Skip to main content

Attestation

Give buyers a clear license record.

Share a branded page with reviewed licenses, snapshot history and the details your buyers need.

For the person who receives the link

What buyers see first.

License attestation is a maintained, buyer-facing record that a specific product ships with reviewed third-party licenses and obligations. It is not a marketing claim and not a raw SBOM dump. It is the page procurement opens when they ask for proof.

  • Copyleft verdict computed worst-case: A reviewer must never see No copyleft on a page that ships GPL

  • A to D health grade with a 0 to 100 score: License coverage, publish freshness, review recency

  • Reviewed by a human: A named signature with title and date, required org-wide if you choose

Compliance health score

A procurement-friendly completeness meter shows how much of the inventory is reviewed and publishable. Buyers see confidence at a glance; your team sees what still blocks publish.

Illustrative example

Attestation pages

A link buyers can reopen.

Shareable URL per product

Each published project gets a stable public URL with approved packages, confirmed licenses, and complete license text. Designed for procurement reviewers with fifteen minutes and a checklist, not developers reading raw manifests.

Immutable snapshot history

Every publish creates a frozen revision. Compare snapshots, see what changed since the last publish, and keep archived attestation pages live forever: Buyers bookmark a URL that stays valid.

Page watchers for buyers

Procurement contacts can subscribe to revision updates by email. When you republish after a dependency change, subscribers get notified: An engagement loop that keeps proof current without manual outreach.

View analytics show you which buyers are actually reading the page

Your page, your rules

Brand it. Gate it. Keep control.

Your brand, one token

A hex brand color drives the top border, links, and accents; drop in a logo or keep the monogram. The recolor applies live.

Your domain, automatic TLS

Serve every page from your own hostname with a per-provider DNS guide and a Check DNS button. Up to ten hostnames per organization.

Password plus invisible bot protection

Gate any page behind a shared password with an invisible Turnstile check. Readable for a procurement reviewer, closed to crawlers, and forced noindex.

Branding and custom domain

Default pages live at sourcetrust.app/acme/platform-style URLs: Your organization, then the project. The optional custom domain add-on ($49/mo or $499/yr per organization) serves every project at your hostname, like licenses.yourcompany.com/platform.

Preview before anyone sees it

An authenticated preview renders the real page from your current inventory behind a Preview, not published banner. Built from the same component as the live page, so it can never drift.

A company index that grows with you

Your org root lists every published page with revision and package counts. Toggle it off if you'd rather not.

sourcetrust.app/acme
QR code and a holographic seal

Every page carries a verifiable seal with the Snapshot ID, and exports a QR code for slide decks, packaging, and vendor portals.

Attestation pages

Attestation details

What is license attestation?

License attestation is a maintained, buyer-facing record that a specific product ships with reviewed third-party licenses and obligations. It is not a marketing claim and not a raw SBOM dump. It is the page procurement opens when they ask for proof.

Automation helps when the page is tied to import, review gates, and frozen publish snapshots. Without that loop, attestation goes stale the moment dependencies change.

Why do buyers ask for an attestation page?

Because questionnaires and diligence checklists need a stable URL they can reopen later. A PDF emailed once does not update when your lockfile does. A reviewed page with snapshot history does.

How is attestation different from a scanner report?

Scanner reports help your team find issues. Attestation is the controlled subset you are willing to represent externally: component identity, license posture, notices, and attributions, after human review.

Start with the files you already have.

Free to import and review. No credit card needed.

Start for free

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.