Skip to content

License

OpenTremor uses two open source licences: the GNU AGPL v3 for the server, and Apache-2.0 for everything that plugs into it. Both are approved by the Open Source Initiative. Here is what that means in practice.

  • Use it — yes, and you owe nothing. Self-host it for your team or your whole company, commercially, forever. Every analyzer, unlimited.
  • Change it — yes, share your changes. Patch the server however you like; if other people use your modified version over a network, offer them its source.
  • Extend it — yes, under any licence. Write analyzers, fork the Terraform provider or the Helm chart — proprietary included.
ModulesWhat they areLicenceIn practice
core · platform · dashboard · task-schedulerThe server: the API, the analysis engine, the web UI and the schedulerAGPL-3.0-or-later + analyzer plugin exceptionFree to use and modify. Changes to it stay open for the people who use them.
analyzer-* · terraform-provider · deployments · monitoring · docsEverything that plugs into the server: analyzers, the Terraform provider, the Helm chart, Grafana dashboards, docsApache-2.0Permissive. Fork it, embed it, close it — keep the LICENSE and NOTICE files.
I want to…Allowed?What I owe
Self-host OpenTremor for my team or company, as it shipsYesNothing. Commercial use included — every analyzer, unlimited.
Call it from my own scripts, CI jobs or MCP agentsYesNothing. Code that talks to OpenTremor over its API is a separate program; the AGPL covers OpenTremor, not your code.
Write my own analyzer and keep it closed-sourceYesNothing, as long as it uses core only through the analyzer plugin API.
Fork an analyzer, the Terraform provider, the Helm chart or the Grafana dashboardsYesKeep the LICENSE and NOTICE files and mark the files you changed. A closed-source fork is fine.
Modify the server and run it for my own companyYes — share your changesOffer your modified source to the people who use that instance — here, your colleagues. An internal Git repo does it. Nothing has to go public.
Run OpenTremor as a hosted service for my own customersYes — share your changesUnmodified: nothing beyond keeping the notices. Modified: offer your customers the modified source under the AGPL. Neither licence gives you the OpenTremor name.
Ship the server inside my own product — an image, an appliance, an installerAGPL, or a commercial licenceYour customers receive the source of the server, and of whatever you built into it, under the AGPL.
Copy parts of core’s source code into my own productAGPL, or a commercial licenceYour product becomes a work based on an AGPL program, and the AGPL applies to it in full.
WhoSituationOutcome
A platform teamRuns OpenTremor on its own Kubernetes cluster for 200 engineers, every analyzer onFree, unlimited, forever. Nothing to publish, no one to ask.
A consultancyBuilds a paid analyzer for a client’s in-house configuration languageCovered by the plugin exception; it can ship under whatever licence the contract says.
An SREForks the Helm chart for an unusual cluster setup and keeps it privateApache-2.0: keep the NOTICE file and they’re done.
A fintechPatches core to plug in an internal approval systemFine. Their engineers — the people using that instance — can get the patched source. The rest of the world doesn’t.
A startupAdds features and sells it as its own hosted review serviceAllowed. Its customers are entitled to the modified source under the AGPL — and it needs its own name.
A security vendorWants to bundle the server in a closed-source on-premise applianceEither the appliance’s server code ships under the AGPL, or the vendor takes a commercial licence.

Is OpenTremor really open source? Yes. Both the GNU AGPL v3 and Apache-2.0 are OSI-approved, and every module carries one of them. There is no “source-available” tier and no time-delayed licence.

Will the AGPL spread to my own code? Only to code that becomes part of the server itself — a modified core, or core’s source copied into your product. Scripts, CI jobs and agents that call the API are separate programs, and analyzers that use the plugin API are explicitly carved out.

Do I have to publish my changes on GitHub? No. The AGPL asks you to offer the source to the people who use your modified version — not to the whole world.

Why not one licence for everything? Because the pieces do different jobs. Copyleft on the server keeps improvements to it open. Copyleft on analyzers would force every third-party analyzer to be AGPL too, so the plugin boundary gets a permissive licence and an explicit exception instead.

What does “or later” mean? You may follow the terms of AGPL version 3, or of any later version the Free Software Foundation publishes — your choice.

The AGPL doesn’t suit my use. Now what? A separate commercial licence, which replaces the AGPL’s obligations for your use, is available from the copyright holder — see the contact in any module’s NOTICE file.