Frequently asked questions
How does licensing work?
You buy an annual Team or Enterprise subscription; we email you a signed license key you paste into your server (or set as an environment variable). Validation is fully offline — your server never phones home.
Does it work air-gapped / offline?
Yes. The server and its license validation are entirely offline. Nothing leaves your network.
Where does my package data live?
On your infrastructure — a single Docker image with a /data volume. You own it.
What's free vs paid?
Community (self-hosting, v3 protocol, SSO login, basic keys, one feed) is free. Team adds vulnerability quarantine, trusted publishing, and MCP — it secures one team's feed. Enterprise adds scoped keys and multiple feeds on top, for running an organisation's package platform.
How do I upgrade from Community?
Buy a Team or Enterprise license on the pricing page and paste the emailed key under Administration → License. Features unlock immediately — no reinstall.