PROVEN OUTCOMES
Independent · buyer-side · paid only by you · every engagement confidential. See all case studies →
WHAT WE DO
We map every open source dependency you run and the license state of each one.
We size the exposure and the cost to cure, in terms your board will recognize.
We contain the risk and reroute to safe alternatives or negotiated terms.
Explore the full set of engagements on our open source license risk advisory services, or start with a confidential risk assessment.
WHY INDEPENDENT
We are paid only by you. The advice you receive is the advice you need, not the product someone needs to sell.
THE RED GIANTS
The largest nodes in the network. Each carries a license that has already changed.
HOW WE WORK
buyer side. Paid only by you.
vendor fees or reseller margins
the license families we map cold
Engagement figures are confidential. We map, quantify, and contain exposure across the relicensing wave.
BROWSE BY TOPIC
Every guide on this site lives in one of eight topic hubs. Start with the hub closest to your exposure, or start with the research.
Open source license risk
What the risk is, where it hides in your estate, and how to assess it before it becomes a finding.
28 GUIDESLicense change & relicensing
BSL, SSPL, and the relicensing wave: how a license change reaches software you already run.
23 GUIDESHashiCorp & Terraform licensing
The move to the BSL, what it means for Terraform users, and the options you actually have.
26 GUIDESRedis, Elastic & database relicensing
The database license changes explained, deployment by deployment.
20 GUIDESCommercial open source licensing
When a commercial license is the answer and how to negotiate it from the buyer side.
24 GUIDESRemediation & alternatives
Forks, migrations, and safe paths off relicensed projects.
16 GUIDESM&A open source compliance
Finding and pricing open source exposure before the deal closes.
18 GUIDESOpen source governance & SBOM
Policies, approval gates, and dependency visibility that prevent the next surprise.
DATA STUDY · 2026State of Relicensing Exposure 2026
Our research study: how far the relicensing wave reaches into enterprise estates, with the numbers.
COMMON QUESTIONS
Open source license risk is the exposure an enterprise carries when software it runs in production changes its license terms. When a project relicenses from an open source license to a source available license such as the Business Source License or the Server Side Public License, competitive use restrictions, copyleft obligations and commercial license demands can apply to software already running in your environment.
HashiCorp moved Terraform, Vault, Consul, Nomad and Packer to the Business Source License as of August 2023. Redis moved to a dual Redis Source Available License and Server Side Public License model as of March 2024. Elasticsearch and Kibana moved to the SSPL and the Elastic License as of 2021. MongoDB moved to the SSPL in 2018. Confirm current terms with your own counsel.
No. Source available is not the same as open source. The Server Side Public License and the Business Source License are not OSI approved open source licenses. The source may be readable, but the terms restrict competitive production use and can carry distribution and commercial obligations that open source licenses do not.
Start by mapping every open source dependency you run and the current license state of each one, including transitive dependencies layers down in the tree. Then quantify the exposure and the cost to cure, and contain it by rerouting to safe alternatives or negotiating commercial terms. A confidential open source license risk assessment maps this blast radius for you.
No. We provide commercial and licensing risk advisory, not legal advice. We map exposure and quantify cost from the buyer side. For interpretation of license terms and compliance questions, we always recommend you engage your own counsel.
CONTAINMENT
A confidential open source license risk assessment.
INDEPENDENT. BUYER SIDE. PAID ONLY BY YOU.