SourceTrust
Public proof that your software's open-source licenses are in order. SourceTrust turns the dependency list you already have into a reviewed, public compliance page: every open-source package you ship, its license, and what you did about each obligation.
Almost every software product is built on open-source packages. Each package comes with a license, and most licenses ask for something in return: keep the copyright notice, include the license text, or share your changes. When a customer's procurement or legal team reviews a vendor, they increasingly ask for proof that this is handled and kept up to date. SourceTrust makes that proof simple to produce and simple to read. Import the dependency file you already have (lockfiles for JavaScript, Python, Java, Go, Rust, .NET, Ruby, PHP, Swift and Dart, or a CycloneDX or SPDX SBOM).
- Category
- Developer Tools
- EU hosting
- EU region available
- HQ
- Denmark
- Pricing
- Freemium, Creating projects, importing and reviewing is free. Eligible public GitHub repositories publish their page for $0. Paid: $29 per project per month or $299 per year, with no per-user fees. Custom domain add-on $49/mo or $499/yr.
- Import lockfiles and SBOMs: 17 formats across JavaScript, Python, Java, Go, Rust, .NET, Ruby, PHP, Swift, Dart, CycloneDX and SPDX
- Every package listed with its license and a plain-language explanation of what that license asks
- Review each obligation, then publish a branded public attestation page anyone can read without a login
- Connect a GitHub repository and imports run automatically
- Publish on your own URL or a custom domain
- Exports in CycloneDX, SPDX, NOTICE, CSV, JSON, HTML, Markdown and PDF
This tool has no MCP server (yet).
