Source you can read. A core you can run. A license that converts.
The probectl core is published under the Business Source License 1.1: read it, build it, change it and run it in production, at no charge and with no signed license. Four years after a release is published, it converts to the Mozilla Public License 2.0.
Core · BSL 1.1
Everything outside the ee/, pkg/, proto/ and examples/ trees, apart from third-party code that keeps its own license: the control plane, every agent and collector, the BGP analyzer, the console and the deployment tooling. Production use is permitted. Not permitted: offering the core to third parties as a hosted or managed service, embedding it in a competing product, or working around the license key. Operating it inside a customer's own deployment as that customer's service provider is permitted.
Clients · MPL 2.0
The public Go SDK under pkg/, the wire contracts under proto/ and the examples. Embed them in your own software, or speak probectl's protocols from another implementation; the core's use grant never attaches to it.
Enterprise & MSP · commercial
Proprietary features under ee/, switched on by an offline Ed25519-signed license: bring-your-own-key, governance, guarded remediation, HA support and siloed isolation for Enterprise, plus the provider plane and metering for MSPs, who resell under the probectl name. The FIPS build is a separate artifact of the same tier. The commercial terms are a draft pending counsel; until they are final, production and resale rights under ee/ exist only through a separately signed agreement.
- Licensor
- certctl LLC
- Change date
- Four years after each version is published
- Change license
- Mozilla Public License 2.0
- Runtime gate
- Offline signature check, never a phone-home
This page is a summary. The LICENSE file in the repository is the binding text, with ee/LICENSE for the commercial tree. There is no published price list; commercial terms are set per agreement.