Start from an existing customer-provided CycloneDX or SPDX JSON SBOM rather than cloning and executing arbitrary code.
Open-source licence review
SBOM licence review for enterprise procurement
How to turn an existing CycloneDX or SPDX JSON SBOM into a deterministic licence disposition queue and buyer-ready evidence.
Best fit
Small SaaS vendors entering enterprise procurement, software agencies handing code to clients and due-diligence providers.
What the focused offer actually does
Turn one existing CycloneDX or SPDX JSON SBOM into a deterministic open-source licence review queue and buyer-ready evidence pack.
Current commercial scope: US$500 one-time
Practical workflow
Four checks before you add more software.
The useful unit is a bounded operating workflow: explicit input, evidence, human judgement where needed, and a visible handoff.
Normalise components deterministically before applying licence policy.
Keep unknown or ambiguous licences in a needs-review state for human disposition.
Export the input/tool provenance with the result; licence review is not legal clearance.
Primary / official source basis
Check the source, not just our summary.
Reviewed 2026-08-31. Source owner: SPDX / OWASP CycloneDX.