Skip to main content

Pricing

One price per product. No per-user fees, no minimums

Legal, engineering, and procurement all touch the same record, so we don't charge per head. Free until you publish. $29/mo or $299/yr per shipped product.

SourceTrust · Pricing

Per project

$25/mo per product$29/moSave $49/yr

$299 billed yearly, 14% less than paying monthly ($348).

Every project includes

  • Unlimited users across your organization
  • Import from your repo, lockfiles & SBOMs
  • Branded attestation page with review gates
  • Every export format, from one snapshot
  • Repo auto-sync & publish-drift checks
  • 2 watched branches (Published + Testing)

Free to build. Pay only when you publish.

Start for free

Planning several products or a procurement review? Request a live walkthrough.

You control what's exposed

  • Password-protect any page; invisible bot protection keeps scrapers out
  • Keep attestation pages out of search engines with per-page indexing controls
  • Security findings stay vendor-only. They never appear on your public page
How attestation pages stay yours

Optional add-ons

  • Extra watched branch

    Beyond Published + Testing, per project

    $5/mo$50/yr

  • Custom domain

    One hostname for every attestation page in your org

    $49/mo$499/yr

  • Security monitoring

    Daily OSV advisory scans, vendor-only, org-wide

    $200/mo$2000/yr

On top of any project. Same monthly or yearly choice as your plan.

Free while you work

Create projects, import dependencies, and review licenses for as long as you need.

Billing starts at publish

Nothing is charged until your first publish or export download.

Swap projects freely

Archive a project to free its slot; published snapshots stay live.

01Why per project

Cheaper than rebuilding the record under pressure

Most teams only inventory third-party obligations when a deal, audit, or legal review forces it, after the scramble has already started.

The manual alternative
  • One enterprise deal delayed because nobody can produce current third-party license disclosure
  • One audit week spent reconstructing attributions from lockfiles and memory
  • One legal review billed by the hour for dependencies nobody documented
The enforcement record

Open-source licenses are enforceable copyright licenses. When obligations are missed, courts have made vendors pay.

EUR 900,000

Entr'ouvert v. Orange (France, 2024)

GPL code distributed without source. Includes EUR 150,000 in moral damages.

EUR 7,500

Steck v. AVM (Germany, 2024)

An individual developer enforced LGPL obligations against a major vendor.

Real cases, not a prediction about your product. Outcomes vary by jurisdiction and the facts.

Read the enforcement record

Keeping that record current, reviewed, and published runs $299 a year per project. About $25 a month.

02What's included

Everything in each project

Ingest

  • Import from repo auto-sync or SBOMs and lockfiles (CycloneDX SBOM, npm (package-lock.json), pnpm (pnpm-lock.yaml), Yarn (yarn.lock), Bun (bun.lock), and more)
  • Two watched branches per project (Published + Testing)
  • Flag missing license text and obligation gaps before publish

Confirm and verify

  • Clear overview of every package in the project
  • Auto-fetch license text and bulk-approve safe licenses
  • License identity, full text, and obligations tied to each component
  • Approval steps before anything goes live

Publish

  • Branded attestation page per product with review gates
  • Full license text, not a vague open-source paragraph
  • Snapshot history, page watchers, and optional custom domain
  • Multi-format exports from the same frozen snapshot

Monitor

  • Publish drift visibility when inventory diverges from last snapshot
  • License-version advisory on package re-licensing
  • Repo auto-sync and dependency review comments
  • Optional vendor-only OSV security monitoring add-on

03The billing unit

What counts as a project?

One project is one shipped product you track in SourceTrust, usually the git repo (or repos) behind it, plus its own inventory, compliance page, and exports. A single product often spans a frontend, backend, API, and workers in one record.

  • SPA, backend, and API from the same codebase
  • Mobile app in the App Store or Play Store
  • CLI, SDK, or embedded firmware bundle

04FAQ

Questions

Can we start with one product?

Yes. There is no minimum. Start with the product under the most scrutiny, then add lines as your portfolio grows.

Do you charge per user?

No. SourceTrust includes unlimited users in your organization.

Can we use our own domain?

Yes. The add-on is $49/mo or $499/yr per organization, one fee for every compliance page in the org. Non-refundable once provisioned. See our refund policy for details.

Is this the same as publishing a vulnerability SBOM?

No. A compliance page shows license posture, confirmed licenses, full license text, and attribution duties procurement reviewers check. A raw SBOM lists component versions and is often treated as sensitive security data. SourceTrust publishes what buyers ask for in license diligence, not an attack-surface map.

When am I charged?

Creating projects, importing dependencies, and reviewing licenses is free. A project counts toward your subscription on first publish or first export download. Archive a project to free the slot.

What are watched branches?

Each connected project watches two branches by default, on GitHub, GitLab, or Azure DevOps: Published (feeds the buyer attestation page) and Testing (internal review). Extra slots beyond the two included are available as a per-project add-on.

Do you scan our projects for public vulnerabilities?

Only if you add security monitoring ($200/mo or $2000/yr per organization). It scans your dependencies for known advisories and alerts your team privately. Findings are vendor-only and never appear on the public attestation page.

Can we switch between monthly and yearly?

Yes. Change billing period from your account settings.

Do you offer invoicing or annual contracts?

Yes, for multiple products or procurement requirements. Email hello@sourcetrust.dev.

Estimate your exact total

Answer a few questions about what you ship; we'll total projects and add-ons, monthly or yearly.

Find your price

Open our own license page before you buy.

It's the same deliverable you get per project: Live, maintained, and inspectable right now.

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.