OSS Licensing & Compliance
ISO5230 consulting
Do you have concerns about open-source libraries or APIs used in your product?
Unsure whether their licenses could create compliance risks for your project in the future, or evaluating licensing options you’re not fully confident about?
Protect your copyright.
The First
Code-level audit to ensure your product is compliant with open source licensing to avoid any legal issue.
The Second
Process and business level audit to protect your licensing and copyrights.
The Third
Shield your project with ISO5230:2020 certification for open source license compliance audit.
Contact us
tQCS Limited.
Unit 01, 82F, International Commerce Centre, 1, Austin Road West Kowloon, Hong Kong
+852 2824 8796
Service.OSS@tqcs.io
business registration 68326347
Licensing Type
Open-source licenses define how software may be used, modified and distributed. They are generally grouped into three types:
| Type | Examples | Key Characteristics |
|---|---|---|
| Permissive | MIT · BSD · Apache 2.0 | Allow broad commercial use, modification and redistribution. Proprietary source code can generally remain closed, provided requirements such as copyright notices, license texts and attribution are fulfilled. |
| Weak Copyleft | LGPL · MPL · EPL | Require modified OSS code to remain open within a limited boundary — typically a library, file or module. Separate proprietary code may generally remain closed when the applicable conditions are met. |
| Strong Copyleft | GPL · AGPL | Impose broader source-code disclosure and same-license requirements. GPL obligations generally arise upon distribution, while AGPL can also apply when modified software is provided as a network service. |
Permissive vs Restrictive
| Permissive Licenses | Restrictive — or Copyleft — Licenses |
|---|---|
| Allow broad reuse in proprietary products | Require covered code to remain open source |
| Usually do not require proprietary source-code disclosure | May require disclosure when software is modified, combined or distributed |
| Mainly require notices, attribution and license copies | Apply source-code and same-license obligations |
| MIT · BSD · Apache 2.0 | LGPL · MPL · EPL · GPL · AGPL |
Both types permit commercial use. The key difference is how much source code must be disclosed and whether the same license must be applied.
The specific obligations depend on the license version, modifications, software architecture, linking method and method of distribution.
Open Source License Compliance Audit
Open source software accelerates development, but every license comes with different rights, obligations and business implications.
tQCS helps organizations understand OSS license types, evaluate compliance requirements and make informed decisions before open source components are integrated into commercial and embedded products.
Working with LGPLv2.1, LGPLv3 and GPL.
Audit on Open-Source Compliance status of a project within an organization in accordance with the Open Chain standards (ISO/IEC 5230:2020), led by Software Compliance Academy.
Technical Compliance check on use of open-source code on its license responsibility
Upon successful audit, the customer will receive ISO standard certification on Open-Source Compliances, valid for legal, process and technical aspects.