{
  "schema": "marketnow-licensing/1.0",
  "url": "https://marketnow.site/licensing",
  "generated_at": "2026-09-25T00:00:00Z",
  "summary": {
    "npm_packages": "MIT OR Apache-2.0 (12 packages)",
    "repo_scaffolding": "MIT",
    "uts_specification": "CC-BY-NC-ND 4.0",
    "layer3_core": "AL-1.0 + commercial (proprietary/)",
    "website": "MIT OR Apache-2.0"
  },
  "matrix": [
    {
      "component": "marketnow-mcp, agent-trust-card, marketnow-install-stack, @marketnow/uts, @marketnow/trust-core, @marketnow/trust-adapters (≥1.0.3), @marketnow/trust-gateway, @marketnow/cline-trust-plugin, @marketnow/uta-conformance, @marketnow/sentinel-rules, @marketnow/trust-mcp-middleware, @marketnow/trust-observability",
      "license": "MIT OR Apache-2.0",
      "scope": "All 12 npm packages as published on the registry (SPDX dual license expression). Free to use, modify and redistribute under either license at your option.",
      "verify": "registry.npmjs.org → versions[].license, or: npm view &lt;pkg&gt; license"
    },
    {
      "component": "@marketnow/trust-adapters 1.0.0 – 1.0.2",
      "license": "AL-1.0 (historical)",
      "scope": "Versions 1.0.0–1.0.2 were published under AL-1.0 (AliceLabs Source-Available). The package was relicensed to MIT OR Apache-2.0 starting at 1.0.3 (2026-09-20). Old tarballs keep their original license — the registry history is the proof.",
      "verify": "registry.npmjs.org/@marketnow/trust-adapters → versions 1.0.0–1.0.2"
    },
    {
      "component": "UTA repository root (conformance, specs tooling, docs, CI)",
      "license": "MIT",
      "scope": "The open-core scaffolding of this repository: everything that is not the proprietary Layer-3 core.",
      "verify": "github.com/alicelabs-llc/universal-trust-adapter → /LICENSE"
    },
    {
      "component": "Plugin Template (uta-monorepo/packages/plugin-template)",
      "license": "MIT OR Apache-2.0",
      "scope": "Interface + boilerplate for third-party format adapters.",
      "verify": "uta-monorepo/packages/plugin-template/package.json"
    },
    {
      "component": "UTS Specification (spec/UTS-v1.md + uts-v1.json)",
      "license": "CC-BY-NC-ND 4.0",
      "scope": "The Universal Trust Schema specification documents: readable and shareable verbatim, no derivatives, non-commercial.",
      "verify": "github.com → spec/UTS-v1.md + README Open-Core table"
    },
    {
      "component": "Layer 3 core — TrustEngine + Sentinel + Interceptor (proprietary/)",
      "license": "AL-1.0 + commercial options",
      "scope": "The source-available engine core. Review and internal use free; commercial hosting/resale of the core requires a commercial license.",
      "verify": "proprietary/LICENSE-AL-1.0 + proprietary/COMMERCIAL-LICENSE.md"
    },
    {
      "component": "marketnow.site website (aep-marketplace)",
      "license": "MIT OR Apache-2.0",
      "scope": "The marketplace site that serves this page.",
      "verify": "marketnow/aep-marketplace/LICENSE in the repository"
    },
    {
      "component": "Conformance test vectors + Rekor anchors + CRL/OCSP data",
      "license": "Published verbatim (part of repo MIT)",
      "scope": "Test vectors, digests, anchors and revocation records are published exactly so strangers can verify — they are not separately relicensed.",
      "verify": "marketnow.site/uta/conformance/ + /api/crl"
    }
  ],
  "license_evolution": [
    {
      "package": "@marketnow/trust-adapters",
      "change": "AL-1.0 -> MIT OR Apache-2.0",
      "effective_version": "1.0.3",
      "effective_date": "2026-09-20",
      "verification": "npm registry per-version license history"
    }
  ],
  "contact": "legal@alicelabs.site"
}
