ZeroRoot Docs
Security architecture

Licensing

The Go SDK, the CLI and the install surface are Apache-2.0. Everything else is Elastic License 2.0, and this page states both of its restrictions.

Two statements cover it.

The Go SDK, the CLI, the microVM operator and the Helm charts are Apache-2.0. What you write against them is yours. The license puts no obligation back on you.

Everything else is Elastic License 2.0. You may read, run, modify, and self-host it. You may not offer it to third parties as a managed service, and you may not remove the license-key check. Elastic License 2.0 is source-available, not open source.

The map

RepositoryLicenseWhat it is
sdkApache-2.0Go SDK — agent, tool, and plugin contracts, the harness API
adkApache-2.0The gibson CLI — scaffold, build, validate, enrol, submit missions
setecApache-2.0Kubernetes operator for Firecracker microVMs via Kata. Useful standalone
ast-checksApache-2.0Static checks the SDK depends on
chartsApache-2.0The Helm charts you install the platform with
gibsonElastic License 2.0The control plane
dashboardElastic License 2.0The web interface
gibson-executorElastic License 2.0One microVM image, one binary, parsers for common security and ops tools
sdk-tsElastic License 2.0TypeScript SDK
zerocool-pluginsElastic License 2.0opencode plugins for running a coding agent under Gibson's controls
docs-siteElastic License 2.0This documentation
zitadel-loginMITA fork of the ZITADEL login application. A fork keeps its upstream license

The License column is generated. pnpm regen:licensing reads the LICENSE file of each repository and writes what it finds into this page. A build gate fails if anyone edits the column by hand.

Why this page states the two restrictions

A procurement reviewer stops on Elastic License 2.0. So it is better to say what it forbids than to leave someone to find out:

  1. You may not provide the software to third parties as a managed service.
  2. You may not circumvent the license-key functionality, or remove or obscure protected notices.

Neither restricts internal use. You may run the control plane for your own organization, on your own infrastructure, modified as you like.

Elastic License 2.0 is not approved by the Open Source Initiative. GitHub reports it as NOASSERTION and the repository sidebar says nothing useful. Read the LICENSE file at the root of the repository.

Components you write

A component you build with the SDK is your code. It links against Apache-2.0 libraries, and the license carries no obligation to publish it or to license it back to us. You may keep it private, sell it, or open it under whatever terms you choose.

What to check

  1. The LICENSE file in each repository matches the table above.
  2. Nothing you build against is Business Source License or source-available with a delayed conversion. The Apache-2.0 rows above are the surface you build against.
  3. The Elastic restrictions apply to every row the table marks Elastic License 2.0.

On this page