Software Escrow Verifier
The deposit is 170 days old and matches 11 of 24 repository files (45.8%): 4 build-critical and 3 other files missing, 6 files changed, 2 releases never deposited.
Deposited 2026-04-07, 170 days before the as-of date 2026-09-24. An update is required every 90 days, so it was due 2026-07-06: 170 - 90 = 80 days overdue.
Method1Files are compared by path (normalized to forward slashes) and SHA-256. A different hash on the same path means the deposited copy is out of date.
2Build-critical files: build scripts (Makefile, pom.xml, build.gradle, pyproject.toml, package.json, *.csproj), dependency lock files (poetry.lock, package-lock.json, yarn.lock, go.sum, Cargo.lock, requirements*.txt), container definitions (Dockerfile, compose files), CI configuration (.github/workflows, .gitlab-ci.yml, Jenkinsfile) and database migrations (migrations/, db/migrate/, alembic/versions/, Flyway V__ scripts).
| Severity | Issue | Path |
|---|---|---|
| High | Deposit older than update frequency | (whole deposit) |
| High | Release not deposited | v4.2.1 |
| High | Release not deposited | v4.3.0 |
Escrow deposit manifest, plus a git log or file inventory
Deposit gap report and a cure notice to the vendor (Cure notice to the depositor, Deposit gap report (CSV))
$3,000 / month, 30% to the referring partner
Read in memory for the session, never stored, never used to train a model.
Letters, notices and legal analysis are drafts, not legal advice. Have a qualified lawyer review them before they are sent or relied on.