OpenSource Risk Experts
Map your blast radius

WHITE PAPERS

Open source risk white papers for the people who carry it.

Our open source risk white papers give CISOs, legal leads, and procurement heads longer form analysis on relicensing, the Business Source License and the Server Side Public License, and the vendor specific changes at HashiCorp, Redis, and Elastic. Each is gated: leave a name and a work email and you go straight to the paper.

RELICENSING

The Open Source License Risk Playbook

A step by step method for mapping a blast radius, sizing exposure, and drawing a containment boundary when a core dependency changes terms.

28 pagesPDF
Get the white paper
LICENSES

The Relicensing Survival Guide: BSL and SSPL Explained

What the Business Source License and the Server Side Public License restrict, what triggers them, and how to read a term sheet before it reads your deployment.

22 pagesPDF
Get the white paper
HASHICORP

The HashiCorp and Terraform Exposure Guide

How the August 2023 move to the Business Source License reaches Terraform, Vault, Consul, Nomad, and Packer, and how to scope what is genuinely exposed.

24 pagesPDF
Get the white paper
MIGRATION

The Redis and Elastic Migration Guide

Reading the SSPL service condition for Redis and Elastic, and weighing forks such as Valkey and OpenSearch against negotiated terms.

20 pagesPDF
Get the white paper
M AND A

The Buy Side Guide to Open Source Risk in M&A

A diligence framework for surfacing relicensing exposure in a target, with a costing approach you can take into the deal.

24 pagesPDF
Get the white paper

COMMON QUESTIONS

Questions buyers ask.

What do the open source risk white papers cover?

They cover the relicensing playbook, a field guide to the Business Source License and the Server Side Public License, the HashiCorp and Terraform exposure, the Redis and Elastic migration, and open source risk in M and A diligence.

Why are the white papers gated?

Each paper asks for a name and a work email so we can confirm the reader is a qualified buyer. Once you submit a valid work email, you go straight to the paper.

Do you accept personal email addresses?

No. The gate requires a corporate email and blocks free or personal domains such as gmail, outlook, and yahoo. Please use your work email.

Is the analysis legal advice?

No. The white papers provide commercial and licensing risk analysis, not legal advice. For interpretation of license terms, consult your own counsel.

CONTAINMENT

Map your blast radius before it spreads.

A confidential open source license risk assessment. Independent, buyer side, paid only by you.

Not ready to talk? Read the free open source license risk guides first.

Map your blast radius