> For the complete documentation index, see [llms.txt](https://framework.aic.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://framework.aic.io/company-operating-manual/intellectual-property-and-accelerators/open-source-and-third-party-components.md).

# Open Source and Third-Party Components

### Purpose

Open-source and third-party components can accelerate delivery but must be managed carefully.

### Required Checks

Before use, check:

* licence type
* commercial restrictions
* attribution requirements
* security vulnerabilities
* maintenance status
* compatibility with customer requirements
* export or regulatory restrictions
* support model
* IP contamination risk

### Approved Use

A component may be used where:

* the licence is acceptable
* security risk is acceptable
* the component is actively maintained or risk-managed
* the customer permits its use
* the component does not conflict with the project IP model

### Records

Projects should record:

* component name
* version
* licence
* source
* purpose
* approval status
* known vulnerabilities
* mitigation
