Skip to main content

About · Copenhagen

We're making license compliance boring, in the good way

SourceTrust builds compliance infrastructure for the license obligations every product ships with, and almost no one keeps current. Based in Copenhagen.

We built this because “we use open source” is not an answer procurement accepts, and a spreadsheet from last quarter is not proof. We'd rebuilt one too many attribution files at midnight before a release, reconstructing what shipped from lockfiles and memory.

Open source isn't free of obligations; it's a contract most teams never read. The gap is rarely intent. It's time, attribution, and a maintenance loop that keeps breaking every sprint. So we built the loop: Import what you ship, review it once, publish proof, and get told when the next release changes your obligations.

And we hold ourselves to it. Our own license page is public, maintained, and built on the exact product we sell. If we can't keep our record current, why would you trust us with yours?

Independent and EU-based

SourceTrust is built and run in Copenhagen, Denmark. We are software tooling, not a law firm: The platform handles inventory, review, publish gates, a hosted compliance page per product, and exports when engineering needs the files in a repo or release.

The company started in 2026. Building from inside the EU keeps us close to the procurement and regulatory expectations our customers answer to.

What we believe

Open source is not permission to ship without obligations. Most teams discover the gap only when a customer, auditor, or lawyer asks.

A SOC report or ISO certificate does not replace knowing what is in your build and what each license requires. Our job is to keep that record maintainable as your dependencies change.

We built the product for ourselves first, then opened it up on fair and reasonable terms, which is why pricing is per project with unlimited members and no per-user fees.

How we build

  • Precise

    Confirmed licenses and full text, not paraphrased summaries or “we think it's fine” toggles. What's inferred is labeled as inferred.

  • Accountable

    Publish gates mean you can't claim compliance you haven't reviewed. We state the limits plainly: Infrastructure, not legal advice.

  • Unhurried

    No urgency theater, no scare walls. Counsel-ready infrastructure that reads calm, because trust isn't sold with fear.

Come say hello.

Questions about diligence, procurement, or invoicing for multiple products? We answer our own email.

hello@sourcetrust.dev

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.