Open source & attributions

Standing on strong shoulders.

Qvasir is proprietary software built deliberately on open standards and best-of-breed open-source infrastructure. This page credits the projects and standards we depend on. Product deliveries include complete license and notice files for every bundled component.

Standards & frameworks

ProjectRole in QvasirLicense / terms
MITRE ATT&CK® Adversary tactic & technique framework — detection mapping and coverage reporting MITRE ATT&CK Terms of Use (free with attribution — see notice below)
OCSF — Open Cybersecurity Schema Framework Canonical event taxonomy — every log source is classified into OCSF classes Apache License 2.0
CVSS / CVE ecosystem Vulnerability scoring and identification for zero-day-driven detection generation Respective publishers' terms (FIRST.org, MITRE CVE®)

ATT&CK® content notice: © The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE does not endorse this product.

Infrastructure components

ProjectRole in QvasirLicense
Vector Log collection and shipping at the edge Mozilla Public License 2.0
Redpanda Kafka®-compatible streaming backbone for event ingestion Business Source License 1.1 (source-available)
ClickHouse® High-performance event store powering search and backtesting Apache License 2.0
PostgreSQL Primary application database PostgreSQL License
Redis® Caching, task queues, and session state RSALv2 / SSPLv1 (source-available)
Caddy Reverse proxy and TLS termination Apache License 2.0
MinIO S3-compatible object storage GNU AGPL v3
Prometheus client libraries Metrics and observability Apache License 2.0

Application frameworks & libraries

The platform is built with, among others: FastAPI, SQLAlchemy, Celery, Pydantic, Alembic, and confluent-kafka (Python, MIT/BSD licenses); Go and its ecosystem including franz-go and clickhouse-go (BSD/Apache licenses); Next.js, React, MUI, Prisma, KafkaJS, Monaco Editor, and Cytoscape.js (MIT/Apache licenses); and the official Anthropic, OpenAI, and Google AI provider SDKs. A complete, versioned inventory of third-party components with their license texts and required notices ships with every product release.

We're grateful to the maintainers of all of these projects. Open source is why a platform like Qvasir can exist — and why your data and detections stay portable.