Trust

Everything your review will ask for.

Licence, security, continuity, governance and roadmap — in one place, with anchors you can link to directly. This page is written to be cited, not admired.

Licence

What you run is MIT

Everything your business would actually run on is MIT licensed — one of the most permissive licences there is. Use it commercially, change it, redistribute it. No production licence, no seat count, nothing phoning home. The source is public, so you can check that rather than take our word for it.

What is commercial

Cratis Studio — where your team designs together — is a paid product, in beta now, with pricing published rather than quoted. What you design in it stays yours and comes out in a format you can take elsewhere, and the software it produces keeps running whether you keep paying us or not. Support plans, advisory work and workshops are the other commercial part: our time, not the software.

Source for every product is at github.com/Cratis.

Continuity

What happens if we stop

The software your business runs on is open source and public. It sits on your own infrastructure, works with the systems you already have, and speaks open standards. There is no licence to renew, nothing phoning home, and no proprietary format holding your data.

Cratis Studio is the exception, and a deliberate one: it is a product you pay for, so it is the one part you would lose. What your team designed in it comes out with you, and the software it produced keeps running — because that is what your business actually depends on.

If Cratis ceased to operate tomorrow, you would keep the rest of it — the software, your data, and the right to continue it yourself. Nothing to renew, nothing to migrate off.

Every support plan additionally guarantees a ninety-day wind-down with handover documentation, and a refund of the unused remainder of the term.

We think that makes us a lower-lock-in choice than most vendors ten times our size. It's certainly a more honest one.

Versioning and support windows

Semantic versioning, taken literally

We follow the industry-standard versioning scheme, and we apply it literally. Any change that could break something you rely on is labelled as a major change — even when calling it something smaller would be more convenient for us. That label is checked automatically before anything ships.

Why our major numbers are high

Some of our version numbers look high. That is not twenty rewrites — it is twenty changes we declared honestly on the day they shipped, rather than quietly folding them into something that sounds smaller. We would rather the number be honest than flattering.

What we haven't published yet

We're writing a formal support-window and long-term-support policy — which majors get security fixes, for how long, and what the upgrade commitment is. It isn't published, because we won't commit to a window we can't currently hold.

If you need to know where a specific version stands before you commit to it, ask us and you'll get a straight answer rather than a marketing one.

What it runs on

The platform supports current and previous generations of its runtime, and runs on the major databases you are likely to already operate. Your operations team will not be asked to adopt anything unfamiliar.

Test builds

Everything we publish publicly is a stable release. Pull-request builds go to GitHub Packages as 1.2.3-pr<n>.<sha>, built in Debug — for verifying a fix before it merges, not for production.

Current compatibility baselines are maintained in the documentation: version compatibility. Pin explicit package versions and image tags in anything you deploy.

Security

Reporting a vulnerability

Report it privately through the affected project, or email oss@cratis.io with a subject starting Security:. Please don't open a public issue first.

Full disclosure process →

What to include

Which product and version, what kind of issue it is, how to reproduce it, and what it would let someone do. There is no bounty programme — we would rather say so plainly than imply one.

For going live safely, there is a full operational checklist covering security, storage, monitoring and backups: production readiness.

Governance

How decisions get made

Small fixes move quickly and in the open. Larger design decisions start as public discussion and end as a durable record. Anything that could break your system arrives with notes on what changed and what to do. Security issues are handled privately first.

Governance in full →

Roadmap

What we're building is public, including the parts that aren't ready. Studio is marked "coming soon" because it is coming soon, not because it's shipping quietly.

Public roadmap →

Data and privacy

What the software sends us

Nothing. There is no telemetry, no licence check, and no usage reporting of any kind. What runs in your infrastructure stays in your infrastructure.

What this website collects

No cookie banner, because there's nothing to consent to. If we add analytics it will be a privacy-preserving, cookieless product, and this section will name it.

If we work together

Anything you share under an engagement or support plan stays confidential, and we won't name you as a customer without written permission. We don't want your credentials or your production data — and we'd rather you didn't have to trust us with them.

The company

Registered details

Cratis is built by two people, working in the open. Full legal entity details — registered name, organisation number, address and VAT registration — will be listed here and in the footer of every page.

Need them for a supplier form before then? Ask us and we'll send them over the same day.

Who you'd be dealing with

Both founders, directly. There is no sales team to route you through and no support tier to escalate past. More about us →

Terms

Support plan terms — severity definitions, response commitments, cancellation and the continuity clause — are being finalised for publication. Ask and we'll send the current draft.