Trust & licensing

Everything your client's security team will ask — answered before they ask.

Your name goes on the product, so you carry the questionnaire. This page is what you answer it with: open code, signed releases, a published vulnerability process, long-term support, and a licence with an exit written into it.

The questionnaire

Six questions every client asks. Six answers you can give.

  • Can we read the code?

    Yes — all of it. The kernel and the products are source-available. Nothing your client runs is a black box to you or to them.
  • Are releases signed?

    Every release is built from a tagged commit, signed, and ships with a software bill of materials listing every dependency.
  • How are vulnerabilities handled?

    A published disclosure address, a fixed response window, CVE advisories, and backported fixes on every supported branch.
  • How long is a version supported?

    Long-term supported branches with published support windows, release notes, breaking-change notices and upgrade playbooks.
  • How should it be deployed?

    A hardened deployment profile for on-premises and regulated environments: reference topology, security baseline, logging requirements, backup and restore.
  • What do we hand to procurement?

    A legal and procurement package: licence terms, support terms, the compatibility matrix and the connector certification list.
Licensing

Open code. A commercial agreement with a partner, not with your client.

Two licences, one rule: the client never signs anything with Aurelion. You do, once.
  • Apache 2.0

    Connectors, SDK utilities and most secondary components. Permissive, OSI-approved, inspectable.
  • BUSL 1.1 — the kernel

    Source-available. You can read it, run it, test it and build on it. Running it in production for a client is covered by your partner agreement.
  • The change date

    BUSL carries a change date written into the licence. On that date the kernel converts to an open licence. If Aurelion disappears, the code does not.
Boundaries

What you can do without asking. What the partner agreement covers.

Without asking

  • Read, build and run the whole code base.
  • Run proofs of concept and evaluation deployments for prospective clients.
  • Deploy for clients and run it as a service under your own brand, under your partner agreement.
  • Modify, extend and add connectors — and keep the modifications.

Under the partner agreement

  • Production use of the kernel for a paying client.
  • Shipping the products under your brand to your clients.
  • Access to signed release artifacts, long-term supported branches and the certification list.
  • Support escalation to Aurelion and the capped founder hours.
Not trapped

Three guarantees written down, not promised.

  • Partner pricing is fixed

    Your terms do not change for the life of the relationship.
  • Your modifications are yours

    Connectors, policies, screens you build stay with you.
  • The kernel converts to open

    On the change date in the licence, whatever happens to Aurelion as a company.
FAQ

Common questions.

Can my client read the code?
Yes. That is usually the end of the security-review conversation, not the start of it.
Can I run a proof of concept before signing anything?
Yes. Evaluation and proof-of-concept use needs no agreement.
Can I modify the kernel?
Yes. Modifications stay yours. If they are useful to other partners we will ask to merge them, and credit you.
What happens if Aurelion is acquired or shuts down?
Your partner pricing is fixed for the life of the relationship, your installations keep running, and on the change date the kernel becomes open-licensed regardless.
Does Aurelion ever contact my client?
No. Aurelion never deploys at, hosts for, or speaks to your client. Support goes through you.
Is any of this a hidden install meter?
No. There is no telemetry that phones home, no per-install counter. Commercial terms are per client, agreed in writing.
Security contact

Found something? Tell us first.

Vulnerability reports go to the security address and get a response inside the published window.