AxiometrikSecurity Assessment & Remediation

Third-Party and Open-Source Notices

Applies to Axiometrik BETA build 0.9.0  ·  Updated August 12, 2026

Axiometrik incorporates open-source and other third-party components, and retrieves public reference data from a small number of external services. This page reproduces the notices those impose and discloses every outbound connection the software makes.

This page is a published copy, not the controlling document. A notice file identifying the third-party components accompanies the software itself. Where the two differ, the file shipped with the software controls (Article 2.8 of the Beta Software License Agreement).

Required attribution

U.S. National Vulnerability Database. This product uses data from the NVD API but is not endorsed or certified by the NVD.

That wording is prescribed by NVD's terms and is reproduced verbatim. It applies to raw NVD data only — scores, gap analyses and other outputs computed by Axiometrik are not attributed to the NVD and must not be presented as NVD products.

OpenStreetMap. County resolution uses the Nominatim geocoding service. Map data © OpenStreetMap contributors, available under the Open Database License (ODbL) 1.0.

Outbound network services — the complete list

Five external hosts, all read-only lookups, all initiated by the local application. No assessment content, evidence file, finding or score is transmitted to any of them.

HostPurposeWhat leaves the machine
services.nvd.nist.govCVE lookup for software inventory and vulnerability featuresCVE and CPE identifiers; a product name being looked up
www.cisa.govCISA Known Exploited Vulnerabilities catalog Nothing identifying — the catalog is retrieved, not queried
api.fdic.govFDIC BankFind institution and branch lookup An institution name and state
nominatim.openstreetmap.orgCity/state to coordinates, for county resolutionA city and state
geo.fcc.govCoordinates to county FIPS code A latitude/longitude pair

Each of these backs an optional feature. An installation with no internet access, or with these hosts blocked, loses those five lookups and nothing else — assessment, evidence handling, policy generation, attestation and reporting are entirely local.

The CISA KEV catalog is not bundled with the software. It is retrieved from CISA at the time of use, so a build has no embedded copy of it.

What is actually distributed

The development dependency graph is far larger than the shipped payload. What reaches an end user is:

License composition

Across both dependency graphs the licensing is permissive. No GPL, AGPL or LGPL-only component is present in the JavaScript graph.

JavaScript / TypeScript

MIT predominates, with ISC, Apache-2.0, BSD-2/3-Clause, BlueOak-1.0.0, 0BSD, Python-2.0 and Unlicense also present. The only copyleft is weak-copyleft MPL-2.0, in build-time tooling that is not distributed.

Rust

Overwhelmingly MIT OR Apache-2.0 dual-licensed, with Unicode-3.0, BSD-3-Clause, Zlib and Unlicense combinations. Seven MPL-2.0 crates ship — listed below.

MPL-2.0 components and source availability

The following Mozilla Public License 2.0 crates are distributed in the compiled binary. They arrive through the application framework and webview stack and are not modified by Axiometrik. MPL-2.0 is file-level weak copyleft: it does not affect Axiometrik's own source, and the source of these files is available from each project upstream.

CrateVersion
cssparser0.29.6, 0.36.0
cssparser-macros0.6.1
selectors0.24.0, 0.36.1
dtoa-short0.3.5
option-ext0.2.0

Source for any of these is available from its upstream repository, or on request to legal@axiometrik.net.

Dual-license elections

Where a component offers a choice of licenses, Axiometrik elects as follows and records that election here so it is not left ambiguous:

ComponentOfferedElected
jszipMIT or GPL-3.0-or-laterMIT
r-efiMIT or Apache-2.0 or LGPL-2.1-or-later MIT

The complete notice file

The full per-component notice file, reproducing the copyright and permission notices of every distributed dependency, accompanies the software. Licensees must not remove, alter or fail to reproduce it (Article 2.8). A copy is available on request to legal@axiometrik.net.

Reporting an attribution error

If you believe a component is missing from this page or attributed incorrectly, please write to legal@axiometrik.net and we will correct it.