Skip to content

Open first · Enterprise adds

Enterprise adds depth. Open stays complete.

The open (AGPL) build is the complete governance platform; the enterprise edition takes nothing away — it adds capability for organizations at scale, under specific regulation, or needing risk-mitigation depth.

Ground truth for enterprise AI.

The open-core line

Three promises that define the edition boundary

These are structural product commitments, not contractual service promises.

  1. 01

    What is open never moves to a paid tier.

    Every capability in the AGPL build stays in the AGPL build. Enterprise is additive new code, never a feature removed from the open product.

  2. 02

    The AGPL core has no artificial performance or size limits.

    There are no throttles, synthetic delays or hidden feature flags in the open binary. The only edition boundary is the 3-user community cap.

  3. 03

    The criterion is published.

    Security-core and the complete observe → map → govern → audit loop are free. Commercial means scale-operation plus a legal exception to AGPL obligations.

Additive capability

What Enterprise adds, by theme

Enterprise extends the complete open platform where larger or regulated organizations need more operational depth. It does not replace the open governance loop.

Open foundation: 29 wired modules · 26 compliance framework catalogs · 157 public integrations.

Identity & access

The open build provides complete single-IdP OIDC and SAML, WebAuthn/FIDO2, PIV/CAC and non-human identity lifecycle. Enterprise adds per-tenant multi-IdP federation, SSO enforcement, SAML SP metadata, CyberArk Conjur integration and seat entitlement beyond the community cap. These are scale and policy-operating capabilities, not a replacement for open identity security.

Content & data security

Open includes deterministic PII, injection and jailbreak guardrails plus a deny-closed DLP egress gate. Enterprise adds deep content inspection across messages, retrieval, MCP renders and Claude Code hook input, as well as enhanced erasure coordination and computer-use governance. The extra depth targets injection, exfiltration and unsafe-action patterns across more governed channels.

Threat & incident

The open build includes guardian findings, tier floors and the estate kill switch. Enterprise adds threshold-based automatic suspension, curated threat intelligence, continuous attack-graph scanning and bidirectional incident close-loop workflows. Operators configure thresholds, cooldown and escalation rather than delegating every decision to automation.

Compliance & regulatory

Open maps 26 framework catalogs and exports sealed OSCAL evidence. Enterprise adds DORA register structuring, ISO 42001 AIMS readiness material, SSP and POA&M workflows, and sector-specific overlays. These add-ons automate evidence gathering and report structuring. They do not certify the organization or guarantee compliance.

Operations & resilience

Open includes S3 Object Lock WORM archival, a signed ledger and backup/restore with chain verification. Enterprise adds named regulatory retention floors, long-horizon legal hold, examiner evidence bundles, Azure and GCS immutable sinks, and durable at-least-once event delivery. It adds regulated operating depth without removing the open resilience baseline.

Integration

Open provides static upstream credentials, a CAEP receiver, Terraform, SDKs and typed webhooks. Enterprise adds RFC 8693 token exchange, outbound CAEP SETs, deny-closed tool-definition pinning and an MCP elicitation mediator. These capabilities harden short-lived credentials and runtime trust between systems.

Curated comparison

Six flagship differences

One representative capability per theme. The downloadable matrix is the authoritative, row-by-row due-diligence source.

Capability Community (AGPL) Enterprise
Identity & access Complete single-IdP OIDC and SAML. Multiple IdPs per tenant, domain routing and enforced SSO policy.
Content & data Core text DLP with a deny-closed posture when content is not scanned. Content firewall for injection, exfiltration and unsafe actions across message, retrieval and MCP-render channels.
Threat & incident Kill switch, guardian findings and tier-floor enforcement. Threshold circuit breaker, curated threat intelligence and continuous attack-graph scanning.
Compliance 26 framework catalogs with OSCAL evidence export. DORA register, ISO 42001 AIMS readiness, SSP and POA&M workflows, and sector overlays.
Operations & resilience S3 Object Lock WORM, signed ledger and verified backup/restore. Named regulatory floors, legal hold, Azure/GCS immutable sinks and durable at-least-once delivery.
Integration Static credentials and a CAEP receiver. RFC 8693 token exchange, outbound CAEP SETs, tool-definition pinning and MCP elicitation mediation.

Additive, no rug-pull: an open capability stays open; Enterprise adds separate code for scale and risk depth.

The 3-user community cap is a fair-monetization edition boundary, not a security control or performance limit.

License validation is attestation-only. The open binary never reads a license to enable, disable or block a capability.

Download the full capability matrix

Open-first by design

What you do not need Enterprise for

The AGPL build already contains the complete observe → map → govern → audit loop and its security core.

  • Full inventory, permitted-versus-observed access map, sessions, orchestration graph and health telemetry.
  • Cedar authorization with RBAC, deny overlays, scoped grants and four deny-closed enforcement points.
  • Two-person approvals, dual-control break-glass and the estate kill switch.
  • Governed Claude Code launch, attach, govern and stop workflows with managed-settings delivery.
  • Single-IdP OIDC and SAML, WebAuthn/FIDO2, PIV/CAC and AAL step-up.
  • Non-human identity lifecycle and agent-identity federation.
  • PII, prompt-injection and jailbreak guardrails, DLP egress and BYOK/CMEK.
  • Hash-chained, Ed25519-signed audit ledger with sealed append-only evidence.
  • 26 compliance framework catalogs and SIEM export and push formats.
  • FinOps budgets that deny or throttle spend.
  • Evaluations with a blocking CI gate and red-team sandboxes.
  • A single static artifact, SQLite or Postgres, Docker/Kubernetes/Helm, Terraform and SDKs across 157 public integrations.
  • S3 Object Lock WORM archival and backup/restore with chain verification.

Procurement facts

Read this before evaluating

The useful enterprise conversation starts with the boundaries as they are today.

Release stage
Pre-1.0 preview. No release tag has been published; artifacts verify against the source commit, not a tag.
Compliance
Readiness and posture, not certified status. Evidence and report automation do not certify the organization or guarantee compliance.
Air-gapped
Air-gapped applies to the control plane, not Claude inference. Hosted Claude still reaches its provider API; only self-hostable models can run fully offline.
Support / SLA
SLA here means best-efforts response targets from a single maintainer. It is not penalty-backed and does not provide 24×7 coverage.
FIPS
FIPS is an optional build using CMVP module #5247, not an Olivares-level certification.

Enterprise evaluation questions

Does Enterprise remove anything from Community?

No. The AGPL build remains the complete governance platform. Enterprise adds separate scale-operation, regulatory-depth and risk-mitigation code.

Is the community cap a technical or security limit?

No. The 3-user cap is the only edition boundary and exists for fair monetization; the open core has no synthetic performance or size limits.

Do the compliance add-ons certify us?

No. They automate evidence gathering, readiness material and report structure. Certification or a compliance determination comes from the relevant accredited body or authority.

Can the whole deployment run offline?

The self-hosted control plane can run air-gapped. Hosted inference such as Claude still requires its provider API; only a self-hostable model can run fully offline.

Evaluate the additive value against your requirements

Write to enterprise@olivares.ai with the scale, regulatory or risk requirement you need to test. No checkout or portal is part of this evaluation path.