Commercial Features
This page is normative. LCEL § 1 defines a Commercial Feature as a capability that is both
- listed on this page, and
- identified as a Commercial Feature by the software itself, at the moment you ask for it.
A capability that fails either test is not a Commercial Feature, and the licence grants its use freely. There is no third way to designate one — not a pricing page, not a blog post, not a support email.
The list
| Feature | Machine name | Tier | Enforced today |
|---|---|---|---|
| Private mesh across the WAN | private-mesh | Personal | not yet — see below |
| Role-based access control | rbac | Team | no |
| Namespace creation | namespaces | Team | no |
| Backup to a Lucenia-operated bucket | hosted-backup | add-on | no |
That is the whole list. Four capabilities.
Nothing is enforced today. No Lucenia signing key has been issued, so no Entitlement can be verified and every capability above currently runs as if it were free. That is deliberate and it is visible in the source: the node logs a warning at every start saying the gate is not armed. We would rather ship an honest "not yet" than a gate that looks real and is not.
What is never a Commercial Feature
LCEL § 2.1(a) puts these beyond our reach permanently. They are not "free for now" — they cannot be moved onto the list above:
- How many nodes, peers, devices or users you run. Any number. No registration, no licence key, no counter. This is in the licence grant itself, not policy, and there is a test in the repository whose only job is to fail the build if the promise is removed.
- How many documents, indexes or queries you have. Your hardware is your limit.
- Running on a LAN, on one machine, or offline. Forever.
- Participating in the public ROC retrieval mesh. Searching it and contributing to it are both free. Every node that joins makes public retrieval better, so charging for it would be charging for the thing that creates the value.
- Backing up to a bucket you own.
gnarl repo addpointed at your own S3, R2, GCS or MinIO is free and always will be. Only a bucket we operate is a Commercial Feature, because that is the only part we pay for. - Self-hosting anything, including your own relay and your own bootstrap.
Four rules we cannot break
These are limits on Lucenia, written into the licence because a list of paid features is only trustworthy alongside the rules for how it may change.
Quantity in Core Use is never chargeable. § 2.1(a), above. A quantity inside a paid feature — how many role assignments RBAC may hold — is a term of that feature, not a cap on anything that was ever free.
Verification never phones home. § 2.1(b). An Entitlement is a signed file your node checks locally, with arithmetic. Gnarl does not contact Lucenia to start, to run, or to keep running. It works on an aircraft, in a facility with no internet, and on a mesh that has never seen either.
Expiry degrades; it does not destroy. § 2.1(c). When a subscription lapses, the node drops to the free tier and keeps running. Your data stays readable, your indexes stay intact, nothing is deleted, and no binary stops working. A lapsed card is never data loss.
No retroactive designation. § 2.1(d). A capability released as free cannot be moved onto this list in a version you already run. Designating a new Commercial Feature takes a new release, and you choose whether to install it.
How an Entitlement works
A short signed file, issued when you subscribe:
{
"account_id": "…",
"mesh_id": "…",
"tier": "personal",
"features": ["private-mesh"],
"not_before": 1760000000,
"not_after": 1763000000
}
Your node reads it from its data directory and checks the signature against a public key compiled into the binary. That is the entire check. No account lookup, no callback, no telemetry.
Renewal, not revocation. An Entitlement is valid for 35 days and reissued every 30. Cancelling simply stops the reissue, and the file expires on its own. There is no revocation list to distribute and nothing to check against — which is what lets verification stay offline. The five-day margin means an outage on our side never costs you a feature.
Circumventing the check
LCEL § 4.6 prohibits disabling, patching out, forging or otherwise bypassing Entitlement verification. It is the one modification that § 2 and § 7's internal-use permissions do not cover, and it is the only thing that Article prohibits — you may still modify Gnarl freely for any purpose that leaves verification intact.
We would rather say this plainly than rely on obscurity. The list above is short, the free tier is genuinely useful, and the rules limiting what we may ever charge for are binding on us before they are binding on you.
Questions about a specific deployment: gnarl@lucenia.io.