Third-Party Component Licences
Last updated: 30 August 2026ThreadWare is built on open-source and third-party components. This page lists them, and the licence each one is used under. It is reviewed and republished at every ThreadWare release.
ThreadWare itself is licensed, not sold. The components below carry their own
licences and nothing here grants any right to ThreadWare’s own source code. Equally, nothing in
any Lomapax agreement restricts your rights under these licences in respect of those components
alone. The full open-source notices file — the complete text of every licence listed here
— is supplied with the software as THIRD_PARTY_NOTICES.md, and is available on
request.
Why we publish this
Most of these components are permissively licensed — MIT, Apache-2.0, BSD, the PostgreSQL licence — and those licences ask for very little: essentially that the copyright and permission notice travels with the software. Publishing this register is how we meet that obligation.
There is a second reason, which matters more to our customers. Component licences change. In 2025 a charting library we used moved from MIT to a revenue-gated commercial licence; we removed it and replaced it with an MIT alternative. A component that is free today can become chargeable at the next version, and the only defence is to know exactly what is in the product and to check before upgrading. We review every component licence at every release, and we will not adopt a version that introduces a charge or a restriction for a customer without telling them first.
Platform and runtime
| Component | Role in ThreadWare | Licence |
|---|---|---|
| .NET / ASP.NET Core | Runtime, web API, hosting | MIT |
| .NET MAUI, Microsoft.Maui.Controls | Android and iOS applications | MIT |
| Microsoft.AspNetCore.* (Identity, Components, WebAssembly, JwtBearer) | Authentication, Blazor, WebAssembly hosting | MIT |
| Microsoft.Extensions.* (Hosting, Configuration, Logging) | Host, configuration, Windows services | MIT |
| Microsoft.IdentityModel.*, System.IdentityModel.Tokens.Jwt | Token issue and validation | MIT |
| System.Device.Gpio, IoT.Device.Bindings | Edge device I/O | MIT |
| Xamarin.AndroidX.Biometric | Biometric sign-in on Android | MIT binding over AndroidX (Apache-2.0) |
| CommunityToolkit.Maui | Mobile application helpers | MIT |
| SixLabors.ImageSharp | Image handling on the Raspberry Pi collector, via IoT.Device.Bindings | Apache-2.0 |
Database and data access
| Component | Role in ThreadWare | Licence |
|---|---|---|
| PostgreSQL | Primary database | PostgreSQL Licence |
| TimescaleDB | Time-series tag data | Apache-2.0 (core) / Timescale Community |
| pgvector | Vector search for the AI assistant | PostgreSQL Licence / MIT (.NET client) |
| pg_cron | In-database scheduling | PostgreSQL Licence |
| Npgsql, Npgsql.EntityFrameworkCore.PostgreSQL | PostgreSQL data access | PostgreSQL Licence |
| Microsoft.EntityFrameworkCore | Object-relational mapping and migrations | MIT |
| Microsoft.Data.SqlClient | SQL Server secondary database | MIT |
User interface
| Component | Role in ThreadWare | Licence |
|---|---|---|
| MudBlazor | Primary UI component library | MIT |
| Plotly.Blazor and plotly.js | Charts and trends | MIT |
| BlazorDateRangePicker | Date range selection | MIT |
| Blazored.LocalStorage / SessionStorage | Client-side storage | MIT |
| LeafletForBlazor and Leaflet | Maps | MIT wrapper over Leaflet (BSD-2-Clause) |
| NetcodeHub.Packages.Components.FileUpload | File upload | MIT |
| IBM Plex Sans / IBM Plex Mono | Typefaces | SIL Open Font Licence 1.1 |
AI, documents, logging and integration
| Component | Role in ThreadWare | Licence |
|---|---|---|
| Microsoft.SemanticKernel | AI orchestration and agents | MIT |
| Serilog and its sinks | Structured logging | Apache-2.0 |
| Hangfire.Core | Background jobs and schedules | LGPL-3.0 — the free core library, used unmodified. Hangfire Pro and Ace are commercial and are not used. |
| Newtonsoft.Json | JSON serialisation | MIT |
| Swashbuckle.AspNetCore | OpenAPI documentation | MIT |
| NWebsec.AspNetCore.Middleware | Security headers | BSD-3-Clause |
| ClosedXML, ClosedXML.Report | Spreadsheet generation | MIT |
| DocumentFormat.OpenXml | Word and Excel documents | MIT |
| PDFsharp-MigraDoc | PDF generation | MIT |
| QRCoder | QR codes on visitor passes | MIT |
| ZXing.Net.Maui, ZXing.Net | Camera scanning of visitor passes (phone app) | MIT; ZXing.Net Apache-2.0 |
| Xamarin.AndroidX.Camera (CameraX) | Android camera for pass scanning | MIT AND Apache-2.0 |
| UglyToad.PdfPig | PDF text extraction for the AI assistant | Apache-2.0 |
| PDFtoImage | PDF page rendering | MIT, bundling PDFium (BSD-3-Clause) |
| NModbus | Modbus device communication | MIT |
| OPCFoundation.NetStandard.Opc.Ua | OPC-UA client for plant device data | OPC Foundation MIT License 1.00 (MIT) |
| Smtp2Go.ApiClient | Transactional e-mail | MIT (client); the service under its own terms |
| AWSSDK.S3 | Optional object storage | Apache-2.0 — only where enabled |
| Azure.Identity | Optional identity | MIT — only where enabled |
| System.IO.Packaging, System.Data.OleDb, System.Runtime.Serialization.Formatters | Legacy document and data interop | MIT |
The AI provider
The AI assistant uses a commercial AI provider — currently OpenAI — under that provider’s API terms and price list. This is a usage-based service rather than a licensed component: it is charged per use, the provider may change its prices and retire models, and we may substitute a provider of equivalent capability on notice.
Licences the customer holds
These are not ours to grant. Where they apply, the customer holds them directly.
| Item | Note |
|---|---|
| Any SCADA system, data historian and data access component for a clients' data | Required for any third-party application to read data programmatically. A prerequisite, not something we can supply. |
| Windows Server, and SQL Server or CALs where applicable | The customer’s own operating environment |
| OCR software for scanned image-only documents | Only where scanned documents are in scope |
| An AI provider account, where the customer holds its own | Usage-based and billed by the provider |
| Google Play and the Apple App Store | The mobile applications are distributed under the stores’ own terms |
Accuracy, and which document prevails
This page is compiled by hand from the licence files and package metadata that each component ships. It is published in good faith and reviewed at every ThreadWare release, but it is a reproduction offered for convenience — not a definitive statement of any third party’s licence terms — and it may contain errors or omissions.
Where anything on this page differs from the licence as published by the copyright holder, that publisher’s own licence prevails. Nothing here varies, extends or limits the rights and obligations those licences create, and nothing here reduces what they require of us. Components also change between releases, so the notices file shipped with your version of the software is the one that describes that version.
If you find an error, a missing component, or any conflict between this page and a publisher’s own licence, please tell our administrator at admin@threadware.co.za rather than assume it is deliberate. Corrections are made at the source and republished everywhere the register appears.
Questions
Lomapax (Pty) Ltd — admin@threadware.co.za. A dated copy of this register, or of the full notices file carrying each licence in its entirety, is available on request for your records. See also our Terms of Use and Privacy Policy.