
How to Review a Reverse-Engineering Ban in a Software Licence
Log a reverse-engineering ban: lawful-exception floor, pentest carve-out, ordinary API integration, and an escrow lift — then carve, narrow, or walk.
Key takeaway in 30 seconds
Knowing how to review a reverse-engineering ban in a software licence means logging the exact ban words, an except-as-permitted-by-applicable-law floor plus a named interoperability purpose, a pentest carve-out with a named tester and dated window, documented-call language that lets authenticated integration through, and a post-escrow lift for maintenance. Then carve, narrow, or walk.
Cal, Ops at an 18-person UK health-tech, is about to treat “Customer shall not reverse engineer, decompile or disassemble” as boiler. Finance signed off. Knowing how to review a reverse-engineering ban in a software licence is a 25-minute hunt: demand a lawful-exception floor and a named interoperability purpose, write a pentest carve-out, save ordinary documented integration, then lift the ban on escrow release.
September 2026. English law; exclusive courts of England and Wales. The packet — the exact file set that will be signed — is the on-prem clinic-ops licence, an API (application programming interface) schedule, and an escrow exhibit — attached schedule or appendix — dated today. No “except as permitted by applicable law.” No interoperability sentence.
Security’s Q3 pentest is booked, and vendor Slack already calls it reverse engineering they will treat as breach. The API schedule bans abuse, scrape, or reverse engineer endpoints. Escrow post-release is “internal use only” and clause 9 is not disapplied. Friday is booked. The rush is the problem: typical mistake is treating the ban as boiler, and the hidden risk is a health-check becoming a termination event under Legal’s pressure.
A statutory interoperability needle is not a pentest licence. Even a lawful-exception floor did not save systematic disassembly in the English High Court. Jones Day (May 2025) on IBM United Kingdom Ltd v LzLabs GmbH [2025] EWHC 532 (TCC): IBM had a lawful-exception floor Cal lacks. The court still found breach in the majority of 51 alleged items. Put the exception in the paper; clause 9 has zero.
Disclaimer: Checkory provides AI support, not legal advice. Consult a qualified lawyer for binding decisions.
How to review a reverse-engineering ban in a software licence?
Circle clause 9. A blanket “shall not reverse engineer, decompile or disassemble” with no lawful-exception floor is a fail. Demand that floor plus a named interoperability purpose: an independent program that operates with theirs. Log the floor and the purpose, or “blanket ban — fail.”
Do: put the floor in the paper. Don’t: hope CDPA (Copyright, Designs and Patents Act 1988) section 50B will cover a Friday pentest. CDPA s.50B is a needle: interoperability only, necessary parts. Section 50BA is observe-while-running, not disassembly. Section 296A voids a term only insofar as it hits 50B(2) or 50BA — not the rest of clause 9. For example, Law Insider samples repeat the commercial floor Cal dropped. 50C error-correction can be contracted out.

Typical mistake
“The law lets us decompile anyway” treats CDPA 50B as a pentest licence. 50B is a needle. 50C can be contracted out.
Why does a scheduled pentest need a security-testing carve-out?
A scheduled pentest is authorised adversary-technique testing, not a hobby. If clause 9 treats it as reverse engineering, Security’s diary is a breach clock. Write a named tester, environment, dated window, and no production dump — or log “pentest = breach — fail.”
Do: authorise Customer and a named tester under confidentiality for a scoped pentest in a dated window. Don’t: treat 50BA as that engagement letter. NCSC (National Cyber Security Centre) CHECK defines a pentest as using the same tools and techniques as an adversary might. NCSC (1 July 2026) still recommends you have a system pen tested. In practice, ask in writing: authorised test, or treated as breach?

Cal’s reverse-engineering log
| Row | Cal’s paper | Write |
|---|---|---|
| Ban vs exception | Shall not reverse engineer; no floor | Except as permitted by law + named interoperability purpose |
| Pentest | Scheduled test = breach | Named tester, dated window, no production dump |
| API abuse | Abuse / scrape / reverse engineer endpoints | Documented authenticated calls in; scrape / substitute out |
| Escrow lift | Internal use only; clause 9 survives | On release: compile, adapt, maintain / correct errors |
When does API abuse language block ordinary integration?
“Abuse” does not only mean a flood. A sentence that bans scrape or reverse engineer endpoints can also catch Cal’s documented connector. Rewrite so documented, authenticated, rate-limited calls are in; undocumented probing and a substitute product stay out.
Do: name the intended integration and permit documented, authenticated, rate-limited calls. Don’t: leave “abuse” undefined next to “reverse engineer endpoints.” Microsoft APIs Terms (October 2025) grant a licence for documented APIs and still ban scrape and reverse engineer except as applicable law expressly permits. Cal’s sentence does not separate interoperate from replicate.

Which fight is this — a buyer restriction, or inbound copyleft?
This paper restricts the buyer. It is not a hunt for their GPL inside the deliverable. Time with counsel — a qualified lawyer, not the chatbot — spent on SBOM annexes while clause 9 stays a blanket ban is the wrong hunt.
If the fight is inbound open-source / copyleft contamination of a vendor deliverable, that is a different hunt: open-source copyleft vendor deliverable review. Stay here for the buyer restriction. Do: one sentence, then return to clause 9. Don’t: clone an SBOM hunt.
Should escrow release lift the reverse-engineering ban for maintenance?
Receiving a zip of source is not a right to compile it. If clause 9 survives release, the vault is a folder she may not open. Write that on release Customer may compile, adapt, and maintain / correct errors in the released materials, including via a confidential contractor.
Do: disapply clause 9 for released materials used to keep the clinic system running. Don’t: treat “internal use only” as a maintenance licence. techUK escrow: it is one thing to receive the source; it is another to understand what rights you have. If the fight is what sits in the vault and when it releases, that is a different hunt: source-code escrow deposit and release review. Escrow release should lift the reverse-engineering ban for maintenance; then stay here.
How do you carve, narrow, or walk?
Carve only if the log shows a lawful-exception floor, a pentest carve-out covering the booked test, ordinary API integration saved, and a post-escrow lift. Narrow means redline those four. Walk — pause Friday — if the blanket ban, pentest-as-breach, API-abuse, and no post-escrow lift remain.
Success bar: a one-page log plus one Friday pause sentence. Workflow: ban vs interoperability exception → pentest / bug-bounty carve-out → API abuse vs ordinary integration → not copyleft → escrow release lifts the ban → carve / narrow / walk. Verify clause 9 before you sign. Escalate that package. Optional: upload the same PDF to document analysis for a first-pass — first machine pass that extracts clauses before a human reads every page. A human still opens clause 9. Verify every High flag — a severity-high finding a named human still opens.
Hunt
Freeze the packet
Licence + API schedule + escrow release line, dated today. Search reverse engineer / decompile / pentest / API abuse. Open clause 9.
Hunt ban vs exception
Circle “shall not reverse engineer, decompile or disassemble” with no except-as-permitted floor. Demand that floor plus a named interoperability purpose.
Hunt the pentest carve-out
Circle Slack treating a scheduled pentest as reverse engineering. Write named tester, dated window, no production dump.
Hunt API abuse
Circle abuse / scrape / reverse engineer endpoints. Documented authenticated calls in; scrape / substitute-product out.
Hunt the escrow lift
Circle “internal use only” that does not disapply clause 9. On release: compile, adapt, maintain / correct errors, including via a confidential contractor.
Carve, narrow, or walk
Carve only if all four rows hold. Narrow = redline the four. Walk if blanket ban + pentest-as-breach + API-abuse + no post-escrow lift remain.
Frequently asked questions
Can we decompile to fix a bug?▼
Does the reverse-engineering ban survive escrow release?▼
Is a pentest reverse engineering?▼
Does CDPA 50B cover our Friday health-check?▼
Is this the copyleft / SBOM hunt?▼
If we already reviewed the escrow deposit, are we done?▼
Highlight the reverse-engineering clause
Upload the same PDF. A human still opens clause 9 and the API schedule.
Start document analysisWhat to do next
How to Review GPL/AGPL Copyleft Contamination in a Software Deliverable
Inbound OSS / copyleft in their deliverable. This page is a licence restriction on the buyer.
RelatedHow to Review a Source-Code Escrow Deposit and Release Trigger
What sits in the vault and when it releases. This page is whether release lifts the reverse-engineering ban.
RelatedHow to Review Ownership of AI Outputs in a Vendor Contract
Open the sibling checklist after this screen.
RelatedHow to Prepare a Contract Packet for First-Pass Review
Open the sibling checklist after this screen.
Sources
- CDPA s.50B — Decompilation
- CDPA s.50BA — Observing, studying and testing of computer programs
- CDPA s.50C — Other acts permitted to lawful users
- CDPA s.296A — Avoidance of certain terms
- Jones Day — UK Court Rules on Reverse Engineering of Mainframe Software (May 2025)
- Law Insider — Limitations on Reverse Engineering, Decompilation and Disassembly
- Microsoft APIs Terms of Use (last updated October 2025)
- NCSC — CHECK penetration testing
- NCSC — Building more resilient CNI (1 July 2026)
- techUK escrow — Our contracts and service
Related guides


