Pricing
One price per product. No per-user fees, no minimums
Legal, engineering, and procurement all touch the same record, so we don't charge per head. Free until you publish. $29/mo or $299/yr per shipped product.
Per project
$25/mo per product$29/moSave $49/yr
$299 billed yearly, 14% less than paying monthly ($348).
Every project includes
- Unlimited users across your organization
- Import from your repo, lockfiles & SBOMs
- Branded attestation page with review gates
- Every export format, from one snapshot
- Repo auto-sync & publish-drift checks
- 2 watched branches (Published + Testing)
Free to build. Pay only when you publish.
Planning several products or a procurement review? Request a live walkthrough.
You control what's exposed
- Password-protect any page; invisible bot protection keeps scrapers out
- Keep attestation pages out of search engines with per-page indexing controls
- Security findings stay vendor-only. They never appear on your public page
Optional add-ons
Extra watched branch
Beyond Published + Testing, per project
$5/mo$50/yr
Custom domain
One hostname for every attestation page in your org
$49/mo$499/yr
Security monitoring
Daily OSV advisory scans, vendor-only, org-wide
$200/mo$2000/yr
On top of any project. Same monthly or yearly choice as your plan.
Free while you work
Create projects, import dependencies, and review licenses for as long as you need.
Billing starts at publish
Nothing is charged until your first publish or export download.
Swap projects freely
Archive a project to free its slot; published snapshots stay live.
01Why per project
Cheaper than rebuilding the record under pressure
Most teams only inventory third-party obligations when a deal, audit, or legal review forces it, after the scramble has already started.
- One enterprise deal delayed because nobody can produce current third-party license disclosure
- One audit week spent reconstructing attributions from lockfiles and memory
- One legal review billed by the hour for dependencies nobody documented
Open-source licenses are enforceable copyright licenses. When obligations are missed, courts have made vendors pay.
EUR 900,000
Entr'ouvert v. Orange (France, 2024)
GPL code distributed without source. Includes EUR 150,000 in moral damages.
EUR 7,500
Steck v. AVM (Germany, 2024)
An individual developer enforced LGPL obligations against a major vendor.
Real cases, not a prediction about your product. Outcomes vary by jurisdiction and the facts.
Read the enforcement recordKeeping that record current, reviewed, and published runs $299 a year per project. About $25 a month.
02What's included
Everything in each project
Ingest
- Import from repo auto-sync or SBOMs and lockfiles (CycloneDX SBOM, npm (package-lock.json), pnpm (pnpm-lock.yaml), Yarn (yarn.lock), Bun (bun.lock), and more)
- Two watched branches per project (Published + Testing)
- Flag missing license text and obligation gaps before publish
Confirm and verify
- Clear overview of every package in the project
- Auto-fetch license text and bulk-approve safe licenses
- License identity, full text, and obligations tied to each component
- Approval steps before anything goes live
Publish
- Branded attestation page per product with review gates
- Full license text, not a vague open-source paragraph
- Snapshot history, page watchers, and optional custom domain
- Multi-format exports from the same frozen snapshot
Monitor
- Publish drift visibility when inventory diverges from last snapshot
- License-version advisory on package re-licensing
- Repo auto-sync and dependency review comments
- Optional vendor-only OSV security monitoring add-on
03The billing unit
What counts as a project?
One project is one shipped product you track in SourceTrust, usually the git repo (or repos) behind it, plus its own inventory, compliance page, and exports. A single product often spans a frontend, backend, API, and workers in one record.
- SPA, backend, and API from the same codebase
- Mobile app in the App Store or Play Store
- CLI, SDK, or embedded firmware bundle
04FAQ
Questions
Can we start with one product?
Yes. There is no minimum. Start with the product under the most scrutiny, then add lines as your portfolio grows.
Do you charge per user?
No. SourceTrust includes unlimited users in your organization.
Can we use our own domain?
Yes. The add-on is $49/mo or $499/yr per organization, one fee for every compliance page in the org. Non-refundable once provisioned. See our refund policy for details.
Is this the same as publishing a vulnerability SBOM?
No. A compliance page shows license posture, confirmed licenses, full license text, and attribution duties procurement reviewers check. A raw SBOM lists component versions and is often treated as sensitive security data. SourceTrust publishes what buyers ask for in license diligence, not an attack-surface map.
When am I charged?
Creating projects, importing dependencies, and reviewing licenses is free. A project counts toward your subscription on first publish or first export download. Archive a project to free the slot.
What are watched branches?
Each connected project watches two branches by default, on GitHub, GitLab, or Azure DevOps: Published (feeds the buyer attestation page) and Testing (internal review). Extra slots beyond the two included are available as a per-project add-on.
Do you scan our projects for public vulnerabilities?
Only if you add security monitoring ($200/mo or $2000/yr per organization). It scans your dependencies for known advisories and alerts your team privately. Findings are vendor-only and never appear on the public attestation page.
Can we switch between monthly and yearly?
Yes. Change billing period from your account settings.
Do you offer invoicing or annual contracts?
Yes, for multiple products or procurement requirements. Email hello@sourcetrust.dev.
Estimate your exact total
Answer a few questions about what you ship; we'll total projects and add-ons, monthly or yearly.
Open our own license page before you buy.
It's the same deliverable you get per project: Live, maintained, and inspectable right now.