OpenSource Risk Experts
Get a free exposure review

OPEN SOURCE LICENSE RISK

The software you depend on can change the rules overnight.

Open source license risk is real. Open licenses are quietly becoming source available, and the terms you adopted may not be the terms you run today.

Independent, buyer-side license-risk advisory for enterprises running Terraform, Redis, Elastic and other relicensed software — we map your exposure and show you the cheapest clean path.

Get a free exposure review

SCROLL. ONE NODE IS ABOUT TO FLIP.

THE RELICENSE EVENT

When an open source project relicenses, the risk propagates to everything you built on it.

HashiCorp moved Terraform to the Business Source License. As of August 2023.

Redis moved to the SSPL and the RSALv2. As of March 2024.

Elasticsearch and Kibana moved to the SSPL. As of 2021.

THE HIDDEN EXPOSURE

Most enterprises have never mapped their blast radius.

So the exposure stays invisible until a vendor or an auditor finds it first. The red is already in your tree, buried layers down.

CONTAINMENT

We draw the boundary. The spread stops at the line.

Risk is isolated. Safe paths reroute around the contained zone, and you regain control of your own dependencies.

Get a free exposure review

A confidential open source license risk assessment.

PROVEN OUTCOMES

What an independent, buyer-side review delivers.

USD 1.4M
commercial surprise avoided
71%
saved by forking instead of paying
38%
off Redis Enterprise, negotiated
40 teams
Terraform BSL exposure mapped

Independent · buyer-side · paid only by you · every engagement confidential. See all case studies →

WHAT WE DO

Assess. Quantify. Remediate.

Assess

We map every open source dependency you run and the license state of each one.

Quantify

We size the exposure and the cost to cure, in terms your board will recognize.

Remediate

We contain the risk and reroute to safe alternatives or negotiated terms.

Explore the full set of engagements on our open source license risk advisory services, or start with a confidential risk assessment.

WHY INDEPENDENT

No vendor. No reseller. No incentive but yours.

We are paid only by you. The advice you receive is the advice you need, not the product someone needs to sell.

THE RED GIANTS

The projects driving the risk.

The largest nodes in the network. Each carries a license that has already changed.

BSL

HashiCorp

Terraform and the HashiCorp stack moved to the Business Source License. As of August 2023.

SSPL

Redis

Redis moved to the SSPL and the RSALv2. As of March 2024.

SSPL

Elastic

Elasticsearch and Kibana moved to the SSPL. As of 2021.

SSPL

MongoDB

MongoDB moved to the SSPL. As of 2018.

HOW WE WORK

Independent by design, on every engagement.

100%

buyer side. Paid only by you.

0

vendor fees or reseller margins

BSL·SSPL·AGPL

the license families we map cold

Engagement figures are confidential. We map, quantify, and contain exposure across the relicensing wave.

BROWSE BY TOPIC

Open source license risk, mapped topic by topic.

Every guide on this site lives in one of eight topic hubs. Start with the hub closest to your exposure, or start with the research.

24 GUIDES

Open source license risk

What the risk is, where it hides in your estate, and how to assess it before it becomes a finding.

28 GUIDES

License change & relicensing

BSL, SSPL, and the relicensing wave: how a license change reaches software you already run.

23 GUIDES

HashiCorp & Terraform licensing

The move to the BSL, what it means for Terraform users, and the options you actually have.

26 GUIDES

Redis, Elastic & database relicensing

The database license changes explained, deployment by deployment.

20 GUIDES

Commercial open source licensing

When a commercial license is the answer and how to negotiate it from the buyer side.

24 GUIDES

Remediation & alternatives

Forks, migrations, and safe paths off relicensed projects.

16 GUIDES

M&A open source compliance

Finding and pricing open source exposure before the deal closes.

18 GUIDES

Open source governance & SBOM

Policies, approval gates, and dependency visibility that prevent the next surprise.

DATA STUDY · 2026

State of Relicensing Exposure 2026

Our research study: how far the relicensing wave reaches into enterprise estates, with the numbers.

COMMON QUESTIONS

Open source license risk, answered.

What is open source license risk?

Open source license risk is the exposure an enterprise carries when software it runs in production changes its license terms. When a project relicenses from an open source license to a source available license such as the Business Source License or the Server Side Public License, competitive use restrictions, copyleft obligations and commercial license demands can apply to software already running in your environment.

Which open source projects have changed their license?

HashiCorp moved Terraform, Vault, Consul, Nomad and Packer to the Business Source License as of August 2023. Redis moved to a dual Redis Source Available License and Server Side Public License model as of March 2024. Elasticsearch and Kibana moved to the SSPL and the Elastic License as of 2021. MongoDB moved to the SSPL in 2018. Confirm current terms with your own counsel.

Is source available the same as open source?

No. Source available is not the same as open source. The Server Side Public License and the Business Source License are not OSI approved open source licenses. The source may be readable, but the terms restrict competitive production use and can carry distribution and commercial obligations that open source licenses do not.

How do I assess my open source license risk?

Start by mapping every open source dependency you run and the current license state of each one, including transitive dependencies layers down in the tree. Then quantify the exposure and the cost to cure, and contain it by rerouting to safe alternatives or negotiating commercial terms. A confidential open source license risk assessment maps this blast radius for you.

Do you provide legal advice on license compliance?

No. We provide commercial and licensing risk advisory, not legal advice. We map exposure and quantify cost from the buyer side. For interpretation of license terms and compliance questions, we always recommend you engage your own counsel.

CONTAINMENT

Map your blast radius before it spreads.

A confidential open source license risk assessment.

Get a free exposure review

INDEPENDENT. BUYER SIDE. PAID ONLY BY YOU.