Skip to content

Open first · Enterprise adds

Enterprise adds depth. Open stays complete.

The open (AGPL) build is the complete governance platform and nothing is taken away from it. What is paid is a ladder: Business, its four add-ons, and Enterprise. This page says which of them actually sells each capability, so you do not buy the wrong one.

Ground truth for enterprise AI.

The open-core line

Three promises that define the edition boundary

These are structural product commitments, not contractual service promises.

  1. 01

    What is open never moves to a paid tier.

    Every capability in the AGPL build stays in the AGPL build. Business, its add-ons and Enterprise are additive new code, never a feature removed from the open product.

  2. 02

    The AGPL core has no artificial performance or size limits.

    There are no throttles, synthetic delays or hidden feature flags in the open binary, and no user cap: users are unlimited on every edition.

  3. 03

    The criterion is published.

    Security-core and the complete observe → map → govern → audit loop are free. Commercial means scale-operation plus a legal exception to AGPL obligations.

Additive capability

What each paid edition adds, by theme

Business, its four add-ons and Enterprise extend the complete open platform where larger or regulated organizations need more operational depth. Each paragraph names the edition that sells the capability; the add-ons require an active Business subscription and are bought self-serve. The open governance loop is never replaced.

Open foundation: 30 wired modules · 26 compliance framework catalogs · 158 public integrations.

Identity & access

The open build provides complete single-IdP OIDC and SAML, WebAuthn/FIDO2, PIV/CAC and non-human identity lifecycle. The Identity & Scale add-on for Business adds per-tenant multi-IdP federation, group mapping, require-SSO enforcement, SAML SP metadata, read-only CyberArk Conjur and more than one active identity provider. Above five active providers, or above two production deployments, the scope moves to Enterprise. These are scale and policy-operating capabilities, not a replacement for open identity security.

Content & data security

Open includes deterministic PII, injection and jailbreak guardrails plus a deny-closed DLP egress gate. The AI Runtime Security add-on for Business adds deep content inspection across messages, retrieval, MCP renders and Claude Code hook input; computer-use governance and further runtime controls join the same add-on, at the same price, as each passes its gate. Enhanced right-to-erasure coordination belongs to the Regulated Operations add-on instead. The extra depth targets injection, exfiltration and unsafe-action patterns across more governed channels.

Threat & incident

The open build includes guardian findings, tier floors and the estate kill switch. Business, in its Starter preset, adds the threat-intel catalog on a declared cadence; the Regulated Operations add-on adds bidirectional incident close-loop workflows with PagerDuty and Opsgenie. Operators keep configuring the open enforcement points: the paid pieces add catalogue and workflow depth, not autonomy.

Compliance & regulatory

Open maps 26 framework catalogs and exports sealed OSCAL evidence. The Compliance Packs add-on for Business adds DORA register structuring, ISO 42001 AIMS readiness material, SSP and POA&M workflows, and sector-specific overlays. It automates evidence gathering and report structuring: it drafts, and your counsel or auditor reviews. It does not certify the organization or guarantee compliance.

Operations & resilience

Open includes S3 Object Lock WORM archival, a signed ledger and backup/restore with chain verification. The Regulated Operations add-on for Business adds named regulatory retention floors, long-horizon legal hold and examiner evidence bundles; the Identity & Scale add-on adds durable at-least-once event delivery over your own NATS. LTS, air-gapped and OTA-mirror operation, multi-entity setups and more than two production deployments are Enterprise. It adds regulated operating depth without removing the open resilience baseline.

Integration

Open provides static upstream credentials, a CAEP receiver, Terraform, SDKs and typed webhooks. Business, in its Starter preset, adds deny-closed tool-definition pinning; the AI Runtime Security add-on adds the MCP elicitation mediator; custom, scoped credential exchange is agreed under Enterprise. These capabilities harden short-lived credentials and runtime trust between systems.

Enterprise only

Enterprise is not a hidden pile of extra modules: it is contracted work, sold by annual order form over email and never through self-serve checkout. It covers custom, scoped credential exchange; scoped dedicated engineering such as policy authorship, tuning and bespoke connectors; LTS, air-gap and OTA-mirror operation; multi-entity structures; more than two production deployments; more than five active identity providers; OEM, MSP and redistribution rights; capped indemnity; DPA and procurement paperwork; and best-effort first-response objectives. Everything else on this page is sold self-serve as Business or one of its four add-ons.

Curated comparison

Six flagship differences

One representative capability per theme, each attributed to the edition that actually sells it. The add-ons require an active Business subscription; Enterprise is an annual order form by email. The downloadable matrix is the authoritative, row-by-row due-diligence source.

Capability Community (AGPL) Paid edition that sells it
Identity & access Complete single-IdP OIDC and SAML. Identity & Scale add-on (requires Business): more than one active IdP per tenant, routing by tenant or domain, and require-SSO enforcement.
Content & data Core text DLP with a deny-closed posture when content is not scanned. AI Runtime Security add-on (requires Business): content firewall for injection, exfiltration and unsafe actions across message, retrieval and MCP-render channels.
Threat & incident Kill switch, guardian findings and tier-floor enforcement. Business, Starter preset: threat-intel catalog on a declared cadence. Regulated Operations add-on: bidirectional incident close-loop.
Compliance 26 framework catalogs with OSCAL evidence export. Compliance Packs add-on (requires Business): DORA register, ISO 42001 AIMS readiness, SSP and POA&M workflows, and sector overlays.
Operations & resilience S3 Object Lock WORM, signed ledger and verified backup/restore. Regulated Operations add-on: named regulatory floors, legal hold and examiner evidence bundles. Identity & Scale add-on: durable at-least-once delivery.
Integration Static credentials and a CAEP receiver. Business, Starter preset: tool-definition pinning. AI Runtime Security add-on: MCP elicitation mediation. Enterprise: custom scoped credential exchange.

Additive, no rug-pull: an open capability stays open; the paid editions add separate code for scale and risk depth.

The edition boundary is the commercial licence and the jobs the add-ons do — never a head count. Users are unlimited on every edition.

License validation is attestation-only. The open binary never reads a license to enable, disable or block a capability.

Download the full capability matrix

Open-first by design

What you do not need Enterprise for

The AGPL build already contains the complete observe → map → govern → audit loop and its security core.

  • Full inventory, permitted-versus-observed access map, sessions, orchestration graph and health telemetry.
  • Cedar authorization with RBAC, deny overlays, scoped grants and four deny-closed enforcement points.
  • Two-person approvals, dual-control break-glass and the estate kill switch.
  • Governed Claude Code launch, attach, govern and stop workflows with managed-settings delivery.
  • Single-IdP OIDC and SAML, WebAuthn/FIDO2, PIV/CAC and AAL step-up.
  • Non-human identity lifecycle and agent-identity federation.
  • PII, prompt-injection and jailbreak guardrails, DLP egress and BYOK/CMEK.
  • Hash-chained, Ed25519-signed audit ledger with sealed append-only evidence.
  • 26 compliance framework catalogs and SIEM export and push formats.
  • FinOps budgets that deny or throttle spend.
  • Evaluations with a blocking CI gate and red-team sandboxes.
  • A single static artifact, SQLite or Postgres, Docker/Kubernetes/Helm, Terraform and SDKs across 158 public integrations.
  • S3 Object Lock WORM archival and backup/restore with chain verification.

Procurement facts

Read this before evaluating

The useful enterprise conversation starts with the boundaries as they are today.

Release stage
Pre-1.0 preview. No release tag has been published; artifacts verify against the source commit, not a tag.
Compliance
Readiness and posture, not certified status. Evidence and report automation do not certify the organization or guarantee compliance.
Air-gapped
Air-gapped applies to the control plane, not Claude inference. Hosted Claude still reaches its provider API; only self-hostable models can run fully offline.
Support
No edition carries a contractual SLA. Enterprise support is a best-effort first-response objective from a single maintainer: no penalty, no credit, no remedy and no 24×7 coverage. Community is community support and Business is business-hours email, both best-effort.
FIPS
FIPS is an optional build using CMVP module #5247, not an Olivares-level certification.

Enterprise evaluation questions

Does Enterprise remove anything from Community?

No. The AGPL build remains the complete governance platform. Enterprise adds separate scale-operation, regulatory-depth and risk-mitigation code.

Does the open edition limit how many people can use it?

No. Users are unlimited on every edition, Community included. The boundary is the commercial licence and the add-ons, not a head count, and the open core has no synthetic performance or size limits.

Do the compliance add-ons certify us?

No. They automate evidence gathering, readiness material and report structure. Certification or a compliance determination comes from the relevant accredited body or authority.

Can the whole deployment run offline?

The self-hosted control plane can run air-gapped. Hosted inference such as Claude still requires its provider API; only a self-hostable model can run fully offline.

Evaluate the additive value against your requirements

Write to enterprise@olivares.ai with the scale, regulatory or risk requirement you need to test. No checkout or portal is part of this evaluation path.