CheckoryCheckory
Clause 9 circled on a licence: blanket reverse-engineering ban versus interoperability floor and pentest carve-out

How to Review a Reverse-Engineering Ban in a Software Licence

Log a reverse-engineering ban: lawful-exception floor, pentest carve-out, ordinary API integration, and an escrow lift — then carve, narrow, or walk.

9 min readArticle
💡

Key takeaway in 30 seconds

Knowing how to review a reverse-engineering ban in a software licence means logging the exact ban words, an except-as-permitted-by-applicable-law floor plus a named interoperability purpose, a pentest carve-out with a named tester and dated window, documented-call language that lets authenticated integration through, and a post-escrow lift for maintenance. Then carve, narrow, or walk.

Cal, Ops at an 18-person UK health-tech, is about to treat “Customer shall not reverse engineer, decompile or disassemble” as boiler. Finance signed off. Knowing how to review a reverse-engineering ban in a software licence is a 25-minute hunt: demand a lawful-exception floor and a named interoperability purpose, write a pentest carve-out, save ordinary documented integration, then lift the ban on escrow release.

September 2026. English law; exclusive courts of England and Wales. The packet — the exact file set that will be signed — is the on-prem clinic-ops licence, an API (application programming interface) schedule, and an escrow exhibit — attached schedule or appendix — dated today. No “except as permitted by applicable law.” No interoperability sentence.

Security’s Q3 pentest is booked, and vendor Slack already calls it reverse engineering they will treat as breach. The API schedule bans abuse, scrape, or reverse engineer endpoints. Escrow post-release is “internal use only” and clause 9 is not disapplied. Friday is booked. The rush is the problem: typical mistake is treating the ban as boiler, and the hidden risk is a health-check becoming a termination event under Legal’s pressure.

A statutory interoperability needle is not a pentest licence. Even a lawful-exception floor did not save systematic disassembly in the English High Court. Jones Day (May 2025) on IBM United Kingdom Ltd v LzLabs GmbH [2025] EWHC 532 (TCC): IBM had a lawful-exception floor Cal lacks. The court still found breach in the majority of 51 alleged items. Put the exception in the paper; clause 9 has zero.

Disclaimer: Checkory provides AI support, not legal advice. Consult a qualified lawyer for binding decisions.

How to review a reverse-engineering ban in a software licence?

Circle clause 9. A blanket “shall not reverse engineer, decompile or disassemble” with no lawful-exception floor is a fail. Demand that floor plus a named interoperability purpose: an independent program that operates with theirs. Log the floor and the purpose, or “blanket ban — fail.”

Do: put the floor in the paper. Don’t: hope CDPA (Copyright, Designs and Patents Act 1988) section 50B will cover a Friday pentest. CDPA s.50B is a needle: interoperability only, necessary parts. Section 50BA is observe-while-running, not disassembly. Section 296A voids a term only insofar as it hits 50B(2) or 50BA — not the rest of clause 9. For example, Law Insider samples repeat the commercial floor Cal dropped. 50C error-correction can be contracted out.

Workflow from circling clause 9 through a lawful-exception floor to a named interoperability purpose
Workflow from circling clause 9 through a lawful-exception floor to a named interoperability purpose

Typical mistake

“The law lets us decompile anyway” treats CDPA 50B as a pentest licence. 50B is a needle. 50C can be contracted out.

Why does a scheduled pentest need a security-testing carve-out?

A scheduled pentest is authorised adversary-technique testing, not a hobby. If clause 9 treats it as reverse engineering, Security’s diary is a breach clock. Write a named tester, environment, dated window, and no production dump — or log “pentest = breach — fail.”

Do: authorise Customer and a named tester under confidentiality for a scoped pentest in a dated window. Don’t: treat 50BA as that engagement letter. NCSC (National Cyber Security Centre) CHECK defines a pentest as using the same tools and techniques as an adversary might. NCSC (1 July 2026) still recommends you have a system pen tested. In practice, ask in writing: authorised test, or treated as breach?

Comparison of a booked pentest treated as breach versus a named tester, dated window, and no production dump
Comparison of a booked pentest treated as breach versus a named tester, dated window, and no production dump

Cal’s reverse-engineering log

RowCal’s paperWrite
Ban vs exceptionShall not reverse engineer; no floorExcept as permitted by law + named interoperability purpose
PentestScheduled test = breachNamed tester, dated window, no production dump
API abuseAbuse / scrape / reverse engineer endpointsDocumented authenticated calls in; scrape / substitute out
Escrow liftInternal use only; clause 9 survivesOn release: compile, adapt, maintain / correct errors

When does API abuse language block ordinary integration?

“Abuse” does not only mean a flood. A sentence that bans scrape or reverse engineer endpoints can also catch Cal’s documented connector. Rewrite so documented, authenticated, rate-limited calls are in; undocumented probing and a substitute product stay out.

Do: name the intended integration and permit documented, authenticated, rate-limited calls. Don’t: leave “abuse” undefined next to “reverse engineer endpoints.” Microsoft APIs Terms (October 2025) grant a licence for documented APIs and still ban scrape and reverse engineer except as applicable law expressly permits. Cal’s sentence does not separate interoperate from replicate.

Checklist saving documented authenticated API calls while scrape and reverse-engineer endpoints stay out
Checklist saving documented authenticated API calls while scrape and reverse-engineer endpoints stay out

Which fight is this — a buyer restriction, or inbound copyleft?

This paper restricts the buyer. It is not a hunt for their GPL inside the deliverable. Time with counsel — a qualified lawyer, not the chatbot — spent on SBOM annexes while clause 9 stays a blanket ban is the wrong hunt.

If the fight is inbound open-source / copyleft contamination of a vendor deliverable, that is a different hunt: open-source copyleft vendor deliverable review. Stay here for the buyer restriction. Do: one sentence, then return to clause 9. Don’t: clone an SBOM hunt.

Should escrow release lift the reverse-engineering ban for maintenance?

Receiving a zip of source is not a right to compile it. If clause 9 survives release, the vault is a folder she may not open. Write that on release Customer may compile, adapt, and maintain / correct errors in the released materials, including via a confidential contractor.

Do: disapply clause 9 for released materials used to keep the clinic system running. Don’t: treat “internal use only” as a maintenance licence. techUK escrow: it is one thing to receive the source; it is another to understand what rights you have. If the fight is what sits in the vault and when it releases, that is a different hunt: source-code escrow deposit and release review. Escrow release should lift the reverse-engineering ban for maintenance; then stay here.

How do you carve, narrow, or walk?

Carve only if the log shows a lawful-exception floor, a pentest carve-out covering the booked test, ordinary API integration saved, and a post-escrow lift. Narrow means redline those four. Walk — pause Friday — if the blanket ban, pentest-as-breach, API-abuse, and no post-escrow lift remain.

Success bar: a one-page log plus one Friday pause sentence. Workflow: ban vs interoperability exception → pentest / bug-bounty carve-out → API abuse vs ordinary integration → not copyleft → escrow release lifts the ban → carve / narrow / walk. Verify clause 9 before you sign. Escalate that package. Optional: upload the same PDF to document analysis for a first-pass — first machine pass that extracts clauses before a human reads every page. A human still opens clause 9. Verify every High flag — a severity-high finding a named human still opens.

Hunt

1

Freeze the packet

Licence + API schedule + escrow release line, dated today. Search reverse engineer / decompile / pentest / API abuse. Open clause 9.

2

Hunt ban vs exception

Circle “shall not reverse engineer, decompile or disassemble” with no except-as-permitted floor. Demand that floor plus a named interoperability purpose.

3

Hunt the pentest carve-out

Circle Slack treating a scheduled pentest as reverse engineering. Write named tester, dated window, no production dump.

4

Hunt API abuse

Circle abuse / scrape / reverse engineer endpoints. Documented authenticated calls in; scrape / substitute-product out.

5

Hunt the escrow lift

Circle “internal use only” that does not disapply clause 9. On release: compile, adapt, maintain / correct errors, including via a confidential contractor.

6

Carve, narrow, or walk

Carve only if all four rows hold. Narrow = redline the four. Walk if blanket ban + pentest-as-breach + API-abuse + no post-escrow lift remain.

Frequently asked questions

Can we decompile to fix a bug?
Not on this paper. CDPA s.50C error-correction can be contracted out. Write an error-correction carve-out.
Does the reverse-engineering ban survive escrow release?
Yes, unless the paper lifts it. Write a maintain / support / error-correction lift for released materials.
Is a pentest reverse engineering?
The vendor will say yes on this paper — that is why you carve. Write named tester, dated window, no production dump.
Does CDPA 50B cover our Friday health-check?
No. Section 50B is a needle for an independent interoperable program. It is not a pentest licence. Put a security-testing carve-out in the paper.
Is this the copyleft / SBOM hunt?
No. Stay here for the buyer restriction on their software. Inbound OSS / copyleft contamination is a different hunt (https://checkory.com/en-gb/blog/open-source-copyleft-vendor-deliverable-review).
If we already reviewed the escrow deposit, are we done?
No. Deposit completeness, verification, and release triggers are a different hunt (https://checkory.com/en-gb/blog/source-code-escrow-deposit-release-review). This page is whether release lifts the ban for maintenance.

Highlight the reverse-engineering clause

Upload the same PDF. A human still opens clause 9 and the API schedule.

Start document analysis

What to do next

Sources

Related guides

Updated: September 20, 2026