License
A plain-language summary of the Caisson Commercial License: one perpetual license across every module and bundle.
Summary only: the EULA is the binding document
This page is a plain-language summary of the Caisson Commercial License. It is informational and is not a substitute for the full Commercial License Agreement (“EULA”), which is the binding document and is provided at purchase. Where this summary and the EULA differ, the EULA governs.
The licensing model
Caisson ships two tracks. The Base substrate (kernel, auth, tenancy-rls, ui, billing, jobs, email, ai-config, mcp-server, registry-schema, observability, rate-limit, ds-manifest, and the generator tooling: cli, migrate, license-verify) is Apache-2.0, open source, free to use. Every commercial module (the compliance and provenance primitives, the local-first and agentic modules, credits, and the registry service) and every bundle that composes them ship under a single proprietary Commercial License (LicenseRef-Caisson-Commercial).
The commercial track is the kit pattern: you purchase, you build, you ship your own products without per-seat or per-project fees, but you do not redistribute or resell the kit itself.
What you may do
Under the Caisson Commercial License, purchasing an entitlement grants you a perpetual, non-exclusive, worldwide license to use, modify, and integrate the source code in your own products and services, subject to the restrictions below.
You may
- Use the source code in unlimited commercial projects and products you build and operate yourself.
- Modify the source code to fit your product's requirements.
- Deploy the code on your own infrastructure or cloud accounts.
- Include compiled or bundled output from the code in your products (subject to the no-redistribution restriction: your product ships, the kit source does not ship as a kit).
- Transfer the license to another entity that acquires your business or the product in which the code is embedded (contact us for transfer terms).
You may not
- Redistribute, resell, or publish the source code as a standalone kit, boilerplate, library, or template that competes with Caisson.
- Sub-license the kit to third parties as a kit: your customers may use your product, never the underlying Caisson source.
- Remove or obscure license notices, SPDX identifiers, or the attribution in the code.
- Use the code in a product whose primary purpose is to provide a competing compliance infrastructure kit, boilerplate service, or source-code library.
The full text of the Commercial License Agreement, which is the binding document, is published at caisson.sh/legal/eula. The LicenseRef-Caisson-CommercialSPDX identifier in each package's package.json resolves to that document.
How the license is delivered
Caisson uses an offline Ed25519 license key for entitlement verification. When you purchase:
- You receive an entitlement record and a signed Ed25519 offline license key covering the modules you purchased.
- Your entitlement grants access to
registry.caisson.sh, the private npm registry serving entitled packages under the@caissonscope, authenticated with your license token. - The license key is verified at install time and optionally at runtime (for license-gated features). Verification is local, and no call home is required for the perpetual license.
- Your purchase includes 12 months of registry-pull updates from your Order date, renewable afterward at 40% of the then-current list price per year; letting it lapse never revokes access to versions already delivered. An Updates Subscription, where purchased, additionally delivers new versions of your entitled packages while it is active. Both are optional; the perpetual license does not expire.
Which license applies where
Two licenses, split by package. The Base substrate is Apache-2.0, open source; the commercial modules and the bundles that compose them ship under the Caisson Commercial License.
The open Base substrate: free to use, modify, and redistribute under the Apache-2.0 terms.
@caisson modules (including field-crypto, audit-worm, signing-primitive, credits, and the local-first modules), the registry service, and the six bundles that compose them: Compliance, AI-Production, Local-first, Agentic-Dev, Provenance, and Everything. The licensefield in each package’s own manifest is what binds, not this summary.CommercialLicenseRef-Caisson-Commercial: a perpetual paid license, no redistribution of the kit.
Common questions
Can I use Caisson to build a SaaS product I sell to customers?
Can I include Caisson in an open-source project I publish?
What happens when I modify the source?
Is the license perpetual?
Does Caisson claim to be SOC 2 certified or HIPAA certified?
Licensing questions
For licensing questions, volume pricing, transfer requests, or EULA negotiation:
Caisson Software LLC
Atlanta, Georgia, USA
[email protected]