Vendor offers open-source code insurance

31.10.2005
Software license compliance analysis vendor Open Source Risk Management Inc. (OSRM) is adding insurance coverage to its offerings to help businesses ensure the open-source license integrity of software companies they acquire or applications they are using internally.

In an announcement Monday, New York-based OSRM said it will offer insurance policies of up to US$10 million to help protect businesses from legal risk involving open-source code in certain situations. OSRM has partnered with London-based insurance underwriting company Kiln PLC and Lloyd's of London insurance broker Miller Insurance Services Ltd. to offer the insurance program.

Daniel Egger, CEO of OSRM, said the three companies are aiming their new insurance offering at specific needs, including software development companies that want to be sure the open-source components that they incorporate into proprietary applications are being used properly within their open-source licenses. "It comes up in special circumstances," Egger said, including when software companies acquire other vendors and want to ensure that the product lines they are buying comply with licenses for included open-source code.

The insurance costs about $20,000 for $1 million in coverage, or about 2% of the desired coverage amount.

The issue for many software companies, Egger said, is that they sometimes use open-source software in proprietary applications without regard to whether the use could conflict with open-source software licenses. "There are plenty of ways to link into open-source software that won't trigger any alarms" involving licenses, he said.

According to OSRM, one common scenario involves proprietary software, such as trading tools or inventory management applications that use one or more open-source components. By making the tools available on a company extranet or sending them to external partners or suppliers, a company could be seen as distributing the code -- a violation of the open-source General Public License unless the company also makes the modified code freely available to competitors, according to OSRM.