Open source software in your product: what the terms need to say

An explanation of what customer terms need to say about the open source in a software product, with the fixed-fee drafting of those provisions at £995 in five working days.

Share

Open source software in your product: what the terms need to say

An explanation of what a software business's customer terms need to say about the open source components in its product, and the drafting of those provisions, covering the licences and what they require, copyleft and the difference between distribution and SaaS, disclosure of components to customers, warranties and indemnities that carve out open source, the customer's obligations when it distributes the product, contributions and the business's own policy, and the position for consumers. £995, delivered in five working days.

Buy now, £995

Every software product contains open source, and every set of customer terms has to say something about it: what the components are, what their licences require of the business and of the customer, that the business does not warrant code it did not write, and, for copyleft licences, whether the product is distributed in a way that triggers their obligations at all. This page sets out what the terms need to say, and I draft the provisions, within a set of customer terms or as a supplement to yours, for a fixed fee of £995, delivered in five working days.

Who this is for

Software businesses in England and Wales whose products, whether SaaS, downloadable, embedded or delivered as source, include open source libraries and frameworks, and whose customers, investors or acquirers ask what the terms say about them.

What the terms need to say about open source

The licences and what they require

Open source components are copyright works licensed under their own terms under the Copyright, Designs and Patents Act 1988, and the terms should say that those components are provided under those licences, which prevail over the business's terms for the components, that the customer receives the rights the licences grant and no more from the business, and where the licences require it, that notices, attributions and licence texts are provided with the product; permissive licences ask for little beyond attribution, and the terms should meet even that, because a business that ignores attribution has breached the licence it depends on.

Copyleft, distribution and SaaS

Copyleft licences such as the GPL require that software incorporating the component and distributed to others is made available under the same licence, which for a downloadable or embedded product can mean the business's own code; providing a service over a network is not distribution under most such licences, so a SaaS product can use copyleft components without releasing its code, except under licences written for network use, of which the AGPL is the main one. The terms should reflect the decision the business has made: which components are used, how the product is delivered, and whether the customer receives source code and rights as a result.

Disclosure of components to customers

The terms should provide that the business will make available a list of the open source components in the product and their licences, in the documentation, in the product, or on request, and should say that the list may change with releases; enterprise customers and acquirers ask for the list, and a business that can produce it has answered the question that decides whether its IP is what it claims. The list should be maintained from the build rather than written for the occasion.

Warranties and indemnities that carve out open source

The business's warranty that the product does not infringe third-party rights, and its indemnity for infringement claims, should exclude the open source components, which are licensed as they are by their authors without warranty, and should exclude claims arising from the customer's combination of the product with other software; the business warrants what it wrote and that it has complied with the licences for the rest. Against a business customer those exclusions are tested for reasonableness under section 3 of the Unfair Contract Terms Act 1977, and identifying the components makes the exclusion reasonable.

The customer's obligations when it distributes the product

Where the customer may distribute the product or embed it in its own (a reseller, an OEM, a developer using an SDK), the terms should require the customer to comply with the open source licences in its own distribution, to preserve notices, to provide source code where a licence requires it, and not to combine the product with copyleft code in a way that would subject the business's code to that licence, with an indemnity for breach; a customer that triggers a copyleft obligation for the business's code has done something the business cannot undo.

Contributions, the business's policy and consumers

The terms should say that the business may contribute fixes to open source projects without disclosing customer information, that customers who contribute code or feedback to the product license it to the business, and, where the business releases its own code under an open source licence, that the licence governs that code. Consumers' rights in digital content under section 34 of the Consumer Rights Act 2015 apply to the product as a whole regardless of the components' licences, so a consumer-facing product cannot use open source disclaimers to exclude the statutory remedies, and the terms should keep the consumer and business provisions apart.

What it costs

SaaS or technology contract, £995. One contract drafted for how your product or service is sold, delivered and supported. Five working days.

Buying online forms the engagement on payment. The scope is what the saas and technology contracts page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • A bespoke contract drafted for how your product is sold, delivered and supported
  • Service levels you can meet, with remedies that are proportionate rather than aspirational
  • A liability position that is defensible and will survive enterprise procurement
  • IP and data provisions that fit together rather than contradicting each other
  • A commercial note on where you will get pushback and what is worth conceding
  • One round of amendments

What is not included

  • Negotiating individual enterprise deals, which I quote separately
  • Advice on the law of jurisdictions outside England and Wales
  • Technical security certification or audit
  • Regulatory advice for regulated sectors such as financial services or health

Questions I am often asked

We use GPL libraries in our SaaS product. Do we have to release our code?

Generally not, because providing a service over a network is not distribution under the GPL, unless a component is under the AGPL or a similar network licence. The terms reflect the decision, and the component list is what supports it.

An acquirer's lawyers want our open source list. What if we do not have one?

Build it from the product's dependencies now; the terms commit the business to making it available, and an acquirer's due diligence will not proceed without it.

Can we give an IP indemnity that covers the whole product?

You can, but it is unusual and expensive, because the open source components are outside your control. The terms carve them out and warrant compliance with their licences instead, which is what most customers accept.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: September 2026. Email geoffrey@caesar.co.uk.