Open Source Software Policy
For Informational Purposes Only
An operational policy governing the acquisition, use, modification, distribution, contribution, and release of open-source software, AI-generated code, and source-available materials.
What This Document Does
The Open Source Software Policy establishes a comprehensive governance framework for how an organization acquires, evaluates, uses, modifies, distributes, contributes to, and releases open-source software and related materials. It maps to actual repositories, package managers, build systems, containers, products, SaaS services, and AI code tools — creating an operational system that engineering, legal, and security teams can implement together, not a legal-only policy that sits unread in a shared drive.
Why Startups Need This
Modern software products typically contain 80–95% open-source components. Without a formal OSS policy, startups risk license violations that could require releasing proprietary source code, security vulnerabilities from unmonitored dependencies, intellectual property contamination from incompatible licenses, and due-diligence failures that derail acquisitions or financings. These risks compound when teams use AI code-generation tools that may produce snippets of uncertain provenance or when acquiring companies with unknown open-source exposure.
This policy creates a three-tier risk classification system (preapproved, review-required, and prohibited), integrates with CI/CD pipelines to enforce compliance at build time, requires SBOM generation tied to released builds, and addresses the unique challenges of AI-assisted code, model weights, datasets, and acquisitions.
Key Provisions
Three-Tier Risk Classification
Classifies components into preapproved (permissive licenses with standard use), review-required (copyleft, modified, or architecturally sensitive), and prohibited/exception tiers. Classification considers actual use, modification, interaction, architecture, and distribution model — not just the license family name. Unknown or no-license components are blocked by default.
CI/CD Release Controls
Integrates with build and deployment pipelines to block unapproved, prohibited, or unknown high-risk components. Prevents silent scanner suppression, preserves approval and scan evidence, verifies notice and source packages are included in release artifacts, and assigns exception authority for urgent releases.
SBOM and Inventory Management
Requires maintaining a complete inventory of direct and transitive components with versions, hashes, provenance, licenses, modifications, and vulnerability status. Generates versioned SBOMs tied to released builds aligned with current CISA/NTIA guidance, with defined access, sharing, retention, and correction procedures.
AI-Assisted Code Governance
Addresses code generated by AI tools (Copilot, ChatGPT, Claude) with requirements for approved tool configurations, prompt secrecy, similarity and provenance review proportionate to risk, dependency/security/license testing, human review, and escalation for authorship and inventorship questions.
Acquisition Due Diligence
Requires code scan, provenance verification, SBOM, license schedule, representations, remediation plans, source/escrow rights, and ownership chain verification before integrating any acquired codebase. Prevents inheriting unknown license obligations that could affect the acquiring company’s entire product portfolio.
Emerging Provisions (2025–2026)
Model, Dataset, and Font Licensing
Extends open-source governance beyond traditional software to cover ML model weights, training datasets, fonts, documentation, and creative assets with open or source-available licenses — each with distinct use restrictions, attribution requirements, and commercial limitations that require separate analysis.
Software Supply Chain Security
Incorporates current CISA secure-software guidance with dependency pinning, artifact signing and provenance attestation, malicious-package detection, and vulnerability remediation SLAs — reflecting the evolving regulatory landscape for software supply chain integrity.
How to Use This Template
Download the .docx and adapt the bracketed placeholders to your organization’s specific technology stack, tooling, and risk tolerance. The policy includes ten exhibits covering the license/use risk matrix, intake form, architecture questionnaire, SBOM checklist, CI/CD release gate, contribution request form, exception register, incident playbook, acquisition diligence schedule, and training matrix. Start by completing the license risk matrix for your actual stack, then configure the CI/CD release gate to match your build pipeline.
Related Forms
Information Security Policy
Software Development Agreement
Commercial AI Service Terms
Disclaimer: This template is provided for informational and educational purposes only and does not constitute legal advice. Every business situation involves unique circumstances, and applicable laws vary by jurisdiction. Montague Law recommends consulting with a licensed attorney before using any legal template or making legal decisions. Use of this template does not create an attorney-client relationship with Montague Law.