Commercial Self-Hosted

Commercial Self-Hosted Licensing.

Use Evydence under AGPL when that fits your organization.

Buy Evydence Commercial Self-Hosted when you need private commercial terms, AGPL exception, async support, signed release/evidence delivery, or deployment review.

Release dossier verify-ready
01

Artifact digest

02

SBOM inventory

03

Vulnerability decision

04

Signed package

Community AGPL vs Commercial Self-Hosted

Public AGPL license Separate written commercial agreement
Public GitHub issues Private async support
Best-effort community help Agreed support and upgrade path
Self-evaluation Optional deployment-readiness review
AGPL obligations apply Extra permission for agreed use cases

Paid options

Commercial Self-Hosted License

Private commercial terms, procurement-friendly licensing, and an agreed support path.

Async Support

Private written support for troubleshooting, upgrade planning, deployment questions, and release evidence workflows.

Deployment Readiness Review

Written review of configuration, backup/restore, evidence handling, deployment architecture, and known limitations.

Release Evidence Package Review

Written review of one evidence package, including gaps, assumptions, limitations, and customer-safe sharing concerns.

Custom Integration

Collector adapters, evidence workflows, report templates, CI/CD integration, or deployment hardening.

Release evidence readiness review

A concrete paid starting point: install or review one self-hosted Evydence deployment profile, configure one product release, connect one CI evidence path, generate the first customer-safe package, verify it offline, and document gaps, assumptions, limitations, operator responsibilities, and external dependencies.

  • one short readiness summary
  • one deployment-checklist pass with accepted gaps
  • one SBOM, vulnerability, build, artifact, and release-bundle upload path where the operator already has the files or commands
  • one customer-safe package or evidence bundle with manifest, hashes, verification material, limitations, and non-claims
  • one prioritized follow-up list

What is excluded

  • hosted SaaS operation
  • legal compliance advice or certification
  • audit opinion or regulator acceptance
  • secure-release guarantees
  • complete SBOM proof or authoritative vulnerability coverage
  • unlimited integration work, scanner replacement, broad GRC workflow, or custom customer portal development

Commercial boundary

Commercial terms do not turn Evydence into a legal compliance guarantee, security certification, vulnerability scanner, or managed SaaS service.

Next step

Evaluate the technical truth on GitHub.

The website qualifies the business problem. The repository remains the source of truth for code, docs, release artifacts, limitations, and verification evidence.