Polaris, Identity Token System
Copyright 2026 Egor Khaklin

This product is licensed under the Apache License, Version 2.0 (see the
LICENSE file at the root of this repository, or
http://www.apache.org/licenses/LICENSE-2.0).

The license text is carried once, at the repository root. The four packages
(polaris_sql, polaris_web, polaris_cli, polaris_zk) are parts of this one work,
not separately distributed projects, so none carries its own copy; polaris_zk
declares `license = "Apache-2.0"` in its Cargo manifest, which is what a Rust
consumer reads.

================================================================================
About this work
================================================================================

Polaris is a pre-pilot identity-token system: ML-DSA-65 signatures under an
audited algorithm-migration path, zero-knowledge verification, and an
append-only audit of record, enforced in the database schema rather than in
policy. What the cryptography does and does not buy, including what a break
in the underlying lattice assumption would cost, is stated in
docs/PRODUCTION-READINESS.md.

Pre-pilot means it works end to end and outside wallets and an outside
conformance suite have exercised it, but it has not run a pilot. It runs on
notional data: it has never held real identity data, it is not deployed to
any population, and the physical token it models is not manufactured. The constitution (the ten hard constraints C1 to C10 and
the vocation) is MISSION.md.

================================================================================
Components and their separate notices
================================================================================

The Rust prover/verifier in polaris_zk/ depends on the Plonky2 library
(https://github.com/0xPolygonZero/plonky2), used here unmodified. Plonky2
is dual-licensed under MIT/Apache-2.0.

The Atlas (polaris_web/static/atlas-map.js) renders with MapLibre GL JS
(vendored under polaris_web/static/vendor/maplibre-gl.js), 3-Clause BSD,
copyright MapLibre contributors; original license header preserved in the
vendored source. The street-level basemap uses CARTO's free dark-matter
vector tiles, which are derived from OpenStreetMap data (© OpenStreetMap
contributors, ODbL) and served by CARTO (© CARTO); both are attributed in
the on-map attribution control.

The web application uses Flask, Werkzeug, psycopg2 and redis-py. Each
retains its own license; consult requirements.txt for versions and the
upstream repositories for license text. Three dependencies are named here
because their licenses are not permissive. Each is used unmodified, as a
library through its public API, which is the use its license is written for;
its terms attach to it, not to this work:

- psycopg2 (used through the psycopg2-binary wheel) is LGPL 3 with an
  OpenSSL exception.
- psycopg 3 (psycopg and psycopg-binary), which Patroni uses in the database
  image (polaris_web/requirements-patroni.txt), is LGPL 3.
- certifi, the CA certificate bundle that requests reads, is MPL 2.0.
  requests arrives through the OpenTelemetry exporter, and the database
  image pins certifi directly.

A redistributor who MODIFIES one of them takes on its license's obligations
for that modified copy.

Every other dependency of every package (Python, Rust and npm) is under a
permissive license: Apache-2.0, MIT, MIT-0, BSD-2/3-Clause, ISC, PSF-2.0,
CC0-1.0 or Unicode-3.0, or a choice of licenses that includes MIT or
Apache-2.0. None is incompatible with this work's Apache 2.0 license, and
none imposes a copyleft obligation on it.

The macOS launcher (Polaris.command + polaris_mac_launch.sh) is original
to this work.

The project report in its three versions (polaris_project_report.pdf,
polaris_project_report_v2.pdf and polaris_project_report_v3.pdf), the Russian
edition of Version 3 (polaris_project_report_v3_ru.pdf), the evidence record
and its Russian edition (polaris_evidence_record_v3.pdf and
polaris_evidence_record_v3_ru.pdf) and the mathematical edition
(polaris_math.pdf), all under docs/paper/, are part of the same release and
inherit the same Apache 2.0 license. The report's bibliography credits
external sources under fair-use academic citation conventions.

================================================================================
Names and marks
================================================================================

The Apache License covers this work's code, documents and image files, except
the OpenID Certified mark (openid-certified-mark-on-white.png, in docs/assets/
and site/), which belongs to the OpenID Foundation and is used under its
certification terms. The license grants no right to the names and marks the
files carry (section 6): the Polaris name, logo and star mark, the owl
emblem, and the Khaklin Technologies name and lockup. TRADEMARKS.md says what
that allows.

================================================================================
Attribution
================================================================================

If you build on Polaris, whether the code, the schema, or its patterns
(the audit-of-record discipline above all), retain the LICENSE and NOTICE
files and the author attribution, per Apache 2.0 section 4.

The audit-of-record discipline is the project's central methodological
contribution: state-changing decisions are recorded in the schema by
append-only tables guarded by triggers, and on the filesystem by
CHANGELOG.md and the git history. The same discipline applies at the
license level: provenance is preserved.
