A ctlplne studio product
Licensing alpha

Source you can read. A core you can run. A license that converts.

The trstctl core is published under the Business Source License 1.1: read it, build it, change it and run it in production, at no charge and with no signed license. Four years after a release is published, it converts to the Mozilla Public License 2.0.

Core · BUSL 1.1

Everything outside the ee/ and clients/ trees, apart from third-party code that keeps its own license: the control plane, the isolated signer, the agent, the console, the patent-pending families (proof-carrying algorithm succession, agent delegation, cross-plane reconciliation, verifiable decommission) and post-quantum cryptography. Production use is permitted. Not permitted: offering the core to third parties as a hosted or managed service, embedding it in a competing product, or working around the license key. Operating it inside a customer's own deployment as that customer's service provider is permitted.

Clients · MPL 2.0

The Go, TypeScript, Python and Java SDKs, the embedded client, the GitHub Action and the Terraform provider. Embed them in your own software; the core's use grant never attaches to it.

Enterprise & Provider · commercial

Proprietary features under ee/, switched on by an offline Ed25519-signed license: bring-your-own-key custody, governance evidence packs, remediation workflows, HA federation, and the Provider plane for multi-customer operation, with metering and siloed isolation, plus managed-service and resale rights for MSPs.

Licensor
certctl LLC
Change date
Four years after each version is published
Change license
Mozilla Public License 2.0
Patents
Pending; terms to be published separately

This page is a summary. The LICENSE file in the repository is the binding text, with ee/LICENSE for the commercial tree.