OpenSource Risk Experts
Map your blast radius

SERVICES

Open source license risk services that map, quantify, and contain exposure.

Our open source license risk services cover eight engagements, each scoped to the exposure you carry today. We work from the buyer side, name the risk plainly, and leave you with a dependency tree you can defend to a vendor, an auditor, or your board.

01

Open Source License Risk Assessment

FOUNDATION

We map every open source dependency you run and the license state of each one, direct and transitive. You receive a complete, current picture of what governs your software, including the components that have quietly changed terms since you adopted them.

  • Full dependency tree
  • License state per node
  • Risk ranked findings
02

Relicensing Exposure Review

BSL / SSPL

When a project moves from an open license to a source available one, we quantify what the change costs you. We trace the blast radius through everything built on the affected component and size the financial and operational exposure in board language.

  • Blast radius map
  • Cost of exposure
  • Cost to cure
03

Open Source Remediation Advisory

CONTAIN

We contain the risk and reroute to safe alternatives or negotiated terms. Every option is weighed on engineering cost, license posture, and timeline, so the path you choose holds under scrutiny and does not simply move the exposure somewhere else.

  • Containment plan
  • Safe path migration
  • Sequenced roadmap
04

Open Source Commercial License Negotiation

BUYER SIDE

When a commercial license is the right answer, we negotiate the terms from your side of the table. The agreement reflects your actual usage and leverage rather than a list price built for someone else.

  • Usage baseline
  • Term strategy
  • Negotiation support
05

Open Source Governance and Policy

PREVENT

We set the rules before the next change lands. Policy, approval gates, and license allowlists are built to your risk tolerance and wired into the way your teams ship, so a future relicense is caught at intake rather than in an audit.

  • License policy
  • Approval gates
  • Intake controls
06

SBOM and Dependency Mapping

SBOM

We produce a software bill of materials that sees the full tree, layers down, and keeps it current. The same map that satisfies a regulator is the map that lets you find a relicensed component before it becomes a finding.

  • SPDX / CycloneDX
  • Transitive depth
  • Continuous refresh
07

Open Source M and A Due Diligence

DEAL

We find the exposure before the deal closes. A target's dependency tree can carry relicensing risk that materially changes valuation, and we surface it during diligence, with a remediation cost attached, while there is still room to price it in.

  • Target tree review
  • Valuation impact
  • Red flag memo
08

Open Source Compliance Audit Defense

DEFEND

When a vendor or an auditor comes knocking, we stand up the evidence. A defensible record of what you run, under which terms, and since when turns an open ended inquiry into a bounded, answerable question.

  • Evidence pack
  • Position memo
  • Auditor liaison

Not sure where your exposure sits? Most engagements start with the assessment, which maps your blast radius and tells you plainly what changed and what it costs. See the case studies or read why our independence matters.

COMMON QUESTIONS

Questions buyers ask.

What are open source license risk services?

Open source license risk services map the open source you run, quantify the exposure created when a project relicenses, and contain it through remediation, negotiation, or governance. The aim is a dependency tree you can defend to a vendor, an auditor, or your board.

Where should we start?

Most buyers start with an open source license risk assessment, which maps every dependency and its current license state. From there we scope a relicensing exposure review, remediation, or negotiation as needed.

Do you cover BSL and SSPL projects specifically?

Yes. Our relicensing exposure review focuses on Business Source License and Server Side Public License projects such as HashiCorp, Redis, and Elastic, and traces the blast radius through everything built on them.

Is this legal advice?

No. These are commercial and licensing risk advisory services, not legal advice. For interpretation of license terms and compliance, we recommend your own counsel.

CONTAINMENT

Map your blast radius before it spreads.

A confidential open source license risk assessment. Independent, buyer side, paid only by you.

Not ready to talk? Read the free open source license risk guides first.

Map your blast radius