The engine is open because the argument depends on it
You are being asked to let software tell you what the law requires. The only defensible answer to “why should we believe it?” is that you can read how it was produced — so the pipeline, the schemas, the checks and the corpus are public.
Two commitments
These are the load-bearing promises of the open-core model. They are written down so that they can be held against us later.
Public-law corpus data is always open
Every regime's consolidated texts, obligation atoms, cross-reference graph and releases are CC BY 4.0, and the licence identifiers are recorded in each release's own metadata. The commercial line is drawn at operations, not at the data.
Anything required to self-host stays open source
The hosted product is a control plane around the open data plane, never a fork of it. If you need something to run OpenRegs yourself, it is in the open repository — not held back to make hosting the only viable option.
The features an open-core project usually keeps
The second commitment is easy to write and easy to quietly break, so here is the list it would be broken by. Every capability below is the kind a compliance vendor holds back to make hosting the only path — and every one of them is in the Apache-2.0 engine, running on your own machine, with no account and nothing phoning home.
Being told a change happened
openregs feedis the whole outbound side: JSON and RSS feeds per filter, HMAC-signed webhook subscriptions, at-least-once delivery with a retry schedule and a delivery log. Run it yourself and nothing about your subscriptions passes through us. ReferenceSeeing what actually changed
openregs diffcompares two releases and classifies every change substantive or editorial. The manifest is built into the release, so a consumer holding two releases can reproduce the same answer without asking anything. ReferenceMapping obligations to your controls
The mapping format is a versioned schema in the spec, and
openregs coverageandopenregs impactare the two commands that read it. The auditor-facing report is generated locally, as one self-contained HTML file. ReferenceGetting the change into your repository
The release-bump integrations for GitHub Actions and GitLab CI are in the engine repository, and the test suite runs them against two complete consuming repositories. There is no proprietary connector in the path. Reference
Checking that a release is what it says it is
openregs pullandopenregs verifydo the signature, trust, digest, provenance and transparency-log checks offline. Verification held back would make a hosted service the only place the answers could be trusted, which is precisely the failure the commitment names. Reference
What is left for the hosted product is the operating of it: an account, a key, a bill, a console, somebody on call. That is the line, and the test for which side a feature falls on is written down rather than decided case by case.
How it is licensed
Code and corpus are licensed apart, because they are different kinds of thing and a consumer usually wants one of them.
| What | Scope | Licence |
|---|---|---|
| Code | The pipeline, CLI, servers and schemas — everything outside the regime directories. | Apache-2.0 |
| Corpus data | Each regime's canonical texts, obligation atoms, graph and releases. | CC BY 4.0 |
Why CC BY 4.0 and not ODbL. CC BY covers copyright and the sui generis database right in one instrument and asks only for attribution, so a firm can embed the corpus in a proprietary compliance system — which ODbL's share-alike on derived databases would prevent.
Neither licence relicenses the law. The project's NOTICE states the terms each regulator publication service publishes under, and every canonical text names the source document, digest and retrieval instant behind it.
Who is answerable
Turning law into data other people rely on means somebody has to be answerable for each answer. Governance is deliberately short, and most of it is machine-checked.
Teams, not people
Ownership is assigned to maintainer teams in a single roster file, so one person leaving never leaves a path unowned. Review routing is generated from that roster, never written by hand.
The machine proposes, humans merge
The identity that opens obligation-atom proposals can never approve one. Every atom reaches the corpus through a pull request a human maintainer reviewed.
Escalation is written down
Review service levels and what happens when a team stops answering are in GOVERNANCE.md, not in anyone's head.
Contributing an obligation atom, from the text it is read out of to the release that ships it, is documented command by command in CONTRIBUTING.md.
Licensing questions
The answers a legal team asks for before the engineering team is allowed to depend on something.