Legal
Third-party notices
Every third-party component is reviewed on its own licence. Being on GitHub is not the same as being free for commercial use, and a permissive licence still carries obligations.
Software
What GenCMS builds on.
Integrated means the code ships in the product. Reference only means it informed a design decision and no code was copied.
| Component | Licence | Status | Role | Obligations |
|---|---|---|---|---|
| Next.js | MIT | Integrated | Application framework for this website. | Retain copyright and permission notice. |
| React | MIT | Integrated | UI runtime. | Retain copyright and permission notice. |
| Tailwind CSS | MIT | Integrated | Design-token and utility layer behind the GenCMS design system. | Retain copyright and permission notice. |
| Inter | SIL Open Font License 1.1 | Integrated | Interface typeface. | Retain the OFL notice; the font is not sold on its own. |
| node-postgres | MIT (ISC for split2) | Integrated | PostgreSQL client for the transactional tenant storage registry. | Retain copyright and permission notices for the package and permissive transitive dependencies. |
| Tencent AI-Infra-Guard | Apache License 2.0 | Planned adapter | Candidate second scanner behind the GenCMS Guard adapter interface. | Retain LICENSE and NOTICE; state the integration in product documentation and the About page; cite in any published security research. |
| mattpocock/skills | MIT | Reference only | Reference for small composable skill packages and agent-oriented instruction sets. | No code copied. Retain the notice if any file is ever vendored. |
| Cursor Plugins | MIT | Reference only | Reference for plugin packaging and marketplace metadata conventions. | No code copied. Retain the notice if any file is ever vendored. |
| OpenViking | AGPL-3.0 | Reference only | Architecture reference for unifying agent memory, knowledge and skills. | Network copyleft. Not integrated, and not to be integrated without a deliberate decision to comply with AGPL obligations for the hosted service. |
GenCMS Guard
Which scanner is actually running.
Guard is built behind an adapter interface so the product is never coupled to one scanner. Being clear about which adapter produced a result is part of the trust claim.
GenCMS rules
Running todayAn independently written static rule engine covering eleven check families. No third-party scanning code is included in it, so no third-party attribution is owed for a result it produced.
AI-Infra-Guard adapter
PlannedTencent Zhuque Lab’s AI-Infra-Guard is Apache-2.0 and carries an explicit attribution requirement. If GenCMS enables that adapter, the statement below appears in the product documentation and on the About page, and the LICENSE and NOTICE files ship with the distribution.
This project integrates AI-Infra-Guard, open-sourced by Tencent Zhuque Lab. https://github.com/Tencent/AI-Infra-Guard Apache License 2.0 · LICENSE and NOTICE retained. Copyright 2024-2026 Tencent Zhuque Lab.
GenCMS Guard
│
▼
Scanner Adapter Interface
├── GenCMS rules (shipping)
├── AI-Infra-Guard (planned, attribution required)
└── future scannersEvery scan result names the adapter that produced it. Integrating a third-party engine invisibly would breach its licence and misrepresent where the finding came from.
Design assets
Envato items, registered to this project.
Envato Elements items are used as ingredients in a finished GenCMS product. Raw template files are never redistributed, never made downloadable, and never presented as a GenCMS asset library.
- Author
- Mighty-Design
- Licence
- Envato Elements — commercial, single End Product
- Licensee
- IGEARS TECHNOLOGY LIMITED
- Licence code
- P4V9BA5TKH
- Licence date
- 21 August 2026
- Registered project
- GenCMS — gen-cms.com
- Usage
- Layout reference for the Skills marketplace, publisher analytics and empty states.
- Modified
- Rebuilt in the GenCMS design system — no template files shipped.
- Author
- gardeniaa
- Licence
- Envato Elements — commercial, single End Product
- Licensee
- IGEARS TECHNOLOGY LIMITED
- Licence code
- HT3CMQ2GFB
- Licence date
- 21 August 2026
- Registered project
- GenCMS — gen-cms.com
- Usage
- Layout reference for the Guard report interface, findings panels and status cards.
- Modified
- Rebuilt in the GenCMS design system — no template files shipped.
- Author
- ThemeWant
- Licence
- Envato Elements — commercial, single End Product
- Licensee
- IGEARS TECHNOLOGY LIMITED
- Licence code
- F6HGXTWKC9
- Licence date
- 21 August 2026
- Registered project
- GenCMS — gen-cms.com
- Usage
- Layout reference for the Memory workspace and the application shell.
- Modified
- Rebuilt in the GenCMS design system — no template files shipped.
- Author
- xvelopers
- Licence
- Envato Elements — commercial, single End Product
- Licensee
- IGEARS TECHNOLOGY LIMITED
- Licence code
- DN638CKY2V
- Licence date
- 21 August 2026
- Registered project
- GenCMS — gen-cms.com
- Usage
- UX reference for the knowledge library, source browser and documentation navigation.
- Modified
- Rebuilt in the GenCMS design system — no template files shipped.
Source files for these items are retained privately by IGEARS TECHNOLOGY LIMITED and are not part of any GenCMS distribution. Licence certificates are held with the internal asset register.
Policy
How a third-party component gets approved.
Applied before anything is vendored, not after a licence question is raised.
Repository licence
Read the actual LICENSE file, not the README badge.
Dependency licences
A permissive top level over a copyleft dependency is still copyleft.
NOTICE requirements
Apache-2.0 §4(d) obligations travel with the code.
Attribution
Where the licence names a placement — docs, About page, release notes — use that placement.
Network-use obligations
AGPL reaches hosted services. Reference-only is a decision, not a loophole.
Provider terms
Model provider terms apply on top of the component licence.
Questions about a notice on this page: [email protected]. GenCMS is a product of IGEARS TECHNOLOGY LIMITED.