Legal, Privacy & Compliance
Official documents
Privacy Policy
How StacksAtlas LLC handles website visits, optional email registration, and Business license activation. Your network scan data stays on your appliance.
Read full documentTerms of Service
License grant for Free portable and Business tiers, acceptable use, disclaimers, and limitation of liability.
Read full documentSoftware license (summary)
StacksAtlas software license (summary)
Session scanner for Windows, macOS, and Docker. No license key. Unlimited device discovery for the session; data clears when you exit portable mode. Not for always-on production monitoring, alerts, federation, or multi-user teams. See Terms for full grant.
Perpetual license per Central Hub or standalone always-on appliance. Persistent database, alerts, and fleet. One Business license per appliance. Unlimited device discovery on all tiers. Transfer via Lemon Squeezy customer portal deactivate/reactivate. See licensing guide.
Business license offline grace
Data handling (summary)
- Network inventory: stored only on your appliance (LiteDB on Nodes/standalone; Hub fleet data on the Hub host). Not uploaded to StacksAtlas LLC.
- No product telemetry: we do not collect usage analytics or device lists from your installs.
- Business activation: one-time handshake with Lemon Squeezy (license key + hardware ID hash). See the Privacy Policy.
- Optional email: free $0 checkout on the home page is for release updates only, not required to download portable builds.
- Backups & GDPR: you control local snapshots and permanent delete. See Data Sovereignty.
Your responsibilities as operator
Authorized scanning only
Run discovery only on networks and subnets you own or have explicit permission to monitor. You are responsible for compliance with workplace policy and applicable law.
Install optional tools yourself
Nmap and Npcap are not bundled on any platform (including Docker images on GHCR). Discovery works without them. Install separately for Deep Scan or richer Windows capture, and accept their license terms.
Tailscale is separate
Remote fleet enrollment may use Tailscale. Tailscale is not part of StacksAtlas; its terms and privacy policy apply to your tailnet.
Protect local data
Appliance databases and backups contain sensitive inventory. Secure the host, restrict admin access, and use RBAC/SSO on shared appliances.
Merchant of record
Distribution & code signing
- Windows MSI and portable: Authenticode-signed (STACKSATLAS LLC) when distributed from releases.stacksatlas.com.
- macOS DMG: Developer ID signed and notarized (v1.7.6+).
- Release manifest: Ed25519-signed metadata for in-appliance update checks on Windows.
Open-source attributions
Data registries & identification
StacksAtlas embeds public registry data for MAC vendor lookup and device fingerprinting. Registry data stays on your appliance and is not sent to these organizations.
MAC address vendor identification uses the IEEE Registration Authority public MA-L assignment list (~45,000+ organizations), embedded as oui.json in the appliance. IEEE and the IEEE Registration Authority are not affiliated with StacksAtlas LLC.
Infrastructure & discovery
Components that power network discovery. Nmap and Npcap are not bundled with StacksAtlas on any platform (Windows, macOS, or official Docker images).
Optional deep scan engine. Not redistributed with StacksAtlas. Install separately and accept the Nmap Public Source License.
Optional Windows packet capture driver for raw ARP and deep scan. Not bundled. Install from npcap.com with WinPcap API-compatible mode if prompted.
Backend (.NET)
Core appliance and API dependencies. ASP.NET Core and Microsoft.Extensions packages are used under the MIT license.
PDF report generation under the QuestPDF Community License. Organizations above Community revenue limits must obtain a commercial QuestPDF license.
Microsoft.AspNetCore.SignalR.Client
Real-time federation sync between Hub and enrolled Nodes.
Entity Framework Core + SQLite / SQL Server / PostgreSQL
Optional Hub fleet database backends (SQLite default; SQL Server and PostgreSQL supported).
System.IdentityModel.Tokens.Jwt
JWT authentication for the local API and SSO handoff.
Frontend (appliance UI)
Companion integrations (not bundled)
StacksAtlas pairs with these separate open-source projects on your LAN. They are not included in the StacksAtlas installer — install and license them independently.
Optional AV control platform used with the StacksAtlas Control Bridge (Business permanent install). OpenAVC and the OpenAVC logo are trademarks of OpenAVC LLC; the MIT license covers source code only.
Website (stacksatlas.com)
Documentation and marketing site (separate from the appliance binary).
Material UI (MUI)
Docs and marketing UI components.
@next/mdx
MDX-powered documentation pages.
Recharts
Charts in interactive demos.
Standard open-source license texts
Many bundled libraries use the licenses below. Full license texts are available from the OSI and Apache Foundation: