Skip to main content

Proof

See our own license record.

Inspect the records we publish for SourceTrust, using the same workflow available to your team.

Live proof

Open our live license record.

No slide deck. Our maintained record at sourcetrust.dev/license is the same deliverable you get per project. See how we keep disclosure current before you buy.

  • Every third-party component listed with a confirmed license
  • Full license text. Not a vague “we use open source” paragraph
  • Downloadable bundle for auditors and procurement
  • Publish gates so you do not claim compliance you have not reviewed
Our license page (hosted on sourcetrust.dev)
sourcetrust.dev/license

Live page from this domain, open it before you buy.

Open our license page

Artifact-verified

We verify the file that ships.

Registry metadata is a claim, not proof. On every import and sync, SourceTrust fetches the exact published artifact behind each dependency, so the license on your page is the one that actually ships: The npm tarball, PyPI wheel, crate, jar, gem, or Go module.

  1. Bytes are verified against the registry's own digest before anything is trusted

  2. The LICENSE file is extracted from inside the archive, not read off a website

  3. Runs by itself on repo sync; one click re-verifies the whole project anytime

Six honest states

Six states. Mismatches stay visible.

Every package resolves to one of six honest verification states. Nothing is rubber-stamped: When the file inside the package disagrees with the declared license, the mismatch is flagged red and the shipped file wins.

  • Verified

    The license text matches the shipped artifact exactly.

  • Modified

    A known license with edits; the differences are shown.

  • Mismatch

    Declared one license, shipped another. The highest-value catch.

  • Custom

    A proprietary or bespoke text that needs human judgment.

  • Unconfirmed

    No verified text yet; the package cannot go live like this.

  • Not found

    The artifact carries no license file at all; also worth knowing.

Git for compliance

Every publish creates a frozen revision.

Publishing freezes the reviewed inventory into a snapshot with a deterministic content hash, chained to its parent like a commit. Buyers can archive the Snapshot ID; you can diff and roll back. It cannot be altered without creating a new revision.

Roll back with one click

Republish any prior snapshot as a new revision. History survives; nothing is rewritten.

An append-only audit trail

Imports, approvals, publishes, sign-offs, and rollbacks are recorded, and a public-safe subset renders as the page's changelog. Good-faith diligence you can point at.

Illustrative example

A Snapshot ID buyers can archive

Snapshot ID 8c42af1 · revision 12

The content hash on every page is tamper-evident: Identical content re-publishes as a no-op, changed content makes a new revision.

Diff any two revisions

+3 added · -1 removed · ~2 changed

Added, removed, and changed packages, down to version and license changes, so you can answer what changed between the page they saw and the page today.

Start with the files you already have.

Free to import and review. No credit card needed.

Start for free

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.