Skip to content

License and Security

Current license

Current revisions are distributed under the SXS Source-Available Commercial License 1.0. It is not an OSI-approved open-source license.

The full repository LICENSE is controlling. In summary:

Authoritative texts: LICENSE, NOTICE, and COMMERCIAL_USE.md.

  • non-commercial personal, educational, evaluation, and research use is permitted subject to the license;
  • public projects, deployments, and outputs materially using SXS require clear creator and organization attribution;
  • commercial use requires advance registration, quarterly reporting, and a 10% royalty on Covered Revenue unless a separate signed agreement applies;
  • publication and award submissions have citation/acknowledgment requirements; and
  • scientific status, provenance, and candidate warnings may not be falsified.

The tagged v1.0.0 was previously distributed under MIT. Rights validly received with that copy are not retroactively withdrawn. Current revisions and the v1.1.0, v1.2.0, and v1.3.0 releases carry the current license.

Obtain legal advice

The documentation summarizes project terms and is not legal advice. Review LICENSE, NOTICE, and COMMERCIAL_USE.md, and obtain qualified advice for material commercial or cross-border use.

Security reporting

Do not disclose an exploitable vulnerability in a public issue before the maintainer can assess it. Follow the repository SECURITY.md reporting process and include:

  • affected release/commit;
  • reproducible impact and prerequisites;
  • minimal proof of concept without secrets or personal data; and
  • suggested mitigation if known.

See the complete security policy for the private reporting channel and public scientific-issue scope.

Repository automation also performs CodeQL analysis, pull-request dependency review, weekly Dependabot checks, container SBOM generation, and GitHub artifact attestation. These controls reduce supply-chain risk but do not replace review of scientific assumptions, upstream advisories, or the independent legal checklist.

Scientific integrity issues

Errors that could change reported metrics, candidate classifications, provenance, or discovery wording should also be treated as high-priority integrity reports. Preserve the original evidence and describe the discrepancy without modifying accepted artifacts in place.

Contact

Research collaboration, commercial licensing, and royalty administration: scix.official@gmail.com.