vaulytica

OSS Compliance Audit Document review

Open-source software compliance audit / SBOM document.

Review your document — free → See a sample report

What it checks

Third-party / open-source software inventory

OSS compliance document must inventory third-party / open-source components.

Critical · IPL-030

License enumeration per component

Each component must have its license enumerated (e.g., MIT, Apache-2.0, GPL-3.0).

Critical · IPL-031

Copyleft (GPL / AGPL) obligations addressed

If GPL / AGPL components are used, source-availability and notice obligations must be addressed.

Critical · IPL-032

Notice / attribution file generation

Compliance document must address how attribution notices are generated and distributed.

Warning · IPL-033

Forbidden / discouraged-license list

OSS compliance document should specify forbidden licenses (e.g., SSPL, BUSL non-OSI) or discouraged ones.

Warning · IPL-034

Vulnerability / CVE tracking obligation

OSS compliance documents should require CVE / vulnerability monitoring of inventoried components.

Warning · IPL-035

Every run also applies 104 general checks that belong to any agreement: structure, parties and signatures, defined terms, cross-references, dates, amounts, and one-sided terms.

How it works

  1. Open vaulytica.com — no account, nothing to install.
  2. Drop your PDF or DOCX. The document type is detected and only the checks that belong to it run, inside your browser tab.
  3. Get a Word report in which every finding quotes the clause and cites the rule and source behind it — one of 1,825 checks across 268 document types.
Review your document — free →

More confidentiality & ip documents

Every document type →