Third-Party Licences

Varen itself is proprietary commercial software, provided under its subscription terms. It is built on — and runs alongside — the third-party software listed below. Each entry names the component, the version in use, and its licence; follow the project link for the full licence text. Versions are as deployed on 1 August 2026 and drift upward as components are upgraded.

Platform & infrastructure

These components form the runtime: the SaaS host services, the node stack, and the software the platform is compiled with.

Component Version Licence Project
Go 1.25.0 BSD-3-Clause go.dev
Caddy (HTTPS / reverse proxy) 2.11.3 Apache-2.0 caddyserver.com
PostgreSQL (control-plane database) 16.14 PostgreSQL Licence postgresql.org
Redis (control-plane cache) 7.0.15 BSD-3-Clause redis.io
Qdrant (node vector database) 1.18.2 Apache-2.0 qdrant.tech
Ollama (node embedding runtime) 0.32.1 MIT ollama.com
nomic-embed-text (embedding model) current Apache-2.0 ollama.com
LiteLLM (model gateway) 1.82.6 MIT litellm.ai
Docker Engine & Compose (node runtime) 24+ / v2 Apache-2.0 docker.com
WireGuard (node VPN tunnel) kernel / wireguard-go GPL-2.0 (kernel module); MIT (wireguard-go) wireguard.com
Distroless (node container base image) static-debian12 Apache-2.0 github.com
Distribution (self-hosted image registry) registry:2 Apache-2.0 github.com
Protocol Buffers & gRPC tooling build-time BSD-3-Clause / Apache-2.0 protobuf.dev

SaaS control plane libraries (Go)

Library Version Licence
golang-jwt/jwt (authentication tokens)5.2.3MIT
jackc/pgx (PostgreSQL driver)5.7.3MIT
pdfcpu (PDF processing)0.12.1Apache-2.0
redis/go-redis (Redis client)9.18.0BSD-2-Clause
shopspring/decimal (decimal-safe billing arithmetic)1.4.0MIT
golang.org/x/crypto0.50.0BSD-3-Clause
golang.org/x/net0.52.0BSD-3-Clause
golang.org/x/sync0.20.0BSD-3-Clause
wireguard/wgctrl (WireGuard coordination)2024-12-31MIT
gRPC-Go (node connectivity)1.80.0Apache-2.0
protobuf-go1.36.11BSD-3-Clause
genproto (googleapis/rpc)2026-01-20Apache-2.0
nhooyr.io/websocket1.8.17ISC
yaml.v22.4.0Apache-2.0

Node runtime libraries (Go)

Library Version Licence
google/uuid1.6.0BSD-3-Clause
pdfcpu (PDF processing)0.12.1Apache-2.0
vishvananda/netlink (tunnel interface management)1.3.1Apache-2.0
golang.org/x/crypto0.50.0BSD-3-Clause
golang.org/x/image0.39.0BSD-3-Clause
wireguard-go2025-05-21MIT
gRPC-Go1.80.0Apache-2.0
protobuf-go1.36.11BSD-3-Clause
genproto (googleapis/rpc)2026-01-20Apache-2.0
modernc.org/sqlite (node-local storage; SQLite itself is public domain)1.48.2BSD-3-Clause
nhooyr.io/websocket1.8.17ISC
yaml.v33.0.1Apache-2.0

Desktop application libraries (JavaScript)

Shipped with the browser application:

Library Version Licence
React & React DOM19.2.xMIT
Milkdown (Crepe & kit) (document editor)7.21.xMIT
DOMPurify (HTML sanitising)3.4.xMPL-2.0 or Apache-2.0 (dual)
marked (Markdown rendering)18.0.xMIT
exifr (image metadata)7.1.xMIT
lucide-react (icons)1.14.xISC
qrcode1.5.xMIT
WinBox (floating windows)0.2.xApache-2.0

Build-time only (not shipped to your browser): Vite (MIT), TypeScript (Apache-2.0), Vitest (MIT), @vitejs/plugin-react (MIT), and DefinitelyTyped type definitions (MIT).

Hosted AI providers

Generating answers involves third-party hosted AI services — the Claude, GPT, and Gemini model families, and open-weight models routed via OpenRouter. These are services reached over an API, not software bundled with Varen, so they are not licensed components in the sense above. What they receive, and the terms that govern those requests, are described in Privacy & Data.

This page lists direct dependencies and major platform components. Indirect (transitive) library dependencies are not enumerated; the licence texts for any component are available from the linked project pages.