Skip to content
Open source due diligence

Know your components and licenses.

Open-source due diligence identifies and documents the open-source components inside a deposit and their license obligations, so there are no surprises on recovery.

Component & license inventory

Components and obligations.

Every open-source part found in the deposit, recorded with its license and the obligation it carries. A documented inventory, not an assumption.

ComponentLicenseObligation
React 18.2.0
MIT
Attribution. Retain the copyright and permission notice.
OpenSSL 3.0.12
Apache-2.0
Attribution. Preserve the NOTICE file and license text.
libpq 15.4
BSD-3-Clause
Attribution. Keep the copyright notice and disclaimer.
FFmpeg 6.0
LGPL-2.1
Source availability. Allow the library to be replaced and relinked.
GNU Wget 1.21
GPL-3.0
Copyleft. Offer the corresponding source to recipients.
BusyBox 1.36.1
GPL-2.0
Copyleft. Distribute the corresponding source of the build.

Illustrative inventory, similar to a software bill of materials. The components, versions, and licenses are documented from your deposit. EscrowTech documents these obligations and does not render legal opinions.

Why it matters

No surprises on recovery.

If you ever rely on the deposit, undocumented open-source licenses are a liability you inherit. This documents them first.

Documented, not audited

We list the components and their licenses and document the obligations each carries. We do not render legal opinions on them.

A complement to escrow

This runs alongside your escrow deposit as a specialized complement, not as a stand-alone security or penetration-testing service.

Matched to the risk

Like every verification option, the depth is matched to your risk. It is never automatic on every deposit, and never included by default.

Open-source due diligence documents license obligations so they surface before recovery, not during it. It is one of EscrowTech's verification options, matched to your risk, never automatic; the top of the ladder is never standard or included by default.

Storage & proof

Two vaults. One in a granite mountain.

Deposits are held in two physical, US-based vaults, one inside a granite mountain, monitored around the clock. The provider has to satisfy the people who approve the deal, and EscrowTech is the one their legal teams already recognize.

In operationSince 1992
Buyer recognition80% of the Fortune 500
StorageTwo US sites
In-houseCounsel + developers
CustodyDocumented chain
FAQ

Open-source diligence, answered.

The questions licensees, vendors, and their counsel ask most often.

What is open-source due diligence in software escrow?

It is the work of identifying the open-source components inside an escrow deposit and documenting the license obligations each one carries, so that if you ever rely on the deposit you already know what is inside it and what those licenses require.

Why do open-source components and licenses matter?

Modern software is assembled from open-source parts, and each carries license terms such as attribution, source availability, or copyleft. If those obligations are undocumented, they become a liability you inherit at exactly the moment you are trying to recover and run the software.

What does open-source due diligence identify?

It produces an inventory of the open-source components found in the deposit, each recorded with its version and its license, similar to a software bill of materials, so the makeup of the deposit is documented rather than assumed.

What license obligations does it flag?

The obligations that attach to each license: attribution and notice requirements under permissive licenses like MIT, Apache-2.0, and BSD, and source-availability or copyleft requirements under licenses like LGPL, GPL-2.0, and GPL-3.0. It documents these obligations; it does not render legal opinions.

Is this a security or penetration-testing service?

No. Open-source due diligence is a specialized complement to escrow, focused on the components and license obligations in a deposit. It is not a stand-alone security or penetration-testing offering, and EscrowTech is an escrow specialist rather than a cybersecurity vendor.

How does it relate to verification levels?

It is one of EscrowTech's verification options, chosen by the depth your risk and recovery requirements justify. Like every verification option it is matched to the risk and is never automatic on every deposit; the top of the ladder is never standard or included by default.

When should I run open-source due diligence?

Whenever open-source components make up a meaningful part of the deposited software and you want their licenses documented before a recovery, rather than discovered during one. It is often paired with deposit analysis or build verification for higher-stakes dependencies.

How is open-source due diligence priced?

Starting at a set fee, custom-priced to the deal in front of you, based on the size of the deposit and the depth of the component and license review. You know what you are committing to before the work begins.

Make it safe to depend on.

Tell us what your software runs on. We'll structure the escrow and the verification around it.

Get a quote
No obligation. A member of our team will follow up.
Typical response: under four business hours.

Thanks, we've got it.

A member of our team will be in touch shortly.

Talk to our team(801) 852-8202
Call us(801) 852-8202 Get a quote