Skip to content

Vaultr Journal · Compliance

OpenChain self-certification: what it is, and what it is not 

A licence-compliance conformance statement is not a security certification. We keep the two words apart on purpose.

12 September 2026 · 4 min read

Back to Journal

In August we published Vaultr's OpenChain conformance statement in the trust center. The wording on that page is unusually exact — self-certified, licence compliance, not an audit, not an information-security certification — and this post explains why the precision matters more than the badge.

What OpenChain actually covers

OpenChain is ISO/IEC 5230: a specification for the processes an organisation uses to manage open-source licence compliance across the software it ships. It asks whether you know what licences your dependencies carry, whether you track the obligations they create, and whether you can answer a customer's licence questions from records rather than memory.

Conformance has more than one path. Self-certification — declaring, against the published specification, that your programme meets it — is an officially supported route under the OpenChain programme itself. We chose it because it is the only path our current stage honestly supports.

What it is not

Self-certification is a statement about our own processes. It is not an independent audit, and it is not an information-security certification.

That sentence appears on the trust page and it will keep appearing. Licence compliance and information security are different disciplines with different standards, different evidence and different auditors. A buyer who sees a compliance badge and assumes SOC 2 coverage has been misled by exactly the kind of conflation we publish this site to avoid — ISO/IEC 27001 is a different standard, and we claim no certification against it.

Why exact wording is the point

Every proof row in the trust register carries a status, and ours range from documented to evidence-pending. The OpenChain row says self-attested, because that is what it is. When an independent assessment exists, the wording will change — and until then, the burden is on us to make precision feel like a feature rather than a limitation. For a buyer, precision is the tell: a vendor that scopes its claims tightly is a vendor whose broad claims you can actually use.