Present in the current source
The current pre-1.0 source tree contains the KaryaFlow web application, API, worker, database schema and migrations, a Compose deployment, deterministic sample-data seeding, configuration examples, health checks and backup and restore scripts.
Not yet release-certified
As of 22 July 2026, the repository does not claim a provenance-cleared public release or signed and reproducible official image set. The legal provenance review, immutable image-signing evidence, complete reviewed third-party notices, verified public source location, verified private security-reporting channel and final contributor agreement remain release gates.
No decorative green ticks. A source artefact is not promoted merely because a document says it should exist. Exact-tag tests, signatures, digests and audit evidence must pass first.
What a Community release must include
- Public source and corresponding source for official images.
- Signed, versioned container images and a Docker Compose appliance.
- A guided installation path, configuration validation and diagnostics.
- Backup, restore and upgrade commands with recovery evidence.
- A sample-business and learning sandbox.
- Built-in documentation and deterministic troubleshooting.
- Optional bring-your-own AI credentials or a supported local model, with usable deterministic fallbacks.
- Full data export, a documented exit path, security advisories and a supported-version policy.
What free does—and does not—mean
Community includes the artefacts and documentation needed to operate the applicable release. It does not include individual installation, migration, workflow design, provider onboarding, custom development, response-time commitments or an SLA.
That support boundary never excuses knowingly leaving a confirmed security defect unfixed in a supported release. No release or private reporting channel is supported yet; the current boundary appears on the Security page.
KaryaFlow Community and Evlyr managed help
The intended model is one software core with two operating models. KaryaFlow Community is the self-hostable product. Evlyr is the optional paid layer for managed hosting, migration, implementation, certified connectors, managed AI, contractual support and SLA.
Community rights are not conditional on buying Evlyr. Evlyr must not become a divergent fork of the KaryaFlow core; it should consume KaryaFlow through release contracts, stable APIs and Community-compatible tenant portability. See the licensing boundary.
Evaluation model
The future hosted evaluation surface should be a single shared path at try.karyaflow.com, visibly hosted by Evlyr. Synthetic Playground evaluation can launch before real customer data. A real-data Activation Sprint must wait until tenant-selective export, import preflight, clean-host import-bundle generation, restore verification and retention controls are proven, because portability is not a decorative virtue; it is the thing that keeps a trial from becoming a velvet trap.