Licensing
Licensing that respects your data
AthenaDB's licensing is built on a simple promise: it protects premium capabilities, never your data. Here's how activation, device binding, offline operation, and trials work.
Licensing never holds your data hostage.
Enforcement is deliberately asymmetric. Anything that touches your own data — open, read, query, backup, restore, export — always fails open. Only premium capabilities (cluster, Trust Fabric, sync, advanced packs, embedding quota) fail closed when unlicensed. Export of your own data is granted in every edition, always.
Activation & operation
Activate
AthenaDB sends a signed activation request over a TLS 1.3+ channel (mTLS for server/enterprise) and receives a signed activation token + entitlement bundle, verified against a pinned trust anchor and stored as an encrypted, signed local cache.
Bind privately
Device binding uses salted one-way hashes of stable identifiers — the licensing server never receives raw hardware serials by default. Desktop/Lite use a fuzzy fingerprint with drift tolerance; servers bind to a signed instance identity; mobile is account-login based.
Run offline
Instances keep working from the signed local cache through a generous offline-grace window, so a licensing-server outage is invisible for normal use. Offline and air-gapped activation files, and a customer-hosted enterprise license server, are supported for disconnected environments.
Prove possession
A device activation can carry a signed ECDSA P-256 proof-of-possession, so a leaked license key alone cannot be activated elsewhere.
License types
Trial
A 180-day evaluation license with anti-reset protection. Converts to a paid license with no reinstall or data migration.
Subscription
A time-limited paid license that renews.
Perpetual
A version- or release-bound license with an optional support term.
Enterprise
An organization-wide license spanning server, cluster, sync, Trust Fabric, and identity integration.
License states
Privacy by design
Never sent to the licensing service
The licensing service never sees your documents, memory, queries, RAG prompts, embeddings, or domain records (case numbers, patient data, reports).
Only what licensing requires
It handles only what licensing requires: a license-key hash / activation token, account and product/edition, hashed device and instance identity, activation counts, pack identifiers, and trial state.

