From b171a364693963c4429bde91ce39294acad68403 Mon Sep 17 00:00:00 2001 From: Fabrice Bellamy <12b@distrilab.fr> Date: Fri, 27 Feb 2026 13:48:10 +0100 Subject: [PATCH] doc cleanup --- .github/FUNDING.yml | 4 -- .github/PULL_REQUEST_TEMPLATE.md | 5 +- CONTRIBUTING.md | 30 ++------ ENTERPRISE.md | 116 ------------------------------- 4 files changed, 5 insertions(+), 150 deletions(-) delete mode 100644 .github/FUNDING.yml delete mode 100644 ENTERPRISE.md diff --git a/.github/FUNDING.yml b/.github/FUNDING.yml deleted file mode 100644 index b3c287f..0000000 --- a/.github/FUNDING.yml +++ /dev/null @@ -1,4 +0,0 @@ -# These are supported funding model platforms - -github: polhenarejos -custom: ["https://www.paypal.me/polhenarejos"] diff --git a/.github/PULL_REQUEST_TEMPLATE.md b/.github/PULL_REQUEST_TEMPLATE.md index 07a08ad..121e2ef 100644 --- a/.github/PULL_REQUEST_TEMPLATE.md +++ b/.github/PULL_REQUEST_TEMPLATE.md @@ -33,10 +33,7 @@ By checking the box below, you confirm ALL of the following: - You are the author of this contribution, or you have the right to contribute it. - You have read `CONTRIBUTING.md`. -- You agree that this contribution may be merged, used, modified, and redistributed: - - under the AGPLv3 Community Edition, **and** - - under any proprietary / commercial / Enterprise editions of this project, - now or in the future. +- You agree that this contribution may be merged, used, modified, and redistributed under the AGPLv3 - You understand that submitting this PR does not create any support obligation, SLA, or guarantee of merge. diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index ac193da..08e1aa8 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -2,28 +2,17 @@ Thank you for your interest in contributing to this project. -This repository is published in two forms: -- a Community Edition released under AGPLv3, and -- a proprietary / commercial / Enterprise Edition offered to organizations. - -To keep that model legally clean, we need to be explicit about how contributions can be used. +This repository is published under AGPLv3 By opening a pull request, you agree to all of the following: 1. **You have the right to contribute this code.** You are either the original author of the contribution, or you have obtained the necessary rights/permissions to contribute it under these terms. -2. **Dual licensing permission.** +2. **Licensing.** You agree that your contribution may be: - merged into this repository, and - - used, copied, modified, sublicensed, and redistributed - - under the AGPLv3 Community Edition, and - - under any proprietary / commercial / Enterprise editions of this project, - now or in the future. - - In other words: you are granting the project maintainer(s) the right to include - your contribution in both the open-source (AGPLv3) codebase and in closed-source / - commercially licensed builds, without any additional approval or payment. + - used, copied, modified, sublicensed, and redistributed under the AGPLv3 3. **Attribution.** The maintainers may keep or add attribution lines such as @@ -36,14 +25,6 @@ By opening a pull request, you agree to all of the following: service-level agreement, warranty, or guarantee that the contribution will be reviewed, merged, or maintained. -5. **Potential rejection for business reasons.** - Features that fall under "Enterprise / Commercial" functionality - (e.g. multi-tenant provisioning at scale, centralized audit trails, - corporate policy enforcement, attestation/branding flows, key escrow / dual-control, - etc.) may be declined for the public AGPLv3 tree even if technically valid. - That is normal: some functionality is intentionally offered only - under commercial terms. - If you are not comfortable with these terms, **do not open a pull request yet.** Instead, please open an Issue to start a discussion. @@ -76,9 +57,6 @@ Please keep PRs focused (one logical change per PR if possible). - impact on existing flows / security model - any new dependencies -This helps avoid doing a bunch of work on something that won't be accepted -in the Community Edition. - ### 4. Coding style / security posture - Aim for clarity and small, auditable changes. This code runs in places where secrets live. @@ -91,7 +69,7 @@ in the Community Edition. - In the PR description, please include a short summary of what was changed and why. - At the bottom of the PR description, **copy/paste and confirm the licensing line below**: - > I confirm that I have read `CONTRIBUTING.md` and I agree that this contribution may be used under both the AGPLv3 Community Edition and any proprietary / commercial / Enterprise editions of this project, now or in the future. + > I confirm that I have read `CONTRIBUTING.md` and I agree to its terms A PR without that confirmation may be delayed or closed without merge. diff --git a/ENTERPRISE.md b/ENTERPRISE.md deleted file mode 100644 index f550fed..0000000 --- a/ENTERPRISE.md +++ /dev/null @@ -1,116 +0,0 @@ -# Enterprise / Commercial Edition - -This project is offered under two editions: - -## 1. Community Edition (FOSS) - -The Community Edition is released under the GNU Affero General Public License v3 (AGPLv3). - -Intended for: -- individual users and researchers -- evaluation / prototyping -- internal lab / security testing - -You are allowed to: -- read and study the source code -- modify it -- run it internally - -Obligations under AGPLv3: -- If you distribute modified firmware/binaries/libraries to third parties, you must provide the corresponding source code of your modifications. -- If you run a modified version of this project as a network-accessible service (internal or external), you must offer the source code of those modifications to the users of that service. -- No warranty, no support, no SLA. -- Enterprise features (bulk provisioning, multi-user policy enforcement, device inventory / revocation, corporate PIN rules, custom attestation/identity, etc.) are NOT included. - -The Community Edition will continue to exist. - -## 2. Enterprise / Commercial Edition - -The Enterprise / Commercial Edition is a proprietary license for organizations that need to: - -- deploy this in production at scale (multiple devices / multiple users / multiple teams) -- integrate it into their own physical product or appliance -- run it as an internal service (VM / container / private cloud "HSM / auth backend") for multiple internal teams or tenants -- enforce internal security policy (admin vs user roles, mandatory PIN rules, secure offboarding / revocation) -- avoid any AGPLv3 disclosure obligations for their own modifications and integration code - -### What the Enterprise Edition provides - -**Base license package (always included):** -- **Commercial license (proprietary).** - You may run and integrate the software/firmware in production — including virtualized / internal-cloud style deployments — without being required to disclose derivative source code under AGPLv3. -- **Official signed builds.** - You receive signed builds from the original developer so you can prove integrity and provenance. -- **Onboarding call (up to 1 hour).** - A live remote session to get you from "we have it" to "it’s actually running in our environment" with minimal guesswork. - -**Optional enterprise components (available on demand, scoped and priced per customer):** -- **Production / multi-user readiness.** - Permission to operate the system with multiple users, multiple devices and multiple teams in real environments. -- **Bulk / fleet provisioning.** - Automated enrollment for many tokens/devices/users at once (CSV / directory import), scripted onboarding of new users, initial PIN assignment / reset workflows, and role-based access (admin vs user). -- **Policy & lifecycle tooling.** - Corporate PIN policy enforcement, per-user / per-team access control, device inventory / traceability, and secure revocation / retirement when someone leaves. -- **Custom attestation / per-organization identity.** - Per-company certificate chains and attestation keys so devices can prove "this token/HSM is officially ours," including anti-cloning / unique device identity for OEM and fleet use. -- **Virtualization / internal cloud deployment support.** - Guidance and components to run this as an internal service (VM, container, private-cloud HSM/auth backend) serving multiple internal teams or tenants under your brand. -- **Post-quantum (PQC) key material handling.** - Integration/roadmap support for PQC algorithms (auth / signing) and secure PQC key storage inside the device or service. -- **Hierarchical deterministic key derivation (HD).** - Wallet-style hierarchical key trees (BIP32-like concepts adapted to this platform) for issuing per-user / per-tenant / per-purpose subkeys without exporting the root secret — e.g. embedded wallet logic, tenant isolation, firmware signing trees, large fleets. -- **Cryptographically signed audit trail / tamper-evident event logging.** - High-assurance logging of sensitive actions (key use, provisioning, PIN resets, revocations) with integrity protection for forensic / compliance needs. -- **Dual-control / two-person approval ("four-eyes").** - Require multi-party authorization for high-risk actions such as firmware signing, key export, or critical configuration changes — standard in high-assurance / regulated environments. -- **Secure key escrow / disaster recovery design.** - Split-secret or escrowed backup strategies so you don’t lose critical signing keys if a single admin disappears or hardware is lost. -- **Release-signing / supply-chain hardening pipeline.** - Reference tooling and process so every production firmware/binary is signed with hardware-backed keys, proving origin and preventing tampering in transit or at manufacturing. -- **Policy-locked hardened mode ("FIPS-style profile").** - Restricted algorithms, debug disabled, no raw key export, tamper-evident configuration for regulated / high-assurance deployments. -- **Priority support / security response SLA.** - A direct line and guaranteed response window for production-impacting security issues. -- **White-label demo / pre-sales bundle.** - Branded demo firmware + safe onboarding script so you can show "your product" to your own customers without exposing real production secrets. - -These components are NOT automatically bundled. They are available case-by-case depending on your use case and are priced separately. - -### Licensing models - -- **Internal Use License** - Internal production use within one legal entity (your company), including internal private cloud / virtualized deployments for multiple internal teams. - Optional enterprise components can be added as needed. - -- **OEM / Redistribution / Service License** - Integration into a product/appliance you ship to customers, OR operating this as a managed service / hosted feature for external clients or third parties. - Optional enterprise components (attestation branding, PQC support, HD key derivation, multi-tenant service hardening, audit trail, etc.) can be added as required. - -Pricing depends on scope, fleet size, number of users/tenants, regulatory requirements, and which optional components you select. - -### Request a quote - -Email: pol@henarejos.me -Subject: `ENTERPRISE LICENSE ` - -Please include: -- Company name and country -- Intended use: - - Internal private deployment - - OEM / external service to third parties -- Approximate scale (number of devices/tokens, number of users/tenants) -- Which optional components you are interested in (bulk provisioning, policy & lifecycle tooling, attestation branding / anti-cloning, virtualization/cloud, PQC, HD key derivation, audit trail, dual-control, key escrow, supply-chain signing, hardened mode, SLA, white-label demo) - -You will receive: -1. A short commercial license agreement naming your company. -2. Access to the base package (and any optional components agreed). -3. Scheduling of the onboarding call. - -## Why Enterprise exists - -- Companies often need hardware-backed security (HSM, FIDO2, OpenPGP, etc.) under their own control, but cannot or will not open-source their internal security workflows. -- They also need multi-user / fleet-management features that hobby users do not. -- The commercial license funds continued development, maintenance and new hardware support. - -The Community Edition remains AGPLv3. -The Enterprise Edition is for production, scale, and legal clarity.