Skip to main content

Surfaces

Websites, mobile apps, installers: Same duties, different exposure

Third-party software shows up in every delivery model. Buyers often start with your public website, but compliance follows what you ship.

Last updated: July 2, 2026

01Surfaces

Websites are only the surface. But they are where buyers look first

Every delivery model ships third-party software. A website scan catches what is publicly visible; SourceTrust operationalizes what you actually release.

SurfaceObligation scopeWhat breaksCoverage
Website & web appJS bundles, npm/CDN libraries, fonts, analytics, chat widgets, maps embedsEnterprise asks for a license page; marketing loads scripts nobody inventoriedScannable today
Mobile appSDKs, open-source libraries, fonts, icons, bundled assets in the store buildApp store review, customer security questionnaire, M&A diligence on bundled OSSInventory in app
Desktop & installerInstallers, updaters, embedded runtimes, third-party DLLs and helpersAttribution must ship inside the artifact. A web page alone is not enoughInventory in app
Embedded & on-premFirmware modules, appliance images, air-gapped bundles with hundreds of packagesCopyleft and distribution analysis: Obligations follow the binary, not the pitch deckInventory in app

Delivery changes which obligations bite hardest, not whether they exist. Start with your public website; operationalize the full inventory in SourceTrust.

Run a website surface scan

Continue reading

Related topics

One idea per page: Follow the path that matches your next question.

Next step

When you are ready to move from reading to action:

Run a free surface scan

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.