Code → Apache 2.0
All source code, tooling, and framework components — including WAFPass. Commercial use, modification, and redistribution are explicitly permitted. Includes patent grant.
WAF++ uses a dual-license model: Apache License 2.0 for code and Creative Commons Attribution 4.0 (CC BY 4.0) for documentation. This model is CNCF-compatible and foundation-ready.
The dual-license model keeps WAF++ open, commercially usable, and CNCF-ready — without ambiguity about what you can do with it.
All source code, tooling, and framework components — including WAFPass. Commercial use, modification, and redistribution are explicitly permitted. Includes patent grant.
All written content, guides, pillar documentation, slides, and reference material. Share and adapt freely — attribution to WAF++ required.
By submitting a pull request, you agree your contribution will be published under the respective project licence (Apache 2.0 for code, CC BY 4.0 for docs).
All WAF++ source code, WAFPass, plugins, and tooling are released under the Apache License 2.0 — one of the most permissive and widely adopted open-source licences.
Use WAFPass and all framework code in commercial products, internal tools, and SaaS offerings without any royalties or restrictions.
Fork, modify, and redistribute the code freely. You may distribute modified versions under your own terms as long as the original licence is retained.
Contributors grant an explicit, royalty-free patent licence covering any patents that apply to their contributions — protecting downstream users.
No obligation to open-source your own code when using WAF++ components. Proprietary integrations are fully permitted.
All WAF++ documentation, pillar guides, slides, reference material, and written content are published under CC BY 4.0.
Important legal context for using and contributing to WAF++.
WAF++ is provided “as is” without any express or implied warranties. Use of the framework is at your own risk.
The framework does not replace legal advice, formal certification, or compliance assessments. It provides guidance, evaluation models, and traceable criteria.
By submitting a pull request, you agree that your contribution will be published under the applicable project licence:
WAF++ is fully open source, dual-licensed, and CNCF-compatible. Every line of code, every decision, and every control is public and traceable.
WAF++ now includes an eighth pillar — AI-assisted architecture reviews, autonomous remediation, and policy-aware agents for secure cloud operations.