Licences & SBOM
A signed SBOM will be published alongside the first deployment. Until then, the third-party licences in scope are listed below — taken from the production sweep and the build map.
| Component | Licence | Notes |
|---|---|---|
| Next.js 15 | MIT | App shell |
| React 19 | MIT | Render |
| MapLibre GL JS v6 | BSD-3 | Globe (when shipped) |
| deck.gl | MIT | Overlay (when shipped) |
| Protomaps PMTiles | BSD-3 | Tiles on R2 |
| DuckDB-WASM | MIT | GeoParquet query (when shipped) |
| @noble/ed25519 | MIT | Fallback verify (WebCrypto first) |
| c2patool / c2pa SDK 0.90.1 | Apache-2.0 | Manifest validation |
| OpenSSL 3.6.3 (server) | Apache-2.0 | ML-DSA-65 signing |
| LiteLLM core | MIT | Adapter — MIT core only, never enterprise |
Boundaries: Natural Earth (PD), geoBoundaries (CC BY). Never GADM (non-commercial).