Know your components and licenses.
Open-source due diligence identifies and documents the open-source components inside a deposit and their license obligations, so there are no surprises on recovery.
Components and obligations.
Every open-source part found in the deposit, recorded with its license and the obligation it carries. A documented inventory, not an assumption.
Illustrative inventory, similar to a software bill of materials. The components, versions, and licenses are documented from your deposit. EscrowTech documents these obligations and does not render legal opinions.
No surprises on recovery.
If you ever rely on the deposit, undocumented open-source licenses are a liability you inherit. This documents them first.
Documented, not audited
We list the components and their licenses and document the obligations each carries. We do not render legal opinions on them.
A complement to escrow
This runs alongside your escrow deposit as a specialized complement, not as a stand-alone security or penetration-testing service.
Matched to the risk
Like every verification option, the depth is matched to your risk. It is never automatic on every deposit, and never included by default.
Open-source due diligence documents license obligations so they surface before recovery, not during it. It is one of EscrowTech's verification options, matched to your risk, never automatic; the top of the ladder is never standard or included by default.
See how the verification options fit together. See verification →
Two vaults. One in a granite mountain.
Deposits are held in two physical, US-based vaults, one inside a granite mountain, monitored around the clock. The provider has to satisfy the people who approve the deal, and EscrowTech is the one their legal teams already recognize.
Open-source diligence, answered.
The questions licensees, vendors, and their counsel ask most often.
What is open-source due diligence in software escrow?
It is the work of identifying the open-source components inside an escrow deposit and documenting the license obligations each one carries, so that if you ever rely on the deposit you already know what is inside it and what those licenses require.
Why do open-source components and licenses matter?
Modern software is assembled from open-source parts, and each carries license terms such as attribution, source availability, or copyleft. If those obligations are undocumented, they become a liability you inherit at exactly the moment you are trying to recover and run the software.
What does open-source due diligence identify?
It produces an inventory of the open-source components found in the deposit, each recorded with its version and its license, similar to a software bill of materials, so the makeup of the deposit is documented rather than assumed.
What license obligations does it flag?
The obligations that attach to each license: attribution and notice requirements under permissive licenses like MIT, Apache-2.0, and BSD, and source-availability or copyleft requirements under licenses like LGPL, GPL-2.0, and GPL-3.0. It documents these obligations; it does not render legal opinions.
Is this a security or penetration-testing service?
No. Open-source due diligence is a specialized complement to escrow, focused on the components and license obligations in a deposit. It is not a stand-alone security or penetration-testing offering, and EscrowTech is an escrow specialist rather than a cybersecurity vendor.
How does it relate to verification levels?
It is one of EscrowTech's verification options, chosen by the depth your risk and recovery requirements justify. Like every verification option it is matched to the risk and is never automatic on every deposit; the top of the ladder is never standard or included by default.
When should I run open-source due diligence?
Whenever open-source components make up a meaningful part of the deposited software and you want their licenses documented before a recovery, rather than discovered during one. It is often paired with deposit analysis or build verification for higher-stakes dependencies.
How is open-source due diligence priced?
Starting at a set fee, custom-priced to the deal in front of you, based on the size of the deposit and the depth of the component and license review. You know what you are committing to before the work begins.
Make it safe to depend on.
Tell us what your software runs on. We'll structure the escrow and the verification around it.
Thanks, we've got it.
A member of our team will be in touch shortly.