Source you can read. A core you can run. A license that converts.
The trstctl core is published under the Business Source License 1.1: read it, build it, change it and run it in production, at no charge and with no signed license. Four years after a release is published, it converts to the Mozilla Public License 2.0.
Core · BUSL 1.1
Everything outside the ee/ and clients/ trees, apart from third-party code that keeps its own license: the control plane, the isolated signer, the agent, the console, the patent-pending families (proof-carrying algorithm succession, agent delegation, cross-plane reconciliation, verifiable decommission) and post-quantum cryptography. Production use is permitted. Not permitted: offering the core to third parties as a hosted or managed service, embedding it in a competing product, or working around the license key. Operating it inside a customer's own deployment as that customer's service provider is permitted.
Clients · MPL 2.0
The Go, TypeScript, Python and Java SDKs, the embedded client, the GitHub Action and the Terraform provider. Embed them in your own software; the core's use grant never attaches to it.
Enterprise & Provider · commercial
Proprietary features under ee/, switched on by an offline Ed25519-signed license: bring-your-own-key custody, governance evidence packs, remediation workflows, HA federation, and the Provider plane for multi-customer operation, with metering and siloed isolation, plus managed-service and resale rights for MSPs.
- Licensor
- certctl LLC
- Change date
- Four years after each version is published
- Change license
- Mozilla Public License 2.0
- Patents
- Pending; terms to be published separately
This page is a summary. The LICENSE file in the repository is the binding text, with ee/LICENSE for the commercial tree.