Open-source license compliance audit
We review which open-source libraries and dependencies your product uses and under which licenses: where it is MIT and Apache and where it is copyleft (GPL/AGPL/LGPL), what obligations they impose (attribution, source disclosure), whether there are license conflicts and risky spots for a commercial product. We provide an inventory (SBOM) and a prioritized risk list. Honestly upfront: we are not lawyers — this is a technical inventory and analysis, not a legal opinion; the final interpretation of licenses and the legal assessment for your situation are given by a lawyer.
Open-source license compliance audit — overview

An open-source license compliance audit is a one-time technical review of your product's open-source libraries and dependencies for licenses and related obligations: an inventory of all dependencies, including transitive ones (dependencies of dependencies), with the license identified for each; classification by type (permissive — MIT, Apache, BSD; copyleft — GPL, AGPL, LGPL, MPL; and problematic/unknown); what obligations each license imposes (attribution, including the license text, source-code disclosure for copyleft, usage restrictions); finding conflicts between licenses and risks for your distribution model (especially AGPL for SaaS and copyleft in a proprietary product); dependencies with a missing, ambiguous or dual license; producing a software bill of materials (SBOM) and a prioritized risk list. Honestly and importantly: we are not lawyers — this is a technical inventory and analysis of licenses, NOT a legal opinion and not a guarantee against claims. We identify licenses and typical obligations and flag risky spots, but the final interpretation of a specific license for your situation and the legal assessment are given by a lawyer — our report helps them. Honestly about the method: license identification is done with tools and analysis, and there are limits here — transitive dependencies, libraries with no explicitly stated license, dual licensing and non-standard texts require manual review, and some cases remain "needs to be checked with a lawyer" rather than "definitely allowed/not allowed". It is a snapshot in time: with every update and new dependency the picture changes, so the audit is tied to a specific state of the project. And it is an assessment with a document, not fixing: replacing problematic libraries, adding attribution-notice files and changes are separate work, by us or by your team. An important boundary: this is a license audit, not a dependency security audit (vulnerabilities and CVEs are a separate topic) and not general legal compliance. If the product barely uses third-party dependencies, there is almost nothing to assess and you most likely do not need the audit. Picture this: instead of "it is all open-source libraries, it is free, right" you learn that one dependency is under AGPL and with your SaaS model that is a serious risk (by the letter of such a license you may be required to open the entire product source code), three libraries lack the required attribution, and one pulls in a copyleft dependency nobody knew about — with priorities and a clear "what to ask a lawyer". The base price starts from 18,000 ₽; it depends on the number of dependencies and the stack (this is a manual review on top of tools plus SBOM preparation, so it costs more than a simple scan).
Problems we solve
- You do not know under which licenses your open-source dependencies are.
- You sell or distribute the product and fear violating licenses (especially copyleft/AGPL).
- A client or investor asks for an SBOM or confirmation of license cleanliness.
- You suspect license conflicts or forgotten attribution obligations.
What's included in the Open-source license compliance audit service
- An inventory of all dependencies, including transitive ones
- License identification for each dependency
- Classification: permissive / copyleft / problematic and unknown
- Obligations of each license (attribution, text, source disclosure)
- License conflicts and risks for your distribution model (AGPL/SaaS)
- Dependencies with no license, ambiguous or dual license
- A software bill of materials (SBOM) and a prioritized risk list
- What to fix technically and what to ask a lawyer
What you get
- A clear picture of your dependencies' licenses and their obligations
- Visibility of conflicts and risky spots for your model
- A ready SBOM and a prioritized risk list
- Clarity on what is technical and what is a question for a lawyer
How the work goes: steps
- We clarify the product, stack, distribution model and collect access to the code/dependencies
- We inventory dependencies, identify licenses and obligations, look for conflicts
- We prepare the SBOM and a prioritized risk list and review them with you
Why PDV Expert
- Fixed price and timeline — no surprises on the invoice.
- Report and recommendations in plain language — clear without a technical background.
- In touch at every step and answering questions about the result.
FAQ
Is this a legal opinion on license cleanliness?
No. We are not lawyers: this is a technical inventory and analysis of licenses, not a legal opinion and not a guarantee against claims. We identify licenses, obligations and risky spots, while the final interpretation for your situation is given by a lawyer.
Are all licenses identified for certain?
Identification is done with tools and manual analysis, but there are limits: transitive dependencies, libraries with no explicit license, dual licensing and non-standard texts require manual review, and some cases are "needs checking with a lawyer". No one can give a full mathematical guarantee, and some cases (no license, an abandoned project, a non-standard text) may have no clear resolution even after a lawyer — such modules are usually safer to replace.
Will you replace problematic libraries and add notices?
No, that is separate work. The audit gives an inventory (SBOM), a risk list and recommendations. Replacing libraries, adding attribution files and changes are done separately or by your team.
About the provider
The «Open-source license compliance audit» service is provided by PDV Expert — a team specialising in «Diagnostics & monitoring». We work under contract and deliver a written report with recommendations.