The product
One controlled path from what you ship to proof you can send
Import, review, publish, and stay current, each step gated so the page you publish always matches what actually ships. Here's the whole thing.
Nothing is publishable until it's confirmed. Copyleft and missing-notice flags come from a 700+ license catalog, not a “we think it's fine” toggle. How a review actually runs →
Want to walk through this with us? Request a live walkthrough →
01Inputs
It reads what you already generate.
Connect a repo and the inventory follows every push. No new CI pipeline, no second scanner to configure.
Or bring the files you already have:
- package-lock.json
- pnpm-lock.yaml
- yarn.lock
- bun.lock
- go.mod
- Cargo.lock
- + more
14 formats across 9 ecosystems, including CycloneDX SBOM uploads.
- Auto-synced on push · 3 hours ago
- 4 dependencies added, 1 removed
- Dependency comment posted on #482
Pull request and merge request comments are informational only, nothing gates your merge. SourceTrust reads lockfiles and SBOMs, never your source code.
02Stay current
You'll know the page is stale before your customer does.
When live inventory drifts from your last published snapshot, the project flags it. License-version advisory warns loudly when a package relicenses. Optional security monitoring watches OSV advisories for your team only: Findings never appear on the public page.
- The dashboard banner and status pills name exactly what moved since the published revision
- A Changes tab lists added, updated, and removed packages, so the fix is a review, not an investigation
- One click republishes, and publish on merge can close the loop without you
03You control what's exposed
Every exposure controlPublishing proof doesn't mean publishing everything.
The number one worry about a public compliance page is exposure. Every layer of it is in your hands.
- Password-protect any page; invisible bot protection keeps scrapers out
- Per-page indexing controls keep pages out of search engines
- Lockfiles are parsed in your browser before upload
- Vulnerability findings stay vendor-only, never on the public page
- Read-only viewer and finance roles, enterprise SSO, and optional two-factor auth
- Team review notes are internal and never rendered publicly
One frozen snapshot. Every format diligence asks for.
The hosted page and every export are generated from the same approved snapshot, with provenance and the public URL baked in. They can't disagree.
/acme/platform
Hosted attestation page
Branded, immutable snapshots with revision history. Optional custom domain.
NOTICE
Attribution files
THIRD_PARTY_LICENSES.md and NOTICE for what ships in the artifact.
SPDX
Machine-readable
CycloneDX, SPDX, JSON, CSV and plist for tooling and portals.
PDF
Branded PDF
A clean disclosure document to attach to any questionnaire.
Go deeper
Every part of the platform, one focused page each
- WorkflowFive steps from inventory import to publish gates, a controlled path per shipped product.See the workflow
- Git syncConnect a repo, auto-import on push, Published and Testing branches, and dependency comments on every pull request or merge request.See how sync works
- DeliverablesAttestation page, license disclosure, and multi-format exports from one reviewed snapshot.See deliverables
- ExportsTHIRD_PARTY_LICENSES.md, NOTICE, JSON, PDF, CycloneDX, SPDX, and provenance from frozen snapshots.See export formats
- AttestationBuyer-facing pages with health scores, snapshot history, watchers, and optional custom domain.See attestation pages
- MonitoringPublish drift, license advisory, repo sync, and optional vendor-only security monitoring.See monitoring
- ProofSee how we maintain our own record: Same publish gates and import paths you get as a customer.Inspect the proof
Questions about the platform? hello@sourcetrust.dev
See the whole flow on a real project.
Create a project, import your inventory, and review it, all free. You only pay when you publish.
Unlimited members included on every project.See pricing →