License and Security¶
Current license¶
Current revisions are distributed under the SXS Source-Available Commercial License 1.0. It is not an OSI-approved open-source license.
The full repository LICENSE is controlling. In summary:
Authoritative texts: LICENSE, NOTICE, and COMMERCIAL_USE.md.
- non-commercial personal, educational, evaluation, and research use is permitted subject to the license;
- public projects, deployments, and outputs materially using SXS require clear creator and organization attribution;
- commercial use requires advance registration, quarterly reporting, and a 10% royalty on Covered Revenue unless a separate signed agreement applies;
- publication and award submissions have citation/acknowledgment requirements; and
- scientific status, provenance, and candidate warnings may not be falsified.
The tagged v1.0.0 was previously distributed under MIT. Rights validly
received with that copy are not retroactively withdrawn. Current revisions and
the v1.1.0, v1.2.0, and v1.3.0 releases carry the current license.
Obtain legal advice
The documentation summarizes project terms and is not legal advice. Review
LICENSE, NOTICE, and COMMERCIAL_USE.md, and obtain qualified advice
for material commercial or cross-border use.
Security reporting¶
Do not disclose an exploitable vulnerability in a public issue before the
maintainer can assess it. Follow the repository SECURITY.md reporting process
and include:
- affected release/commit;
- reproducible impact and prerequisites;
- minimal proof of concept without secrets or personal data; and
- suggested mitigation if known.
See the complete security policy for the private reporting channel and public scientific-issue scope.
Repository automation also performs CodeQL analysis, pull-request dependency review, weekly Dependabot checks, container SBOM generation, and GitHub artifact attestation. These controls reduce supply-chain risk but do not replace review of scientific assumptions, upstream advisories, or the independent legal checklist.
Scientific integrity issues¶
Errors that could change reported metrics, candidate classifications, provenance, or discovery wording should also be treated as high-priority integrity reports. Preserve the original evidence and describe the discrepancy without modifying accepted artifacts in place.
Contact¶
Research collaboration, commercial licensing, and royalty administration:
scix.official@gmail.com.