Skip to content
Service Line

Open Source License Compliance

Legal certainty for your software: we identify all open source components, assess license risks and create a complete SBOM, without direct access to your source code.

No-obligation consultation on technical due diligence, integration, and value creation.

Open Source Lizenz-Prüfung

Open Source Compliance

More than just a scanner tool

Open source components are integral to modern software, yet they carry substantial legal and commercial risks that are frequently underestimated during M&A transactions. Conventional scanners often produce uncurated lists riddled with false positives, miss copy-pasted code snippets, and offer no guidance on critical licenses like (A)GPL. We combine automated analysis with experienced licensing and IP specialists to not only identify vulnerabilities, but actively resolve them.

Our Core Areas

Four building blocks for your legal certainty, from technical detection to legal assessment.

Local Scan Without Code Access

Our scanner runs exclusively locally, your code stays with you. We only transmit the names of the dependencies; individual components are analyzed flexibly when needed, even via video call, without transferring source code.

No code access requiredDetection of manually copied componentsAdvanced FOSS code analysis

Minimizing False Positives

Standard scanners produce a multitude of false positives that cost valuable time. Our experienced team of license experts manually reviews every dependency, you receive only relevant, precise results.

Manual reviewLicense experts, not just a toolPrecise, usable results

Legal Review by IP Lawyers

On request, experienced IP lawyers review license agreements such as dual licensing and ensure that all commercial licenses are correctly concluded, for long-term legal certainty.

IP lawyers on the teamDual licensing & commercial licensesClear recommendations

SBOM & Continuous Compliance

We create an SBOM in the format you need and keep it continuously up to date, including CI/CD integration and security alerts whenever a vulnerability appears in one of your dependencies.

SPDX & CycloneDXCRA & OpenChain ISO/IEC 5230CI/CD integration & alerts

Our Process

1

Scan Setup & Validation

We handle the complete setup and configuration of the scan, locally and without additional effort for your team, and ensure complete coverage of all open source components.

2

Component Identification & License Check

We capture all components and dependencies, check every license for proper use, including attribution and usage restrictions, and benchmark the results against requirements like the Cyber Resilience Act.

3

Risk Assessment

We assess the legal and operational risks of each component, from copyleft virality to security vulnerabilities, and prioritize the need for action.

4

Report, SBOM & Update Service

You receive a detailed report and a machine-readable SBOM (SPDX/CycloneDX). On request, we keep checking new dependencies semi-automatically in your CI/CD process.

Your Report & Your SBOM

The final report sets out all findings: license violations, copyleft risks and the recommended measures to resolve them. You receive the SBOM in a standardized format (SPDX or CycloneDX), compliant with OpenChain ISO/IEC 5230 and as a basis for CRA compliance. Our setup ensures that report and SBOM are continuously updated, so you are always up to date.

Inside a BitFlow report
  • Complete SBOM (SPDX or CycloneDX)
  • License risk matrix with priorities
  • Executive summary for decision-makers
  • Concrete recommendations for action
  • Optional: CI/CD integration & security alerts

Why BitFlow

More than a tool

We deliver a complete solution of technical precision and legal expertise, including IP lawyers who make the final call on license questions.

Help with problematic dependencies

Critical licenses like (A)GPL: we not only detect them, but actively support you in replacing or removing the affected components.

Without access to your code

The scan runs locally on your side, only package names are transmitted. Ideal for sensitive code bases and strictly confidential due diligence processes.

Experience from due diligence projects

From numerous DD projects we know what buyers and investors look for, and shape your license situation sustainably clean.

Frequently Asked Questions

What is a license review and why is it important?

A license review is a thorough examination of all of a company's software licenses to ensure they are correctly acquired, used and managed. Whether start-up, SME or enterprise: it creates legal certainty, avoids unnecessary costs and minimizes the risk of legal disputes, not least in M&A processes.

How is a license review performed?

We analyze your software's dependencies with a local scanner, identify all open source components, including manually copied ones, and check every component's license for proper use. We then assess the legal and operational risks and summarize everything in a report with an SBOM.

What is an SBOM and which formats do you support?

A Software Bill of Materials (SBOM) lists all components of your software in machine-readable form. We deliver it in the standard formats SPDX or CycloneDX, compliant with OpenChain ISO/IEC 5230 and as a central basis for meeting Cyber Resilience Act requirements.

What happens if you find critical licenses?

You are not left alone: our license experts and IP lawyers assess the situation, and we actively support you in replacing or removing problematic dependencies, with developers available for fast fixes within 24 hours if needed.

Ready for the next step?

Schedule an introductory call to learn how we can support your team, from initial assessment through to implementation.

Our Deliverables

Machine-readable SBOM and structured risk report for informed decisions.

  • SBOM (SPDX or CycloneDX)
  • License risk matrix
  • Executive Summary
  • Prioritized recommendations

No-obligation consultation on technical due diligence, integration, and value creation.

Request a Sample Report

Review an excerpt from our sample report – free of charge and with no obligation.