SourceTrust

Legal

Cookie Policy

What cookies and similar technologies we use on the marketing site, application, and public attestation pages, and how to control them.

Last updated: July 14, 2026

This cookie policy explains how SourceTrust ("us", "we", "our") uses cookies and similar technologies when you visit our marketing website at https://sourcetrust.dev, use the application at https://app.sourcetrust.dev, or view public license attestation pages at https://sourcetrust.app (including org and project pages such as https://sourcetrust.app/your-org/your-product).

For how we handle personal data more broadly, see our privacy policy.

What cookies and similar technologies are

Cookies are small text files stored in your browser. We also use similar technologies such as local storage and third-party scripts that may set or read cookies when they run.

We group them into essential (required for security, authentication, and core features) and analytics (optional, used only with your consent).

Cookie and storage inventory

The table below lists cookies and similar technologies across our marketing site, application, and public attestation pages. Analytics rows apply only after you choose Accept analytics.

Essential cookies and scripts

Essential cookies and scripts support security, authentication, language preferences, and core functionality. They run regardless of whether you accept analytics.

Analytics cookies and tags

We request analytics cookies and tags only after you choose Accept analytics on our cookie banner.

We use Google Tag Manager (container GTM-MS6H7S5D) in basic consent mode. GTM is not requested unless you opt in. If you select Essential only before it loads, GTM and other analytics tags remain unloaded. If you withdraw after opting in, SourceTrust stops queued analytics events and removes the injected GTM elements. Code already executed by a third-party tag cannot be unloaded from the current document.

When enabled, analytics help us understand how visitors use our marketing site, application, and public attestation pages (for example, which pages are viewed). Data collected through these tags is handled as described in our privacy policy.

How we remember your choice

We store your consent choice in your browser (cookie key sourcetrust_cookie_consent_v1 on .sourcetrust.dev, with localStorage as a fallback on each origin) so we do not ask on every page. The same choice can apply across our marketing site and application subdomains when you enable analytics.

On a new page load, Essential only means we do not request analytics tags. Accept analytics means we load GTM and related tags on eligible routes during subsequent visits until you change your choice.

How to change or withdraw consent

Use Cookie settings in the page footer at any time to open your cookie preferences. Choose Essential only to withdraw analytics consent, or Accept analytics to opt in. We save a withdrawal immediately, stop SourceTrust-owned analytics events, and remove the GTM elements from the current page. When browser storage events are available, we also remove them from other open tabs on the same origin. Code already executed by a third-party tag may remain active until you reload or navigate away. On the next page load, GTM stays unloaded while Essential only remains saved. Withdrawal does not delete analytics cookies already stored; you can delete them through your browser settings.

Clearing site data for the relevant domain in your browser also resets your saved choice and shows the initial cookie banner again on your next visit.

You can also block or delete cookies through your browser settings. Essential features such as sign-in and abuse prevention may not work correctly if you block all cookies.

For general information about controlling cookies in your browser, see internetcookies.com.

Changes and contact

We may update this cookie policy from time to time. We will post the updated policy on this page and update the "Last updated" date.

Questions about cookies: hello@sourcetrust.dev

Name / technologyProviderTypePurposeDuration
sourcetrust_cookie_consent_v1 (cookie + local storage)SourceTrustEssentialRemembers your cookie banner choice on the marketing site, application, and public attestation pagesUp to 12 months, until you clear site data or change your choice
wos-session (and related WorkOS auth cookies)WorkOSEssential (application only)Sign-in session for the authenticated application at https://app.sourcetrust.devSession or per WorkOS session policy
st-langSourceTrustEssential (application only)Stores your chosen UI language in the applicationUp to 12 months
Turnstile / Cloudflare challenge cookies (for example __cf_bm)CloudflareEssentialAbuse prevention, CAPTCHA on the marketing site scan, published license attestation pages, and security on all SourceTrust-hosted pagesShort-lived session cookies per Cloudflare's policies
Hosting and CDN cookiesCloudflareEssentialDeliver the marketing site, application, and public attestation pages safelyVaries; see Cloudflare documentation
Google Tag Manager / Google Analytics tagsGoogleAnalytics (consent required)Measure usage on the marketing site, non-sensitive application routes, and public attestation pages when you choose Accept analytics. We do not load GTM on sign-in, password reset, invitation, two-factor, or staging access routesVaries by tag; commonly up to 24 months for analytics identifiers

Authentication cookies for the signed-in application (for example WorkOS session cookies) are essential for access and are not controlled by the analytics consent toggle. They are described in our privacy policy and sub-processor list.