Open Source Code Audits / Bill of Materials Audit
Escrow London performs audits of software code bases to detect and identify the existence of open-source code. A detailed report is created identifying open-source code and their corresponding licenses.
A Software Bill of Materials Audit provides an inventory of components that make up a piece of software.
Features
- Ensure open source code licensing compliance
- Identify vulnerabilities in open source code within your software
- Understand what code is embedded in your software
- Software Bill of Materials (SBOM) audit
- Understand what components are included within your software
- Ensure your company adheres to regulatory compliance
- Supporting due diligence for software acquisition
- ISO 5230 OpenChain Implementation
Benefits
- Reduces business software licensing risks
- Reduces IT security risks
- Increase compliance of software licensing
- Reduces Supply Chain Risks
- Increases Consumer Confidence
Pricing
£3,950.00 to £17,950.00 a unit
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
3 1 3 8 8 2 0 7 2 7 6 9 8 7 9
Contact
Escrow London
Evan Lever
Telephone: 020 3862 0380
Email: evan@escrowlondon.com
Planning
- Planning service
- No
Training
- Training service provided
- No
Setup and migration
- Setup or migration service available
- Yes
- How the setup or migration service works
-
Buyers need to understand what potentially problematic third-party code may be embedded within their software if hosted in the cloud.
A cloud-hosted application may contain open source code with vulnerabilities that could be exploited by hackers.
A comprehensive Software Bill of Materials (SBOM) is an extremely important process for any software development organisation. An SBOM can be used to modify open source policies and quickly react to published vulnerabilities. A SBOM lets you know exactly what’s in your code at any point in time. Escrow London can assist your organisation in producing and maintaining your SBOM. - Setup or migration service is for specific cloud services
- No
Quality assurance and performance testing
- Quality assurance and performance testing service
- No
Security testing
- Security services
- Yes
- Security services type
-
- Security strategy
- Security risk management
- Security design
- Cyber security consultancy
- Security testing
- Security incident management
- Security audit services
- Certified security testers
- No
Ongoing support
- Ongoing support service
- No
Service scope
- Service constraints
- No
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
- 4 Hours during business hours 8 Hours during weekends/holidays
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Support levels
- Every client is allocated a technical account manager. We do not charge additional fees for basic support.
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Up to Developed Vetting (DV)
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Citation
- ISO/IEC 27001 accreditation date
- 23/10/2023
- What the ISO/IEC 27001 doesn’t cover
- No exclusions
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- Self certification SAQ-A EP
- PCI DSS accreditation date
- 01/09/2023
- What the PCI DSS doesn’t cover
- No exclusions
- Cyber essentials
- No
- Cyber essentials plus
- No
- Other security certifications
- No
Social Value
- Social Value
-
Social Value
Equal opportunityEqual opportunity
We are an equal opportunity employer and strive for a diverse employee profile.
Pricing
- Price
- £3,950.00 to £17,950.00 a unit
- Discount for educational organisations
- Yes