
SourceTrust
Summary
SourceTrust helps teams review third-party software licenses and publish a shareable compliance page for products they ship. It brings direct and transitive dependencies from repositories, lockfiles, and SBOMs into one inventory, then checks retrieved packages against registry digests and reads their license text. Teams must review and confirm records before publication, and the platform flags packages needing a decision. Listed repository connections include GitHub, GitLab, and Azure DevOps; supported inputs include lockfiles and SBOMs, with 14 formats across 9 ecosystems. Outputs include a hosted attestation page, THIRD_PARTY_LICENSES.md, NOTICE, CycloneDX, SPDX, JSON, CSV, plist, and branded PDF. Repository synchronization and publish-drift checks flag differences from the published snapshot. Pages can be password-protected and excluded from search engines. SourceTrust says it reads lockfiles and SBOMs rather than source code, and parses lockfiles in the browser before upload. Eligible public GitHub projects can publish for $0, subject to fair use and SourceTrust attribution. Standard project billing begins at first publish or export download; yearly billing starts at $299.00 USD per year per shipped product. The company describes the software as tooling, not legal advice.
Who it is for
SourceTrust suits teams that need to review dependencies and publish license compliance information for shipped products. Eligible public GitHub projects may qualify for its free publishing option; it is software tooling, not legal advice.
What is good
- Collects dependencies from repositories, lockfiles, and SBOMs
- Flags packages needing a team decision
- Offers multiple license and SBOM export formats
- Pages can be password-protected
What to know first
- Standard project billing starts on first publish or export download
- Free publishing is limited to eligible public GitHub projects
- Free publishing requires fair use and SourceTrust attribution
Verdict
SourceTrust combines dependency inventory, license review, and compliance outputs for shipped products. Teams should note the publication-based billing trigger and that the product is not legal advice.
SourceTrust plans and pricing
All plansCompared on open source license compliance software
- Free plan
- Yessourcetrust.dev
- Paid from
- $299/yrsourcetrust.dev
- Policy enforcement
- bothsourcetrust.dev
- Obligation tracking
- Yessourcetrust.dev
- Attribution reports
- Yessourcetrust.dev
- SBOM import formats
- CycloneDX, SPDXsourcetrust.dev
- Deployment options
- cloudsourcetrust.dev
- Source scan methods
- multiplesourcetrust.dev
Facts
- Purpose
- SourceTrust helps teams review third-party software licenses and publish a shareable license compliance page for products they ship.sourcetrust.dev · 29 Sept 2026
- Inventory
- It gathers direct and transitive dependencies from repositories, lockfiles, and SBOMs into one inventory.sourcetrust.dev · 29 Sept 2026
- Verification
- SourceTrust retrieves the shipped package, checks it against the registry digest, and reads the license text inside it.sourcetrust.dev · 29 Sept 2026
- Review gates
- Nothing is published until the team has reviewed and confirmed the record, and the product flags packages that need a decision.sourcetrust.dev · 29 Sept 2026
- Integrations
- The site lists GitHub, GitLab, and Azure DevOps repository connections, plus lockfile and SBOM imports.sourcetrust.dev · 29 Sept 2026
- Supported inputs
- The platform overview says it supports 14 formats across 9 ecosystems, including CycloneDX SBOM uploads.sourcetrust.dev · 29 Sept 2026
- Exports
- Outputs include a hosted attestation page, THIRD_PARTY_LICENSES.md, NOTICE, CycloneDX, SPDX, JSON, CSV, plist, and branded PDF.sourcetrust.dev · 29 Sept 2026
- Change monitoring
- Repository sync and publish-drift checks flag when the live inventory differs from the published snapshot.sourcetrust.dev · 29 Sept 2026
- Security controls
- Pages can be password-protected and excluded from search engines, and optional vulnerability findings remain vendor-only.sourcetrust.dev · 29 Sept 2026
- Data access
- SourceTrust says it reads lockfiles and SBOMs, never source code, and parses lockfiles in the browser before upload.sourcetrust.dev · 29 Sept 2026
- Open source eligibility
- Eligible public GitHub projects can publish an attestation page for $0 with no card or trial clock, subject to fair use and SourceTrust attribution.sourcetrust.dev · 29 Sept 2026
- Free review
- Projects, dependency imports, and license reviews are free for as long as needed; standard project billing starts on first publish or export download.sourcetrust.dev · 29 Sept 2026
- Support
- SourceTrust offers a live walkthrough and lists [email protected] for platform questions.sourcetrust.dev · 29 Sept 2026
- Audience and limitation
- The company describes the product as license compliance infrastructure for shipped products and says it is software tooling, not a law firm or legal advice.sourcetrust.dev · 29 Sept 2026
Company
- Founded
- 2026sourcetrust.dev · 28 Sept 2026
- Headquarters
- Copenhagen, Denmarksourcetrust.dev · 28 Sept 2026
Best SourceTrust alternatives
See all 12Where it ranks on Everything Xiaomi
Is SourceTrust yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- sourcetrust.dev· checked 29 Sept 2026
- sourcetrust.dev/platform· checked 29 Sept 2026
- sourcetrust.dev/pricing· checked 29 Sept 2026
- sourcetrust.dev/about· checked 29 Sept 2026


