Surfaces
Websites, mobile apps, installers: Same duties, different exposure
Third-party software shows up in every delivery model. Buyers often start with your public website, but compliance follows what you ship.
Last updated: July 2, 2026
01Surfaces
Websites are only the surface. But they are where buyers look first
Every delivery model ships third-party software. A website scan catches what is publicly visible; SourceTrust operationalizes what you actually release.
| Surface | Obligation scope | What breaks | Coverage |
|---|---|---|---|
| Website & web app | JS bundles, npm/CDN libraries, fonts, analytics, chat widgets, maps embeds | Enterprise asks for a license page; marketing loads scripts nobody inventoried | Scannable today |
| Mobile app | SDKs, open-source libraries, fonts, icons, bundled assets in the store build | App store review, customer security questionnaire, M&A diligence on bundled OSS | Inventory in app |
| Desktop & installer | Installers, updaters, embedded runtimes, third-party DLLs and helpers | Attribution must ship inside the artifact. A web page alone is not enough | Inventory in app |
| Embedded & on-prem | Firmware modules, appliance images, air-gapped bundles with hundreds of packages | Copyleft and distribution analysis: Obligations follow the binary, not the pitch deck | Inventory in app |
Delivery changes which obligations bite hardest, not whether they exist. Start with your public website; operationalize the full inventory in SourceTrust.
Continue reading
Related topics
One idea per page: Follow the path that matches your next question.