Open Source License Compliance
Legal certainty for your software: we identify all open source components, assess license risks and create a complete SBOM, without direct access to your source code.
No-obligation consultation on technical due diligence, integration, and value creation.

Open Source Compliance
More than just a scanner tool
Open source components are integral to modern software, yet they carry substantial legal and commercial risks that are frequently underestimated during M&A transactions. Conventional scanners often produce uncurated lists riddled with false positives, miss copy-pasted code snippets, and offer no guidance on critical licenses like (A)GPL. We combine automated analysis with experienced licensing and IP specialists to not only identify vulnerabilities, but actively resolve them.
Our Core Areas
Four building blocks for your legal certainty, from technical detection to legal assessment.
Local Scan Without Code Access
Our scanner runs exclusively locally, your code stays with you. We only transmit the names of the dependencies; individual components are analyzed flexibly when needed, even via video call, without transferring source code.
Minimizing False Positives
Standard scanners produce a multitude of false positives that cost valuable time. Our experienced team of license experts manually reviews every dependency, you receive only relevant, precise results.
Legal Review by IP Lawyers
On request, experienced IP lawyers review license agreements such as dual licensing and ensure that all commercial licenses are correctly concluded, for long-term legal certainty.
SBOM & Continuous Compliance
We create an SBOM in the format you need and keep it continuously up to date, including CI/CD integration and security alerts whenever a vulnerability appears in one of your dependencies.
Our Process
Scan Setup & Validation
We handle the complete setup and configuration of the scan, locally and without additional effort for your team, and ensure complete coverage of all open source components.
Component Identification & License Check
We capture all components and dependencies, check every license for proper use, including attribution and usage restrictions, and benchmark the results against requirements like the Cyber Resilience Act.
Risk Assessment
We assess the legal and operational risks of each component, from copyleft virality to security vulnerabilities, and prioritize the need for action.
Report, SBOM & Update Service
You receive a detailed report and a machine-readable SBOM (SPDX/CycloneDX). On request, we keep checking new dependencies semi-automatically in your CI/CD process.
Your Report & Your SBOM
The final report sets out all findings: license violations, copyleft risks and the recommended measures to resolve them. You receive the SBOM in a standardized format (SPDX or CycloneDX), compliant with OpenChain ISO/IEC 5230 and as a basis for CRA compliance. Our setup ensures that report and SBOM are continuously updated, so you are always up to date.

- Complete SBOM (SPDX or CycloneDX)
- License risk matrix with priorities
- Executive summary for decision-makers
- Concrete recommendations for action
- Optional: CI/CD integration & security alerts
Why BitFlow
More than a tool
We deliver a complete solution of technical precision and legal expertise, including IP lawyers who make the final call on license questions.
Help with problematic dependencies
Critical licenses like (A)GPL: we not only detect them, but actively support you in replacing or removing the affected components.
Without access to your code
The scan runs locally on your side, only package names are transmitted. Ideal for sensitive code bases and strictly confidential due diligence processes.
Experience from due diligence projects
From numerous DD projects we know what buyers and investors look for, and shape your license situation sustainably clean.
Frequently Asked Questions
What is a license review and why is it important?
A license review is a thorough examination of all of a company's software licenses to ensure they are correctly acquired, used and managed. Whether start-up, SME or enterprise: it creates legal certainty, avoids unnecessary costs and minimizes the risk of legal disputes, not least in M&A processes.
How is a license review performed?
We analyze your software's dependencies with a local scanner, identify all open source components, including manually copied ones, and check every component's license for proper use. We then assess the legal and operational risks and summarize everything in a report with an SBOM.
What is an SBOM and which formats do you support?
A Software Bill of Materials (SBOM) lists all components of your software in machine-readable form. We deliver it in the standard formats SPDX or CycloneDX, compliant with OpenChain ISO/IEC 5230 and as a central basis for meeting Cyber Resilience Act requirements.
What happens if you find critical licenses?
You are not left alone: our license experts and IP lawyers assess the situation, and we actively support you in replacing or removing problematic dependencies, with developers available for fast fixes within 24 hours if needed.
Ready for the next step?
Schedule an introductory call to learn how we can support your team, from initial assessment through to implementation.
Our Deliverables
Machine-readable SBOM and structured risk report for informed decisions.
- SBOM (SPDX or CycloneDX)
- License risk matrix
- Executive Summary
- Prioritized recommendations
No-obligation consultation on technical due diligence, integration, and value creation.
Request a Sample Report
Review an excerpt from our sample report – free of charge and with no obligation.