📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Open source and credits

Lavawall® is built on trusted open-source components, chosen so that nothing we put on your computer carries a copyleft obligation, and every component we use is credited here.

We list only the components that live code actually references. Where a component offers a choice of licence, ThreeShield elects the permissive option, noted below. Versions are omitted except where the licence depends on one. Full licence texts are available on request through our contact page. Lavawall itself is a proprietary product; the console theme is commercially licensed and is not open-source software.

The console and its agents

Browser

  • MIT: jQuery, Bootstrap, Popper.js, SweetAlert2, Select2 (and the Select2 Bootstrap 5 theme), DataTables (with its Buttons, ColReorder, Responsive, and SearchPanes extensions), JSZip (dual MIT / GPLv3, MIT elected), pdfmake, ApexCharts, Chart.js, Swiper, jsVectorMap, Choices.js, particles.js, SunEditor, xterm.js, Prism.js, Grid.js, FullCalendar, multi.js, Sortable.js, SimpleBar, Node Waves, Feather Icons, flatpickr, Shepherd.js, and Toastify JS.
  • Apache-2.0: SheetJS (xlsx), Cleave.js, Tom Select, and jsQR.
  • BSD-3-Clause: Quill and highlight.js.
  • BSD-2-Clause: Leaflet.

Icons and fonts

  • Apache-2.0: Remix Icon, Material Design Icons, and Roboto.
  • CC BY 4.0: Boxicons, and Line Awesome (by Icons8, derived from Font Awesome Free; its icons are CC BY 4.0 and its fonts SIL OFL 1.1).
  • SIL OFL 1.1: HK Grotesk.

Server (PHP)

  • MIT: lbuchs/webauthn, endroid/qr-code, Masterminds HTML5, and Sabberworm PHP CSS Parser.
  • BSD-2-Clause: Vectorface GoogleAuthenticator, bacon/bacon-qr-code, and dasprid/enum.
  • LGPL-2.1: PHPMailer, and Dompdf (with php-font-lib; php-svg-lib is LGPL-3.0-or-later).

Dompdf bundles the DejaVu fonts (Bitstream Vera / DejaVu licence) and Adobe’s core-14 font metrics.

Go, by subsystem

Each heading is the directory the daemon builds from, so a subsystem can be credited on its own. Modules pulled in indirectly are listed alongside the direct ones, because the licence obligation is the same either way. Every licence below was read from the module’s own LICENSE file rather than taken from a package index.

  • AWSsync, AWS posture and cost collection: AWS SDK for Go v2, including its service and internal modules (Apache-2.0); go-sql-driver/mysql (MPL-2.0); filippo.io/edwards25519 (BSD-3-Clause).
  • dmarc_email_server / dmarc-go, DMARC report ingestion and SMTP: CertMagic (Apache-2.0); acmez (Apache-2.0); emersion go-message, go-msgauth, go-smtp, go-sasl (MIT); libdns and libdns/cloudflare (MIT); miekg/dns (BSD-3-Clause); klauspost/cpuid (MIT); zeebo/blake3 (CC0-1.0); Uber zap, atomic, multierr (MIT); golang.org/x crypto, mod, net, sys, text, tools (BSD-3-Clause); go-sql-driver/mysql (MPL-2.0).
  • google_sync, Google Workspace synchronization: Google API client for Go and google.golang.org/protobuf (BSD-3-Clause); gRPC, genproto, appengine (Apache-2.0); cloud.google.com/go/compute and its metadata package (Apache-2.0); s2a-go, enterprise-certificate-proxy, groupcache (Apache-2.0); gax-go, golang/protobuf, google/uuid (BSD-3-Clause); OpenTelemetry otel, metric, trace, and otelhttp (Apache-2.0); go-logr and go-logr/stdr (Apache-2.0); httpsnoop (MIT); golang.org/x crypto, net, oauth2, sys, text (BSD-3-Clause); go-sql-driver/mysql (MPL-2.0).
  • elv-go, privilege elevation service: AWS SDK for Go v2 (Apache-2.0); gorilla/websocket (BSD-2-Clause); mattn/go-sqlite3 (MIT); Microsoft/go-winio (MIT); golang.org/x sync, sys, time (BSD-3-Clause); go-sql-driver/mysql (MPL-2.0); filippo.io/edwards25519 (BSD-3-Clause).
  • lavawall-remote/server-go, remote support server: AWS SDK for Go v2 (Apache-2.0); gorilla/websocket (BSD-2-Clause); google/uuid (BSD-3-Clause); go-sql-driver/mysql (MPL-2.0); filippo.io/edwards25519 (BSD-3-Clause).
  • lavawall-remote/lavawall-remote-mac, macOS remote support agent: creack/pty (MIT); gorilla/websocket (BSD-2-Clause); google/uuid (BSD-3-Clause).
  • m365sync, Microsoft 365 synchronization: gopsutil (BSD-3-Clause); go-ole (MIT); yusufpapurcu/wmi (MIT); lufia/plan9stats (BSD-3-Clause); power-devops/perfstat (MIT); shoenig/go-m1cpu (MPL-2.0); tklauser/go-sysconf (BSD-3-Clause); tklauser/numcpus (Apache-2.0); golang.org/x sys, time (BSD-3-Clause); go-sql-driver/mysql (MPL-2.0).
  • hubspotsync, HubSpot synchronization: golang.org/x/image (BSD-3-Clause); go-sql-driver/mysql (MPL-2.0).
  • LANscanGo, local network scanner: golang.org/x/sys (BSD-3-Clause).
  • APIsync, cfsentinel, datagov_m365, domainScan, ingram, osint, phishing, training, ubnt: go-sql-driver/mysql (MPL-2.0); filippo.io/edwards25519 (BSD-3-Clause, indirect).
  • cameramonitor, GW_Windows_Download_Agent: the Go standard library only.

Software Lavawall installs on the endpoint (not incorporated)

Some features install a third-party client on the customer’s endpoint on request. Lavawall orchestrates the vendor’s own official, vendor-signed installer, downloaded from the vendor and verified against a pinned SHA-256. It does not embed, relink, redistribute, or incorporate that software into the Lavawall platform or agents. The vendor conveys the software to the customer; Lavawall triggers and configures the install. Licence obligations for these components rest with the vendor’s distribution, and the component is named here for transparency.

Installed and configured on request:

  • WireGuard®, the official WireGuard client for the platform (for example, the WireGuard for Windows installer), installed on request by the WireGuard configuration feature. Lavawall stores only non-secret configuration and the client’s public key; the client’s private key is generated on the endpoint and never leaves it. “WireGuard” is a registered trademark of Jason A. Donenfeld. Lavawall is not affiliated with or endorsed by the WireGuard project; the name is used only to identify the software being installed.
  • Sophos endpoint protection, deployed and configured from the vendor’s own installer, with its detections surfaced in the unified MDR queue.
  • Huntress, deployed and configured from the vendor’s own installer, with its alerts in the same queue.

Lavawall also installs and keeps updated a wide range of common business and technical applications on request, each from the vendor’s own official installer, and patches them afterward alongside the rest of the catalogue. A selection, among others:

  • Browsers: Brave, Google Chrome, Mozilla Firefox, and Safari.
  • Compression: 7-Zip, and WinRAR.
  • Databases: DB Browser for SQLite, HeidiSQL, MySQL Workbench, and NoSQL Workbench.
  • Document viewers: Adobe Acrobat Reader, Amazon Kindle, Amazon Send to Kindle, and reMarkable.
  • File transfer: FileZilla Client.
  • Gaming: Valve Steam.
  • Images and design: FreeCAD, Inkscape, and IrfanView.
  • Maps and navigation: Google Earth Pro.
  • Messaging: Slack.
  • Music and video: iTunes.
  • Password managers: Bitwarden, KeePass Password Safe 2, and Lavawall Vault.
  • Productivity: LibreOffice, and Obsidian.
  • Remote management: PuTTY, RealVNC Viewer, Splashtop Business, Splashtop Personal, Splashtop Streamer, TeamViewer, and Zoom Remote Control.
  • Security: Burp Suite Community, Eraser (Heidi Computers), VeraCrypt, Wireshark, and Zed Attack Proxy (ZAP).
  • Software development: Docker Desktop, Notepad++, Python 3.13, SourceTree, Yarn, and the Go programming language.
  • Telephony and meetings: Zoom Workplace.
  • VPN and zero trust: Cloudflare WARP, ExpressVPN, FortiClient VPN, and WireGuard.

Product names, logos, and brands are the property of their respective owners. They are named here only to identify software Lavawall can install and configure from each vendor’s own official installer; their inclusion does not imply any affiliation with or endorsement by those owners, and each remains under its own vendor’s licence.

Notes

  • go-sql-driver/mysql is MPL-2.0, which is file-level copyleft. Lavawall uses it unmodified, so notice is the whole obligation.
  • Boxicons and Line Awesome are CC BY 4.0, which asks for visible attribution rather than a notice file alone.
  • The console theme (Velzon by Themesbrand) is commercially licensed and is deliberately absent from the open-source list above; it is not open-source software. ThreeShield licensed it commercially for the Lavawall console and has modified it significantly.

Lavawall® Backup

Lavawall® Resilience Node

The Resilience Node is built with everything from the real-time operating system on the device to the mesh protocol its nodes speak and the drivers that reach the radio and the network appliance.

Device firmware

  • Zephyr RTOS, the real-time operating system at the heart of our device firmware. (Apache-2.0)
  • MeshCore by Scott Powell and contributors, the mesh routing protocol our nodes speak. (MIT)
  • Rhys Weatherley’s Crypto library and Orson Peters’ Ed25519, the cryptographic primitives securing our mesh. (MIT / zlib)
  • nanopb by Petteri Aimonen, compact Protocol Buffers for embedded devices. (zlib)
  • Semtech loramac-node, the LoRa radio driver for our long-range link. (BSD)

Network appliance and tooling

  • gosnmp, SNMP monitoring in our network appliance. (BSD-2-Clause)
  • The Go programming language and its golang.org/x libraries by the Go Authors. (BSD-3-Clause)
  • go.bug.st/serial by Cristian Maglie, USB serial communication. (BSD)
  • Net-SNMP, the SNMP agent on our appliance. (BSD-style)

Hardware SDK

Firmware for Nordic Semiconductor hardware is built with the Nordic nRF Connect SDK.