Our Services
ISO 5230 OpenChain Conformance
The OpenChain Project trust in the open source supply chain. We maintain the industry standard for open source license compliance, ISO 5230 and security assurance ISO 18974 . Source Code Control help companies implement and maintain conformance to these standards Read more ...
Software Composition Analysis as a Service
A combinations tools and services to help organisations build an accurate inventory of open source software components, libraries and frameworks that developers have used to build an application. The output of the service will be SBOMs in the format of industry standards such as ISO 5962 SPDX and CycloneDX Read more...
Technical Due Diligence
Organisations seeking funding or venture capitalists seeking to invest in technology companies should review software source code for potential issues related to intellectual property, copyright and patents issues and conflicts.The VC Service creates a framework policies and processes to ensure risk is not engineered into software code which could affect a return on investment. Read more ...
Training – Managing Open Source Software
We offer a range of courses focused on helping organisations build their knowledge and skills in order to understand and adopt best practices in compliance programs that should be applied across a software supply chain for efficient, effective compliance with open source software licences and design and deliver secure solutions. Read more...
Resources
Interneuron: A Case Study for Professionally Managed Open Source Software
Interneuron: A Case Study for Professionally Managed Open Source Software In the modern digital climate hospitals increasingly rely on technology […]
How to Start an Open Source Program Office
Table of Contents Introduction Starting an OSPO Educating the employees and assigning responsibilities Contributing the code OSPO: a central entity […]
Log4j Vulnerability: What you Need to Know
In December 2021 a vulnerability, with a severity score of 10 out of 10, in a widely used logging library […]