Live data from Hacker News

Ask HN: Huge enterprise customer wants to see our source code

news.ycombinator.com

81–90 of 293 posts

Re: Ask HN: Huge enterprise customer wants to see our source code

#81
You can find templates for proprietary information agreements at EveryNDA:

Defeat the Confusion: Confidentiality v. Non-Disclosure

https://everynda.com/blog/confidentiality-v-non-disclosure/

Examples of Microsofts Shared Source licensing can be found as well. These contracts are typically reserved for heavy hitters. Who have enhanced security or performance requirements. FBI, JP Morgan, etc. And of course Microsoft has open sourced large portions of its own dev tools and sdks.

Microsoft Shared Source Initiative

https://www.microsoft.com/en-us/sharedsource/

I think what you may begin to realize is that its their alternative data that represents the motherload. And its not your algorithms but level of service that will differentiate you. The insights mined from that alternative data may be so valuable as to outweigh your other concerns. And gaining access to it might be the paramount mission for your startup. As the executive, ultimately its your call. Good luck!

https://blog.quandl.com/category/alternative-data

Re: Ask HN: Huge enterprise customer wants to see our source code

#82
According to to their stated motivation, they're not actually interested in the source code: they want to know how your software makes decisions, presumably important ones on behalf of their business. The people who articulate such a request (management), as a rule, are not qualified to answer it by looking at the source code. If that is indeed their concern, they've probably filtered it through their internal development shop, who's come up with the idea that they could review the source code and answer. Management thought that was a splendid way to do it - no need to bother you guys with such tedious busywork (OK, probably slightly rose-tinted, but the general outline of the narrative is plausible).

If this understanding is what they're really after, then that's what you need to think about answering. Worrying about ML as an opaque black box is a bit of a thing these days, so it will probably come up with future clients as well.

If you answering this is not satisfying to them, and they keep insisting on the source code, and they can't articulate why, then they are not being honest, and you should walk away (or at least clearly state that if they don't withdraw that requirement, there will be no agreement).

Re: Ask HN: Huge enterprise customer wants to see our source code

#83

Earlier quoted context omitted.

I work for an enterprise company and we demand the source code for machine learning models from vendors all the time. This isn't like asking for the code to Excel. It's a model derived from our data that has likely no use for anyone but us and is highly susceptible to misunderstandings of the data. We absolutely need to verify your work. Models are the output of the process. It's like going to graphic designer for wo…

> You clearly have no idea what you're talking about. I have no idea what I'm talking about in this specific niche either... but does it normally go over well when you start a conversation that way?

The parent comments author has this in the profile:

>about: CEO at http://www.3scale.net

I'd venture to say there is at least some qualification to answer here.

Re: Ask HN: Huge enterprise customer wants to see our source code

#84
post #3

This is a complete no-no. There really is no justification for this whatsoever. What does "cover their bases" mean? As them to explain what they are trying to achieve and find other ways to assuage their concerns. The only legitimate thing is to have something in case you fail and they have "banked" on you. There is a legit way to solve that. basically if they want that tell them they should pay for an Escrow service…

It's entirely unreasonable for them to demand access to source code. The government and large corporations apparently disagree, or Microsoft wouldn't have their Shared Source Initiative. And for any nay-sayers in the crowd, that should be all that need be known: Microsoft thinks it's okay, and they have a lot more to lose than you do. The only legitimate thing is to have something in case you fail and they have "bank…

Microsoft also has enough legal resources to assure recompense for any license or ip violations...

Re: Ask HN: Huge enterprise customer wants to see our source code

#85

Well, having worked for a small software startup that did just that, I can tell you what we did. We agreed to letting them audit the code with conditions. 1. The audit happened on our computers with someone from our team in control (me). I locked the computer when I wasn't physically there to watch what they did. 2. We removed the most sensitive part of the code and told them what it did. We kept the method signature…

I've done this too. The question is usually a matter of compliance more than anything else. They want to check the licenses of any included packages, makes sure there's no encryption stuff that can't leave the USA, etc. Doing what OP described is great: it lets their folks do the audit with no risk of you loosing "ownership". It shows you are both a good partner and value what you do.

License compliance is incredibly important and unfortunately overlooked by many smaller firms. The potential liability to a GPL or other violation is just not worth it.

Anecdote: We have released code under the Apache 2 License (our biggest project by far is https://github.com/sheetjs/js-xlsx) and we've been roped into negotiations because some companies tried to take shortcuts by copying our code without proper attribution.

Re: Ask HN: Huge enterprise customer wants to see our source code

#86
post #78

I used to work for a company that did model risk management consulting for large banks and source code reviews were a standard part of what we did. What sounds different from the OPs situation is that it is the customer who would be conducting the review and not a third party. Take everything you read here with a grain of salt but it would be best to consult a lawyer. Even if you hold the patents for what your softwa…

Good point. If the OP company is doing something they can't then how are they going to know its fit for purpose? From my experience the big guys don't really have those skills in house OR the ability to organise said skills in a timely fashion.

Re: Ask HN: Huge enterprise customer wants to see our source code

#87
post #3

This is a complete no-no. There really is no justification for this whatsoever. What does "cover their bases" mean? As them to explain what they are trying to achieve and find other ways to assuage their concerns. The only legitimate thing is to have something in case you fail and they have "banked" on you. There is a legit way to solve that. basically if they want that tell them they should pay for an Escrow service…

It's entirely unreasonable for them to demand access to source code. The government and large corporations apparently disagree, or Microsoft wouldn't have their Shared Source Initiative. And for any nay-sayers in the crowd, that should be all that need be known: Microsoft thinks it's okay, and they have a lot more to lose than you do. The only legitimate thing is to have something in case you fail and they have "bank…

Bringing up Microsoft is neither here nor there.

Microsoft made the decision to create Shared Source Initiative only after they were very successful and only after a very, VERY detailed cost vs. benefit analysis.

Furthermore, they are handsomely paid for it (e.g in order to be eligible, you need to pay for at least 10k Windows licenses as per https://www.microsoft.com/en-us/sharedsource/enterprise-sour...) and it's ultimately up to Microsoft to grant/deny access.

And since we're talking about Microsoft, in the early days they were infamous for pumping competition for technical information under the guise of due diligence and then crushing said competition by developing competing products.

The person who asked the question is clearly not at the "successful monopoly" stage as Microsoft but more in the "there are legitimate concerns someone might steal our core ip" stage.

Re: Ask HN: Huge enterprise customer wants to see our source code

#88
Another data point, but I worked for a company that made an expensive DSS for a very lucrative industry. We showed a potential "partner" our code and how it worked and everything. They took our ideas and made their own product as a direct competitor. Reminded me of Apple and Xerox.

Definitely get legal council involved.

A possible way to protect yourself is print it out and put it in old fashioned binders and let them see the binder while you are watching. Not sure if that will fly, but it would be hard(er) for them to steal it. Tell the company your concerns (which are valid) and what methods they would accept. I don't think it's unreasonable for you to bring it up with them.

Re: Ask HN: Huge enterprise customer wants to see our source code

#89
post #80

I'll offer a different pov from many other comments. I work for a fortune 50 basically doing web server stuff. Right now our security team would like to run some startups code synchronously as a module in our web server. Their code could easily cost us millions off dollars (if the outage was small). I need to make sure their sdk is free of race conditions, and has proper timeouts and throttling and has proper metrics…

Are you going to audit all of their code changes from now into perpetuity as well? It seems like you kinda alluded to the thing that would actually be effective, which is not synchronously calling external services in high-uptime-requirement applications...

fantastic question. Just because the software complied with the requirements at one point doesn't mean it will in the future.

Re: Ask HN: Huge enterprise customer wants to see our source code

#90
post #85

Earlier quoted context omitted.

I've done this too. The question is usually a matter of compliance more than anything else. They want to check the licenses of any included packages, makes sure there's no encryption stuff that can't leave the USA, etc. Doing what OP described is great: it lets their folks do the audit with no risk of you loosing "ownership". It shows you are both a good partner and value what you do.

License compliance is incredibly important and unfortunately overlooked by many smaller firms. The potential liability to a GPL or other violation is just not worth it. Anecdote: We have released code under the Apache 2 License (our biggest project by far is https://github.com/sheetjs/js-xlsx ) and we've been roped into negotiations because some companies tried to take shortcuts by copying our code without proper att…

What exactly is the potential liability for a GPL violation?

I've gone 12 rounds with IP lawyers over these theoretical violations (static vs dynamic links). But I found it odd that I could never find a single case of significant liability due to infringement. The nature of damages is unclear and the landscape of counter-parties (with an incentive to sue) is amorphous. It seemed like worst-case, a proven infringer just had to re-write the offending module and make a $10k donation to an open source foundation. I've never knowingly infringed GPL and am not advocating that anyone should; it's just as I said, I found the legal community's focus on this area out of step with their otherwise well-measured calculations of risk and reward.

Post reply on HN