An employee at EpicGames wants me to fill out this questionnaire to use my OSS
twitter.com
twitter.com
In this case I suspect the employee in question simply misunderstood the company process, and had no malicious intent.
Two options:
1) point them to your existing policies and processes for SOC2, IRAP, ISO27001 and similar, the questionnaire is already filled
2) fill it out as best you can if it's going to earn you bank.
Worst they can say is no.
What always gives me pause with this is that my open source software comes with no warranty and I don't want to compromise the license terms. So nailing down the written agreement (what are they going to do with it, and what are they attempting to hold you liable for?) is an opportunity to address that.
(Full disclosure: haven't had this come up in well over a decade.)
I don't know if filling and returning these kinds of forms can have any kinds of legal implications, but if it did, even potentially, there's no way I'd do that for $5k unless I were in absolutely dire need of that money.
Maybe they'll share a third party audit of your code with you.
Maybe the written agreement reiterates "you agree to be bound by the license terms and FULLY UNDERSTAND AND ACCEPT ALL LIABILITY" and you still get $5K.
Besides at the negotiation stage it's still plus costs. It's been a decade, but if you spend $20K on lawyers and liability insurance and they pay you $25K, you still make $5K.
A lawyer to help negotiate a contract. If you find someone who is familiar with OSS and isn’t in a big firm, this might be $1k or so.
Liability insurance.
Any incorporation costs if you choose to incorporate, which (in the US, I’m not a lawyer, and this is not advice) you should seriously consider if you start making money from independent work.
Throw in a bit of support and you might get paid fairly well. Keep in mind that the fact that you got asked for this means that someone wants to use your work enough that they asked the procurement department to set it up.
Also: filling this in can open up liability. There's no way you get it all accurate, and in the event of a breech (e.g. supply chain attack where you get hacked leading to them getting hacked) they could argue that you misrepresented or didn't comply with your stated response.
So the 5k which could never be paid might also not be worth it.
Q: Detailed policies blah blah management of Epic Confidential Data? A: I'll sell it to the highest bidder, unless they want me to fill in some stupid questionnaire first.
A: Data comes in, data goes out. You can't explain that.
Probably some intern or manager with no clue about open source made a mistake there. Better take it to Twitter to get those nice re-tweets, inside of writing a simple email to explain the mistake...
Seriously Jeff, you do great stuff - I always enjoy your writeups and videos.
[edit] mispelt name
If someone's giving something away for free you don't ask for a guarantee, and if you want one for what ever reason you should offer to pay.
You mention greed, but epic seems to be the one wanting the cake and eating it too.
So yes I agree with the "how dare they".
- someone sent a (probably mass vendor targeted) mail asking for a form filling.
- The author interpreted they wanted it for free (which is not even absurd : some open source project have commercial licences and could use both a whatever security standard compliance to gain commercial value AND the legit right to add a big company name on his website) and was outraged because the email didn't contain a commercial offer.
I may be wrong, but IF the mail was really targeted at him (other comment point a believable theory : the security guy mass sent the mail to every 'vendor' lib in the folder, either by mistake or lack of caring) he just panicked and (if he wanted money) missed a business opportunity by either sending a quote for the form filing, trying to negociate an enterprise grade support/consulting or just politely responded "I'm an open source free code provider and have no financial interst in being used by you. Have a nice day."
I have been requested heavy paperwork kiling to allow my work as freelance to be used with 'big client', sended bills for it, and never had a problem with it. Never the funniest part of the project, but money is money.
I get around 50 unsolicited emails a day, many asking for help with my OSS projects, but rarely is there something as cookie-cutter as this that's not outright spam.
I wasn't outraged, more like bemused that they'd think an OSS maintainer for a small personal project would care to spend hours working on security documentation for a little project that's like 1 KB of code.
But this is a small open source project with a single maintainer on a personal account on GitHub.