Proof
See our own license record.
Inspect the records we publish for SourceTrust, using the same workflow available to your team.
Live proof
Open our live license record.
No slide deck. Our maintained record at sourcetrust.dev/license is the same deliverable you get per project. See how we keep disclosure current before you buy.
- Every third-party component listed with a confirmed license
- Full license text. Not a vague “we use open source” paragraph
- Downloadable bundle for auditors and procurement
- Publish gates so you do not claim compliance you have not reviewed
Live page from this domain, open it before you buy.
Open our license pageArtifact-verified
We verify the file that ships.
Registry metadata is a claim, not proof. On every import and sync, SourceTrust fetches the exact published artifact behind each dependency, so the license on your page is the one that actually ships: The npm tarball, PyPI wheel, crate, jar, gem, or Go module.
Bytes are verified against the registry's own digest before anything is trusted
The LICENSE file is extracted from inside the archive, not read off a website
Runs by itself on repo sync; one click re-verifies the whole project anytime
Six honest states
Six states. Mismatches stay visible.
Every package resolves to one of six honest verification states. Nothing is rubber-stamped: When the file inside the package disagrees with the declared license, the mismatch is flagged red and the shipped file wins.
Verified
The license text matches the shipped artifact exactly.
Modified
A known license with edits; the differences are shown.
Mismatch
Declared one license, shipped another. The highest-value catch.
Custom
A proprietary or bespoke text that needs human judgment.
Unconfirmed
No verified text yet; the package cannot go live like this.
Not found
The artifact carries no license file at all; also worth knowing.
Git for compliance
Every publish creates a frozen revision.
Publishing freezes the reviewed inventory into a snapshot with a deterministic content hash, chained to its parent like a commit. Buyers can archive the Snapshot ID; you can diff and roll back. It cannot be altered without creating a new revision.
Roll back with one click
Republish any prior snapshot as a new revision. History survives; nothing is rewritten.
An append-only audit trail
Imports, approvals, publishes, sign-offs, and rollbacks are recorded, and a public-safe subset renders as the page's changelog. Good-faith diligence you can point at.
A Snapshot ID buyers can archive
Snapshot ID 8c42af1 · revision 12The content hash on every page is tamper-evident: Identical content re-publishes as a no-op, changed content makes a new revision.
Diff any two revisions
+3 added · -1 removed · ~2 changedAdded, removed, and changed packages, down to version and license changes, so you can answer what changed between the page they saw and the page today.
Start with the files you already have.
Free to import and review. No credit card needed.
