Skip to main content
OPEN SOURCE · 开源依赖

Full open-source disclosure.

We stand on the shoulders of dozens of OSS projects. This page is InThoth's public dependency and license-compliance declaration — verifiable any time by customers, auditors, and legal teams.

01 — COMMITMENT

Our commitment.

InThoth is built by Inscinstech (苏州英赛斯智能科技有限公司). We commit to:

  1. Full disclosure — every OSS dependency in production is listed on this page (version · license · purpose · upstream repo).
  2. Preserve original copyrights — all forks and wrappers retain upstream LICENSE files and copyright notices; nothing is stripped.
  3. No false in-house claims — we clearly distinguish "in-house (proprietary)" / "built on (fork)" / "depends on (direct dependency)" in both marketing and technical docs.
  4. Compliant downstream distribution — private-deploy bundles include the full LICENSE, NOTICE, and an offline snapshot of this page.
  5. Quarterly updates — this page is updated whenever a dependency changes. The last-updated date is at the bottom.
02 — RUNTIME WRAPPING

Core runtime + brand wrapping.

Which brand names are marketing wrappers, which are direct dependencies, which are forks — visible at a glance.

InThoth brandUpstream OSSLicenseRelationshipNotes
inCoreIn-house agent runtime + OSS infraProprietary · OSS deps under their own licensesBuilt in-houseinCore is Inscinstech-built: the agent runtime, multi-tenant isolation, 21 CFR Part 11 audit layer, and IBS integration are all our own code. Open-source components are infrastructure dependencies only, listed in the matrix above.
InThoth · the platformInscinstech CMC v2.2 knowledge base (proprietary) + BGE-M3 / bge-reranker / ColBERT / Qdrant (RAG) + scikit-learn Gaussian process (DoE) + RDKit / ViennaRNA (chemistry) + OSS infraApache 2.0 / MIT / BSD · proprietary knowledge basePrimarily in-house + OSS depsInThoth's core moat is Inscinstech's CMC v2.2 knowledge base (82+ entries, proprietary), FDA review-doc distillation, the process-prediction and DoE models, the chromatography-column catalog, and the sensitivity-routing layer. Open-source components are infrastructure and published research models, listed individually above.
03 — FULL MATRIX

Full dependency matrix.

Grouped by purpose. Versions reflect the actual production environment at the time of this page's last update.

3.1 Application platform & agent runtime
ProjectVersionLicenseRepoUsed for
ASP.NET Core8.0MITgithub.com/dotnet/aspnetcoreMulti-tenant gateway host
Entity Framework Core8.0MITgithub.com/dotnet/efcoreData access · row-level tenant filters
Npgsql8.0PostgreSQL Licensegithub.com/npgsql/npgsqlPostgreSQL driver
Serilog8.xApache 2.0github.com/serilog/serilogStructured logging
Model Context Protocol (MCP)1.xMITgithub.com/modelcontextprotocolExternal tool wiring, inbound and outbound
Electron33.xMITgithub.com/electron/electronDesktop shell (same frontend as web)
Temporal1.22+MITgithub.com/temporalio/temporalGxP long workflows · 21 CFR Part 11 audit
3.2 Retrieval & RAG
ProjectVersionLicenseRepoUsed for
BGE-M3latestMIThuggingface.co/BAAI/bge-m3Self-hosted embedding model (CLS pooling)
bge-reranker-v2-m3latestApache 2.0huggingface.co/BAAI/bge-reranker-v2-m3Cross-encoder reranking
ColBERTv2.0latestMITgithub.com/stanford-futuredata/ColBERTLate-interaction reranking (optional track)
sentence-transformers2.7+Apache 2.0github.com/UKPLab/sentence-transformersEmbedding / reranking service runtime
RAGatouille0.0.8+Apache 2.0github.com/AnswerDotAI/RAGatouilleColBERT service wrapper
Qdrant1.xApache 2.0github.com/qdrant/qdrantVector database (default backend)
pgvector0.7+PostgreSQL Licensegithub.com/pgvector/pgvectorVector backend alternative (inside Postgres)
3.3 Process ML & DoE
ProjectVersionLicenseRepoUsed for
scikit-learn1.3+BSD-3github.com/scikit-learn/scikit-learnGaussian process (ARD RBF) · applicability domain · calibration
NumPy1.24+BSD-3github.com/numpy/numpyNumerics
SciPy1.10+BSD-3github.com/scipy/scipyOptimization · statistics
FastAPI0.110+MITgithub.com/tiangolo/fastapiService contract shared by all Python microservices
Uvicorn0.27+BSD-3github.com/encode/uvicornASGI server
Pydantic2.xMITgithub.com/pydantic/pydanticRequest / response schemas
3.4 Chemistry & code sandbox
ProjectVersionLicenseRepoUsed for
RDKit2024.3+BSD-3github.com/rdkit/rdkitFingerprints · Tanimoto · SMARTS · Murcko scaffolds · ADMET descriptors
ViennaRNA2.6+ViennaRNA license (commercial use permitted)www.tbi.univie.ac.at/RNA/RNA secondary-structure MFE · oligo accessibility
Gemmi0.6+MPL 2.0github.com/project-gemmi/gemmiStructure file handling (PDB / mmCIF)
Matplotlib3.8+PSF-based (BSD-compatible)github.com/matplotlib/matplotlibFigures generated inside the sandbox
python-docx / openpyxl / python-pptxlatestMITgithub.com/python-openxmlWord / Excel / PowerPoint deliverables
ReportLab · CairoSVG · svglib · PillowlatestBSD-3 / LGPL / MIT / MIT-CMUmultiplePDF and image rendering
3.5 Scientific models reached through compute routingSelf-hosted in-region GPU broker
ProjectVersionLicenseRepoUsed for
OpenFold3latestApache 2.0github.com/aqlaboratory/openfoldCo-folding (backup folding track)
Chai-1latestApache 2.0github.com/chaidiscovery/chai-labCo-folding with ligands / nucleic acids
ESM-2latestMITgithub.com/facebookresearch/esmProtein language model embeddings · variant scoring
LigandMPNNlatestMITgithub.com/dauparas/LigandMPNNInverse folding with ligand / nucleic-acid context
RFantibodylatestBSD-3github.com/RosettaCommons/RFantibodyFramework-grafted antibody CDR design
AiZynthFinder4.xMITgithub.com/MolecularAI/aizynthfinderRetrosynthesis route search
OpenFE1.xMITgithub.com/OpenFreeEnergy/openfeRelative binding free energy (RBFE)
Uni-GBSAlatestLGPL-3.0github.com/dptech-corp/Uni-GBSAMM-GBSA endpoint binding free energy
scGPT · scVI-tools · BorzoilatestMIT / BSD-3 / Apache 2.0multipleSingle-cell and genomics models
3.5 Scientific models reached through compute routingDomestic compliant track — in-region hosting, data never leaves the region
ProjectVersionLicenseRepoUsed for
Uni-FoldlatestApache 2.0github.com/dptech-corp/Uni-FoldProtein folding (AF2 reproduction)
ProtenixlatestApache 2.0github.com/bytedance/ProtenixCo-folding (AF3 reproduction)
Uni-DocklatestApache 2.0github.com/dptech-corp/Uni-DockGPU-accelerated docking
Uni-MollatestMITgithub.com/dptech-corp/Uni-MolMolecular representation and properties
3.5 Scientific models reached through compute routingOverseas managed APIs — blocked outright for sensitive / confidential sessions
ProjectVersionLicenseRepoUsed for
AlphaFold2 / -MultimerhostedVendor terms (hosted API)build.nvidia.comFolding · complex validation — public / internal work only
ESMFold · Boltz-2hostedVendor terms (hosted API)build.nvidia.comFolding and co-folding — public / internal work only
DiffDock · RFdiffusion · ProteinMPNNhostedVendor terms (hosted API)build.nvidia.comDocking and design — public / internal work only
MolMIM · GenMol · Evo2hostedVendor terms (hosted API)build.nvidia.comSmall-molecule generation, genomics — public / internal work only
3.6 Document parsing & office formats
ProjectVersionLicenseRepoUsed for
DocumentFormat.OpenXml3.2MITgithub.com/dotnet/Open-XML-SDKOffice document generation
QuestPDF2026.xMIT (Community)github.com/QuestPDF/QuestPDFPDF report generation
PdfPig0.1.xApache 2.0github.com/UglyToad/PdfPigPDF text extraction
MinerU0.xApache 2.0github.com/opendatalab/MinerUChinese PDF / table / formula parsing
GROBID0.8+Apache 2.0github.com/kermitt2/grobidAcademic PDF metadata extraction
3.7 Frontend
ProjectVersionLicenseRepoUsed for
3Dmol.js2.xBSD-3github.com/3dmol/3Dmol.jsInteractive 3D structure viewer
ECharts5.xApache 2.0github.com/apache/echartsCharts and response surfaces
KaTeX0.16+MITgithub.com/KaTeX/KaTeXMath and chemical equation rendering (with mhchem)
PDF.js4.xApache 2.0github.com/mozilla/pdf.jsIn-app PDF viewing
SheetJS · docx-preview · JSZiplatestApache 2.0 / MIT / MITmultipleIn-app preview of office deliverables
Next.js · Tailwind CSS15 · 3.4+MITgithub.com/vercel/next.jsThis marketing site and the console
3.8 Infrastructure, testing & observability
ProjectVersionLicenseRepoUsed for
PostgreSQL16PostgreSQL License (BSD-like)github.com/postgres/postgresPrimary relational DB · row-level security
Redis7.xBSD-3 (OSS edition)github.com/redis/redisCache · pub/sub
RabbitMQ3.13+MPL 2.0github.com/rabbitmq/rabbitmq-serverMessage queue
MinIO / S3 SDKlatestAGPL v3 (server) / Apache 2.0 (SDK)github.com/minio/minioObject storage for artifacts
DockerlatestApache 2.0github.com/moby/mobyService and sandbox isolation
Playwright1.49+Apache 2.0github.com/microsoft/playwrightBrowser-driven end-to-end tests
xUnit · TestcontainerslatestApache 2.0 / MITmultipleTest suite · real-Postgres integration tests
Sentryself-hostedBSL 1.1 / FSLgithub.com/getsentry/sentryError monitoring
Prometheus · Grafana · LokilatestApache 2.0 / AGPL v3multipleMetrics, dashboards, logs (internal use only)
04 — NOT IN USE

Projects we don't use (avoiding license traps).

For transparency we also disclose the projects we evaluated but did not adopt, and why.

DifyApache 2.0 + commercial addenda — multi-tenant SaaS resale requires licensing talks.
FastGPTSame as Dify.
n8nSustainable Use License — SaaS resale restricted.
ESM-3 (EvolutionaryScale)Non-commercial / commercial license tiers — replaced with Boltz-2.
AlphaFold 3 (Google DeepMind)Commercial restrictions; license complexity — replaced with Boltz-2.
05 — OBLIGATIONS

License obligations summary.

Compliance obligations grouped by license type. This is the self-check list for our engineering and compliance teams, and the transparent commitment to customers.

MIT / BSD / ISC / Apache 2.0

Obligation
  • Retain original copyright notice
  • Retain original LICENSE file
  • Apache 2.0: also retain NOTICE file if any
How we comply
  • All fork repos preserve upstream LICENSE / NOTICE
  • Container images and private-deploy bundles ship with THIRD_PARTY_LICENSES.txt — full text of every dependency license
  • This page is the public source-of-truth declaration

Mozilla Public License 2.0 (MPL 2.0) — RabbitMQ

Obligation
  • Modified MPL 2.0 files must keep MPL marker
  • Modified source must be made available (only the modified files)
How we comply
  • We do not modify RabbitMQ source — used as a black-box service, no MPL disclosure obligation triggered

LGPL — CairoSVG · Uni-GBSA

Obligation
  • Dynamic linking is fine; if the library is modified, the modified source must be made available
  • Users must be able to relink against their own build of the library
How we comply
  • Used unmodified, invoked as separate processes / services — no relinking obligation is triggered
  • If we ever patch them, the patched source ships with the private-deployment bundle

AGPL v3 — Grafana / Loki

Obligation
  • If AGPL software is offered over the network to users, the user must be offered the source
  • Modified source must be made available
How we comply
  • Grafana / Loki are used for internal ops monitoring only; not exposed to customers
  • Customer dashboards are built on our own Next.js frontend, unrelated to Grafana
  • Customers do not interact with Grafana, so AGPL's "network distribution" condition does not trigger

Academic non-commercial — TAP / SAP

Obligation
  • Free for academic use; commercial requires licensing negotiation
How we comply
  • Already in commercial license negotiation with Oxford OPIG; used only in the platform R&D antibody-tools track, not in InThoth
06 — PRIVATE DEPLOYMENT

Additional obligations for private deployment.

When customers purchase Enterprise private deployment, the distribution container images and code bundles must include:

  • THIRD_PARTY_LICENSES.txt — complete dependency list with full license text
  • NOTICE — attribution notice for Apache 2.0 projects
  • LICENSE — inCore's own license (Inscinstech proprietary)
  • /security/open-source offline snapshot — HTML offline version of this page

Customers do not need to make these files public to their own end-users in a private deployment, but they must retain them in the system for audit purposes.

07 — IP BOUNDARY

IP boundaries.

When you buy InThoth, what you own and what you don't.

AssetOwnerWhat the customer gets
Inscinstech CMC knowledge base v2.2 contentInscinstech proprietaryQuery access (by subscription tier); raw data not transferred
InThoth product codeInscinstech proprietaryUsage rights (by subscription tier)
inCore runtime codeInscinstech proprietaryUsage rights / private-deploy code access (Enterprise only)
Customer-uploaded PDFs / sequences / process dataCustomer proprietaryCustomer-owned; InThoth gains no rights
Customer Memory / Skills accumulated in inCore ProfileCustomer proprietaryCustomer can export / destroy / migrate
Agent outputs (briefs / reports / process plans)Customer proprietaryCustomer-owned; may be commercialized, redistributed, adapted
08 — REPORTING

How to report a license issue.

If you find that: we use an OSS project not listed here; the version / license on this page differs from reality; or we have violated an OSS project's license terms — please email:

opensource@inthoth.com.cn
  • Acknowledged within 24 hours
  • Fix / explanation / adjustment within 7 business days
Last updated: 2026-08-10 · v0.3
Maintainer: InThoth engineering team
Review cadence: quarterly
Changelog
  • v0.3 (2026-08-10) — dependency matrix rewritten against the real platform stack: application platform (ASP.NET Core / EF Core / Npgsql), retrieval (BGE-M3 · bge-reranker · ColBERT · Qdrant / pgvector), process ML (scikit-learn Gaussian process), chemistry and sandbox (RDKit · ViennaRNA · Gemmi), scientific models split across the three compute tracks (self-hosted in-region / domestic compliant / overseas hosted), and frontend (3Dmol.js · ECharts · KaTeX). Removed Elasticsearch and its Elastic License obligation — not actually used; added the LGPL obligation (CairoSVG · Uni-GBSA).
  • v0.2 (2026-05-12) — biopharma design tools upgraded to Design + Evaluation; new dependency disclosures (ViennaRNA · BLAST+ · NCBI Entrez · DSIR / Reynolds algorithms et al.) · mAb design extended (IgFold) · Inscinstech proprietary components disclosed.
  • v0.1 (2026-05-12) — Initial release.