Trust that can be checked

Our products make claims that cannot be checked without the code: that we hold no custody, that the cryptography is real, that a customer can recover without us. So we publish the code. We also want the parts that everyone should use to be used by everyone, and the parts that are the product to stay ours to support.

Every component is licensed under this rule. The downpipes engine, console and offline reader are published on GitHub. The control plane is private. We run it, and we do not give its source to anyone. The register at the foot of this page records the status of each component and links to each published repository.

One question decides the layer

For every component, ask:

Do we want other people to run this instead of us, or alongside us?

Nothing else decides the layer. Not how clever the code is. Not how much work it took.

Permissive, source-available, internal

Layer 1: permissive

Licence
Apache-2.0 for libraries, services and native code. MIT is permitted for JavaScript SDKs and where a component is already MIT. Specifications take the licence of the component they ship with.
What goes here
cryptographic cores, SDKs, client libraries, offline readers, archive and protocol specifications, verifiers, shared schemas.
What it allows
anyone may use, modify, embed, sell and host the component. The only obligation is to keep the notice.
Why
these are our adoption and trust surfaces. A crypto crate, a reader or a spec under a restrictive licence does not get audited, embedded or standardised. Apache-2.0 also gives users a patent grant, which removes a reason for a legal team to say no.

Layer 2: source-available

Licence
Elastic License 2.0 (SPDX: Elastic-2.0).
What goes here
the thing a customer deploys and we support. That covers engines and consoles. A harness that ships as part of a product also goes here.
What it allows
anyone may read the code, run it in their own account, modify it, and use it internally, for free, for as long as they like. No feature is gated by payment. The software sends no telemetry unless its operator turns it on.
What it forbids
providing the component to third parties as a hosted or managed service, circumventing licence keys, and removing notices.
Why
someone who sells the product as a service competes with us. A managed-service provider can run the product for its clients under a separate agreement with us, such as the downpipes MSP / MSSP rider. That provider then holds operational access to each client's deployment. Maelstrom still holds no keys and no backup data.

Internal: not published

What goes here
Services and operational tooling that only we run: the control plane, admin portals, billing, status pages, load tests, website source.
Licence
These carry no public licence. All rights reserved. If a component moves from internal to published, it gets a layer under the rule first.

Two other instruments do that work

A copyright licence stops a competitor selling our code. It does not stop them selling it under our name, and it does not stop anyone copying our ideas with their own code.

Speed and customers do the rest.

Keeping the right to relicense

Public products

These may appear in public copy.

Component Layer Licence Published
Product downpipes
Offline reader and archive format specification 1 MIT github.com/downpipes-io/downpipe
Engine 2 Elastic-2.0 github.com/downpipes-io/engine
Console 2 Elastic-2.0 github.com/downpipes-io/console
Control plane (a service we run) Internal All rights reserved No
Internal tooling (testing, support, deployment and internal documentation) Internal All rights reserved No

The downpipes documentation is published as the website docs.downpipes.io. It carries no open licence. You may copy and change its code samples and commands to deploy and operate your own downpipes installation.

Last updated 25 September 2026.

Changes on 25 September 2026: we moved the control plane from Layer 2 to Internal. We set the licence of the downpipes documentation to all rights reserved, and we added our trade mark position.

Talk to us

See how our code is published and what we release in Open Source, or get in touch about a specific component.