Open Source

Apache 2.0 forever for the authorization control point

IntentGate runs on an open core. The components required to operate it as a security control stay Apache 2.0 in perpetuity. The Pro tier adds enterprise operator experience, not capability gates.

The principle

The line will not move under you

The OSS community is watching where the line gets drawn. So are prospective customers and future contributors. When a company moves capabilities that small deployments depend on into a paid tier, it loses trust that took years to build.

Our commitment is encoded as a principle, not a frozen feature list. When a new feature ships, the test is straightforward: if a small deployment cannot operate safely without it, it is OSS. If it is an enterprise operator-experience layer on top, it can be Pro.

We will never relicense the Apache 2.0 components. Fork them. Inspect them. Run them in air-gapped environments. Use them as the security control inside your own product.

Required to operate safely? Open source. Enterprise administration on top? Commercial.

Open core. Enterprise capabilities.

Everything required to build and operate an IntentGate authorization control point is Apache 2.0. The commercial edition adds the identity, workflow, and administration capabilities large organizations expect.

Apache 2.0 · forever
The security control itself
intentgate-gateway

Authorization pipeline, capability tokens, multi-tenant scope, audit chain, webhooks, and SIEM forwarders.

intentgate-extractor

Intent classifier with stub and Anthropic Haiku backends.

Python and TypeScript SDKs

Agent-side capability issuance, presentation, and byte-compatible attenuation.

Helm packaging

Kubernetes deployment for gateway and extractor.

Basic operator console

Full token lifecycle: mint, use, inspect, and revoke.

Commercial · IntentGate B.V.
Enterprise operator experience
+
OIDC SSO, RBAC, and SCIM

Enterprise identity, role assignment, and automatic onboarding and off-boarding.

+
Step-up and approvals

TOTP step-up gating for destructive operations and high-risk tool calls.

+
JIT administration

Time-bounded elevation with reason, approval, and automatic expiry.

+
Notification workflows

Slack, Teams, and PagerDuty routing per tenant.

+
Audit and policy operations

Verification dashboards, export, approvals queues, and assisted Rego authoring.

The permanent rule

Anything required to operate IntentGate as an authorization control point stays Apache 2.0. The commercial tier adds enterprise operator experience, not capability gates.

Track every release

Each repository tags its own releases on GitHub. The release page is the authoritative record of what changed, when it changed, and the commit SHA behind the build.

Run the control point in your environment today

Clone the gateway, start it locally, wire it in front of an agent, and inspect the authorization decisions it produces.