What is an AI-generated code licensing review?+
A fixed-scope senior inspection of whether Copilot, Cursor, Claude Code, or similar tools introduced copyleft, proprietary, or otherwise incompatible licensed material into your repository, including snippets that never appeared as a named package. Delivered as written findings, typically within 5–10 business days after read-only access.
Is this legal advice or a license opinion letter?+
No. Engineering findings. Counsel decides whether you can ship, what notices are required, and how to remediate. If you need an opinion letter, that is a law firm. We tell you what is in the tree.
How is this different from running FOSSA, Black Duck, or an SBOM export?+
Those tools are hygiene for declared dependencies. They do not read whether a generated helper is a close copy of GPL code that never became a package. Run the scanner. Do not hand it to a buyer as the license program.
How is this different from the AI Code Audit?+
Same inspection model, access, and timeline. An AI code audit covers security, architecture, compliance, tests, and licensing. This landing is for teams whose forcing function is the open-source folder in diligence, a GPL hit they cannot explain, or an OSS exhibit. Both can convert into the same senior review if the scope widens.
Do you upload our source to a license-detection model?+
No. Client code stays in client environments. Inspection is a named senior engineer. Scanners you already run can stay in CI.
Do we have to ban Copilot or Cursor?+
No. You have to stop pretending a “we do not use GPL” paragraph describes a year of unreviewed assistant output. Ban the tools if you want. Inspect the tree either way.
What licenses do you look for?+
Copyleft and proprietary are the diligence magnets (GPL, LGPL, AGPL, and similar). Permissive licenses (MIT, Apache, BSD) still need notices. We report what we find against the licenses you say the product ships under. We do not invent a forbidden-license list for a stack we have not scoped.
Will this help with M&A or enterprise diligence?+
Yes. Buyers ask how you know AI-assisted code did not introduce licenses you cannot ship. A severity-ranked findings report from a named engineer is the artifact. A policy PDF is not.
We handle PHI. Can you still do this?+
The copyleft question stays. The access model is not a generic SaaS review. Say PHI on the scoping call. Healthcare product work is Maxiom Labs (https://www.maxiomlabs.com/).
How do we start?+
A 30-minute scoping call, then written scope and NDA. Read-only repository access. Initial findings typically within five business days after access, full report and debrief commonly inside 5–10 business days.