In August we published Vaultr's OpenChain conformance statement in the trust center. The wording on that page is unusually exact — self-certified, licence compliance, not an audit, not an information-security certification — and this post explains why the precision matters more than the badge.
What OpenChain actually covers
OpenChain is ISO/IEC 5230: a specification for the processes an organisation uses to manage open-source licence compliance across the software it ships. It asks whether you know what licences your dependencies carry, whether you track the obligations they create, and whether you can answer a customer's licence questions from records rather than memory.
Conformance has more than one path. Self-certification — declaring, against the published specification, that your programme meets it — is an officially supported route under the OpenChain programme itself. We chose it because it is the only path our current stage honestly supports.
What it is not
Self-certification is a statement about our own processes. It is not an independent audit, and it is not an information-security certification.
That sentence appears on the trust page and it will keep appearing. Licence compliance and information security are different disciplines with different standards, different evidence and different auditors. A buyer who sees a compliance badge and assumes SOC 2 coverage has been misled by exactly the kind of conflation we publish this site to avoid — ISO/IEC 27001 is a different standard, and we claim no certification against it.
Why exact wording is the point
Every proof row in the trust register carries a status, and ours range from documented to evidence-pending. The OpenChain row says self-attested, because that is what it is. When an independent assessment exists, the wording will change — and until then, the burden is on us to make precision feel like a feature rather than a limitation. For a buyer, precision is the tell: a vendor that scopes its claims tightly is a vendor whose broad claims you can actually use.