sustained over many years.
The best time to protect yourself from vendor lock-in is before you sign anything. Here's what to look for — and what to insist on.
Insist on owning your own credentials. This should be non-negotiable. Your domain registrar login, your Microsoft 365 admin account, your server admin passwords — you should own these directly. A good IT provider will set everything up under accounts you control, and they'll have access granted to them, not the other way around. If a provider resists this, walk away.
Require documentation in your hands. Your IT provider should maintain documentation about your environment and give you full access to it. Not just "we have it if you need it" — you should be able to access it independently. This is part of what you're paying for. Check out our IT Buyer's Guide for more questions to ask before signing with any provider.
Ask about data portability before you buy software. Before adopting any significant software platform, ask specifically: how do I get my data out if I want to leave, what format does it export in, and are there any fees associated with export? If the answers are vague or hostile, factor that in before signing.
Read termination clauses carefully. Look for auto-renewal provisions, early termination fees, and any language about data access upon termination. Some contracts explicitly limit your ability to export data within a certain window after cancellation. That's a trap.
Prefer open formats and open standards. This is part of why we favor open source solutions where it makes sense for our clients. Data stored in open formats — standard databases, standard file formats, documented APIs — is inherently more portable than data locked in proprietary systems. It's not always possible, but it's worth weighting in any buying decision.
Separate the hardware from the service. Be cautious about anything where the hardware only works with a vendor's cloud service. If the business model depends on you needing to keep paying, ask what happens to the hardware if you stop. The answer is usually not great.
If you're reading this and recognizing your current situation, here's the honest truth: getting out of vendor lock-in is rarely painless. But it's almost always worth it. Here's how to approach it.
Start by understanding what you actually own. Make a list of every login, every subscription, every piece of hardware and software your business relies on. For each one, ask: is this in my name and under my control, or does it belong to a vendor or provider? This inventory is the foundation of everything else.
Request your documentation and credentials in writing. If you're with an IT provider who holds your credentials, send a written request (email is fine) asking for a complete inventory and all administrative credentials. Doing it in writing creates a record. Give them a reasonable deadline. If they refuse or stall, that tells you everything you need to know about how this relationship ends — and you can factor that into your next steps.
Don't tip your hand too early with a software vendor. If you're planning to migrate away from a platform, do as much preparation as possible before you signal that you're leaving. Some vendors throttle data exports or make them harder once a cancellation is initiated. Export everything you can before pulling the trigger.
Get help with the transition. IT provider transitions in particular benefit from having a neutral third party help facilitate the handoff. Having a new provider involved who knows what to ask for — and who has done this before — makes the process much smoother and reduces the chance that something critical gets lost or withheld. Our managed IT services include transition support specifically because we've seen how badly these handoffs can go without it.
Plan for some cost to escape. Sometimes the exit fee is real and unavoidable. Sometimes paying it is still the right call if the ongoing cost of staying locked in is higher. Do the math: if you're overpaying by $500 a month and the exit fee is $3,000, you break even in six months. The two-year view almost always makes leaving worth it.
This sounds obvious, but vendor lock-in is fundamentally a question of who controls your business. When a vendor or provider owns your data, your credentials, or your infrastructure, they have leverage over you. And they will use it — maybe not deliberately, maybe not with any malice, but it will shape every interaction you have with them from then on.
The best IT relationships are ones where your provider is accountable because they're delivering value, not because you have no other option. When you have freedom to leave, the relationship stays honest. That's true of IT providers, software vendors, and pretty much every business relationship.
If you're not sure where you stand, the answer is probably to do the inventory we described above. Know what you own. Know what you don't. And then make decisions from a position of clarity rather than finding out the hard way when something goes wrong.
We've helped a lot of businesses untangle lock-in situations — some straightforward, some that required real patience and negotiation. If you want to talk through your specific situation, we're happy to take a look.