Trust · from the assurance pack
Licence register
Published from docs/assurance/licence-register.md as it ships with the software: the same text an auditor receives. A reference to another document of the pack or to a runbook is named, not linked; they ship beside it.
What VX Drive ships or runs that is not its own — code compiled into its binaries, libraries
its helpers load, programs it runs, services it runs beside, models, fonts and fixtures — with
each item's licence and the way it is used, because the obligations differ by that. Read from
the lockfiles, the images and the files themselves on 2026-09-28 (release 1.0.0-rc.2); the
last section says how to regenerate it. The worker image carries this document as
/opt/vxdrive/NOTICES/LICENCE-REGISTER.md beside every component's licence text.
The product's own licence
VX Drive is proprietary software; the copyright holder is Patchgate, LLC (the legal entity;
Vertex Lake is the trading name it intends to register for the product). The LICENSE file at
the root of the repository says so (all rights reserved; use only under a written licence
agreement), every crate declares
license = "LicenseRef-Proprietary" and every package "license": "SEE LICENSE IN LICENSE",
so the SBOMs and the package metadata carry it. The proprietary licence is compatible with
every third-party component named below: the one copyleft crate compiled into a binary is
MPL-2.0 (file-level copyleft; its files are unmodified and their source is the crate on
crates.io), the GPL and LGPL programs run as separate processes and are redistributed
unmodified with their source obtainable (next section), and the desktop shell links GTK and
WebKitGTK dynamically, which the LGPL permits. Nothing AGPL is shipped; the AGPL services the
compose file runs beside the product are the operator's to run.
How third-party code is used
| Way | What it means for licensing | Components |
|---|---|---|
| Compiled into our binaries | The licence terms attach to the binary; a copyleft licence would reach our code (none of the compiled code is GPL/LGPL; one MPL-2.0 crate is inside the worker, file-level copyleft, unmodified) | Rust crates; SQLite, zstd, ring and AWS-LC as static C code |
| Loaded into the sandboxed helper process at run time | Dynamic loading, unmodified libraries; the library's own licence applies to the library | PDFium (dlopen), ONNX Runtime (dlopen); pikepdf with libqpdf, pyHanko, pytsk3 with libtsk and libewf, and pyewf, imported by our Python helpers |
| Run as separate programs, each in the worker's sandbox | Only redistribution terms apply: the licence text travels with the image and, for GPL/LGPL programs, their source must be obtainable | Tesseract, qpdf, veraPDF on a JRE, LibreOffice, ffmpeg and ffprobe, flac, MediaConch, heif-dec, pandoc, asciidoctor, WeasyPrint, ExifTool, openssl, 7-Zip, dnglab, Siegfried, whisper-cli, fc-list, and our own vx-media-embed over llama.cpp's library |
| Run as a local service by the worker (not sandboxed; a listening socket) | As above | llama-server (llama.cpp, our build of the unmodified release) |
| Run by the worker outside its sandbox, with a scrubbed environment (they need the network or the database; ADR-0022) | As above | restic, and the ssh and rclone it runs for its sftp and rclone backends; pg_dump and pg_dumpall from PostgreSQL 18's client |
| Run on the appliance host by its own scripts, from images the operator pulls | Not redistributed by us | PostgreSQL with pgvector (pgvector/pgvector:pg18, pinned by digest), the ACME client lego (goacme/lego, MIT, pinned by digest, run by the certificate timer) |
| Run by the server outside any sandbox | As above | smbclient, scanimage with sane-airscan |
| Run beside the product by the compose file | Not redistributed by us; the operator pulls the images | PostgreSQL with pgvector, MinIO, mc |
| Data | The data's own terms | models, PRONOM signatures, fonts, fixtures |
GPL and LGPL components, and their source. Every GPL or LGPL program in the images is an
unmodified Debian trixie package (ffmpeg, pandoc, 7zip, flac,
libimage-exiftool-perl, python3-libewf, libheif, smbclient, sane-utils,
sane-airscan), an unmodified package from the PostgreSQL Global Development Group's apt
repository (postgresql-common, GPL-2.0-or-later, which carries the PostgreSQL 18 client that
Debian trixie does not) or an unmodified upstream release at the version deploy/tools.lock
pins (dnglab). The corresponding source is Debian's source archive at the package versions
the image's SBOM lists (apt-get source <package> on trixie, or snapshot.debian.org),
PGDG's source packages for postgresql-common and postgresql-client-18, and, for dnglab,
its release on GitHub at the pinned tag. VX Drive links none of them and modifies
none of them. llama.cpp is built unmodified from its pinned release; beside it the archive
carries vx-media-embed, VX Drive's own program over llama.cpp's library (MIT permits the
linking; the program's source is in this repository at deploy/llama-tools and travels in
the archive).
Rust crates
Every crate comes from crates.io (no git dependencies, no patches). The direct dependencies of the workspace, by licence; where a crate offers a choice, VX Drive takes the first permissive option named.
- MIT OR Apache-2.0 (or the same pair written the legacy way): ammonia 4.2.0, argon2 0.6.0, async-imap 0.11.3, async-trait 0.1.92, base64 0.23.1, c2pa 0.91.0, chacha20poly1305 0.11.0, chrono 0.4.45, chrono-tz 0.10.4, file-format 0.29.0, flate2 1.1.10, futures 0.3.34 (with futures-core and futures-util), getrandom 0.4.3, hex 0.4.3, hmac 0.13.0, image 0.25.10, ipnet 2.12.2, image_hasher 3.1.1, ipp 7.0.0, landlock 0.4.7, libc 0.2.189, log 0.4.34, mail-auth 0.13.3, mail-parser 0.11.9, md-5 0.11.0, mdns-sd 0.21.4, object_store 0.14.2, ort 2.0.0-rc.13, p256 0.14.0, pdf-writer 0.15.0, pdfium-render 0.9.4, percent-encoding 2.3.2, regex 1.13.1, reqwest 0.13.5, roxmltree 0.21.1, rust_xlsxwriter 0.99.1, rustls-pki-types 1.15.1 (tests), serde 1.0.229, serde_json 1.0.151, sha1 0.11.0, sha2 0.11.0, sqlx 0.9.0, suppaftp 12.1.0 (tests), tar 0.4.46, toml 1.1.6, tauri 2.11.6, tauri-build 2.6.3, tauri-plugin-log 2.9.2, tempfile 3.27.0, thiserror 2.0.21, tokio-rustls 0.26.5, unicode-segmentation 1.13.3, url 2.5.8, utoipa 6.0.0, utoipa-axum 0.3.0, uuid 1.26.1, wasm-bindgen 0.2.128, x509-parser 0.18.1.
- MIT: axum 0.8.9, axum-server 0.8.0, azure_core 1.1.0, azure_identity 1.0.0, azure_security_keyvault_keys 1.0.1 (the vendor's portal, ADR-0026), bytes 1.12.1, cfb 0.15.0, codepage-strings 1.0.2, compressed-rtf 1.0.1, dotenvy 0.15.7, http-body-util 0.1.5 (tests), jsonwebtoken 11.1.0 (the vendor's portal), msg_parser 0.3.6, nix 0.31.3, openidconnect 4.0.1, outlook-pst 1.2.0, outlook-pst-rw 1.2.9 (tests), pulldown-cmark 0.13.4, quick-xml 0.42.0, rusqlite 0.39.0 (with SQLite compiled in, public domain), tokio 1.53.1, tokio-stream 0.1.19, tokio-util 0.7.19, tower 0.5.3 (tests), tower-http 0.7.1, tracing 0.1.44, tracing-subscriber 0.3.23, whatlang 0.18.0, zip 8.6.0.
- Apache-2.0: libunftp 0.23.0, russh 0.63.3, russh-sftp 3.0.0, safetensors 0.8.0, unftp-core 0.1.0, unftp-sbe-fs 0.4.0.
- BSD-3-Clause: ed25519-dalek 3.0.0 (the backup manifests' signature, ADR-0022), kamadak-exif 0.6.1 (BSD-2-Clause), subtle 2.6.1, yara-x 1.20.0, zstd 0.14.0 (the zstd library it compiles in is BSD-3-Clause).
- Apache-2.0 OR ISC OR MIT: rustls 0.23.45, rustls-native-certs 0.8.4.
- Apache-2.0 OR BSD-3-Clause: seccompiler 0.5.0.
- CC0-1.0: notify 8.2.0 (optional in the core); blake3 1.8.7 (CC0-1.0 OR Apache-2.0).
- Unlicense OR MIT: globset 0.4.20, walkdir 2.5.0.
- (Apache-2.0 OR MIT) AND BSD-3-Clause: encoding_rs 0.8.42.
Copyleft in the transitive tree (everything else is permissive; no crate lacks a licence, none is AGPL, SSPL, BUSL, CDDL or EPL):
cssparser 0.38.0anddtoa-short 0.3.5— MPL-2.0, reached throughammoniaand compiled into the worker binary. The MPL's copyleft is per file and the files are unmodified; their source is the crate on crates.io.self_cell 1.3.0(Apache-2.0 OR GPL-2.0-only, via async-imap): taken under Apache-2.0.slog,slog-scope,slog-stdlog(MPL-2.0 OR MIT OR Apache-2.0, via libunftp): taken under MIT.- In the desktop shell only:
cssparser 0.36,cssparser-macros,selectors,option-ext(MPL-2.0, via tauri); GTK, WebKitGTK and libdbus are linked dynamically (LGPL-2.1+). r-efi(with an LGPL option) is resolved for UEFI targets only and is not built.
Native code statically linked: SQLite (public domain), zstd (BSD-3-Clause), ring (Apache-2.0
AND ISC), AWS-LC (ISC, Apache-2.0, MIT and BSD-3-Clause parts). ONNX Runtime and PDFium are
not linked (ort with load-dynamic; pdfium-render binds at run time).
npm packages
The shipped web bundle carries these production dependencies: solid-js and @solidjs/web
2.0.0-rc.9 (MIT), govuk-frontend 6.5.1 (MIT; its documentation is Crown copyright under the
OGL and is not shipped), @tauri-apps/api 2.11.1 (Apache-2.0 OR MIT), 3d-force-graph
1.80.0, force-graph 1.51.4, three 0.186.0, marked 18.0.14, qrcode 1.5.4 (MIT), and
dompurify 3.4.15 (MPL-2.0 OR Apache-2.0, taken under Apache-2.0). The 82 packages of the
production tree are MIT, ISC, BSD-3-Clause or Apache-2.0 without exception. The build strips
licence banners from the bundle, so this register and the packages' own files are the notice.
Development and build only, never shipped: @axe-core/playwright and axe-core 4.13.0
(MPL-2.0), @playwright/test 1.63.0 (Apache-2.0), vite 8.3.0 with lightningcss 1.33.0
(MPL-2.0), @solidjs/vite-plugin 3.0.0-next.44, sass-embedded 1.105.0, typescript 7.0.2
(Apache-2.0), typed-openapi 4.1.0 (MIT by its LICENSE file; the package declares no
field), caniuse-lite (CC-BY-4.0 data) and argparse 2.0.1 (Python-2.0) deep in the build
tools.
The worker image (deploy/Dockerfile.worker)
Base: debian:trixie-slim. Every notice named here is copied into /opt/vxdrive/NOTICES
(tools/ for the archives and pip packages, debian/ for every package's copyright file,
this register, and the worker's own assets' notice).
From pinned archives (deploy/tools.lock):
| Component | Version | Licence | How it runs |
|---|---|---|---|
| Siegfried, with its PRONOM signature data | 1.11.8 | Apache-2.0; the signatures are The National Archives' PRONOM data | separate process sf |
| PDFium (bblanchon's binaries) | chromium/8057 | BSD-3-Clause, with its bundled third-party components (FreeType, libjpeg-turbo, OpenJPEG, lcms2, ICU) under their own permissive licences | loaded into the sandboxed helper |
| ONNX Runtime | 1.28.0 | MIT (its ThirdPartyNotices.txt kept) |
loaded into the sandboxed helper; the models are the operator's |
| veraPDF greenfield | 1.30.2 | GPL-3.0-or-later OR MPL-2.0, taken under the MPL | separate JVM process |
| dnglab | 0.8.0 | LGPL-2.1 | separate process |
llama.cpp, our build of tag b11258 unmodified, with vx-media-embed (our program over its library, deploy/llama-tools) beside it |
b11258-vx2 | MIT | the inference engines, one process per role; the tool in the sandbox, one process per document |
CUDA runtime (the cuda variant only: cudart, cuBLAS, cuBLASLt) |
12.8 | NVIDIA CUDA EULA — redistributable runtime components; the EULA's text is in the cuda image's notices (CUDA-EULA.txt, NVIDIA's published text for the redistributable components; the next llama.cpp archive carries the toolkit's own copy) |
loaded by the CUDA engine |
| whisper.cpp | b5130 (v1.9.4) | MIT | separate process whisper-cli |
| pyHanko and pyhanko-cli (pip) | 0.37.0 / 0.5.0 | MIT; their own dependencies (asn1crypto, cryptography, pyhanko-certvalidator, requests, tzlocal, PyYAML, click) are MIT, Apache-2.0 and BSD | imported by our vxsig.py helper |
From Debian trixie (unpinned within the release; the image digest pins them):
| Package | Licence | How it runs |
|---|---|---|
| tesseract-ocr, -eng, -osd | Apache-2.0 (Leptonica BSD-2-Clause) | separate process |
| qpdf | Apache-2.0 | separate process; libqpdf also inside pikepdf |
| python3 (python3-pip at build only, purged from the running container) | PSF-2.0; MIT | runs our helpers |
| python3-pikepdf | MPL-2.0 | imported by our vxpdf.py helper |
| python3-fonttools | MIT | installed; unused by the helpers |
| weasyprint | BSD-3-Clause | separate process |
| ffmpeg, ffprobe | GPL-2.0-or-later (Debian's build enables GPL codecs) | separate process |
| flac | GPL-2.0-or-later (the CLI; libFLAC is BSD-3-Clause) | separate process |
| mediaconch | GPL-3.0-or-later OR MPL-2.0-or-later | separate process |
| libheif-examples (heif-dec) | MIT; libheif LGPL-3.0-or-later | separate process |
| pandoc | GPL-2.0-or-later | separate process (--sandbox) |
| asciidoctor | MIT | separate process |
| 7zip | LGPL-2.1-or-later with BSD-3-Clause parts | separate process |
| libreoffice-core/-writer/-calc/-impress/-draw/-math (nogui) | MPL-2.0 with LGPL-3.0-or-later parts and many third-party components (Debian's copyright files list them) | separate process soffice.bin |
| openjdk-21-jre-headless | GPL-2.0 WITH Classpath-exception-2.0 | runs veraPDF |
| libimage-exiftool-perl | Artistic-1.0-Perl OR GPL-1.0-or-later | separate process |
| python3-tsk (pytsk3 with libtsk), python3-libewf (pyewf with libewf) | pytsk3 Apache-2.0; The Sleuth Kit CPL-1.0 and IPL-1.0 with GPL-2.0-or-later tools; libewf LGPL-3.0-or-later | imported by our vxtsk.py helper |
| openssl | Apache-2.0 | separate process (openssl ts) |
| restic | BSD-2-Clause | separate process, outside the sandbox (the backups, ADR-0022) |
| openssh-client | BSD-style (the OpenBSD licence) | ssh, run by restic for an sftp destination |
| rclone | MIT | run by restic for an rclone destination |
| postgresql-client-18, with postgresql-common (both from PGDG's apt repository, not Debian's archive) | the PostgreSQL licence; postgresql-common GPL-2.0-or-later | pg_dump and pg_dumpall, outside the sandbox |
| fontconfig | MIT-style (HPND) | separate process fc-list |
| fonts-liberation, fonts-crosextra-carlito, fonts-crosextra-caladea, fonts-dejavu-core, fonts-noto-core | OFL-1.1 (Liberation 2, Carlito, Noto), Apache-2.0 (Caladea), the Bitstream Vera licence (DejaVu) | font data; rendered into reading copies and reports, which those licences permit |
| ca-certificates (curl, unzip and xz-utils at build only) | MPL-2.0 with GPL-2.0-or-later scripts; the curl licence; Info-ZIP; 0BSD and public domain | certificates as data; the three tools serve the build stage and are purged from the running container's final layer (their bytes stay in the image's earlier layers, which is why they are still listed) |
Deliberately absent: Ghostscript (AGPL-3.0; probed by VXDRIVE_TOOL_GS for an operator
who holds a licence and adds it in a derived image), bulk_extractor (GPL-3.0; the bulk
feature extractor is in-house), Epson's network scanner plugin (its licence forbids
redistribution; docs/runbooks/scanner-live.md).
The server image (deploy/Dockerfile)
debian:trixie-slim with the two binaries and ca-certificates, sane-utils (GPL-2.0-or-later;
scanimage), sane-airscan (GPL-2.0-or-later), smbclient (GPL-3.0-or-later) and
avahi-utils (LGPL-2.1-or-later; installed, not invoked). Debian's copyright files are under
/usr/share/doc.
Services the compose file runs beside the product
pgvector/pgvector:pg18 (PostgreSQL licence; pgvector PostgreSQL licence),
quay.io/minio/minio and quay.io/minio/mc (AGPL-3.0: run unmodified, which binds the
operator to nothing; any S3-compatible store serves). The operator pulls these; VX Drive
redistributes none of them. The appliance (ADR-0021) runs the same database image pinned by
digest and, for a public domain's certificates, the ACME client goacme/lego (MIT), also
pinned by digest and pulled by the certificate timer; neither is in a VX Drive image.
Models
The catalogue (deploy/models.json, catalog_version 2026.09) lists only MIT and Apache-2.0
weights, each pinned by SHA-256 and fetched at install time, never at build time:
| Model | Kind | Licence | Source |
|---|---|---|---|
| multilingual-e5-small | embedding (default) | MIT | intfloat, converted with llama.cpp; hosted on the vendor's storage account (vlstoree5183944.blob.core.windows.net, the public-read models container), like every file this repository converts |
| all-minilm-l6-v2 | embedding | Apache-2.0 | sentence-transformers via second-state |
| bge-m3 | embedding | MIT | BAAI via ggml-org |
| qwen3-embedding-0.6b | embedding | Apache-2.0 | Qwen |
| qwen3-0.6b (default), qwen3-1.7b | answers | Apache-2.0 | Qwen |
| smollm2-135m-instruct | answers | Apache-2.0 | HuggingFaceTB via unsloth |
| whisper tiny, base, small (default), medium, large-v3-turbo; the Silero VAD companion | transcripts | MIT | openai/whisper via whisper.cpp; ggml-org/whisper-vad |
| qwen3-reranker-0.6b (default) | re-ranking | Apache-2.0 | Qwen via ggml-org |
| bge-reranker-v2-m3 | re-ranking | Apache-2.0 (its model card; an earlier catalogue said MIT) | BAAI via gpustack |
| smolvlm-500m (default), smolvlm-256m | descriptions | Apache-2.0 | HuggingFaceTB via ggml-org |
| colsmol-500m (default), colsmol-256m | pages by appearance | MIT AND Apache-2.0 (MIT adapters merged onto an Apache-2.0 base) | vidore, merged and converted by this repository |
| colqwen2-2b | pages by appearance | MIT AND Apache-2.0 (MIT adapters on Qwen2-VL-2B-Instruct, Apache-2.0) | vidore, merged and converted by this repository |
Not catalogued on purpose: ColQwen2.5, whose base is under the non-commercial Qwen Research
Licence. The test models the CI toolchain fetches (deploy/tools.lock) are the same families
at their smallest sizes, MIT and Apache-2.0.
Nothing else that learns or matches ships. Voice and face embedders, forgery detectors, YARA rulesets, hash sets (NSRL, Project VIC, CAID, PhotoDNA) and any perceptual matcher are the operator's, registered or placed under their own licence and entitlement; the product records who added each and, for a model, the licence note and limitations the operator entered.
Fonts and design assets
- Roboto (variable, latin and latin-ext), vendored from Google Fonts: SIL OFL-1.1, the
font's own licence field; the licence travels beside the font
(
apps/web/public/assets/fonts/ROBOTO-LICENSE.txt). - GOV.UK Design System:
govuk-frontendis MIT. GDS Transport and the crown are licensed to gov.uk domains only and are not shipped: the font family is overridden, the image function returns nothing, and no GOV.UK image asset is in the bundle (ADR-0008). - The icons (
apps/web/public/icons,apps/desktop/src-tauri/icons): drawn for the product — a navy rounded square, the letters VX set in Liberation Sans Bold (OFL-1.1) and a rule; no third-party mark (theNOTICEbeside each set). - The vendor's web fonts (
vendor/web-kit/public/fonts, ADR-0027; the display face of ADR-0030): Bricolage Grotesque, Literata, Atkinson Hyperlegible Next and Atkinson Hyperlegible Mono, variable woff2 subsets fetched from Google Fonts (theMANIFEST.txtbeside them records each file's source, subset and bytes), all SIL OFL-1.1 with the licence texts beside them (OFL-*.txt) and aNOTICE. - The Vertex Lake wordmark and icon (
vendor/web-kit/src/components/index.tsx,vendor/web-kit/public/icon.svg): drawn for the vendor — a geometric peak over a brass water line with its reflection; no third-party mark. - The audience photographs (
vendor/web/public/audiences, sixteen pictures at three widths): generated on 2026-09-26 with FLUX.2 [max] through Black Forest Labs' API under its commercial terms, from the prompts recorded invendor/web/brand/audiences/manifest.json; synthetic scenes with no real person, place, mark or text in them; decorative on the page (an emptyalt). The full-size originals live outside git, in the vendor's storage account (vendor/web/brand/audiences/README.md). - The vendor's npm packages (
vendor/web,vendor/web-kit,vendor/admin,vendor/portal-client):solid-jsand@solidjs/web2.0.0-rc.9 (MIT),qrcode(MIT),vite(MIT),@solidjs/vite-plugin(MIT),typed-openapi(MIT),marked(MIT; build only, the assurance pages under/trust),@playwright/testand@axe-core/playwright(Apache-2.0 and MPL-2.0, development only),typescript(Apache-2.0); the generated clients and the runtime are the product's own. - Worker assets (
server/vxdrive-workers/assets/NOTICE): Tesseract's GlyphLessFont (Apache-2.0) as the invisible text layer's font, an sRGB profile ("no copyright, use freely"), the EA-PDF XMP schema (University of Illinois, NCSA licence).
Test fixtures
ascii.msg (from the msg_parser crate's test data, MIT), speech-en.mp3 (a LibriVox
recording of a public-domain text, public domain), minutes.md and picture.jpg (made for
the suite), and captured scanner output from the team's own devices; C2PA credentials,
signed PDFs, disk images and recordings are generated at test time.
Regenerating this register
cargo metadata --format-version 1 | jq -r '.packages[] | select(.source != null) | "\(.name)\t\(.version)\t\(.license // "MISSING")"' | sort -u
cargo tree -i <crate> # who pulls a flagged crate in
pnpm licenses list --long # the npm tree; add --prod for what ships
grep -v '^#' deploy/tools.lock # the pinned archives
ls /opt/vxdrive/NOTICES/tools /opt/vxdrive/NOTICES/debian # inside the worker image
The release's sbom.spdx.json and sbom.cdx.json are built from the source tree; the images'
Debian and Python packages are in sbom-server.spdx.json and sbom-workers.spdx.json with
their versions; the archives above and the models are listed here, not there.