Source you can read. A core you can run. A licence that converts.
The trstctl core is published under the Business Source License 1.1. Read it, build it, change it, run it in production, at no charge and with no signed licence. Four years after a release is published, that release converts to the Mozilla Public License 2.0. The client libraries are MPL 2.0 today. Enterprise and Provider features are commercial.
Core · BUSL 1.1
Everything outside the ee/ and clients/ trees: the control plane, the isolated signer, the agent, the console, the patent-pending families (proof-carrying algorithm succession, agent delegation, cross-plane reconciliation, verifiable decommission) and post-quantum cryptography. Production use is permitted. Not permitted: offering the core to third parties as a hosted or managed service, embedding it in a competing product, or working around the licence key. Operating it inside a customer's own deployment as that customer's service provider is permitted.
Clients · MPL 2.0
The Go, TypeScript, Python and Java SDKs, the embedded client, the GitHub Action and the Terraform provider. Embed them in your own software; the core's use grant never attaches to it.
Enterprise & Provider · commercial
Proprietary features under ee/, switched on by an offline Ed25519-signed licence: BYOK and HSM key custody, governance evidence packs, remediation workflows, HA federation, and the Provider plane for multi-customer operation, with metering, white-label and siloed isolation, plus managed-service and resale rights for MSPs.
- Licensor
- certctl LLC
- Change date
- Four years after each version is published
- Change licence
- Mozilla Public License 2.0
- Patents
- Pending; terms to be published separately
This page is a summary. The LICENSE file in the repository is the binding text, with ee/LICENSE for the commercial tree.