About

Licensing

obserae is proprietary software published by Spartan Conseil Cybersécurité. It is available as a free Community edition and as licensed Business, Business+ and Enterprise editions. This page answers, in plain language, the questions people reasonably ask about a closed-source tool they’re about to run on their network. It does not replace the license — the binding terms are in EULA.txt (French) and EULA.en.txt (English courtesy translation), bundled with every release and Docker image.

obserae is currently in an advanced beta (pre-1.0) and running in production at early-adopter sites. Beta describes product maturity and API stability; it does not unlock licensed features. Business, Business+ and Enterprise are activated by a license file installed on the instance and validated locally. Community needs no file, and nothing is ever checked against our servers — see “Do I need a license key or internet access to run it?”.

Is obserae open source?

No. obserae ships as proprietary binaries and Docker images; the source code is not public. You are free to download it, run it, configure it and file issues — but not to read, modify or redistribute the source. A public GitHub repository for docs, releases and issues is not the same as an open-source license, and we’d rather say so up front than have you find it in the fine print.

That said, the source is available for security review on request: a qualified reviewer evaluating obserae for production (say, a security team that won’t run a closed box on its network) can ask for code access under NDA. Write to licensing@spartan-conseil.fr.

Is it free? For whom?

Yes, for two groups (EULA art. 2):

  • Personal use — a natural person, on their own behalf, for non-commercial purposes.
  • Eligible small business — a group of ≤ 20 people and ≤ €2,000,000 annual revenue. Both criteria are cumulative.

Eligibility is self-assessed: the Community edition asks for no license key, no sign-up and no online activation.

Why are there limits, if it’s free?

obserae is both a passion and a business, and the bills are real. The aim is to be generous — free for individuals and small businesses, and with one-off audits allowed — without leaving the door open to abuse. Software usually ends up tightening its license because of abuse at scale, so obserae keeps a few structural limits rather than an unverifiable “fair use” clause.

A structural limit is one a homelabber or a five-person shop barely notices (a single administrator account is plenty for them) but that an 80-person company trying to deploy free at scale feels immediately. It keeps the line clear without anyone having to play policeman — and without punishing the people the free tier is for.

I run a bigger company / an MSP / a paid service on it?

Then you need a commercial license (EULA art. 3) — for any organisation above the small-business threshold, for offering obserae as a managed service (MSSP / SOC-as-a-service), or for paid services (audit, consulting, integration, training) delivered to a client above the threshold. One narrow exception (art. 4): an independent consultant may run a one-off audit of ≤ 30 days on a larger client’s infrastructure, provided the software is removed and the data purged at the end and the report states that permanent use requires a commercial license.

Commercial contact: licensing@spartan-conseil.fr.

Which features are included in each edition?

Community includes the core network-observation and detection workflow: cartography, Flow Matrix, sessions, NFQL investigations, dashboards, alerts, the Community and custom rule sets, and the following outputs: webhook, Discord, Telegram, email (SMTP), and Gotify. Only the built-in local admin account can authenticate in Community.

The Business, Business+, and Enterprise licenses include the same professional feature set:

  • Users & access management — additional user accounts and groups.
  • LDAP and OIDC / SSO — company-directory authentication and single sign-on.
  • Audit log — the tamper-evident who-did-what-when journal.
  • Reports — generated and scheduled operations/compliance documents.
  • Advanced rule sets — the shipped Enterprise and Anomaly rule sets.
  • Professional alert destinations — every output type, including the commercial/SOC integrations that Community does not include.

The three licenses differ by organisation size, not by feature availability: Business is for fewer than 100 employees, Business+ for 101–500 employees, and Enterprise for more than 500 employees. The feature boundary is already active during the beta.

Professional features remain included throughout the 30-day grace period after license expiry. After grace, they become unavailable until a valid license is installed again. Stored professional configuration and data are never deleted: users, groups, identity providers, audit history, reports, schedules, rule sets and outputs return unchanged after renewal.

The principle is simple: organisations that need the professional feature set need a commercial right of use. Community keeps everything an individual or a small team needs; licensed editions are where obserae plugs into the commercial security ecosystem.

Can the terms change under me later?

Not for a version you already have. The license is versioned per release: the terms that shipped with your version are yours to keep, for that version, for good (EULA art. 2.3). If the terms ever change, the change applies only to future versions — downloading one release does not put you at the mercy of whatever a later one decides. Nobody is taken hostage.

Does obserae phone home or send telemetry?

No. The EULA commits to it contractually (art. 7): no usage telemetry, no outbound contact with Spartan Conseil’s or any third party’s servers, and no online license verification. obserae is built to run fully air-gapped.

The only outbound network traffic obserae makes is traffic you turn on:

  • IP-enrichment refreshes — downloading public IP-range lists from AWS, Azure, Google and FireHOL. These are downloads of public data; nothing about you is uploaded. Turn them off with enrichment.enabled: false.
  • Alert delivery — webhooks / Gotify to the destinations you configure, never to a vendor endpoint.

What does the publisher see about my data?

Nothing. Your flows, cartography, detection rules, sessions and reports are your sole property; Spartan Conseil has no access to them and claims no rights over them (EULA art. 6.3).

Do I need a license key or internet access to run it?

Never internet access: no online activation, no online check, no external dependency for ingestion, queries or the GUI. obserae runs entirely offline.

As for a key — the Community edition needs none at all. The commercial editions come with a license file installed on the instance and renewed each year with the subscription; it is validated locally, so an air-gapped deployment renews by dropping in a new file and nothing is ever checked against our servers.

The signed file identifies one commercial edition: Business for fewer than 100 employees, Business+ for 101–500 employees, or Enterprise for more than 500 employees. Install or renew it from Settings → License. The page shows the verified customer and validity details; the consolidated YAML backup also carries the file so a restore reimports it automatically. Professional features remain available for a 30-day grace period after expiry. They are then disabled until renewal, but all users, settings, reports, rule sets and output destinations remain stored and return unchanged when a valid license is installed.

That file is the one thing a commercial edition does need, and it is worth stating plainly. What obserae does not have, and will not have, is an online mechanism: no account, no activation server, no remote check, no kill-switch. A license here is a file you hold, sitting next to your configuration.

For an initial unattended deployment, set license.path in obserae.yaml to a mounted file. The daemon checks its signature against every public root compiled into the binary and imports it into persistent license state; a key placed beside the license is never trusted.

What happens if the project stops, or Spartan Conseil disappears?

Your installation keeps working. There is no remote kill-switch and no license server to fail, so an installed copy keeps running with no internet and no contact with anyone. The license text and binaries are bundled locally, and your data stays yours.

Beyond that, the EULA commits in writing (art. 8.3): should Spartan Conseil permanently cease its activity, or should obserae be permanently discontinued, the source code of the complete Enterprise edition — every feature included — will be released under an open source license allowing users to keep using, maintaining and evolving it, and the already-published builds stay available for download. The proprietary license is there to fund a coherent product, not to strand the people who chose it.

Can I modify, redistribute or reverse-engineer it?

No (EULA art. 5) — beyond the non-waivable interoperability rights French law grants under art. L122-6-1 of the Intellectual Property Code. Spartan Conseil is the sole authorised distributor, through obserae’s official public distribution endpoints.

Can I contribute code?

No — obserae does not accept code contributions, and that is deliberate: a single owner keeps the intellectual property clean and the project’s direction coherent. Issues are very welcome, though — bug reports, reproduction cases and feature suggestions genuinely help. Send them to support@spartan-conseil.fr.

Is there support or an SLA?

A license grants software usage rights only. No license includes support, an SLA, priority fixes, consulting, custom development, or any other service.

This applies equally to Community, Business, Business+ and Enterprise. Updates are published at the publisher’s discretion (EULA art. 8). Any service, if offered, requires a separate written services agreement and is not part of the license or its feature entitlement.

Support contact: support@spartan-conseil.fr.

Anything it must not be used for?

Yes — obserae is not designed or certified for life-critical or high-criticality systems (medical devices, air/rail/maritime traffic control, nuclear or Seveso-classified sites, weapons/defence systems, or critical infrastructure without prior agreement). See EULA art. 10.

Where are the binding terms?

In the repository and in every release / Docker image:

  • EULA.txt — French, the legally binding version.
  • EULA.en.txt — English, courtesy translation (the French version prevails in case of conflict).

Online copy: https://obserae.com/eula/EULA.txt. Commercial licensing: licensing@spartan-conseil.fr.

Download the licence

The full End-User Licence Agreement, as bundled with every release:

French — legally binding · .txt English — courtesy translation · .txt