Open infrastructure
NixOS service wiring, hardening patterns, deployment modules, and component source links are the parts that should become public because they build trust and make the stack auditable.
Source transparency
ReefOffice is built from open-source infrastructure and open-source applications. What you pay for is your own dedicated EU server, plus the managed packaging, automations, onboarding, monitoring and support around that stack.
NixOS service wiring, hardening patterns, deployment modules, and component source links are the parts that should become public because they build trust and make the stack auditable.
Your data lives in standard open-source apps and standard formats: files in Nextcloud, metadata in Paperless, Bitwarden-compatible password exports, business records from Dolibarr, and so on. Export from any app yourself, or ask us for a complete copy.
What you pay for is everything around the open stack: onboarding, monitoring, tested upgrades, daily encrypted backups, managed automations, workflow packs and ongoing support.
Components
These are the main upstream projects used by ReefOffice workspaces. Components are deployed from pinned packages or container images, and commercial/enterprise-only features are avoided unless there is an explicit license decision. We keep upstream license text and branding intact, so this list also serves as public attribution.
| Component | Role | License posture | Source |
|---|---|---|---|
| NixOS | Declarative operating system and reproducible server configuration | MIT-style / mixed open source | Upstream source |
| Nextcloud | Files, calendar, contacts, sharing and office workspace | AGPL-3.0 | Upstream source |
| Collabora CODE | Browser document editing with Nextcloud | MPL-2.0 | Upstream source |
| Paperless-ngx | Document intake, OCR and archive | GPL-3.0 | Upstream source |
| BentoPDF | Client-side PDF tools: split, merge, convert, OCR and sign without uploading files | AGPL-3.0 (includes AGPL WASM libs below) | Upstream source |
| PyMuPDF WASM | PDF rendering and text extraction WASM (bundled with BentoPDF) | AGPL-3.0-only | Upstream source |
| Ghostscript WASM | PostScript/PDF interpreter WASM (bundled with BentoPDF) | AGPL-3.0-only | Upstream source |
| CoherentPDF | PDF generation WASM library (bundled with BentoPDF) | AGPL-3.0-or-later | Upstream source |
| Vaultwarden / OIDCWarden | Bitwarden-compatible password vault; we run OIDCWarden for SSO | AGPL-3.0 | Upstream source |
| Authentik | Single sign-on, identity, 2FA and forward auth | MIT/GPL community edition | Upstream source |
| Component | Role | License posture | Source |
|---|---|---|---|
| Activepieces | No-code automation builder and forms | MIT core | Upstream source |
| ReefCoral | ReefOffice-owned open-source automation runner, recipe catalog and AI-agent skills | Apache-2.0 (runner) + Apache-2.0 with Commons Clause (public recipe catalog) | Upstream source |
| Dolibarr | Scoped quotes, invoices, payments, CRM and support-ticket workflows | GPL-3.0+ | Upstream source |
| Listmonk | Newsletter and mailing-list workflows for client-owned sending domains | AGPL-3.0 | Upstream source |
| Forgejo | Git hosting and project hub when enabled | GPL-3.0+ | Upstream source |
| Uptime Kuma | Central monitoring and per-client status pages | MIT | Upstream source |
| Grist | Spreadsheet-database for structured records and lightweight internal apps | Apache-2.0 | Upstream source |
| code-server (VS Code) | Browser-based VS Code workspace when enabled | MIT | Upstream source |
| Odoo Community | Business management platform: CRM, sales, inventory, accounting and website | LGPL-3.0 | Upstream source |
| Sveltia CMS | Lightweight Git-backed headless CMS for client sites | MIT | Upstream source |
| Postiz | Social publishing calendar and content scheduling | AGPL-3.0 | Upstream source |
| Vikunja | Open-source task and project management | GPL-3.0+ | Upstream source |
| Matrix Synapse | Private chat and collaboration server | Apache-2.0 | Upstream source |
| Component | Role | License posture | Source |
|---|---|---|---|
| Open WebUI | Private AI chat interface and document-aware assistant surface | BSD-3-Clause with branding terms | Upstream source |
| Ollama | Local model runtime for Private AI plans | MIT | Upstream source |
| Qdrant | Vector search for document memory and retrieval workflows | Apache-2.0 | Upstream source |
| Hermes | Self-hosted AI agent workspace | MIT | Upstream source |
| Component | Role | License posture | Source |
|---|---|---|---|
| PostgreSQL | Relational database for service data | PostgreSQL License | Upstream source |
| MariaDB | Database for Dolibarr | GPL-2.0 | Upstream source |
| Redis 8 | Queues and cache for services that need it | AGPLv3 / RSALv2 / SSPLv1 | Upstream source |
| nginx | TLS reverse proxy and access gateway | BSD-2-Clause | Upstream source |
| ClamAV | Malware scanning for uploaded files | GPL-2.0 | Upstream source |
| Trivy | Container image OS-package CVE scanning | Apache-2.0 | Upstream source |
| vulnix | NixOS host package CVE scanning against NVD | BSD-3-Clause | Upstream source |
| CrowdSec | Intrusion prevention and behavior-based blocking | MIT | Upstream source |
| Postfix | SMTP relay for transactional and outbound mail | IPL-1.0 / EPL-2.0 | Upstream source |
| Temporal | Workflow orchestration engine used by Postiz | MIT | Upstream source |
| OpenSearch | Full-text search and analytics used by Postiz | Apache-2.0 | Upstream source |
| Restic | Encrypted backup engine | BSD-2-Clause | Upstream source |
Added value
Our commitment to openness
Send the component name and workspace plan. ReefOffice can provide the pinned version, upstream source link and matching deployment note used for that workspace, including any changes we deploy to AGPL/GPL components.
This page is a practical source-and-licensing summary, not legal advice.