Licensing

Licensing that respects your data

AthenaDB's licensing is built on a simple promise: it protects premium capabilities, never your data. Here's how activation, device binding, offline operation, and trials work.

Core promise

Licensing never holds your data hostage.

Enforcement is deliberately asymmetric. Anything that touches your own data — open, read, query, backup, restore, export — always fails open. Only premium capabilities (cluster, Trust Fabric, sync, advanced packs, embedding quota) fail closed when unlicensed. Export of your own data is granted in every edition, always.

Activation & operation

Activate

AthenaDB sends a signed activation request over a TLS 1.3+ channel (mTLS for server/enterprise) and receives a signed activation token + entitlement bundle, verified against a pinned trust anchor and stored as an encrypted, signed local cache.

Bind privately

Device binding uses salted one-way hashes of stable identifiers — the licensing server never receives raw hardware serials by default. Desktop/Lite use a fuzzy fingerprint with drift tolerance; servers bind to a signed instance identity; mobile is account-login based.

Run offline

Instances keep working from the signed local cache through a generous offline-grace window, so a licensing-server outage is invisible for normal use. Offline and air-gapped activation files, and a customer-hosted enterprise license server, are supported for disconnected environments.

Prove possession

A device activation can carry a signed ECDSA P-256 proof-of-possession, so a leaked license key alone cannot be activated elsewhere.

License types

Trial

A 180-day evaluation license with anti-reset protection. Converts to a paid license with no reinstall or data migration.

Subscription

A time-limited paid license that renews.

Perpetual

A version- or release-bound license with an optional support term.

Enterprise

An organization-wide license spanning server, cluster, sync, Trust Fabric, and identity integration.

License states

Active
Trial Active
Offline Grace
Grace Period
Expired
Suspended
Revoked
Compliance Hold

Privacy by design

Never sent to the licensing service

The licensing service never sees your documents, memory, queries, RAG prompts, embeddings, or domain records (case numbers, patient data, reports).

Only what licensing requires

It handles only what licensing requires: a license-key hash / activation token, account and product/edition, hashed device and instance identity, activation counts, pack identifiers, and trial state.