Licensing & commitments

The promises, written down.

Sondar is commercial software and we don't publish the engine's source. That removed the structural answer to 'what happens if you disappear or triple the price,' so the replacement has to be contractual — and published, because an unpublished commitment convinces nobody.

01

Renewal price cap

Your renewal will not rise by more than 5% per year, or CPI, whichever is greater.

For as long as you remain a customer, on the same tier, at the same or greater node count. This is in the order form, not just on this page. It is cheap for us to give and it directly answers the fear that closed source creates — that once you are dependent, the number moves.

02

Source escrow, with named triggers

Source is released to you on insolvency, discontinuation, or acquisition without a maintained successor.

Held with a third-party escrow agent, verified annually. The triggers are named here rather than described as "customary" — an escrow arrangement whose conditions you cannot read is a word, not a protection. Escrow is included on Enterprise and available to Team on request.

03

Your data is never hostage

Cold-tier data already sits in your object storage in a format readable without Sondar.

Warm and cold segments are open columnar files in your own bucket. Your instrumentation is OpenTelemetry, so repointing it at another backend is a config change rather than a migration project. There is no proprietary archive to unlock, no rehydrate fee, and no exit fee. This is the strongest answer we have on lock-in and it survives closed source completely intact.

04

Breaking changes and upgrades

Stated version-support windows, deprecation notice before removal, and no forced upgrade to keep your license valid.

The exact windows are published in the docs against each release line. An air-gapped install that never contacts us keeps working — license keys verify offline, and expiry warns rather than stops.

05

How node counts are checked

Contractual audit rights, exercised in writing with notice. No phone-home, ever.

There is no activation server and no usage telemetry, which means we genuinely cannot see your deployment. The trade is that node compliance rests on the agreement rather than on a meter — and we would rather have that trade than contradict the air-gap claim.

Being precise about one word

Sondar is not open source, and we won't blur it.

The engine is proprietary. We don't publish its source, and we are not going to describe it as "source-available," "open-core," or any other phrasing that lets someone leave with the wrong impression. This audience punishes that imprecision harder than it punishes the license itself, and rightly.

What that costs you is real, so here is what we do instead: an independent US security firm reads the source and publishes what it found, a second firm tests the running system, every release ships an SBOM and a signed reproducible build, the escrow triggers above are named, and your data sits in your bucket in a format that does not need us.

Against SigNoz and Coroot under Apache 2.0, and OpenObserve under AGPL, we are the only closed engine in the self-hosted tier. We would rather state that plainly and let you weigh it than have you discover it in a comment thread.

The full end-user license agreement is in the docs. This page is the plain-language version of what it commits us to; where they disagree, the agreement governs and we have a bug on this page to fix.