The practice
A senior practitioner does the audit. There is no junior tier and no tool being sold alongside the report.
Open source audits went wrong when they became a product line: a scanner licence, a dashboard, and an output nobody had reviewed. This practice does the opposite — the finding is the deliverable, and someone who has done this for seventeen years signs it.
Background
Seventeen years inside this exact problem.
The practice is led by Sean Fagan, who has spent his career in software composition analysis, SBOM and supply-chain security — including time at Black Duck, FOSSA, Chainguard, Egress and HPE. That is most of the commercial history of this field, seen from the inside.
It also means knowing exactly where those tools stop: undeclared code, vendored trees, forks that drifted, obligations that change with the distribution model, and the long tail of findings a scanner ranks confidently and wrongly. That gap is what an audit is for.
-
Independent
No platform, no renewal
Nothing is being upsold behind the findings. If the right answer is that your existing tooling is adequate and the gap is process, that is what the report says.
-
In-house
Our own fingerprint corpus
Derived-code detection runs against a source corpus built and maintained here — Debian, the crates registry and the most-copied C and C++ projects — rather than a vendor's black box.
-
Reviewed
Hand-reviewed findings
Machine output starts the audit; it does not end it. Every material finding is reviewed, and the reasoning travels with it so you can argue with the call.
Position
Where the practice stops.
-
Audits, not legal advice
Findings are technical and informational: what is in the code, what the licence says, what obligation that creates under a given distribution model. Decisions about legal risk belong to your counsel, and the report is written to be useful to them.
-
Licences, not vulnerabilities
Vulnerability management is usually already owned by a security team with tooling for it. Engagements can include a vulnerability pass, but the default scope is licence, obligation, derived code and provenance.
-
Evidence, not scores
No risk score, no letter grade. Each finding carries the file, the span, the matched origin and the reasoning, because that is what stands up when someone else reviews it.
-
Scoped work, not retainers
Engagements are written down before they start and end when the deliverable lands. Re-scans and follow-on tiers are separate pieces of work, quoted the same way.
Working with counsel
Reports written to be handed to a lawyer.
Most audits end up in front of counsel — in-house, outside, or the other side's. Findings are structured for that reading: the component, the licence text that applies, the distribution model assumed, and what changes if that assumption changes. Where an engagement runs under privilege, the practice takes direction from counsel on how findings are recorded and shared.
Using Open Source is the open source audit practice of Bloomsday Group.
Talk to the person who will run the audit.
No qualification call, no sales engineer. Send the shape of the problem and you get a scope and a straight answer about whether an audit is the right spend right now.