# What Is the License for the IPED Project? A Complete Guide to GPL-3.0 Compliance

> Understand the IPED project license GPL-3.0 compliance. Learn how to share derivative works with full source code access and adhere to open-source principles.

- Repository: [Serviço de Perícias em Informática/IPED](https://github.com/sepinf-inc/IPED)
- Tags: tutorial
- Published: 2026-03-11

---

**The IPED project is released under the GNU General Public License version 3 (GPL-3.0) or later, requiring that any distributed derivative works also provide complete source code under the same license.**

The IPED (Integrated Platform for Electronic Discovery) repository at `sepinf-inc/IPED` provides open-source forensic tools for digital evidence processing. Understanding the specific license for the IPED project is critical for organizations integrating these tools, as the GPL-3.0 imposes distinct obligations regarding source code distribution that differ from permissive alternatives like MIT or Apache-2.0.

## IPED Project License Terms and File Location

The complete license for the IPED project resides in the top-level file [`LICENSE.txt`](https://github.com/sepinf-inc/IPED/blob/main/LICENSE.txt) at the repository root. This file contains the standard GPL-3.0 provisions plus specific additional permissions that modify standard copyleft requirements for this forensic platform.

The project explicitly adopts the "GPL-3.0 or later" clause, allowing users to apply subsequent GPL versions if desired. This declaration appears in the root [`pom.xml`](https://github.com/sepinf-inc/IPED/blob/main/pom.xml) under the `<license>` element, ensuring Maven build tools automatically surface licensing metadata to downstream projects during dependency resolution.

## Core Legal Provisions and Permissions

The GPL-3.0 license affecting IPED distributions includes several critical provisions that govern how the software can be used, modified, and shared:

| Provision | Implication for IPED Users |
|-----------|--------------------------|
| **Copyleft** | Any derivative work incorporating IPED code must be distributed under GPL-3.0 or a compatible license. |
| **Source Availability** | Binary distributions must include complete corresponding source code or a written offer to provide it. |
| **No Warranty** | The software is provided "as is" without implied warranties of merchantability or fitness for purpose. |

### Additional Permissions and Exceptions

The [`LICENSE.txt`](https://github.com/sepinf-inc/IPED/blob/main/LICENSE.txt) file (lines 7-11) contains two specific legal additions that create exceptions to standard GPL-3.0 compatibility rules:

- **The Sleuthkit Linking Exception**: IPED grants explicit permission to link with The Sleuthkit and its dependencies, even though those components use the IBM Public License or Common Public License, which would normally create compatibility conflicts with GPL-3.0.

- **Plugin Exception**: Developers may link or combine IPED with plugins that do **not** alter its entry points, regardless of the plugin's own license terms. This allows proprietary forensic plugins to interface with IPED without triggering full copyleft requirements, provided they don't modify core entry points.

## License Metadata in Maven Configuration

Because IPED is a Maven-based Java application, the license information propagates through the build system. The parent [`pom.xml`](https://github.com/sepinf-inc/IPED/blob/main/pom.xml) declares:

```xml
<licenses>
  <license>
    <name>GNU General Public License v3.0 or later</name>
    <url>https://www.gnu.org/licenses/gpl-3.0.html</url>
    <distribution>repo</distribution>
  </license>
</licenses>

```

Individual modules like [`iped-engine/pom.xml`](https://github.com/sepinf-inc/IPED/blob/main/iped-engine/pom.xml) replicate this declaration, ensuring consistent licensing metadata across the engine core and plugin interfaces.

## Practical License Compliance Examples

### Including IPED as a Maven Dependency

When adding IPED to your project, Maven inherits the GPL-3.0 obligations:

```xml
<dependency>
    <groupId>br.ufpe.cin</groupId>
    <artifactId>iped-engine</artifactId>
    <version>3.0.0</version>
</dependency>

```

Including this dependency triggers license compliance checks in corporate build pipelines, ensuring teams recognize their copyleft obligations before distribution.

### Displaying License Text in Applications

To read and display the [`LICENSE.txt`](https://github.com/sepinf-inc/IPED/blob/main/LICENSE.txt) content in a forensic tool's user interface:

```java
import java.nio.file.Files;
import java.nio.file.Paths;
import java.util.stream.Collectors;

public class ShowLicense {
    public static void main(String[] args) throws Exception {
        String license = Files.lines(Paths.get("LICENSE.txt"))
                              .collect(Collectors.joining("\n"));
        System.out.println(license);
    }
}

```

This utility reads the repository's license file, useful for generating "About" dialog content that satisfies attribution requirements in GUI applications.

### Packaging Source Bundles for Binary Distribution

To comply with GPL-3.0 source distribution requirements when releasing compiled binaries:

```xml
<plugin>
    <artifactId>maven-assembly-plugin</artifactId>
    <configuration>
        <descriptorRefs>
            <descriptorRef>src</descriptorRef>
        </descriptorRefs>
        <finalName>iped-source-bundle</finalName>
    </configuration>
</plugin>

```

Executing this Maven assembly plugin creates `iped-source-bundle.zip`, satisfying the requirement to provide complete corresponding source code when distributing compiled versions of IPED.

## Essential License and Legal Files

| File | Purpose | Location |
|------|---------|----------|
| [`LICENSE.txt`](https://github.com/sepinf-inc/IPED/blob/main/LICENSE.txt) | Complete GPL-3.0 text with Sleuthkit linking exceptions | Repository root |
| [`pom.xml`](https://github.com/sepinf-inc/IPED/blob/main/pom.xml) (root) | Maven license declaration for parent project project-wide build configuration | Root directory |
| [`iped-engine/pom.xml`](https://github.com/sepinf-inc/IPED/blob/main/iped-engine/pom.xml) | Module-specific license metadata for core engine | `iped-engine/` directory |
| [`ThirdParty.txt`](https://github.com/sepinf-inc/IPED/blob/main/ThirdParty.txt) | Third-party component compatibility and license audit | Repository root |
| [`README.md`](https://github.com/sepinf-inc/IPED/blob/main/README.md) | High-level project description and build instructions | Repository root |

## Summary

- The **license for the IPED project** is **GPL-3.0 or later**, explicitly stated in the root [`LICENSE.txt`](https://github.com/sepinf-inc/IPED/blob/main/LICENSE.txt) file.
- **Copyleft obligations** require distributing complete source code for any public derivatives or modified versions of IPED.
- **Two additional permissions** specifically allow linking with The Sleuthkit and certain plugin architectures, even when those components use non-GPL licenses.
- **Maven metadata** in [`pom.xml`](https://github.com/sepinf-inc/IPED/blob/main/pom.xml) files ensures automated build tools recognize and propagate licensing requirements.
- **Compliance documentation** in [`ThirdParty.txt`](https://github.com/sepinf-inc/IPED/blob/main/ThirdParty.txt) tracks dependency licenses to verify GPL-3.0 compatibility across the entire dependency tree.

## Frequently Asked Questions

### What license governs the IPED project?

The IPED project uses the **GNU General Public License version 3 (GPL-3.0) or later**, as stated in the [`LICENSE.txt`](https://github.com/sepinf-inc/IPED/blob/main/LICENSE.txt) file at the repository root. This license requires that any distributed derivative works also be released under GPL-3.0-compatible terms, with complete source code availability to end users.

### Can I use IPED in commercial forensic applications?

Yes, commercial use is permitted under GPL-3.0, but with strict distribution conditions. If you distribute IPED or derivatives (modified or unmodified) to third parties, you must provide the complete corresponding source code under GPL-3.0. Internal use within an organization does not trigger distribution requirements, but SaaS deployments may require careful analysis of the Affero GPL implications if applicable.

### What is the IPED plugin exception and how does it work?

The plugin exception in [`LICENSE.txt`](https://github.com/sepinf-inc/IPED/blob/main/LICENSE.txt) permits linking IPED with plugins that do not alter its entry points, regardless of the plugin's license. This means proprietary forensic plugins can interface with IPED's API without requiring the entire plugin to be GPL-licensed, provided they don't modify IPED's primary entry points or core executable code.

### Where is the license information stored for automated build tools?

The license metadata is declared in the `<license>` element of the root [`pom.xml`](https://github.com/sepinf-inc/IPED/blob/main/pom.xml) and replicated in module-specific files like [`iped-engine/pom.xml`](https://github.com/sepinf-inc/IPED/blob/main/iped-engine/pom.xml). This Maven-standard configuration allows automated software composition analysis (SCA) tools to detect GPL-3.0 obligations when IPED is included as a transitive dependency in other Java projects.