0707Proof
Inspect it. We do not ask you to trust a brochure
See how we maintain our own record: Same publish gates, import paths, and attestation page you get as a customer.
Last updated: July 2, 2026
Artifact-verified
We download what you ship and read the license inside.
Registry metadata is a claim, not proof. On every import and sync, SourceTrust fetches the exact published artifact behind each dependency, so the license on your page is the one that actually ships: The npm tarball, PyPI wheel, crate, jar, gem, or Go module.
- Bytes are verified against the registry's own digest before anything is trusted
- The LICENSE file is extracted from inside the archive, not read off a website
- Runs by itself on repo sync; one click re-verifies the whole project anytime
Six honest states
The metadata says MIT. The artifact says GPL. You hear it from us.
Every package resolves to one of six honest verification states. Nothing is rubber-stamped: When the file inside the package disagrees with the declared license, the mismatch is flagged red and the shipped file wins.
The license text matches the shipped artifact exactly.
A known license with edits; the differences are shown.
Declared one license, shipped another. The highest-value catch.
A proprietary or bespoke text that needs human judgment.
No verified text yet; the package cannot go live like this.
The artifact carries no license file at all; also worth knowing.
Git for compliance
Every publish is an immutable, content-hashed snapshot.
Publishing freezes the reviewed inventory into a snapshot with a deterministic content hash, chained to its parent like a commit. Buyers can archive the Snapshot ID; you can diff and roll back. It cannot be altered without creating a new revision.
A Snapshot ID buyers can archive
The content hash on every page is tamper-evident: Identical content re-publishes as a no-op, changed content makes a new revision.
Snapshot ID 8c42af1 · revision 12
Diff any two revisions
Added, removed, and changed packages, down to version and license changes, so you can answer what changed between the page they saw and the page today.
+3 added · -1 removed · ~2 changed
Roll back with one click
Republish any prior snapshot as a new revision. History survives; nothing is rewritten.
An append-only audit trail
Imports, approvals, publishes, sign-offs, and rollbacks are recorded, and a public-safe subset renders as the page's changelog. Good-faith diligence you can point at.
Verifiable by design
Inspect it. We do not ask you to trust a brochure
See how we maintain our own record, read the limits in our footer, and check the same publish gates and import paths you get as a customer. That is the proof your customers and auditors verify before trusting a vendor. We built this to survive diligence, not to win a slide deck.
See ours at sourcetrust.dev/license. The same attestation page you publish per product, with the same publish gates and import paths
We state plainly: Compliance infrastructure, not legal advice. And publish gates so you cannot claim obligations you have not reviewed
Import paths for real obligation sources: CycloneDX SBOM, npm (package-lock.json), pnpm (pnpm-lock.yaml), Yarn (yarn.lock), Bun (bun.lock), Go (go.mod), Rust (Cargo.lock), Python (uv.lock, poetry.lock), NuGet (packages.lock.json), Maven (pom.xml), Gradle (gradle.lockfile), Composer (composer.lock), Bundler (Gemfile.lock)
SPDX-oriented catalog with obligation and risk derivation from the license, not manual “we think it’s fine” toggles
Repo auto-sync, dual-branch workflows, and publish-drift visibility
Live proof
We publish what we sell. Open ours before you buy
No slide deck. Our maintained record at sourcetrust.dev/license is the same deliverable you get per project. See how we keep disclosure current before you buy.
- Every third-party component listed with a confirmed license
- Full license text. Not a vague “we use open source” paragraph
- Downloadable bundle for auditors and procurement
- Publish gates so you do not claim compliance you have not reviewed
What compliance looks like
Each product gets a reviewed record of third-party obligations. What’s in the build, under what terms, and whether notice and attribution duties are met.
- Public compliance page with full license text
- Attribution and disclosure exports for releases
- Drift flags when dependencies or licenses change
Our license page (hosted on sourcetrust.dev)
Live page from this domain, open it before you buy.
Open our license pageContinue reading
Related topics
One idea per page: Follow the path that matches your next question.
Stop shipping on assumptions
Map your obligations before the next release
Set up a project for each repo, review your obligations, publish when ready, and keep the record aligned with every release. Download license and attribution files when engineering needs them, with pipeline checks so the next update does not undo what you already approved. Your SOC report is not a substitute.
Not ready to start yet? View pricing