Open-Source Attribution
PentestOps incorporates third-party open-source components. This notice sets out how we use them, the licence obligations we accept, and how to obtain the corresponding source for anything we distribute to you.
We do not fork or modify these components. They run as standalone processes that our platform invokes through their published interfaces, and none of them is statically linked into our proprietary code.
What is included, and where to find the list
The complete list of third-party components in the build you received, with the exact version and the full licence text of each, is included with that build. It is written into the agent and platform images we distribute, so the notice always matches the software actually in front of you rather than whatever the website happened to say on the day.
Operators can print it at any time with pentest-agent --licenses, and
it is also written to the image at /opt/pentest-agent/LICENSES. If you
are evaluating PentestOps and want the list before you install anything, or you
need it in a particular format for a supply-chain review, email
legal@pentestops.ai and we will send it.
Components fall into these categories: network and host discovery, service and version identification, web application and API scanning, credential testing, Windows and directory assessment, container and Kubernetes assessment, and transport. Software we run only on our own infrastructure to operate the service is not distributed to you and is therefore outside the scope of this notice.
Licence compliance & obligations
GPL and AGPL licensed components are bundled as standalone executables and invoked as separate processes. We do not statically link any GPL code into our proprietary application code, and our orchestration layer interacts with them only through their published command-line and IPC interfaces. Each component is shipped unmodified. The full licence text of every one, and the identity of each, is included with the build you receive.
Written offer for corresponding source. For any GPL or AGPL licensed component we distribute, we will provide the complete corresponding source code for the exact version shipped to you, on a physical medium or by download at your option, for a charge no greater than our cost of performing the distribution. This offer is valid for three years from the date you received the component. To exercise it, email legal@pentestops.ai with the component name and the version of the agent or platform image you received. The upstream project links on this page are provided for convenience only and are not a substitute for this offer, because upstream repositories move on from the revision you were given.
Apache 2.0 / MIT / BSD tools are bundled under their permissive licences with full attribution preserved in our agent and platform images. Upstream copyright notices and licence texts are retained in the binary distributions.
Commercially-licensed components are either avoided in default deployments or licensed separately. We do not redistribute proprietary editions.
Scope of this notice. It covers the third-party components distributed to you in the agent and platform images. Software we run only on our own infrastructure to operate the service is not distributed, and is therefore not listed here.
Versions are pinned and mirrored internally for reproducible builds and supply-chain integrity, and version bumps follow upstream security advisories. The exact versions in the build you received are recorded in the licence material shipped inside that build, rather than published here.
Reporting a licence issue: legal@pentestops.ai · Security disclosures: security@pentestops.ai
See the toolchain in action
Run a free demo scan against a domain you own and watch discovery, service detection and configuration checks report back live. No installation and no agent required.