COUNCIL OF SOVEREIGN AI
the measurement body for AI agent compliance with statute

Licences & SBOM

A signed SBOM will be published alongside the first deployment. Until then, the third-party licences in scope are listed below — taken from the production sweep and the build map.

ComponentLicenceNotes
Next.js 15MITApp shell
React 19MITRender
MapLibre GL JS v6BSD-3Globe (when shipped)
deck.glMITOverlay (when shipped)
Protomaps PMTilesBSD-3Tiles on R2
DuckDB-WASMMITGeoParquet query (when shipped)
@noble/ed25519MITFallback verify (WebCrypto first)
c2patool / c2pa SDK 0.90.1Apache-2.0Manifest validation
OpenSSL 3.6.3 (server)Apache-2.0ML-DSA-65 signing
LiteLLM coreMITAdapter — MIT core only, never enterprise

Boundaries: Natural Earth (PD), geoBoundaries (CC BY). Never GADM (non-commercial).