§ in practice selected engagements, anonymised

One method: lawyer, engineer and consultant in the same room.

Client identities are withheld and identifying details generalised. Each engagement combined qualified legal analysis, hands-on compliance engineering, and management consultancy — the Orcro trio.

§C-01

Open source strategy and capability roadmap

Client European enterprise process-automation software vendor · Scope Germany / global · Duration 2 months, 24-month phased roadmap

Challenge

An OpenChain gap analysis for a re-architected cloud platform, plus a review of the Open Source Program Office — with everything required to be transaction-ready ahead of an anticipated liquidity event within three years.

Approach

We deployed our OpenChain Capability Maturity Model across twelve organisational disciplines: legal analysis of supply chain obligations, warranties and indemnities; engineering assessment of pipeline automation and SCA toolchains; and a maturity evaluation mapped to the client’s existing corporate OKRs.

Outcome: a three-year strategic roadmap that makes compliance maturity a measurable input to exit-readiness, not a deal-room surprise.
[number 1 on the list]
§C-02

Multi-jurisdictional regulatory alignment at platform scale

Client Global consumer technology and digital-entertainment group · Scope Global · Duration Ongoing, multi-phase

Challenge

Facing the EU Cyber Resilience Act, DORA, and SBOM mandates simultaneously, the client needed a standardised global approach to container-image compliance and sandbox-environment governance — without slowing rapid engineering deployment cycles.

Approach

Engineering analysis of dense repository architectures, with open source compliance containers built to automate licence validation; legal interpretation of how emerging regulation bears on the mobile open source ecosystem and AI-driven agentic systems; and a uniform, audit-ready framework synthesised for executive leadership.

Outcome: regulatory theory translated into engineering reality — one compliance posture across jurisdictions, no deployment slowdown.
§C-03

Financial-infrastructure, audit, code and AI licensing

Client International financial-sector institution · Scope Cross-border · Duration Long-term partnership

Challenge

Highly sensitive cross-border financial-infrastructure proofs-of-concept involving multi-party codebases, requiring data-sharing guidelines, IP terms, and AI-model licensing parameters that satisfy multiple sovereign legal regimes at once.

Approach

Meticulous code and architectural review of advanced cloud and container environments; structured statements of work and advisory papers on AI and data-governance models; operational design validated against international institutional governance criteria.

Outcome: multi-party innovation projects that proceed at pace because the legal and licensing groundwork holds under sovereign-level scrutiny.
§C-04

M&A transaction readiness under deal pressure

Client Market-leading vertical document-management provider · Scope UK / global · Duration Intensive, transaction-driven

Challenge

Ahead of a nine-figure acquisition, investors demanded bulletproof verification of IP clean lines in the proprietary codebase to support stringent representations and warranties.

Approach

Rather than a static code-scan report that offers little commercial comfort, we applied ISO/IEC 5230 to evaluate the underlying engineering processes: technical risk diagnostics paired with transactional legal analysis of weak points in the historical software pipeline.

Outcome:[consider remediation plan] an exit-ready baseline that protected asset valuation and expedited deal closure.
§C-05

Copyleft bottleneck turned market differentiator

Client VC-backed digital training platform · Scope Australasia · Duration 3 months

Challenge

Acting for a venture capital firm steering an exit, due diligence flagged copyleft dependencies embedded deep in the platform’s core processing engine — threatening to stall the entire transaction.

Approach

Instead of recommending costly engineering rewrites, we advised the board to intentionally open-source the core engine under a strategic framework — eliminating the compliance bottleneck while increasing developer adoption — and restructured the technical architecture to match.

Outcome: an existential transactional hurdle converted into a differentiator that satisfied incoming investors.
§C-06

Finding what the scanners missed

Client Tier 1 automotive and smart-mobility manufacturer · Scope Global supply networks · Duration 4 months

Challenge

Integrating third-party software into safety-critical automotive systems, the client’s automated SCA tooling reported no major risks — yet leadership felt exposed on unknown sub-tier supply chain liabilities.

Approach

Recognising that automated scans routinely miss deeply layered custom distributions, we ran an OpenChain-based process audit. The deep-dive revealed the vendor was shipping an entire embedded Linux stack with zero compliance documentation or licensing coverage.

Outcome: a remediation roadmap imposed on the vendor — supply chain secured without disrupting production timelines.
§C-07

A market-first W&I insurance product for open source risk

Client International specialty B2B insurer · Scope UK / EU · Duration 6 months

Challenge

The insurer wanted to underwrite open source software risk in technology M&A through a novel warranties-and-indemnities product — but lacked any reliable methodology to quantify an organisation’s software process health.

Approach

We integrated ISO/IEC 5230 directly into underwriting parameters, building a risk-profile matrix on our Capability Maturity Model with technical benchmarking criteria — letting underwriters assess process health objectively rather than relying on an unreliable code snapshot.

Outcome: a brand-new insurance offering with materially reduced operational risk for the underwriter.
§C-08

[Consider ditching/rephrasing for accuracy]Research-infrastructure architecture and governance review

Client National environmental research institution · Scope UK · Duration 3 months

Challenge

Vast volumes of complex geospatial and environmental data flowing through a polyglot open source stack, requiring end-to-end architectural evaluation against modern security, governance, and open-data licensing standards.

Approach

Extensive pipeline and codebase analysis to deconstruct the architecture, bridged with legal oversight into custom legal-technical briefing notes covering cloud governance, structural security risk, and open scientific compliance standards.

Outcome: automated data-delivery pipelines aligned with state-of-the-art governance — and documentation the institution can defend.
§C-09

“Open Source 2.0” across a multinational

Client Global diversified enterprise technology corporation · Scope Global · Duration 12 months

Challenge

Baseline licence compliance had been achieved, but every division ran conflicting processes, tooling, and risk criteria. The executive suite wanted lasting cross-divisional consistency, community leadership, and unified supply chain KPIs.

Approach

Our CMM dashboard deployed across the multinational footprint — but through multi-tier stakeholder workshops mapping expectations across hundreds of engineering teams, not top-down dictate, paired with licence-enforcement guardrails designed by our legal and engineering leads.

Outcome: cultural alignment plus guardrails — a sustainable continuous-improvement loop rather than a compliance binder on a shelf.
§C-10

[links to project]The Eclipse Corinthian Project: industry-wide legal precedents for open source M&A

Client Eclipse Foundation — The Corinthian Project · Scope Global ecosystem · Duration Collaborative industry initiative, launched at FOSDEM

Challenge

Corporate transactions everywhere are slowed by fragmented, inconsistent legal questionnaires and ill-fitting representations and warranties around open source risk. The ecosystem needed a vendor-neutral repository of legal precedents for multi-jurisdictional due diligence.

Approach

Orcro co-founded and drove the architectural design of the Corinthian Project, authoring the inaugural legal precedents, templates, and due-diligence question sets — anchored directly to ISO/IEC 5230.

Outcome: a collaborative repository now shaping international due-diligence practice at the intersection of open source law and process.
§C-11

Developer compliance enablement across borders

Client Multi-national research-infrastructure collaboration · Scope Pan-European · Duration Long-term recurring

Challenge

High-consequence open source projects developed by distributed cross-border teams, with institutional IP to protect and compliance fragmentation to prevent. The hard part: turning abstract licensing theory into daily engineering practice developers actually embrace.

Approach

A licence-compatibility framework and custom compliance matrices built for international research collaboration, mapped live onto automated scanning tools in interactive developer workshops — legal instruction and toolchain engineering delivered together.

Outcome: distributed engineers who detect and resolve licence incompatibilities autonomously, as part of the workflow.
§C-12

Licensing strategy for decentralised infrastructure

Client European blockchain innovation network · Scope EU · Duration Intensive masterclass engagement

Challenge

Ecosystem partners needed to map traditional permissive and copyleft frameworks onto distributed-ledger architectures, smart-contract execution, and dual-licensing models — without stifling community innovation.

Approach

Definitive guidance on decentralised licensing, token governance, and smart-contract IP boundaries, alongside practical pipeline integration of code scanning within containerised microservices — aligned to the partners’ enterprise scaling and maturity frameworks.

Outcome: a governance strategy that holds at the bleeding edge, delivered as training the ecosystem could operationalise immediately.

Seem familiar? Like what you see?

Tell us which — and we’ll tell you, plainly, what it would take to make it defensible.

get_in_touch →[fix button]