One method: lawyer, engineer and consultant in the same room.
Client identities are withheld and identifying details generalised. Each engagement combined qualified legal analysis, hands-on compliance engineering, and management consultancy — the Orcro trio.
Open source strategy and capability roadmap
Challenge
An OpenChain gap analysis for a re-architected cloud platform, plus a review of the Open Source Program Office — with everything required to be transaction-ready ahead of an anticipated liquidity event within three years.
Approach
We deployed our OpenChain Capability Maturity Model across twelve organisational disciplines: legal analysis of supply chain obligations, warranties and indemnities; engineering assessment of pipeline automation and SCA toolchains; and a maturity evaluation mapped to the client’s existing corporate OKRs.
Multi-jurisdictional regulatory alignment at platform scale
Challenge
Facing the EU Cyber Resilience Act, DORA, and SBOM mandates simultaneously, the client needed a standardised global approach to container-image compliance and sandbox-environment governance — without slowing rapid engineering deployment cycles.
Approach
Engineering analysis of dense repository architectures, with open source compliance containers built to automate licence validation; legal interpretation of how emerging regulation bears on the mobile open source ecosystem and AI-driven agentic systems; and a uniform, audit-ready framework synthesised for executive leadership.
Financial-infrastructure, audit, code and AI licensing
Challenge
Highly sensitive cross-border financial-infrastructure proofs-of-concept involving multi-party codebases, requiring data-sharing guidelines, IP terms, and AI-model licensing parameters that satisfy multiple sovereign legal regimes at once.
Approach
Meticulous code and architectural review of advanced cloud and container environments; structured statements of work and advisory papers on AI and data-governance models; operational design validated against international institutional governance criteria.
M&A transaction readiness under deal pressure
Challenge
Ahead of a nine-figure acquisition, investors demanded bulletproof verification of IP clean lines in the proprietary codebase to support stringent representations and warranties.
Approach
Rather than a static code-scan report that offers little commercial comfort, we applied ISO/IEC 5230 to evaluate the underlying engineering processes: technical risk diagnostics paired with transactional legal analysis of weak points in the historical software pipeline.
Copyleft bottleneck turned market differentiator
Challenge
Acting for a venture capital firm steering an exit, due diligence flagged copyleft dependencies embedded deep in the platform’s core processing engine — threatening to stall the entire transaction.
Approach
Instead of recommending costly engineering rewrites, we advised the board to intentionally open-source the core engine under a strategic framework — eliminating the compliance bottleneck while increasing developer adoption — and restructured the technical architecture to match.
Finding what the scanners missed
Challenge
Integrating third-party software into safety-critical automotive systems, the client’s automated SCA tooling reported no major risks — yet leadership felt exposed on unknown sub-tier supply chain liabilities.
Approach
Recognising that automated scans routinely miss deeply layered custom distributions, we ran an OpenChain-based process audit. The deep-dive revealed the vendor was shipping an entire embedded Linux stack with zero compliance documentation or licensing coverage.
A market-first W&I insurance product for open source risk
Challenge
The insurer wanted to underwrite open source software risk in technology M&A through a novel warranties-and-indemnities product — but lacked any reliable methodology to quantify an organisation’s software process health.
Approach
We integrated ISO/IEC 5230 directly into underwriting parameters, building a risk-profile matrix on our Capability Maturity Model with technical benchmarking criteria — letting underwriters assess process health objectively rather than relying on an unreliable code snapshot.
[Consider ditching/rephrasing for accuracy]Research-infrastructure architecture and governance review
Challenge
Vast volumes of complex geospatial and environmental data flowing through a polyglot open source stack, requiring end-to-end architectural evaluation against modern security, governance, and open-data licensing standards.
Approach
Extensive pipeline and codebase analysis to deconstruct the architecture, bridged with legal oversight into custom legal-technical briefing notes covering cloud governance, structural security risk, and open scientific compliance standards.
“Open Source 2.0” across a multinational
Challenge
Baseline licence compliance had been achieved, but every division ran conflicting processes, tooling, and risk criteria. The executive suite wanted lasting cross-divisional consistency, community leadership, and unified supply chain KPIs.
Approach
Our CMM dashboard deployed across the multinational footprint — but through multi-tier stakeholder workshops mapping expectations across hundreds of engineering teams, not top-down dictate, paired with licence-enforcement guardrails designed by our legal and engineering leads.
[links to project]The Eclipse Corinthian Project: industry-wide legal precedents for open source M&A
Challenge
Corporate transactions everywhere are slowed by fragmented, inconsistent legal questionnaires and ill-fitting representations and warranties around open source risk. The ecosystem needed a vendor-neutral repository of legal precedents for multi-jurisdictional due diligence.
Approach
Orcro co-founded and drove the architectural design of the Corinthian Project, authoring the inaugural legal precedents, templates, and due-diligence question sets — anchored directly to ISO/IEC 5230.
Developer compliance enablement across borders
Challenge
High-consequence open source projects developed by distributed cross-border teams, with institutional IP to protect and compliance fragmentation to prevent. The hard part: turning abstract licensing theory into daily engineering practice developers actually embrace.
Approach
A licence-compatibility framework and custom compliance matrices built for international research collaboration, mapped live onto automated scanning tools in interactive developer workshops — legal instruction and toolchain engineering delivered together.
Licensing strategy for decentralised infrastructure
Challenge
Ecosystem partners needed to map traditional permissive and copyleft frameworks onto distributed-ledger architectures, smart-contract execution, and dual-licensing models — without stifling community innovation.
Approach
Definitive guidance on decentralised licensing, token governance, and smart-contract IP boundaries, alongside practical pipeline integration of code scanning within containerised microservices — aligned to the partners’ enterprise scaling and maturity frameworks.
Seem familiar? Like what you see?
Tell us which — and we’ll tell you, plainly, what it would take to make it defensible.
get_in_touch →[fix button]