# Commercial Policy ota is open source under Apache 2.0 and governed as a maintainer-led open-core project. The commercial model stays separate from the core codebase and should not blur the public contract. ## What is open - the CLI - the repo and workspace contracts - the JSON output and docs - the contract-first readiness model ## What is not accepted - external code contributions ## What is reserved - the `ota` name - the logo and branding - commercial packaging and enterprise offerings See [brand-policy.md](brand-policy.md) for the brand usage boundary. See [governance.md](governance.md) for the project governance model. ## Monetization boundary Enterprise value should stay outside the open-core contract surface when possible. The core stays small, deterministic, and broadly adoptable. Monetization belongs in separate services, private modules, hosting, support, or commercial packaging built around the open core.