# ADR 0002 — Apache-2.0 **Status:** Accepted, 2026-09-02. Supersedes the MIT choice in the archived architecture (§8). ## Decision **Apache-2.0**, and the repository is public on GitHub (`karti-ai/openmail`). The Gitea mirror (`OSS/openmail`) stays as the fallback if the project ever needs to go private. ## Why not MIT Same freedoms, but Apache-2.0 adds three things that matter here: - **§3, express patent grant.** Email authentication is a standards thicket — DKIM, DKIM2, ARC, DMARC. MIT's patent grant is implicit at best, and that is what enterprise legal review flags. - **§6, trademark reservation.** "OpenMail" is a generic name with at least three unrelated projects already using it. Apache-2.0 protects the name while the code stays free. - **§5, contributor terms.** Inbound contributions are licensed on the same terms without a separate CLA. Inbound compatibility is clean: every dependency is Apache-2.0 or MIT. ## Why not AGPL AGPL + a commercial exception is the standard way to protect a future hosted offering — it is exactly what Stalwart does (`AGPL-3.0-only OR LicenseRef-SEL`). We reject it because it makes us unusable by the commercial agent builders who are the intended audience, and because being *the* permissive option is the entire competitive position. Stalwart's AGPL is the reason its competitors must run it in a sidecar; we do not want to be that for someone else. ## Consequences - "No GPL/AGPL/LGPL anywhere" remains policy, but the *reason* changed. Under MIT it was a compatibility fact; under Apache-2.0 it is a deliberate choice, since Apache-2.0 is one-way-incompatible with GPL-2-only. Enforced in CI by `cargo-deny`. - Every source file gets no licence header (the `LICENSE` + `NOTICE` pair is sufficient and headers rot); `NOTICE` must be shipped with any redistribution and lists third-party attribution. - Anyone may fork this closed. That is the intent, not a leak.