Bring imports, license evidence and approvals into one workflow. Publish the reviewed record and keep it current.
Review gate
LICENSEEvidence found
→
Human reviewObligations resolved
→
Approved
Import
Inventory what creates obligations
Import from GitHub, GitLab, or Azure DevOps auto-sync, or 10+ lockfile and SBOM formats
Every import classifies packages as new, updated, or unchanged first, so you see exactly what will land.
Learn more
Import from repo auto-sync or upload CycloneDX SBOM, npm (package-lock.json), pnpm (pnpm-lock.yaml), Yarn (yarn.lock), Bun (bun.lock), Go (go.mod), Rust (Cargo.lock), Python (uv.lock, poetry.lock), NuGet (packages.lock.json), Maven (pom.xml), Gradle (gradle.lockfile), Composer (composer.lock), Bundler (Gemfile.lock). Each row is a license you must satisfy. Add fonts, icons, SDKs, and manual entries automated imports miss. Nothing is “done” until a human confirms the license; imports start as needs review.
Set SaaS, binary, or library context. SourceTrust surfaces the license risks that apply.
This choice is not cosmetic. It changes which compatibility warnings and license obligations appear.
What the engine checks
You declare how the product is distributed: Hosted service, shipped binary, library, or a mix. That choice changes which compatibility warnings and obligations appear, because AGPL in a SaaS backend is a different legal question than AGPL in an internal tool.
Warnings only for patterns that have caused real disputes: AGPL and SSPL in SaaS, GPL in shipped binaries, BUSL, Elastic 2.0 in managed services, OFL fonts
Deduplicated: Twenty AGPL packages produce one warning, not twenty
Re-licensing watch: Flags dependencies pinned inside known license-change windows, like Redis to AGPL or HashiCorp to BUSL
Illustrative exampleLicense intelligence
Distribution contextSaaS
queue-workerAGPL-3.0
AGPL package in your hosted service
Review the AGPL network clause before this package goes live.
Keep license and copyright notices
Guided review
Clear safe packages. Review the exceptions.
Safe, verified packages clear in bulk. The rest stay gated until the license, text, and obligations are resolved.
Auto-approve safe defaults
One click clears every permissive package with verified text and no open obligations, and says exactly why it skipped the rest.
A wizard for the rest
One package at a time with a progress bar and Approve, Skip, or Park. Each shows a plain-language situation card: What the system saw, and the single next action.
Obligations become checkboxes
License law splits into notices we render for you and the manual steps only your team can take, each with a what-this-means-for-you explainer. The Publish button stays gated until they're ticked.
Review obligations per package
Match SPDX-style licenses, not raw manifest strings. Auto-fetch license text, bulk-approve safe licenses, and surface copyleft and distribution risk from the catalog. Full license text is required before publish for notice-bearing terms. External duties must be acknowledged or publish is blocked.
Illustrative examplePackages
Auto-approved 138 packages.
4 packages need attention.
charting-libGPL-3.0
Needs review
LicenseConfirmed as GPL-3.0
License textAuto-fetched by the system
Offer the corresponding source
Share the source if you ship this package to customers.
Check off the manual steps.
Publish
Publish an attestation page per project
Each project gets a branded public attestation page from reviewed inventory; link from docs, trust centers, and RFP responses. Only approved packages with complete license text appear. Publish is blocked until your team has verified what you represent.
Every component on this page passed Acme Inc's review: license confirmed, license text on file, obligations acknowledged.
Revision01
Download compliant files when you need them
Generate disclosure, NOTICE, JSON, PDF, CycloneDX, and SPDX exports from the same frozen snapshot as the live page. Download into repos, attach to releases, or archive for audits. Exports include provenance and the public URL when published.
NOTICEJSONPDFCycloneDXSPDX
Govern obligations across products
Org-wide compliance dashboard, cross-project inventory search, and audit trail for compliance-relevant changes. Published vs Testing branch lanes for connected projects. License catalog maintained without redeploy.
OrganizationProject (one per shipped product)
Each project’s page and exports describe that product only. Obligations do not bleed across projects.
We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.