ComplyRoll
Copyright 2026 Kyle Versluis

Licensed under the Apache License, Version 2.0 (the "License"); you may not use this
software except in compliance with the License. You may obtain a copy of the License at

    http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software distributed under the
License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND,
either express or implied. See the License for the specific language governing permissions
and limitations under the License.

The "ComplyRoll" name is not licensed under the License (Section 6); it identifies this
project and may not be used to endorse or promote derived products without permission.

Third-party data redistributed unmodified under src/complyroll/data/:

  fedramp-consolidated-rules.json
  fedramp-common-definitions-schema-2026-06-24.json
  fedramp-vulnerability-detail-report-schema-2026-06-24.json
  fedramp-accepted-vulnerability-info-schema-2026-06-24.json
  fedramp-historical-ver-activity-schema-2026-06-24.json

These files are published by the U.S. General Services Administration (GSA) FedRAMP Program
Management Office in the public repositories https://github.com/FedRAMP/rules and
https://github.com/FedRAMP/schemas. As works of the United States Government they are not
subject to copyright protection in the United States (17 U.S.C. 105). They are redistributed
here byte-for-byte at the Git commits recorded in src/complyroll/data/fedramp-rules-source.json
and src/complyroll/data/fedramp-ver-schemas-source.json, and they are not covered by the
License above. See src/complyroll/data/README.md for provenance details.

FedRAMP is a registered trademark of the U.S. General Services Administration. ComplyRoll is an
independent project and is not affiliated with, endorsed by, or approved by GSA or the FedRAMP
Program Management Office.
