Third-Party and Open-Source Notices
Axiometrik incorporates open-source and other third-party components, and retrieves public reference data from a small number of external services. This page reproduces the notices those impose and discloses every outbound connection the software makes.
This page is a published copy, not the controlling document. A notice file identifying the third-party components accompanies the software itself. Where the two differ, the file shipped with the software controls (Article 2.8 of the Beta Software License Agreement).
Required attribution
U.S. National Vulnerability Database. This product uses data from the NVD API but is not endorsed or certified by the NVD.
That wording is prescribed by NVD's terms and is reproduced verbatim. It applies to raw NVD data only — scores, gap analyses and other outputs computed by Axiometrik are not attributed to the NVD and must not be presented as NVD products.
OpenStreetMap. County resolution uses the Nominatim geocoding service. Map data © OpenStreetMap contributors, available under the Open Database License (ODbL) 1.0.
Outbound network services — the complete list
Five external hosts, all read-only lookups, all initiated by the local application. No assessment content, evidence file, finding or score is transmitted to any of them.
| Host | Purpose | What leaves the machine |
|---|---|---|
services.nvd.nist.gov | CVE lookup for software inventory and vulnerability features | CVE and CPE identifiers; a product name being looked up |
www.cisa.gov | CISA Known Exploited Vulnerabilities catalog | Nothing identifying — the catalog is retrieved, not queried |
api.fdic.gov | FDIC BankFind institution and branch lookup | An institution name and state |
nominatim.openstreetmap.org | City/state to coordinates, for county resolution | A city and state |
geo.fcc.gov | Coordinates to county FIPS code | A latitude/longitude pair |
Each of these backs an optional feature. An installation with no internet access, or with these hosts blocked, loses those five lookups and nothing else — assessment, evidence handling, policy generation, attestation and reporting are entirely local.
The CISA KEV catalog is not bundled with the software. It is retrieved from CISA at the time of use, so a build has no embedded copy of it.
What is actually distributed
The development dependency graph is far larger than the shipped payload. What reaches an end user is:
- A single bundled server file, with its statically-imported dependencies inlined
- A Node.js runtime binary, which carries its own MIT license together with the notices of its bundled components — OpenSSL, V8, libuv, zlib and others
- Two dependency trees that cannot be bundled and are extracted at first launch:
better-sqlite3(native binding) andpdfkit(on-disk font files) - The compiled Rust binary and its statically linked crates
- Migration SQL and the compiled front-end assets
License composition
Across both dependency graphs the licensing is permissive. No GPL, AGPL or LGPL-only component is present in the JavaScript graph.
JavaScript / TypeScript
MIT predominates, with ISC, Apache-2.0, BSD-2/3-Clause, BlueOak-1.0.0, 0BSD, Python-2.0 and Unlicense also present. The only copyleft is weak-copyleft MPL-2.0, in build-time tooling that is not distributed.
Rust
Overwhelmingly MIT OR Apache-2.0 dual-licensed, with Unicode-3.0, BSD-3-Clause, Zlib and Unlicense combinations. Seven MPL-2.0 crates ship — listed below.
MPL-2.0 components and source availability
The following Mozilla Public License 2.0 crates are distributed in the compiled binary. They arrive through the application framework and webview stack and are not modified by Axiometrik. MPL-2.0 is file-level weak copyleft: it does not affect Axiometrik's own source, and the source of these files is available from each project upstream.
| Crate | Version |
|---|---|
cssparser | 0.29.6, 0.36.0 |
cssparser-macros | 0.6.1 |
selectors | 0.24.0, 0.36.1 |
dtoa-short | 0.3.5 |
option-ext | 0.2.0 |
Source for any of these is available from its upstream repository, or on request to legal@axiometrik.net.
Dual-license elections
Where a component offers a choice of licenses, Axiometrik elects as follows and records that election here so it is not left ambiguous:
| Component | Offered | Elected |
|---|---|---|
jszip | MIT or GPL-3.0-or-later | MIT |
r-efi | MIT or Apache-2.0 or LGPL-2.1-or-later | MIT |
The complete notice file
The full per-component notice file, reproducing the copyright and permission notices of every distributed dependency, accompanies the software. Licensees must not remove, alter or fail to reproduce it (Article 2.8). A copy is available on request to legal@axiometrik.net.
Reporting an attribution error
If you believe a component is missing from this page or attributed incorrectly, please write to legal@axiometrik.net and we will correct it.