Open source, AGPL-3.0
Restow is one repository, one container image and one release.
Everything outside the ee/ directory is AGPL-3.0 with
the Restow Module Exception, an additional permission that lets the
core be combined with modules regardless of their license. The
Business and Service Provider features live in ee/,
under the source-available Restow Enterprise License: the code is
visible, but using an edition feature in production needs a license
key.
Restow's core is licensed AGPL-3.0: freely usable, inspectable and modifiable software, including the Community edition, which is free of charge for one organization with no mailbox limit and no license key at all, and the AGPL-3.0 code already released cannot be withdrawn, whatever happens to this project later.
What's public today
The complete source code, including the ee/ directory,
is public on
GitHub,
where every release is published. Version 0.1.0, the first
public release,
is out now as a beta: test it before you rely on it, and keep an
independent backup alongside it while it is new.
See how Restow is built for
the full account of the development process this code goes
through.
Why AGPL-3.0, specifically
AGPL closes the loophole plain GPL leaves open for network software: a provider running a modified Restow as a service has to publish those modifications too, not just installations they physically hand someone a copy of. For a self-hosted backup and archive tool, aimed partly at service providers running it for clients, that matters more than it would for a desktop app.
The Restow Module Exception (LICENSE-EXCEPTION.md in the
repository) is an additional permission under section 7 of the AGPL:
the core may be combined with modules, and the result distributed,
regardless of the modules' license. The files in ee/
are such modules, and so is any other work that talks to the core
only through the extension interface defined in that file.
One repository, two licenses
There is no separate closed-source product. The code in
ee/ is under the Restow Enterprise License
(ee/LICENSE in the repository). You may read it, run
it, copy it unmodified and change it for development and testing.
Using an edition feature in production needs a valid license key for
that edition, and the license check may not be removed or
circumvented. Without a key the features stay locked: a locked menu
entry stays visible, greyed out, and leads to the license settings,
with no banners or pop-ups.
What the paid editions actually add (and don't)
Business and Service Provider unlock what lives in
ee/: legal holds, the SMTP journal receiver, archive
deletion runs (enforced retention), the audit log viewer (search,
details, chain verification), Microsoft (Entra ID) sign-in for end
users, the provider team (roles, tenant scopes), scheduled summary
reports, the cross-tenant provider API and the provider view of the
dashboard (tenant matrix, alerts). All of it is always present in
the image, and the license key decides at runtime which of it is
active. Not all of it is finished: on this site the audit log viewer
is still in development and Microsoft sign-in for end users is not
enabled yet, see the roadmap. The white-label
option for Service Providers is planned, not built.
Deliberately in the core, in every edition: the archive format (readable without a server), the database schema, the settings for archive retention and the recording of the audit log. Every read and every restore is written to the hash-chained audit log in every edition; only viewing, searching and verifying it is Business and Service Provider.
The license key is a fair-play mechanism, not DRM: it is verified
offline against a signed Ed25519 key, does not phone home, does not
expire your access to a version you already have, and never limits
restore. Restore is never limited by edition, in any version. See
pricing for exact terms. If development
ever stops, the project has committed to announce it at least twelve
months in advance and then publish ee/ under the
AGPL-3.0; installations keep running without a key.
Contributing
Contributions need two things: agreeing to the Contributor License
Agreement (an automated check on each pull request asks for it once)
and a Developer Certificate of Origin sign-off on every commit
(git commit -s). The details are in
CONTRIBUTING.md
in the repository.
Getting your data back without Restow at all
Open source extends past the application code to the data itself: the chunk-store format is open and documented, and a small standalone tool restores from it even with no Restow server running, so open source here also means you can get your own backup back even in the worst case, not just read the code. See exit costs and vendor lock-in for why that specific guarantee is worth having in writing.
Frequently asked
Is Restow really open source, or open core with a locked-down free tier?
Both parts are in one public repository, and the honest label is open core. The core is AGPL-3.0 with the Restow Module Exception, and the free Community edition already includes full Microsoft 365 and IMAP backup, server and client backup, mail import and export, non-destructive restore and weekly restore checks, with no mailbox limit and no license key required. The Business and Service Provider features (for example legal holds, the journal receiver, enforced retention, the audit log viewer and the cross-tenant provider API) live in ee/ under the source-available Restow Enterprise License, not under the AGPL: the code is visible, but using them in production needs a license key. It is the same codebase and the same image, not a smaller version of the same feature.
Where's the code?
On GitHub, github.com/restow-backup/restow: everything outside ee/ under the AGPL-3.0 with the Restow Module Exception, and ee/ under the Restow Enterprise License. Every release is published there, starting with 0.1.0, the first public release.
Is the license key a form of DRM?
No. It doesn't call home, doesn't expire your access, and never limits restore. Restore is never limited by edition or license in any version of Restow. It's a fair-play mechanism that unlocks Business/Service Provider features once, offline, against a signed Ed25519 key; nothing about it can remotely disable the software.
Can I read, run and change the code in ee/?
You can read it, run it and copy it unmodified, and you can change it for development and testing. Without a license key the edition features stay locked. Using an edition feature in production, including a modified one, needs a valid license key for that edition, and the license check may not be removed or circumvented.
What does a contribution need?
Agreement to the Contributor License Agreement (an automated check on each pull request asks for it) and a Developer Certificate of Origin sign-off on every commit (git commit -s). CONTRIBUTING.md in the repository has the details.