Third-Party Licences
Varen itself is proprietary commercial software, provided under its subscription terms. It is built on — and runs alongside — the third-party software listed below. Each entry names the component, the version in use, and its licence; follow the project link for the full licence text. Versions are as deployed on 1 August 2026 and drift upward as components are upgraded.
Platform & infrastructure
These components form the runtime: the SaaS host services, the node stack, and the software the platform is compiled with.
| Component | Version | Licence | Project |
|---|---|---|---|
| Go | 1.25.0 | BSD-3-Clause | go.dev |
| Caddy (HTTPS / reverse proxy) | 2.11.3 | Apache-2.0 | caddyserver.com |
| PostgreSQL (control-plane database) | 16.14 | PostgreSQL Licence | postgresql.org |
| Redis (control-plane cache) | 7.0.15 | BSD-3-Clause | redis.io |
| Qdrant (node vector database) | 1.18.2 | Apache-2.0 | qdrant.tech |
| Ollama (node embedding runtime) | 0.32.1 | MIT | ollama.com |
| nomic-embed-text (embedding model) | current | Apache-2.0 | ollama.com |
| LiteLLM (model gateway) | 1.82.6 | MIT | litellm.ai |
| Docker Engine & Compose (node runtime) | 24+ / v2 | Apache-2.0 | docker.com |
| WireGuard (node VPN tunnel) | kernel / wireguard-go | GPL-2.0 (kernel module); MIT (wireguard-go) | wireguard.com |
| Distroless (node container base image) | static-debian12 | Apache-2.0 | github.com |
| Distribution (self-hosted image registry) | registry:2 | Apache-2.0 | github.com |
| Protocol Buffers & gRPC tooling | build-time | BSD-3-Clause / Apache-2.0 | protobuf.dev |
SaaS control plane libraries (Go)
| Library | Version | Licence |
|---|---|---|
| golang-jwt/jwt (authentication tokens) | 5.2.3 | MIT |
| jackc/pgx (PostgreSQL driver) | 5.7.3 | MIT |
| pdfcpu (PDF processing) | 0.12.1 | Apache-2.0 |
| redis/go-redis (Redis client) | 9.18.0 | BSD-2-Clause |
| shopspring/decimal (decimal-safe billing arithmetic) | 1.4.0 | MIT |
| golang.org/x/crypto | 0.50.0 | BSD-3-Clause |
| golang.org/x/net | 0.52.0 | BSD-3-Clause |
| golang.org/x/sync | 0.20.0 | BSD-3-Clause |
| wireguard/wgctrl (WireGuard coordination) | 2024-12-31 | MIT |
| gRPC-Go (node connectivity) | 1.80.0 | Apache-2.0 |
| protobuf-go | 1.36.11 | BSD-3-Clause |
| genproto (googleapis/rpc) | 2026-01-20 | Apache-2.0 |
| nhooyr.io/websocket | 1.8.17 | ISC |
| yaml.v2 | 2.4.0 | Apache-2.0 |
Node runtime libraries (Go)
| Library | Version | Licence |
|---|---|---|
| google/uuid | 1.6.0 | BSD-3-Clause |
| pdfcpu (PDF processing) | 0.12.1 | Apache-2.0 |
| vishvananda/netlink (tunnel interface management) | 1.3.1 | Apache-2.0 |
| golang.org/x/crypto | 0.50.0 | BSD-3-Clause |
| golang.org/x/image | 0.39.0 | BSD-3-Clause |
| wireguard-go | 2025-05-21 | MIT |
| gRPC-Go | 1.80.0 | Apache-2.0 |
| protobuf-go | 1.36.11 | BSD-3-Clause |
| genproto (googleapis/rpc) | 2026-01-20 | Apache-2.0 |
| modernc.org/sqlite (node-local storage; SQLite itself is public domain) | 1.48.2 | BSD-3-Clause |
| nhooyr.io/websocket | 1.8.17 | ISC |
| yaml.v3 | 3.0.1 | Apache-2.0 |
Desktop application libraries (JavaScript)
Shipped with the browser application:
| Library | Version | Licence |
|---|---|---|
| React & React DOM | 19.2.x | MIT |
| Milkdown (Crepe & kit) (document editor) | 7.21.x | MIT |
| DOMPurify (HTML sanitising) | 3.4.x | MPL-2.0 or Apache-2.0 (dual) |
| marked (Markdown rendering) | 18.0.x | MIT |
| exifr (image metadata) | 7.1.x | MIT |
| lucide-react (icons) | 1.14.x | ISC |
| qrcode | 1.5.x | MIT |
| WinBox (floating windows) | 0.2.x | Apache-2.0 |
Build-time only (not shipped to your browser): Vite (MIT), TypeScript (Apache-2.0), Vitest (MIT), @vitejs/plugin-react (MIT), and DefinitelyTyped type definitions (MIT).
Hosted AI providers
Generating answers involves third-party hosted AI services — the Claude, GPT, and Gemini model families, and open-weight models routed via OpenRouter. These are services reached over an API, not software bundled with Varen, so they are not licensed components in the sense above. What they receive, and the terms that govern those requests, are described in Privacy & Data.
This page lists direct dependencies and major platform components. Indirect (transitive) library dependencies are not enumerated; the licence texts for any component are available from the linked project pages.