Skip to main content

0707Proof

Inspect it. We do not ask you to trust a brochure

See how we maintain our own record: Same publish gates, import paths, and attestation page you get as a customer.

Last updated: July 2, 2026

Artifact-verified

We download what you ship and read the license inside.

Registry metadata is a claim, not proof. On every import and sync, SourceTrust fetches the exact published artifact behind each dependency, so the license on your page is the one that actually ships: The npm tarball, PyPI wheel, crate, jar, gem, or Go module.

  • Bytes are verified against the registry's own digest before anything is trusted
  • The LICENSE file is extracted from inside the archive, not read off a website
  • Runs by itself on repo sync; one click re-verifies the whole project anytime
Artifact-verified

Six honest states

The metadata says MIT. The artifact says GPL. You hear it from us.

Every package resolves to one of six honest verification states. Nothing is rubber-stamped: When the file inside the package disagrees with the declared license, the mismatch is flagged red and the shipped file wins.

Verified

The license text matches the shipped artifact exactly.

Modified

A known license with edits; the differences are shown.

Mismatch

Declared one license, shipped another. The highest-value catch.

Custom

A proprietary or bespoke text that needs human judgment.

Unconfirmed

No verified text yet; the package cannot go live like this.

Not found

The artifact carries no license file at all; also worth knowing.

Git for compliance

Every publish is an immutable, content-hashed snapshot.

Publishing freezes the reviewed inventory into a snapshot with a deterministic content hash, chained to its parent like a commit. Buyers can archive the Snapshot ID; you can diff and roll back. It cannot be altered without creating a new revision.

  • A Snapshot ID buyers can archive

    The content hash on every page is tamper-evident: Identical content re-publishes as a no-op, changed content makes a new revision.

    Snapshot ID 8c42af1 · revision 12

  • Diff any two revisions

    Added, removed, and changed packages, down to version and license changes, so you can answer what changed between the page they saw and the page today.

    +3 added · -1 removed · ~2 changed

  • Roll back with one click

    Republish any prior snapshot as a new revision. History survives; nothing is rewritten.

  • An append-only audit trail

    Imports, approvals, publishes, sign-offs, and rollbacks are recorded, and a public-safe subset renders as the page's changelog. Good-faith diligence you can point at.

Verifiable by design

Inspect it. We do not ask you to trust a brochure

See how we maintain our own record, read the limits in our footer, and check the same publish gates and import paths you get as a customer. That is the proof your customers and auditors verify before trusting a vendor. We built this to survive diligence, not to win a slide deck.

  • See ours at sourcetrust.dev/license. The same attestation page you publish per product, with the same publish gates and import paths

  • We state plainly: Compliance infrastructure, not legal advice. And publish gates so you cannot claim obligations you have not reviewed

  • Import paths for real obligation sources: CycloneDX SBOM, npm (package-lock.json), pnpm (pnpm-lock.yaml), Yarn (yarn.lock), Bun (bun.lock), Go (go.mod), Rust (Cargo.lock), Python (uv.lock, poetry.lock), NuGet (packages.lock.json), Maven (pom.xml), Gradle (gradle.lockfile), Composer (composer.lock), Bundler (Gemfile.lock)

  • SPDX-oriented catalog with obligation and risk derivation from the license, not manual “we think it’s fine” toggles

  • Repo auto-sync, dual-branch workflows, and publish-drift visibility

Live proof

We publish what we sell. Open ours before you buy

No slide deck. Our maintained record at sourcetrust.dev/license is the same deliverable you get per project. See how we keep disclosure current before you buy.

  • Every third-party component listed with a confirmed license
  • Full license text. Not a vague “we use open source” paragraph
  • Downloadable bundle for auditors and procurement
  • Publish gates so you do not claim compliance you have not reviewed

What compliance looks like

Each product gets a reviewed record of third-party obligations. What’s in the build, under what terms, and whether notice and attribution duties are met.

  • Public compliance page with full license text
  • Attribution and disclosure exports for releases
  • Drift flags when dependencies or licenses change

Our license page (hosted on sourcetrust.dev)

sourcetrust.dev/license

Live page from this domain, open it before you buy.

Open our license page

Stop shipping on assumptions

Map your obligations before the next release

Set up a project for each repo, review your obligations, publish when ready, and keep the record aligned with every release. Download license and attribution files when engineering needs them, with pipeline checks so the next update does not undo what you already approved. Your SOC report is not a substitute.

Not ready to start yet? View pricing

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.