Enforcer Brand Icon
Enforcer-CCA
Access ControlsAWSKubernetesSOC 2 (Roadmap)
ProofFeaturesSecurityPricingAbout
Talk to the founder
Enforcer Brand Icon
Enforcer-CCA

Enforcer checks how your cloud is really configured against ISO 27001 every day, and keeps a dated record. It runs alongside the compliance tool you already have.

Platform

  • Features
  • Proof
  • Security & data handling
  • Support Portal

Solutions

  • AWS
  • Kubernetes
  • SOC 2 (Roadmap)

Company

  • About Us
  • Roadmap
  • Pricing
  • Why live-state evidence

Connect

  • Talk to the founder

Ask AI about Enforcer

Start a custom consultation with your favorite AI strategist. Click any LLM platform below to automatically open a session pre-loaded with our detailed, fact-checked product brief.

Prompt Overview

“You are a GRC and compliance strategist advising a cloud-native company that sells to banks or other regulated enterprises. Analyze the business value of Enforcer CCA, a tool that turns the live state of cloud infrastructure into dated comp...”

© 2026 Enforcer-CCA · Runs in your own infrastructure
Terms and ConditionsPrivacy Policy

Core Policies

Terms of ServicePrivacy PolicyCookie PolicyDisclaimer PolicyAcceptable Use Policy

Enterprise & SaaS

End User License Agreement (EULA)Data Processing AddendumEnterprise License TermsSecurity Responsibility MatrixSupport & SLA FrameworkConfidentiality Agreement

Disclaimers & Liability

Limitation of LiabilityWarranty DisclaimerAI & Automation DisclaimerCompliance Responsibility Disclaimer

Legal Operations

Intellectual Property TermsOpen Source DisclosureExport Control PolicyGoverning Law & DisputesIndemnification Clauses
Enforcer Marketing | Enforcer Dashboard

Open Source Disclosure

Effective: May 1, 20266 min readJurisdiction: Maharashtra, India

Quick Summary (Plain English)

Discloses third-party libraries and compliance licenses.

Enforcer Labs Private Limited

Effective Date: May 1, 2026
Last Updated: May 17, 2026
Applies To: Enforcer Marketing | Enforcer Dashboard


1. Overview

Enforcer Labs products incorporate open source software components. This document provides disclosure of significant open source components, their licenses, and applicable obligations in compliance with open source license requirements.

Enforcer Labs' proprietary software is not open source. It is proprietary software licensed under the terms set forth in the EULA and Enterprise License Terms. The use of open source components within our products does not change the proprietary nature of the Enforcer Labs software.


2. Open Source License Categories

The open source components used in Enforcer Labs products fall under the following license categories:

License CategoryImplicationRisk Level
MIT LicensePermissive; minimal restrictionsLow
Apache License 2.0Permissive; patent grant includedLow
BSD (2-Clause / 3-Clause)Permissive; attribution requiredLow
ISC LicensePermissive; functionally equivalent to MITLow
PSF LicensePython Software Foundation; permissiveLow
LGPLWeak copyleft; dynamic linking permittedMedium

Enforcer Labs does not incorporate any AGPL, GPL, SSPL, or strong copyleft licensed components in its proprietary products.


3. Enforcer Marketing — Open Source Components

The Enforcer Marketing website uses the following major open source frameworks and libraries:

ComponentVersionLicensePurpose
Next.js16.2.5MITWeb application framework
React19.2.4MITUI rendering library
React DOM19.2.4MITDOM rendering for React
Tailwind CSS4.xMITUtility-first CSS framework
Lucide React1.14.xISCIcon library
MDX (loader, react, next)3.xMITMarkdown/JSX content
TypeScript5.xApache-2.0Type-safe JavaScript
ESLint9.xMITCode linting
Autoprefixer10.xMITCSS vendor prefixing
PostCSS8.xMITCSS transformation

4. Enforcer Dashboard — Open Source Components

4.1 Backend (Python)

ComponentVersionLicensePurpose
FastAPI0.115.xMITAPI framework
Uvicorn0.34.xBSD-3-ClauseASGI server
SQLAlchemy2.0.xMITORM and database toolkit
Asyncpg0.30.xApache-2.0PostgreSQL async driver
Alembic1.18.xMITDatabase migrations
Pydantic2.10.xMITData validation
Dynaconf3.2.xMITConfiguration management
HTTPX0.28.xBSD-3-ClauseHTTP client
PyJWT2.12.xMITJSON Web Token handling
Passlib1.7.xBSD-3-ClausePassword hashing
SlowAPI0.1.xMITRate limiting
Boto31.43.xApache-2.0AWS SDK
Prefect3.6.xApache-2.0Workflow orchestration
OpenAI1.60.xMITOpenAI API client
LangChain0.3.xMITLLM framework
LangChain-OpenAI0.3.xMITLangChain OpenAI integration
Pytz2026.xMITTimezone handling
Python-Multipart0.0.xApache-2.0Multipart form parsing

4.2 Frontend (Node.js)

ComponentVersionLicensePurpose
Next.js16.2.5MITWeb application framework
React19.2.4MITUI rendering library
React DOM19.2.4MITDOM rendering
Tailwind CSS4.xMITCSS framework
TypeScript5.xApache-2.0Type-safe JavaScript

4.3 Infrastructure

ComponentVersionLicensePurpose
PostgreSQL16.xPostgreSQL LicensePrimary database
Redis7.xBSD-3-ClauseCaching and message broker
Nginx1.xBSD-2-ClauseReverse proxy
PgBouncer1.xISCConnection pooling
Docker24.xApache-2.0Containerization

5. License Obligations

5.1 Attribution

All open source components retain their original copyright notices and license text. Attribution is provided in this document and within the Software's LICENSES directory (where applicable).

5.2 MIT / ISC / BSD Licenses

These permissive licenses require:

(a) retention of copyright notices in redistributed source code;

(b) inclusion of license text in binary distributions;

(c) no endorsement claims using the authors' names without permission (BSD-3-Clause).

No restrictions on proprietary use, modification, or distribution.

5.3 Apache License 2.0

In addition to attribution requirements:

(a) a patent license is granted from contributors;

(b) modifications must be documented with a NOTICE file if applicable;

(c) no trademark license is granted.


6. SBOM (Software Bill of Materials)

Enforcer Labs maintains a machine-readable Software Bill of Materials (SBOM) for each release of Enforcer Dashboard. The SBOM is available:

(a) within the release artifacts in CycloneDX or SPDX format;

(b) upon request to licensed customers at legal@enforcer-cca.com.


7. Vulnerability Disclosure

Enforcer Labs monitors all open source dependencies for known vulnerabilities using automated scanning tools. Critical vulnerabilities in dependencies are addressed per the timeline in the Security Responsibility document (09_security_responsibility.md).


8. No Copyleft Contamination

8.1 Enforcer Labs confirms that no component of its proprietary software is derived from, linked with, or distributed alongside software under GPL, AGPL, SSPL, or other strong copyleft licenses that would require disclosure of Enforcer Labs' proprietary source code.

8.2 All open source components are used in accordance with their respective license terms and in a manner that preserves the proprietary nature of Enforcer Labs' software.


9. Contact

For open source licensing inquiries:

Enforcer Labs Private Limited
Email: legal@enforcer-cca.com


This document is subject to attorney review. The open source component list should be regenerated from the actual SBOM before each major release.