NQ DATA engineers count what is installed and what you actually hold rights to. Crowe lawyers assess the risk and tell you what to do about it. The result is seen by you alone.
Do not answer on the merits and do not run the tools the vendor sent until you know your real picture. First an internal check under NDA and a review of the letter with a Crowe lawyer — then the reply.
Illustrative figures. In a real report every line has a source: purchase document, vendor account, scan result.
From: vendor compliance team
The latest BSA measurement (2017). Since then vendors have moved to subscriptions and see far more about every installation.
Under Moldova’s copyright law computer programs are protected as literary works (art. 23). An installation without a licence is an infringement.
Civil — compensation to the right holder; contraventional — art. 96 of the Contravention Code; criminal — art. 185¹ of the Criminal Code. Which one applies to you is for a lawyer to assess.
Two minutes. Answers stay in your browser: nothing is saved or sent until you decide to send the result yourself.
A spreadsheet counts — if it is kept up to date.
You reply at once to “close the matter”.
A lawyer reads the letter and the contract: what the vendor is entitled to ask for and what it is not.
You run the vendor’s tool: it sees everything, including what was not asked about.
Engineers take an internal inventory: you are the first to see the picture.
You learn the gap from the vendor’s calculation — at list price.
We match installations with rights: part of the “gap” is closed by documents and a correct count.
You sign the report and an urgent purchase.
Crowe prepares the reply and a confidentiality agreement and conducts the negotiations.
You pay for what you might not have had to buy.
You buy only what is needed and keep records that will stand the next review.
A technical audit without a lawyer gives numbers but no answer to “what does this mean for us”. A lawyer without an inventory has nothing to rely on. Here both work on one project.
Every program on every computer and server, with the version, the user and the source of the right to use it.
Installed, owned, gap — per vendor and product, with the count rules that were applied.
What the findings mean under your contracts and Moldovan law, and how to respond if a vendor asks.
First what can be switched off or reassigned, then what has to be bought — with priorities and amounts.
We sign a non-disclosure agreement before we see a single computer.
We are partners of Microsoft and Autodesk — that is why we know their rules. But the report is yours: we do not pass results to vendors or anyone else.
The inventory collects what is installed and on which hardware — not the contents of documents, mail or databases.
The report starts with what you can stop paying for. Whatever has to be bought, you may buy from any supplier.
Software from these vendors is what we check most often. The names are trademarks of their owners; we act for you, not for them.
Windows Server is counted by processor cores, and each user or device also needs a client licence (CAL); remote desktop needs its own. SQL Server is licensed either by cores or as “server plus CAL”. Virtual machines multiply the count. This is where the gap is found most often.
Subscriptions are assigned to named users: one account shared by several engineers is a violation. Old perpetual versions and copies of unknown origin on forgotten workstations are the usual reason for a vendor letter.
Licences are tied to named accounts. Shared logins, subscriptions still assigned to people who left and old boxed versions installed on more machines than were bought are found in almost every audit.
Since 2023 the Java SE subscription is counted by the number of all employees, not of those who use Java. A database on a virtualised cluster may have to be licensed for every physical core of that cluster.
After the move to Broadcom new licences are sold only as subscriptions counted by cores. Old perpetual licences remain valid, but their support is no longer renewed — and a subscription is calculated differently from what you are used to.
Paying only for the cores a virtual machine actually uses is allowed on condition that the vendor’s ILMT tool is installed and keeps its reports. Without it the count is made on the full capacity of the server.
Seven questions and a risk profile in two minutes. A reason to talk — or to sleep well.
Start the self-checkInventory, matching with rights, legal opinion and a remediation plan. For those who want to know before anyone asks.
Order an auditA lawyer and an engineer read the letter, check the deadline and the contract and agree with you on the plan of the reply.
Send the letterThe price is on request: it depends on the number of workstations, servers and vendors. You get a fixed quote before the work starts.
No. We sign an NDA before the work starts, and the report belongs to you. We do not pass audit results to vendors or to any third party.
The report starts with what can be removed, reassigned or replaced with a cheaper plan, and only then lists what has to be bought. You are free to buy it from any supplier.
The inventory is taken with a scanning tool — with a small agent or without one, as you prefer. It collects the list of installed programs and hardware data, not the contents of files, mail or databases.
Record the date and the deadline, do not reply on the merits, do not run the vendor’s tools and do not delete anything. Send us the letter: a lawyer and an engineer will review it and propose the plan of the reply.
In the vendor’s audit the vendor sees the result first and calculates the claim. Here you see it first, with a lawyer’s assessment, and decide yourself what to do next.
It depends on the size: an office without servers takes days, a company with servers, branches and several vendors takes weeks. You get the timeline together with the quote.
The price is on request and depends on the number of workstations, servers and vendors. Before the work starts you receive a fixed quote for the technical and the legal part.
This page is for information and is not legal advice. Legal references are given as of 10 October 2026; how they apply to your company is assessed by a lawyer.
Sources: BSA Global Software Survey 2018; Law no. 230/2022 on copyright and related rights; Contravention Code, art. 96; Criminal Code, art. 185¹.
Tell us what worries you — a vendor letter, a server nobody remembers how was licensed, or simply the wish to know. We will call back, sign an NDA if you wish and suggest where to start.