SourceTrust

Legal

Acceptable Use Policy

Prohibited misrepresentation, security abuse, scan misuse, and rules for hosted compliance pages.

Last updated: June 13, 2026

This Acceptable Use Policy ("AUP") describes prohibited and restricted uses of the SourceTrust website at https://sourcetrust.dev and application at https://app.sourcetrust.dev (together, the "service"). It forms part of your agreement with us and should be read with our Terms of Service, privacy policy, and - where applicable - our Data Processing Agreement.

We may update this policy to address new abuse patterns or legal requirements. Continued use after an update constitutes acceptance where permitted by the Terms.

General standards

The service is for organizations and professionals managing third-party license obligations for products they ship. You must use it lawfully, honestly, and in a way that does not harm other users, third parties, or the integrity of the service.

You are responsible for all activity under your account and for ensuring that users you invite act within this policy.

Identity, authorization, and misrepresentation

You must not:

  • register or use the service while impersonating another company, person, or product;
  • publish a compliance page or export that presents another organization's products, brands, or domains as yours without their authorization;
  • misrepresent your compliance posture or imply that SourceTrust certifies, approves, audits, or guarantees your legal or regulatory compliance; or
  • provide false organization, billing, or contact information.

Public compliance pages are your representations to buyers and auditors. SourceTrust provides infrastructure to help you publish reviewed inventory - not an endorsement of your legal conclusions.

Content and intellectual property

You must not upload, import, publish, or distribute through the service:

  • content you do not have the right to use;
  • material that infringes third-party intellectual property, privacy, or publicity rights;
  • personal data about individuals unless you have a lawful basis and appropriate notices; or
  • content that is unlawful, defamatory, harassing, or intended to deceive recipients.

Security and technical abuse

You must not:

  • probe, scan, or test the vulnerability of the service or circumvent access controls;
  • reverse engineer the service except where mandatory law prohibits this restriction;
  • resell, sublicense, or provide unauthorized third-party access to the application without our written consent;
  • use the service to distribute malware, spam, or abusive automated traffic;
  • interfere with other users' use of the service or with our or our providers' infrastructure; or
  • attempt to extract data from the service through scraping or bulk automated access beyond documented APIs and normal product use.

Public site scan

The free site scan on https://sourcetrust.dev is a limited preview for evaluation. You must not:

  • submit URLs you do not own or lack authorization to test;
  • automate scan requests, bypass rate limits, CAPTCHA (Turnstile), or other abuse controls;
  • use scan results to misrepresent SourceTrust as having audited, certified, or approved a third party's compliance; or
  • rely on scan output as a complete compliance assessment or substitute for importing and reviewing what you actually ship.

We may throttle, block, or terminate access to the scan for violations or to protect the service.

Repository imports and integrations

When connecting repositories or imports:

  • connect only repositories, organizations, and sources you are authorized to access for compliance review;
  • do not circumvent GitHub, GitLab, or Azure DevOps permissions, install the GitHub App or paste an access token where you lack authority, or connect repos you do not control;
  • do not use imported data to build unrelated datasets, train models, or resell inventory extracted through the service; and
  • respect applicable license, export-control, and sanctions laws when reviewing and publishing obligations.

Security monitoring add-on

If you enable optional security advisory monitoring:

  • do not misrepresent OSV or advisory alerts as a penetration test, security audit, compliance certification, or public disclosure on customer-facing compliance pages;
  • do not imply that advisory notifications alone mean vulnerabilities are remediated or that your products are secure; and
  • treat alerts as operational signals for your organization's review, consistent with our Terms of Service.

Hosted compliance pages

You must not publish hosted compliance pages or exports that:

  • knowingly omit required license notices or attributions you have identified in your reviewed inventory;
  • claim obligations are satisfied when required review, approval, or publish gates in the application have not been completed; or
  • create a likelihood of confusion about which organization stands behind the published attestation.

If you use a customer-branded hostname, you must not use it for phishing, malware distribution, impersonation, or other abuse that harms third parties or the service.

We may unpublish, suspend, or remove hosted pages without notice where we reasonably believe content violates this policy, the Terms, or applicable law, or creates liability for the service - including in response to credible third-party complaints.

To report abuse or request review of hosted content: hello@sourcetrust.dev.

Enforcement

We may investigate suspected violations, request information, suspend features, unpublish pages, or terminate accounts where we reasonably believe this policy or the Terms has been breached, non-payment occurred, or continued access creates risk to the service or third parties.

Serious or repeated violations may result in immediate termination without refund, subject to our refund policy and applicable law.