Keep code licensing, project identity and authority boundaries distinct.
Licence
RuleOak v0.50.0 first-party open-source source is Apache-2.0 unless a file states otherwise. Repository LICENSE, NOTICE, AUTHORS, SPDX metadata and third-party notices remain authoritative.
Trademarks
Open-source licensing does not automatically license RuleOak names, logos or other marks. Follow the repository trademark notice.
Versioning and release truth
A public tag identifies a source release. Runtime/platform compatibility and external deployment claims remain evidence-scoped and may require separate qualification.
Contributions
Contributions should preserve the public authority/evidence model rather than introduce a private authorization fork into the open kernel. Security reports should use the private disclosure path.
No paid-tier weakening
The open trust foundation should not be intentionally weakened to manufacture a commercial tier. Commercial or organizational extensions must preserve the public authority boundary.