Devseis Endpoint Auditor Copyright 2026 Devseis This product includes software developed by Devseis (https://huggingface.co/Devseis). If you redistribute it or build on it, keep this NOTICE file and credit "Devseis Endpoint Auditor" in your documentation, as required by the Apache License 2.0, section 4(d). Licensing - Source code: Apache License 2.0 (LICENSE). - Data and content: Creative Commons Attribution 4.0 International (LICENSE-DATA): catalog/, library/, baseline.conf, organisational.conf, docs/, synthetic data, training data and the vulnerability bundle. Attribution: "Devseis Endpoint Auditor by Devseis, CC BY 4.0". Third-party data in the vulnerability bundle - OSV.dev data (Ubuntu, Debian, Red Hat, AlmaLinux, Rocky Linux), CC BY 4.0. - This product uses data from the NVD API but is not endorsed or certified by the NVD. - CISA Known Exploited Vulnerabilities catalog, CC0 1.0. - EPSS scores by FIRST.org. Standards - The catalog refers to ISO/IEC 27001:2022 Annex A controls by number and short title only; no ISO text is reproduced. ISO/IEC 27001 is a trademark of ISO/IEC. GDPR and EU AI Act references cite EUR-Lex (Commission Decision 2011/833/EU on reuse of Commission documents). - The base language model, Qwen2.5-0.5B-Instruct, is licensed under Apache 2.0 by the Qwen team, Alibaba Cloud.