Skip to content

Source transparency

Open where it builds trust. Managed where it adds value.

ReefOffice is built from open-source infrastructure and open-source applications. What you pay for is your own dedicated EU server, plus the managed packaging, automations, onboarding, monitoring and support around that stack.

Open infrastructure

NixOS service wiring, hardening patterns, deployment modules, and component source links are the parts that should become public because they build trust and make the stack auditable.

Portable customer data

Your data lives in standard open-source apps and standard formats: files in Nextcloud, metadata in Paperless, Bitwarden-compatible password exports, business records from Dolibarr, and so on. Export from any app yourself, or ask us for a complete copy.

The managed service

What you pay for is everything around the open stack: onboarding, monitoring, tested upgrades, daily encrypted backups, managed automations, workflow packs and ongoing support.

Components

Open-source stack and source links

These are the main upstream projects used by ReefOffice workspaces. Components are deployed from pinned packages or container images, and commercial/enterprise-only features are avoided unless there is an explicit license decision. We keep upstream license text and branding intact, so this list also serves as public attribution.

Core workspace

ComponentRoleLicense postureSource
NixOSDeclarative operating system and reproducible server configurationMIT-style / mixed open sourceUpstream source
NextcloudFiles, calendar, contacts, sharing and office workspaceAGPL-3.0Upstream source
Collabora CODEBrowser document editing with NextcloudMPL-2.0Upstream source
Paperless-ngxDocument intake, OCR and archiveGPL-3.0Upstream source
BentoPDFClient-side PDF tools: split, merge, convert, OCR and sign without uploading filesAGPL-3.0 (includes AGPL WASM libs below)Upstream source
PyMuPDF WASMPDF rendering and text extraction WASM (bundled with BentoPDF)AGPL-3.0-onlyUpstream source
Ghostscript WASMPostScript/PDF interpreter WASM (bundled with BentoPDF)AGPL-3.0-onlyUpstream source
CoherentPDFPDF generation WASM library (bundled with BentoPDF)AGPL-3.0-or-laterUpstream source
Vaultwarden / OIDCWardenBitwarden-compatible password vault; we run OIDCWarden for SSOAGPL-3.0Upstream source
AuthentikSingle sign-on, identity, 2FA and forward authMIT/GPL community editionUpstream source

Workflow and business apps

ComponentRoleLicense postureSource
ActivepiecesNo-code automation builder and formsMIT coreUpstream source
ReefCoralReefOffice-owned open-source automation runner, recipe catalog and AI-agent skillsApache-2.0 (runner) + Apache-2.0 with Commons Clause (public recipe catalog)Upstream source
DolibarrScoped quotes, invoices, payments, CRM and support-ticket workflowsGPL-3.0+Upstream source
ListmonkNewsletter and mailing-list workflows for client-owned sending domainsAGPL-3.0Upstream source
ForgejoGit hosting and project hub when enabledGPL-3.0+Upstream source
Uptime KumaCentral monitoring and per-client status pagesMITUpstream source
GristSpreadsheet-database for structured records and lightweight internal appsApache-2.0Upstream source
code-server (VS Code)Browser-based VS Code workspace when enabledMITUpstream source
Odoo CommunityBusiness management platform: CRM, sales, inventory, accounting and websiteLGPL-3.0Upstream source
Sveltia CMSLightweight Git-backed headless CMS for client sitesMITUpstream source
PostizSocial publishing calendar and content schedulingAGPL-3.0Upstream source
VikunjaOpen-source task and project managementGPL-3.0+Upstream source
Matrix SynapsePrivate chat and collaboration serverApache-2.0Upstream source

Private AI and search

ComponentRoleLicense postureSource
Open WebUIPrivate AI chat interface and document-aware assistant surfaceBSD-3-Clause with branding termsUpstream source
OllamaLocal model runtime for Private AI plansMITUpstream source
QdrantVector search for document memory and retrieval workflowsApache-2.0Upstream source
HermesSelf-hosted AI agent workspaceMITUpstream source

Platform plumbing

ComponentRoleLicense postureSource
PostgreSQLRelational database for service dataPostgreSQL LicenseUpstream source
MariaDBDatabase for DolibarrGPL-2.0Upstream source
Redis 8Queues and cache for services that need itAGPLv3 / RSALv2 / SSPLv1Upstream source
nginxTLS reverse proxy and access gatewayBSD-2-ClauseUpstream source
ClamAVMalware scanning for uploaded filesGPL-2.0Upstream source
TrivyContainer image OS-package CVE scanningApache-2.0Upstream source
vulnixNixOS host package CVE scanning against NVDBSD-3-ClauseUpstream source
CrowdSecIntrusion prevention and behavior-based blockingMITUpstream source
PostfixSMTP relay for transactional and outbound mailIPL-1.0 / EPL-2.0Upstream source
TemporalWorkflow orchestration engine used by PostizMITUpstream source
OpenSearchFull-text search and analytics used by PostizApache-2.0Upstream source
ResticEncrypted backup engineBSD-2-ClauseUpstream source

Added value

What the managed service adds

  • Your own dedicated EU server, reserved for you and never shared with another client.
  • A managed control plane that provisions, monitors, updates and backs up your server.
  • Custom automations and vertical workflow packs, built and maintained around how your business works.
  • Guided onboarding, data migration, support and incident response.
  • Your configuration, secrets and data stay private to you: never shared, mined or resold.

Our commitment to openness

What is open, and what stays managed

  1. This page stays live and current: every component, its license and its upstream source.
  2. Source for exact versions we run, including changes to copyleft components, is published in our public repository (e.g. containers/bentopdf/ for BentoPDF) and available to every client on request.
  3. ReefCoral, our open-source automation runner, recipe catalog and AI-agent skill kit, is public and Apache-2.0 at codeberg.org/ReefOffice/reefcoral. The public recipe catalog uses Apache-2.0 with Commons Clause to protect against resale as a competing service.
  4. Managed operations, custom automations and per-client hardening stay part of the paid service; we never publish anything that maps a client’s live environment.

Need the exact source for a client review?

Send the component name and workspace plan. ReefOffice can provide the pinned version, upstream source link and matching deployment note used for that workspace, including any changes we deploy to AGPL/GPL components.

Ask about source

This page is a practical source-and-licensing summary, not legal advice.