Skip to content

Compliance & open core

Reeflex ships as an open core: the engine, the adapters, and the base policy packs are Apache 2.0 and free forever. A separate commercial tier packages that evidence for specific regulatory frameworks — it never adds safety, and it never enters a public repository.

NIS2 Article 21(2) is the current driver, not a future one. It is already transposed into national law across the EU and essential/important entities are already being audited against it; a documented, timestamped record of risk-management measures — what a decision register produces — is exactly what those audits check for. The EU AI Act's Articles 12/14 (record-keeping, human oversight) matter for the same reasons, but their high-risk obligations only start applying on 2 December 2027, per the Digital Omnibus (Regulation (EU) 2026/1744) — building for them now is preparation ahead of a deadline, not a response to an audit happening today. Reeflex's evidence model (below) covers both, in that order.

  • Open core — the licensing boundary, component by component, and what it does and does not mean for contributors and adapter authors.
  • Regulatory framework mapping (NIS2 21(2) · DORA · EU AI Act Art.12/14 · GDPR) is part of the commercial tier and is not documented here; see Open core for the boundary and what the open tier already gives an auditor today — a deterministic, replayable decision record, not just a post-hoc log.