Legal & Licensing
WAF++ uses a dual-license model: Apache License 2.0 for code and Creative Commons Attribution 4.0 (CC BY 4.0) for documentation. This model is CNCF-compatible and foundation-ready.
Two licences, one framework
The dual-license model keeps WAF++ open, commercially usable, and CNCF-ready — without ambiguity about what you can do with it.
Apache License 2.0
All WAF++ source code, WAFPass, plugins, and tooling are released under the Apache License 2.0 — one of the most permissive and widely adopted open-source licences.
Commercial use
Use WAFPass and all framework code in commercial products, internal tools, and SaaS offerings without any royalties or restrictions.
Modification & redistribution
Fork, modify, and redistribute the code freely. You may distribute modified versions under your own terms as long as the original licence is retained.
Explicit patent grant
Contributors grant an explicit, royalty-free patent licence covering any patents that apply to their contributions — protecting downstream users.
No copyleft obligations
No obligation to open-source your own code when using WAF++ components. Proprietary integrations are fully permitted.
Creative Commons BY 4.0
All WAF++ documentation, pillar guides, slides, reference material, and written content are published under CC BY 4.0.
What you can do
Share — copy and redistribute the material in any medium or format
Adapt — remix, transform, and build upon the material
Commercial use — use the documentation for any purpose, including commercially
One condition
Attribution required — you must give appropriate credit to WAF++, provide a link to the licence, and indicate if changes were made.
Disclaimer & contributions
Important legal context for using and contributing to WAF++.
Disclaimer
WAF++ is provided “as is” without any express or implied warranties. Use of the framework is at your own risk.
The framework does not replace legal advice, formal certification, or compliance assessments. It provides guidance, evaluation models, and traceable criteria.
Contribution & compliance
By submitting a pull request, you agree that your contribution will be published under the applicable project licence:
Built in the open.
WAF++ is fully open source, dual-licensed, and CNCF-compatible. Every line of code, every decision, and every control is public and traceable.