Skip to main content

The product

One controlled path from what you ship to proof you can send

Import, review, publish, and stay current, each step gated so the page you publish always matches what actually ships. Here's the whole thing.

Nothing is publishable until it's confirmed. Copyleft and missing-notice flags come from a 700+ license catalog, not a “we think it's fine” toggle. How a review actually runs →

Want to walk through this with us? Request a live walkthrough →

01Inputs

It reads what you already generate.

Connect a repo and the inventory follows every push. No new CI pipeline, no second scanner to configure.

Or bring the files you already have:

  • package-lock.json
  • pnpm-lock.yaml
  • yarn.lock
  • bun.lock
  • go.mod
  • Cargo.lock
  • + more

14 formats across 9 ecosystems, including CycloneDX SBOM uploads.

acme/platformConnected
main · Publisheddevelop · Testing
  • Auto-synced on push · 3 hours ago
  • 4 dependencies added, 1 removed
  • Dependency comment posted on #482

Pull request and merge request comments are informational only, nothing gates your merge. SourceTrust reads lockfiles and SBOMs, never your source code.

02Stay current

You'll know the page is stale before your customer does.

When live inventory drifts from your last published snapshot, the project flags it. License-version advisory warns loudly when a package relicenses. Optional security monitoring watches OSV advisories for your team only: Findings never appear on the public page.

  • The dashboard banner and status pills name exactly what moved since the published revision
  • A Changes tab lists added, updated, and removed packages, so the fix is a review, not an investigation
  • One click republishes, and publish on merge can close the loop without you

How drift detection works

03You control what's exposed

Every exposure control

Publishing proof doesn't mean publishing everything.

The number one worry about a public compliance page is exposure. Every layer of it is in your hands.

  • Password-protect any page; invisible bot protection keeps scrapers out
  • Per-page indexing controls keep pages out of search engines
  • Lockfiles are parsed in your browser before upload
  • Vulnerability findings stay vendor-only, never on the public page
  • Read-only viewer and finance roles, enterprise SSO, and optional two-factor auth
  • Team review notes are internal and never rendered publicly

One frozen snapshot. Every format diligence asks for.

The hosted page and every export are generated from the same approved snapshot, with provenance and the public URL baked in. They can't disagree.

  • /acme/platform

    Hosted attestation page

    Branded, immutable snapshots with revision history. Optional custom domain.

  • NOTICE

    Attribution files

    THIRD_PARTY_LICENSES.md and NOTICE for what ships in the artifact.

  • SPDX

    Machine-readable

    CycloneDX, SPDX, JSON, CSV and plist for tooling and portals.

  • PDF

    Branded PDF

    A clean disclosure document to attach to any questionnaire.

See the whole flow on a real project.

Create a project, import your inventory, and review it, all free. You only pay when you publish.

Unlimited members included on every project.See pricing →

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.