Skip to content
KaryaFlow OS

Evidence-bound release status

What is available, and what is not yet certified

The Community release contract is source plus a deployable appliance. This page separates the present source state from that complete release contract.

Last updated 22 July 2026

Present in the current source

The current pre-1.0 source tree contains the KaryaFlow web application, API, worker, database schema and migrations, a Compose deployment, deterministic sample-data seeding, configuration examples, health checks and backup and restore scripts.

AGPL-declared source treeAGPL-3.0-only is declared in the root and runtime workspaces; provenance clearance is still open.
Self-build Compose applianceApplication and supporting services can be built from this source; this is not an official certified image set.

Not yet release-certified

As of 22 July 2026, the repository does not claim a provenance-cleared public release or signed and reproducible official image set. The legal provenance review, immutable image-signing evidence, complete reviewed third-party notices, verified public source location, verified private security-reporting channel and final contributor agreement remain release gates.

No decorative green ticks. A source artefact is not promoted merely because a document says it should exist. Exact-tag tests, signatures, digests and audit evidence must pass first.

What a Community release must include

  • Public source and corresponding source for official images.
  • Signed, versioned container images and a Docker Compose appliance.
  • A guided installation path, configuration validation and diagnostics.
  • Backup, restore and upgrade commands with recovery evidence.
  • A sample-business and learning sandbox.
  • Built-in documentation and deterministic troubleshooting.
  • Optional bring-your-own AI credentials or a supported local model, with usable deterministic fallbacks.
  • Full data export, a documented exit path, security advisories and a supported-version policy.

What free does—and does not—mean

Community includes the artefacts and documentation needed to operate the applicable release. It does not include individual installation, migration, workflow design, provider onboarding, custom development, response-time commitments or an SLA.

That support boundary never excuses knowingly leaving a confirmed security defect unfixed in a supported release. No release or private reporting channel is supported yet; the current boundary appears on the Security page.

KaryaFlow Community and Evlyr managed help

The intended model is one software core with two operating models. KaryaFlow Community is the self-hostable product. Evlyr is the optional paid layer for managed hosting, migration, implementation, certified connectors, managed AI, contractual support and SLA.

Community rights are not conditional on buying Evlyr. Evlyr must not become a divergent fork of the KaryaFlow core; it should consume KaryaFlow through release contracts, stable APIs and Community-compatible tenant portability. See the licensing boundary.

Evaluation model

The future hosted evaluation surface should be a single shared path at try.karyaflow.com, visibly hosted by Evlyr. Synthetic Playground evaluation can launch before real customer data. A real-data Activation Sprint must wait until tenant-selective export, import preflight, clean-host import-bundle generation, restore verification and retention controls are proven, because portability is not a decorative virtue; it is the thing that keeps a trial from becoming a velvet trap.