Skip to main content

This page is a licence and notice summary, not artifact-specific release evidence. The source SBOM, licence inventory and extracted notice bundles validate for each currently enabled surface listed below. Artifact-specific release evidence for a packaged artifact is a separate record bound to that artifact's exact release; it is not complete, and this page must not be relied on or distributed in its place.

Third-Party Notices

LEM includes an upstream Hermes Agent engine made available under the MIT License. The LEM Product Layer is proprietary to NOVUS POINT LIMITED and its licensors, is licensed and not sold, and is not covered by the MIT License. Every other bundled component remains subject to its own licence; the LEM product as a whole is not represented as MIT-licensed.

Hermes Agent and Nous Research are trade marks of their respective owners. They are referred to here solely to identify the licensed component; no affiliation with, sponsorship by, or endorsement from Nous Research is claimed or implied.

Required Notices

The release gate tracks third-party notice evidence in lem/security/third-party-notices.json.

The notice bundle for each release reproduces the licence text and attributions for every component in that release. The MIT License covering the upstream Hermes Agent engine is reproduced in full below. A copy of the complete machine-readable notice bundle for any supplied release may be requested using the contact route at the foot of this page.

MIT License — upstream Hermes Agent engine

MIT License

Copyright (c) 2025 Nous Research

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.

The repository also contains generated, content-validated SBOM, notice-bundle and extraction evidence for each surface listed below. That source-level evidence does not replace an artifact-specific verification: every packaged release must preserve all applicable notices and be bound to the exact release commit and artifact.

The current source inventory also identifies the direct runtime components used for password/TOTP authentication, local QR generation, invoice PDFs, browser automation for AI agents, KaTeX mathematical notation rendering in Markdown output and the distributed font families:

  • otplib 13.4.1 — MIT
  • qrcode 1.5.4 — MIT
  • PDFKit 0.19.1 — MIT
  • agent-browser 0.26.0 — Apache-2.0
  • @streamdown/math 1.0.2 — Apache-2.0 (Copyright 2023 Vercel, Inc.)
  • Inter variable font - SIL Open Font License 1.1 (embedded in generated invoice documents only)
  • @fontsource-variable/inter-tight 5.3.0 (Inter Tight) - SIL Open Font License 1.1 (distributed with the dashboard, bootstrap installer and docs site)
  • JetBrains Mono - SIL Open Font License 1.1 (web font files served with the dashboard)

This list names the direct runtime components used for those purposes only. It is not the complete component inventory for any surface: the complete inventory, and the licence text and any NOTICE content for every component in it, are in the notice bundle for the release concerned, which may be requested using the contact route at the foot of this page.

Across the surfaces listed below the notice bundles include components under, among others, the MIT, MIT-0, ISC, BSD-2-Clause, BSD-3-Clause, Apache-2.0, MPL-2.0, MPL-1.1, CC BY 4.0, SIL OFL-1.1 and 0BSD / Unlicense / CC0 licences. For each such component the notice bundle for the release concerned retains the applicable licence text and any NOTICE content the licence requires to accompany a distribution, including the licence copy and NOTICE file required by clause 4 of the Apache License 2.0, the copyright notice required by the BSD licences, and the attribution and licence link required by CC BY 4.0.

The SIL Open Font License 1.1 text and the copyright notice for each font travel with the font files themselves wherever those files are redistributed, as that licence requires. The copyright notices are: "Copyright 2020 The Inter Project Authors (https://github.com/rsms/inter)" for Inter; "Copyright 2022 The Inter Project Authors (https://github.com/rsms/inter-tight)" for Inter Tight; and "Copyright 2020 The JetBrains Mono Project Authors (https://github.com/JetBrains/JetBrainsMono)" for JetBrains Mono. A copy of the SIL Open Font License 1.1 text applying to any redistributed font may be requested using the contact route at the foot of this page.

One component recorded in the source inventory is not under an open-source licence. gsap 3.15.0 remains installed as an optional peer dependency of @nous-research/ui and is recorded in the SBOM for the LEM dashboard and the LEM bootstrap installer with the scope "optional". It is not imported or required by any LEM first-party code, so no LEM entry point reaches it and it is not emitted into the built dashboard bundle. It is supplied under the GSAP Standard "no charge" licence published by its licensor at https://gsap.com/standard-license. That licence was read at that URL on 2026-08-03 and permits commercial, hosted use at no charge; its only relevant restriction applies to products that let users build visual animations without code, which LEM is not. No GSAP licence has been purchased, and none is required for the use described here. The package ships no licence text of its own — its package metadata references that URL only — so the notice bundle records the licence by that reference, and the dated licence-review record for it is held in this repository at lem/security/evidence/third-party/gsap-licence-review-2026-08-03.md.

Surfaces Covered by the Current Notice Manifest

The current notice manifest covers the following surfaces. Of these, the LEM Cloud control plane and the LEM dashboard are the sellable surfaces: they are the surfaces through which the hosted service is supplied to customers under an executed Order Form. The LEM terminal UI, the LEM bootstrap installer and the public docs and sales docs site are not sellable surfaces and are not supplied, licensed or sold under any Order Form.

  • LEM Cloud control plane — the hosted platform that operates a customer's workspace under an executed Order Form. It is operated by NOVUS POINT LIMITED and is not delivered to the customer as a separately licensed artifact.
  • LEM dashboard — supplied to customers. It is the core customer surface of the hosted delivery model recorded in the Order Form.
  • LEM terminal UI — internal operations surface. It is not supplied to customers and no customer licence to it is granted.
  • LEM bootstrap installer — internal build and deployment tooling. It is not supplied to customers and no customer licence to it is granted.
  • LEM public docs and sales docs site — public informational material. It is published rather than supplied under an Order Form, and its use is governed by the LEM Website Terms of Use.

Notice evidence is generated for every surface listed above, whether or not it is a sellable surface, so that no component is omitted if the scope of supply later changes.

Disabled Planned Distributions

The LEM Mac Connector direct-download package is represented in the source inventory so that its dependencies cannot be omitted accidentally. That inventory entry is the only record held for this surface: no SBOM, notice bundle or extraction evidence has been generated for it. It is disabled and is not a sellable surface until its separate packaging, signing, notarization and release-specific notice evidence is complete.

Customer Access

This page will be linked from the public site before paid sales open. If a customer receives a direct-download desktop artifact, the release evidence must also include the signed artifact reference, notarization status, and any bundled notice file required for that artifact.

Review Process

Notice evidence for each surface is generated and reviewed before release. That review covers the surface's package manifest, lockfile, distribution description, generated evidence and approval bound to the exact release, together with a record of any third-party code or service loaded into that surface at runtime (including hosted authentication, bot-protection and CAPTCHA scripts). New paid surfaces, and any runtime-delivered third-party code or service added to an existing surface, are recorded in the notice manifest before that surface is sold.

Status of this page

This page is informational and non-contractual. It does not vary, extend or form part of any executed agreement. Where a software artifact ships its own notice file, that file controls for that artifact. Third-party and open-source components are provided under their own licence terms, and NOVUS POINT LIMITED gives no warranty, condition or undertaking in respect of them beyond what the executed agreement states. Nothing on this page grants any right in any third party's software, trade marks or other intellectual property.


NOVUS POINT LIMITED, a company incorporated in England and Wales, company number 08146241, registered office 124 City Road, London, England, EC1V 2NX. Third-party notice and attribution enquiries may be sent to jakub@novus-point.com, the contact route published in the LEM Website Terms of Use, clause 8.3.