Trust Center

Software Bill of Materials

In compliance with the Cyber Resilience Act (EU) 2024/2847, Article 13, Veritome maintains a transparent record of all software components used in the platform. This SBOM is automatically generated from the platform's dependency manifest.
46
Runtime Dependencies
20
Build Dependencies
66
Total Packages
3
License Types

License Distribution

Other50 packages
MIT11 packages
Apache-2.05 packages

Runtime Dependencies (46)

PackageVersionLicense
@anthropic-ai/sdk0.115.0MIT
@aws-sdk/client-s33.1098.0Apache-2.0
@aws-sdk/s3-request-presigner3.1098.0Apache-2.0
@dnd-kit/core6.3.1Other
@hello-pangea/dnd18.0.1Other
@phosphor-icons/react2.1.10MIT
@prisma/client6.19.3Apache-2.0
@react-pdf/renderer4.5.1Other
@sentry/nextjs10.69.0Other
@tiptap/extension-placeholder3.29.2Other
@tiptap/pm3.29.2Other
@tiptap/react3.29.2Other
@tiptap/starter-kit3.29.2Other
@upstash/ratelimit2.0.8Other
@upstash/redis1.38.0Other
bcryptjs3.0.3Other
better-auth1.6.25MIT
bullmq6.0.0Other
date-fns4.4.0MIT
framer-motion12.43.0MIT
ioredis5.11.1Other
jose6.2.5Other
mammoth1.12.0Other
next16.3.0MIT
next-intl4.13.4Other
otplib12.0.1Other
pdf-lib1.17.1Other
pdf-parse2.4.5Other
posthog-js1.408.1Other
posthog-node5.46.1Other
prisma6.19.3Apache-2.0
qrcode1.5.4Other
react19.2.8MIT
react-dom19.2.8MIT
react-hook-form7.83.0Other
react-markdown10.1.0Other
recharts3.10.1Other
rehype-highlight7.0.2Other
remark-gfm4.0.1Other
resend6.18.1Other
rss-parser3.13.0Other
satori0.29.0Other
sharp0.35.3Other
sonner2.0.7Other
stripe22.4.0MIT
zod4.4.3MIT

Build Dependencies (20)

PackageVersionLicense
@commitlint/cli21.2.1Other
@commitlint/config-conventional21.2.0Other
@playwright/test1.62.0Other
@storybook/nextjs10.5.5Other
@storybook/react10.3.5Other
@tailwindcss/postcss4Other
@types/node26Other
@types/pdf-parse1.1.5Other
@types/qrcode1.5.6Other
@types/react19Other
@types/react-dom19Other
dotenv-cli11.0.0Other
eslint9Other
eslint-config-next16.3.0Other
lefthook2.1.10Other
opentype.js2.0.0Other
storybook10.3.5Other
tailwindcss4MIT
tsx4.23.1Other
typescript6Apache-2.0

This SBOM is generated from the platform's package manifest and updated with each deployment. Licence labels are indicative and classified best-effort; consult each package for its authoritative licence. For machine-readable SBOM formats (SPDX, CycloneDX), contact security@veritome.eu.