Skip to main content

0507Attestation

What license attestation is (and why buyers ask for it)

A branded public page that shows reviewed third-party licenses for a shipped product. Health scores, snapshot history, page watchers, and optional custom domain, built for procurement reviewers.

Last updated: July 19, 2026

Attestation pages

A link you paste into the questionnaire, not a PDF you rebuild

Enterprise procurement wants a link they can paste into a security questionnaire, not a PDF someone rebuilt last quarter. Each project publishes a branded, server-rendered attestation page with approved packages and full license text.

  • Shareable URL per product

    Each published project gets a stable public URL with approved packages, confirmed licenses, and complete license text. Designed for procurement reviewers with fifteen minutes and a checklist, not developers reading raw manifests.

    Paste the link in your RFP response instead of scheduling another diligence call.

  • Compliance health score

    A procurement-friendly completeness meter shows how much of the inventory is reviewed and publishable. Buyers see confidence at a glance; your team sees what still blocks publish.

  • Immutable snapshot history

    Every publish creates a frozen revision. Compare snapshots, see what changed since the last publish, and keep archived attestation pages live forever: Buyers bookmark a URL that stays valid.

  • Page watchers for buyers

    Procurement contacts can subscribe to revision updates by email. When you republish after a dependency change, subscribers get notified: An engagement loop that keeps proof current without manual outreach.

  • Branding and custom domain

    Default pages live at sourcetrust.app/acme/platform-style URLs: Your organization, then the project. The optional custom domain add-on ($49/mo or $499/yr per organization) serves every project at your hostname, like licenses.yourcompany.com/platform.

  • Trust signals

    Optional password gate with bot protection, publisher signatures on snapshots, and a SourceTrust trust seal on public pages. Deliberately not a raw SBOM: License posture and attribution, not an attack-surface map.

What buyers do not see

Attestation pages publish the legal and compliance subset: Component identity, license posture, notices, and attributions. They deliberately omit version-exact detail that would help attackers cross-reference known vulnerabilities.

Optional security monitoring ($200/mo or $2000/yr per organization) scans for OSV advisories on your side only, findings never appear on the public page.

What is license attestation?

License attestation is a maintained, buyer-facing record that a specific product ships with reviewed third-party licenses and obligations. It is not a marketing claim and not a raw SBOM dump. It is the page procurement opens when they ask for proof.

Automation helps when the page is tied to import, review gates, and frozen publish snapshots. Without that loop, attestation goes stale the moment dependencies change.

Why do buyers ask for an attestation page?

Because questionnaires and diligence checklists need a stable URL they can reopen later. A PDF emailed once does not update when your lockfile does. A reviewed page with snapshot history does.

How is attestation different from a scanner report?

Scanner reports help your team find issues. Attestation is the controlled subset you are willing to represent externally: component identity, license posture, notices, and attributions, after human review.

For the person who receives the link

The one-screen answer procurement is scanning for.

The first thing on every page is what a vendor reviewer actually needs: A conservative copyleft verdict, a letter grade they can paste into a risk dashboard, and a named human who signed the review. Readable in minutes, not a PDF to decode.

  • Copyleft verdict computed worst-case: A reviewer must never see No copyleft on a page that ships GPL
  • A to D health grade with a 0 to 100 score: License coverage, publish freshness, review recency
  • Reviewed by a human: A named signature with title and date, required org-wide if you choose
  • View analytics show you which buyers are actually reading the page
For the person who receives the link

Your page, your rules

White-label it, gate it, or take it off Google. You decide.

The page must not look or behave like a third-party tool. Brand it, serve it from your own domain, and control exactly who can read it.

  • Your brand, one token

    A hex brand color drives the top border, links, and accents; drop in a logo or keep the monogram. The recolor applies live.

  • Your domain, automatic TLS

    Serve every page from your own hostname with a per-provider DNS guide and a Check DNS button. Up to ten hostnames per organization.

    licenses.acme.com/platform

  • Password plus invisible bot protection

    Gate any page behind a shared password with an invisible Turnstile check. Readable for a procurement reviewer, closed to crawlers, and forced noindex.

  • Preview before anyone sees it

    An authenticated preview renders the real page from your current inventory behind a Preview, not published banner. Built from the same component as the live page, so it can never drift.

  • A company index that grows with you

    Your org root lists every published page with revision and package counts. Toggle it off if you'd rather not.

    sourcetrust.app/acme

  • QR code and a holographic seal

    Every page carries a verifiable seal with the Snapshot ID, and exports a QR code for slide decks, packaging, and vendor portals.

Stop shipping on assumptions

Map your obligations before the next release

Set up a project for each repo, review your obligations, publish when ready, and keep the record aligned with every release. Download license and attribution files when engineering needs them, with pipeline checks so the next update does not undo what you already approved. Your SOC report is not a substitute.

Not ready to start yet? View pricing

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.