FeaturesPricingBlogDownload
Sign inTry free →

Legal

Open-Source Licenses — Android

The Android client is the only one where, on top of the AstriaVeilLink cryptographic core, a proxy subsystem is also linked (a full async runtime with TLS over ring/BoringSSL) along with a JNI bridge to Kotlin. Beyond the cryptographic core below, the engine uses the following components:

Last reviewed: September 27, 2026.

← All clients and the website

Our own code is proprietary and is not listed on any of these pages.

MIT License

The following components are distributed under the MIT license. For components dual-licensed as “MIT OR Apache-2.0”, the MIT option is elected.

  • RustCrypto — aead, aes, aes-gcm, block-buffer, chacha20, chacha20poly1305, cipher, cpufeatures, crypto-common, ctr, digest, ghash, hkdf, hmac, inout, opaque-debug, poly1305, polyval, sha2, typenum, universal-hash, zeroize
    Copyright (c) 2016–2026 The RustCrypto Project Developers; Copyright (c) 2017–2022 Artyom Pavlov; Copyright (c) 2019 MobileCoin, LLC; Copyright (c) 2015–2018 Vlad Filippov; Copyright (c) 2006–2009 Graydon Hoare; Copyright (c) 2014 Paho Lurie-Gregg
  • generic-array — Copyright (c) 2015 Bartłomiej Kamiński
  • rand (rand, rand_chacha, rand_core, getrandom) — Copyright (c) 2014 The Rust Project Developers; Copyright 2018 Developers of the Rand project
  • ppv-lite86 — Copyright (c) 2019 The CryptoCorrosion Contributors
  • libc — Copyright (c) The Rust Project Developers
  • cfg-if — Copyright (c) 2014 Alex Crichton
  • thiserror — Copyright (c) 2019 David Tolnay
  • zerocopy — Copyright 2019–2023 The Fuchsia Authors (multi-licensed; used under MIT)
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.

BSD-3-Clause License

The following dalek-cryptography components (elliptic-curve cryptography) are distributed under the BSD-3-Clause license:

  • curve25519-dalek — Copyright (c) 2016–2021 isis agora lovecruft; Copyright (c) 2016–2021 Henry de Valence; Copyright (c) 2012 The Go Authors. All rights reserved.
  • x25519-dalek — Copyright (c) 2017–2021 isis agora lovecruft; Copyright (c) 2019–2021 DebugSteven. All rights reserved.
  • subtle — Copyright (c) 2016–2024 Isis Agora Lovecruft, Henry de Valence. All rights reserved.
Redistribution and use in source and binary forms, with or without
modification, are permitted provided that the following conditions are met:

1. Redistributions of source code must retain the above copyright notice, this
   list of conditions and the following disclaimer.

2. Redistributions in binary form must reproduce the above copyright notice,
   this list of conditions and the following disclaimer in the documentation
   and/or other materials provided with the distribution.

3. Neither the name of the copyright holder nor the names of its contributors
   may be used to endorse or promote products derived from this software
   without specific prior written permission.

THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND
ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE
FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER
CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.

Apache License 2.0

The Android applications (phone and Android TV) also use the following components, distributed under the Apache License, Version 2.0:

  • AndroidX (Core, Activity, Lifecycle, DataStore, Hilt integration) — Copyright (c) The Android Open Source Project
  • Jetpack Compose (UI, Foundation, Material 3, Animation) — Copyright (c) The Android Open Source Project
  • Kotlin and kotlinx.coroutines — Copyright (c) JetBrains s.r.o. and Kotlin Programming Language contributors
  • Dagger and Hilt — Copyright (c) The Dagger Authors
  • OkHttp, Okio — Copyright (c) Square, Inc.
  • Retrofit — Copyright (c) Square, Inc.
  • Gson — Copyright (c) Google Inc.
  • ZXing Android Embedded and ZXing (phone app QR scanner) — Copyright (c) Journey Mobile, Copyright (c) ZXing authors

Licensed under the Apache License, Version 2.0; you may not use these components except in compliance with the License. They are provided “AS IS”, without warranties or conditions of any kind. The full text of the License is available at:

https://www.apache.org/licenses/LICENSE-2.0

The phone application additionally includes a library distributed under the Bouncy Castle Licence (an MIT-style licence):

  • Bouncy Castle (phone app) — Copyright (c) 2000–2024 The Legion of the Bouncy Castle Inc. (Bouncy Castle Licence, MIT-style)

Transport and networking layer

  • tokio, tokio-util — Copyright (c) Tokio Contributors
  • rustls, tokio-rustls, rustls-pki-types (Apache-2.0 / MIT / ISC — MIT elected) — Copyright (c) The rustls contributors
  • ipstack (MIT OR Apache-2.0 — MIT elected) — Copyright (c) ipstack contributors
  • etherparse (MIT OR Apache-2.0 — MIT elected) — Copyright (c) etherparse contributors

Platform-specific components

  • jni-rs (MIT OR Apache-2.0 — MIT elected) — Copyright (c) 2016 Prevoty, Inc. and the jni-rs contributors
  • ahash (MIT OR Apache-2.0 — MIT elected) — Copyright (c) 2018 Tom Kaitchuck
  • cesu8 (Apache-2.0 OR MIT — MIT elected) — Copyright (c) 2016 Eric Kidd

Two further components (same author) are distributed under a composite ISC-style license with portions inherited from BoringSSL/OpenSSL. Both are used unmodified via their public APIs and do not require the source of AstriaVPN itself to be disclosed:

  • ring and untrusted — ISC-style terms for new code plus OpenSSL/BoringSSL-derived portions under their own terms (same author, Brian Smith). Full text: github.com/briansmith/ring
Support chat