# Commercial Support & Services — `@trelyan/verify-pqc`

> The toolkit is open source under the **MIT License** and always will be. This document
> describes the **optional paid support and services** TRELYAN offers around it. It does not
> change or restrict the MIT grant on the code.

## Read this first — what you're getting

`@trelyan/verify-pqc` is a **reference implementation**. It has **not** undergone an independent
cryptographic or side-channel audit. It is provided **"AS IS", without warranty of any kind**
(see [`LICENSE`](./LICENSE)). A commercial agreement adds **support and services** — it does
**not** turn the software into an audited or certified product and does **not** add a warranty
of cryptographic correctness. An independent audit is on our roadmap; talk to us if you want to
sponsor or accelerate it (that is the step that unlocks warranted, GA terms).

## The code is free. Always.

You may use, copy, modify, embed, and self-host the SDK — including in production and commercial
systems — **for free, forever, with no fee to TRELYAN**. The tiers below sell *support and
priority around* the toolkit, not the right to use it (MIT already grants that). The one exception:
the Enterprise tier may include **private or pre-release modules that are not part of the MIT
codebase** — those are licensed to you separately under the Enterprise agreement, not under MIT.

## Tiers

### Community — **$0** (MIT)
- The full SDK, the free CBOM **A–F badge** + GitHub Action, the TLS **posture scan**, and the
  public verifier.
- Community issue tracker. Best-effort, **no SLA**.
- Genuinely enough for many teams.

### Commercial Support — **$7,500 / year**
For teams running `verify-pqc` in production who want a contract behind it:
- Priority email support with a **response-time** target (a target on *our response*, not an SLA
  on the code's correctness).
- Guidance on correct integration, key handling, and trust-model configuration.
- Early access to new modules and advance notice of breaking changes.
- A named point of contact.
- On request, a signed dependency / SBOM attestation for your procurement file.

### Enterprise — **custom (from ~$15,000 / year)**
Everything in Commercial Support, plus:
- Private or pre-release modules and custom verifiers (licensed under the Enterprise agreement, **not** MIT).
- **Best-effort** prioritized fixes (no SLA) and roadmap input.
- Architecture and integration review (**not** a security audit) and design-partner collaboration.
- Deeper, negotiated response-time commitments.

### Pilots & Evidence Packs
Fixed-scope engagements — firmware-signing and verifiable-identity pilots, payment-authorization
integration, code-security sweeps, NIS2 / CRA readiness, and the **$7,500 Evidence Pack Express** —
are described at **https://trelyan.foundation/pilots**.

## What we will not sell or claim

- **No certification.** We do not sell a "certified" status or a "Verified-by-TRELYAN" seal. The
  toolkit is unaudited; any badge it produces is a *preview signal, not an assurance*.
- **No open-ended indemnity or warranty.** Commercial Support does not include indemnity beyond
  the fees paid for the then-current term, and does not warrant the software is defect-free or fit
  for a particular purpose.
- **Private / pre-release modules are *earlier*, not safer.** They are not more secure or more
  audited than the public MIT code — just newer and less battle-tested.
- **Nothing here changes the MIT grant** on the open code.

## Contact

Commercial support / enterprise: **fondation@trelyan.ch** · book a call:
**https://cal.com/brandon-sellam-kjltvd/30min**

*Prices are in USD, are starting points, and are scoped per signed agreement. © 2026 TRELYAN Inc.
The software is licensed under MIT (see [`LICENSE`](./LICENSE)); this document describes optional
paid support and services only.*
