Aral.ai

Open Source & Third-Party SDK Disclosures

Last audited September 18, 2026

1. Open Source Statement

Aral.ai is built upon the foundation of world-class open-source software and open standards. We are immensely grateful to the maintainers and contributors of these libraries. In compliance with software licenses, this page documents the key third-party software, SDKs, and open-source packages utilized across our application ecosystem.

2. Audited Third-Party SDKs & Libraries

React & React DOMMIT License
Frontend UI Engine

User interface component library and DOM rendering engine.

Next.jsMIT License
Full-Stack Framework

React framework for server-side rendering, routing, and static site generation.

PDF.js (pdfjs-dist)Apache License 2.0
Document Renderer

Mozilla HTML5 PDF reader for client-side document canvas rendering.

Tailwind CSSMIT License
Styling Engine

Utility-first CSS framework for design systems.

Lucide ReactISC License / MIT
Icon System

Clean and accessible open-source icon set for UI elements.

Framer MotionMIT License
Animation Engine

Production-ready motion and gesture animation library.

Capacitor Core & NotificationsMIT License
Mobile Bridge

Cross-platform native mobile runtime for iOS and Android deployment.

FastAPI & UvicornMIT / BSD-3-Clause
Backend Microservices

High-performance Python ASGI web framework and server.

PyMuPDF (fitz)AGPL-3.0 / Commercial License
Document Parsing Engine

High-speed Python bindings for MuPDF for server-side PDF extraction.

Supabase Python ClientMIT License
Database & Auth Client

Client for PostgreSQL, user authentication, and row-level security.

Google GenAI SDKApache License 2.0
AI Model Integration

Official Google Gemini AI SDK for grounded text generation and summarization.

PyJWT & CryptographyMIT / Apache 2.0 / BSD
Security & Token Validation

Secure JSON Web Token encoding and cryptographic signature validation.

3. Security & Data Safety Audit

All third-party SDKs and dependencies are regularly audited for security vulnerabilities using automated dependency scanners (`npm audit` and `pip-audit`). We enforce strict sandboxing, row-level security (RLS), and HTTPS/TLS encryption to protect all user communication.

4. Trademark & Intellectual Property Notice

All brand names, trademarks, logos, and service marks referenced herein (including Google, Meta, Facebook, Supabase, and Mozilla) belong to their respective registered owners. Reference to third-party services does not imply endorsement or affiliation beyond standard API integration.