Skip to content
CLEARANCE
Licence clearance for AI-built stacks

Your code is Apache-2.0.
Your weights are CC-BY-NC.
You cannot ship.

That sentence is the entire product. Every other licence tool reads one of the five places an obligation hides. Clearance reads all five and returns a decision — with the clause, the file and the line where it lives, and an honest confidence level.

No account No network calls in --offline Single static binary
clearance check . — my-saas
~$ clearance check .

CLEARANCE VERDICT — my-saas
========================================
SHIP:        DO NOT SHIP
BLOCKERS:    1
CONDITIONS:  2
SCANNED:     47 dependencies · 3 weight files · 2 upstream CLIs
CORPUS:      2026.09.2 · signed ✓

[BLOCK]   firecrawl                    AGPL-3.0-only
          clause:  LICENSE §13 (network use)
          reason:  you run a MODIFIED version and expose it over HTTP
          evidence: node_modules/firecrawl/LICENSE:1-9
          fix:     swap to crawl4ai (Apache-2.0, same capability)
          confidence: HIGH

[COND]    kokoro-82m                   Apache-2.0 (code AND weights)
          note:    clean commercial path; attribution required

[COND]    hey-gem weights              Custom community licence
          note:    >1k MAU triggers a commercial gate
          evidence: LICENSE.md §3.2
          confidence: MEDIUM — clause text is ambiguous

---
This is an informational finding based on the licence text as published on the
date recorded. It is not legal advice. Ambiguous clauses are flagged as such.
Important decisions should be reviewed by a qualified professional.

~$ 
01

The answer is distributed across five places.
No single tool reads them together.

The problem was never that licences are hard to find. It is that "can I ship this?" depends on five documents, and the one that blocks you is rarely the one you checked.

01
The code licence
AGPL-3.0 §13 — run a modified version as a network service and you must offer the Corresponding Source to every user who touches it. Network use alone is not the trigger; network use plus modification is. Almost everyone gets this backwards.
read by: Snyk, FOSSA, ScanCode
02
The model-weights licence
A permissively licensed inference repository loading weights under CC-BY-NC-4.0. No commercial use — and nothing in the code licence tells you that. The weights file is a dependency with its own terms, and it lives in a different document.
read by: nobody
03
The platform ToS
A repository that orchestrates a third-party CLI inherits that platform's terms. Cookie-based access to a service whose ToS prohibits automation is a licence problem, not a coding problem.
read by: nobody
04
Excluded brand assets
Name, logo and icon are frequently reserved even where the code is free. A fork may be required to rebrand — a condition nobody writes down, and one that shows up in a trademark complaint rather than a build failure.
read by: nobody
05
Territorial clauses
Commercial use permitted in some jurisdictions, requires prior application in others. Your verdict depends on where you sell — which is a fact only you can declare.
read by: nobody

02

The check no competitor runs

Weight files are detected by magic bytes, not by extension. Licences are resolved from GGUF metadata, config.json and model-card frontmatter. Then Clearance compares the code licence against the weights licence — and says so when they disagree.

code-vs-weights divergence Do not ship
Code licence
Apache-2.0 High
LICENSE:1–4

Permissive. Commercial use, modification and distribution all permitted.

Weights licence
CC-BY-NC-4.0 High
model-card.md:12

Non-commercial only. The NC clause is unambiguous.

Divergence. The repository's licence permits everything you need. The weights it downloads do not. A code-only scanner returns SHIP here, and it is wrong in the direction that costs money.
Detected by
Magic bytes.safetensors .gguf .onnx
GGUF metadatalicence key
config.json_name_or_path
Model cardYAML frontmatter
Sibling LICENSEfilename + text hash
If none of those resolve

The file is not ignored. It becomes Undetermined and the verdict cannot be SHIP. Unknown never rounds toward a pass — that is the single most dangerous behaviour in this category, and every SCA tool exhibits it.


03

Four rules. Six properties. One test each.

The decision layer is pure — no I/O, no clock, no randomness — so the same inputs produce a byte-identical verdict. These are the rules, in order, and the first one that matches wins.

The fold
01any HIGH-confidence blockerDO NOT SHIP
02else, any undeterminedUNDETERMINED
03else, any conditionSHIP CONDITIONAL
04elseSHIP
A LOW-confidence finding can never block a build. An uncertain reading must not fail someone's pipeline — that is how a compliance tool becomes a liability.
Formal properties, each with a named test
PropertyTest
A blocker dominates everything below itTestBlockerDominates
Unknown outranks a conditionTestUndeterminedBeatsCondition
Unknown never collapses to SHIPTestUnknownNeverShips
LOW confidence cannot blockTestLowConfidenceNeverBlocks
The fold is order-independentTestFoldCommutative
Identical inputs produce identical outputTestVerdictDeterminism

04

What it will never do

A tool that produces verdicts has to be defined as much by its refusals as its features. These are not roadmap items. They are the product's boundaries.

Never
Execute your code

No os/exec on project files. No build. No test run.

Run a package manager

Dependencies are read from committed lockfiles, never installed.

Phone home

Zero telemetry. --offline makes zero outbound calls, enforced by test.

Scan for vulnerabilities

Clearance is about permission, not exploits. Hard boundary.

Always
Cite or stay silent

No citation, no finding. A test asserts it on every rendered finding.

State confidence

Every finding carries HIGH, MEDIUM or LOW. A MEDIUM is never shown as certain.

Carry the disclaimer

Present in every human and Markdown output. Enforced by TestDisclaimerPresent.

Say when it does not know

UNDETERMINED is a first-class verdict, not an error.

And published

When a verdict is wrong, there is a public process for it: how to report it, what happens next, how fast the corpus changes, and what the changelog entry looks like.

corpus changelog correction record 24h triage
Read the process

A confidence level may never rise without a correction block in the corpus — E-CORPUS-006 refuses to load the entry otherwise. Confidence laundering is a build error here.


05

Every entry in the corpus was read out of the licence text by a human

This is the most unusual thing about the project, so it is on the landing page rather than buried in a roadmap. If the traps are not real, the product should not exist — so the corpus is small, hand-written, and cited, rather than scraped.

What the corpus holds today

Twelve licences and twelve traps, every one of them read out of the actual document and carrying a citation to the clause it came from. A verdict is only as good as this data.

12
licences
12
traps
82
citations

The corpus is not throwaway work. Adding an entry is a data change, not a code change: the judgement lives in the YAML, so a wrong interpretation is fixed by editing it rather than by shipping a new binary.

Why this is on the homepage

Every tool in this category launches with a feature list. Clearance launches with the data its verdicts are made of, and the method used to write it.

A tool launch says "here is a CLI" and asks for trust before use. Publishing the corpus says "here is exactly what we will judge you against" and lets you check it yourself.

The corpus is deliberately small. Twelve licences and twelve traps, each with a citation, is something one reader can check in an afternoon. A scraped list of thousands of entries is not, and the verdicts it produces cannot be defended.


06

What the existing tools do

Snyk, FOSSA, Black Duck, Mend, FOSSology and ScanCode are good at what they do. What they do is produce a report, for a legal team, priced for an enterprise.

Dimension
SCA / SBOM tooling
Clearance
Output
A report. A list of licences and obligations to interpret.
A verdict — SHIP, SHIP CONDITIONAL, DO NOT SHIP, UNDETERMINED.
Layers read
Code licence. One of the five.
Code, weights, platform ToS, excluded assets, territories.
Price of entry
"Contact sales." Enterprise floor around $799/month.
Free to use. Source-available under FSL-1.1-ALv2 — it is not open source.
Audience
Legal and AppSec teams.
The person who built the thing and cannot afford a lawyer.
When unknown
Frequently rounds toward a pass.
Returns UNDETERMINED. Unknown never rounds toward SHIP.
Weights
Not modelled.
Detected by magic bytes. Divergence checked against the code licence.

The one sentence a competitor cannot honestly write: "We will tell you a dependency is unsafe to ship, even when that answer costs us the sale." A per-dependency verdict has no room to soften an answer.


Start here

Point it at a project.
Get a decision.

One binary. No account, no server, no configuration you did not write yourself. The first run tells you what it could not classify — which is usually the most useful line in the output.

install
# linux amd64. darwin and windows builds are on the same path.
~$ curl -fsSLO https://clearancedev.vercel.app/dl/clearance_0.1.0-rc.2_linux_amd64.tar.gz
~$ tar -xzf clearance_0.1.0-rc.2_linux_amd64.tar.gz
~$ ./clearance version

# the signed corpus is in the archive, beside the binary
~$ clearance check .