Licensing & what's free

damn.dev is proprietary, self-hosted software. Governance and observation are free; running agents needs a license. How the free tier, the trial, and applying a license work.

damn.dev is proprietary, commercial software that you self-host: it runs on infrastructure you control and your data never leaves it. It is not open source. Two things are worth understanding up front: what runs for free, and what a license unlocks.

What's free, forever, no license#

Seeing your AI estate runs at no charge on your own infrastructure:

  • The tamper-evident audit trail (Trace), every action, approval, and rejection, exportable in full.
  • The Registry, an inventory of every agent and AI tool, native or external, and the Systems map of what each one can reach.
  • Discovery of AI tools running on your machines, and the connectors that observe the coding agents your team already uses (Claude Code, Cursor, and others).
  • Cost visibility: what your agents are spending.
  • Writing enforcement rules and running them in observation. Every rule you write matches real actions and records what it would have blocked. You get the finding, the count, and the audit record, with nothing yet stopped.

The free tier is genuinely useful on its own. Install damn.dev, connect the AI tools your team already runs, and you have a complete, audited picture of your AI estate at no cost, including a measured list of what your own policy says should not be happening.

What a license unlocks#

A license unlocks the controls that act rather than observe:

  • Enforcing rules. Turning a rule from observation into a block, so a matching action is actually stopped before it runs. See Policy & enforcement.
  • Issuing a provider key per agent, with a spend limit and automatic revocation when it's crossed, see a key per agent. Seeing what every key costs and what it unlocks stays free; issuing and revoking on your behalf is the licensed half.
  • Revoking an OAuth grant in your tenant from here. Seeing every grant, and being told when an approved app quietly gains new access, stays free.
  • Compliance packs and framed audit reports. Your full audit log exports without a license, on any plan. What a license adds is the regime's policy baseline, its pre-built rules, and the report framing.
  • The agent builder: creating and running your own agents, delegation, missions, and the COO orchestrator.
  • Other enterprise capabilities (SSO, and more, see Enterprise & advanced controls).

The line is observe vs. act. Seeing what your AI estate is and does is free forever, and so is being told what your rules would have stopped. Reaching out and changing it (blocking an action, running an agent, issuing or revoking a credential) is what a license pays for.

A rule without a license is not switched off. It still loads, still matches, and still writes what it would have blocked to your audit trail, labelled as observation so a record can never imply an action was stopped when it was not. Nothing is hidden and no rule is deleted.

Licenses can cover governance without the agent builder#

A license carries a list of what it covers, so the agent builder is priced separately from the enterprise governance controls. Two shapes are common:

Enterprise governanceRuns your own agents
Governance onlyyesno
Governance + agent builderyesyes

On a governance-only license, everything in the free tier plus your enterprise controls works normally, and the platform simply doesn't run native agents. It is not an error state and nothing warns you about it repeatedly, Settings → License says plainly that the builder isn't part of this license, and that's the end of it. If you want it added, talk to us.

Where the agent builder lives#

A standard install governs the AI your company already runs; building your own agents is the unlock. So when it isn't licensed, the surfaces that only make sense for agents you run: Agents, Skills and Team, aren't offered in the Console, and the one door that is says so: Overview → "Build & run your own agents". It tells you what the unlock is and how to ask for it.

Once it's licensed, those surfaces return to the Console and the Workspace shell (channels, the COO, missions) becomes available.

Nothing is deleted, and nothing is hidden that you'd go hunting for. Existing agents stay exactly where they are and remain visible. A workspace that already runs its own agents keeps all of its surfaces even if a license lapses, so you never open the app to find your own work unreachable.

No trial to expire#

A standard install governs the AI your company already runs, and that half never asks for anything. The licensed capabilities are simply locked until you have a license, and each one says what it is and how to ask for it at the moment you reach for it. There is no countdown and no clock to miss.

It never bricks. A lapsed license never stops governance or destroys your data. A governance tool must never stop governing on a billing lapse. Nothing already issued is revoked, no agent loses a credential it's using, no rule is deleted, and every view stays visible. Enforcing rules fall back to observation and keep recording. Only acting stops. Applying a fresh token restores enforcement on the next action, with nothing to reconfigure.

You can always turn things off. Revoking a provider key, revoking an MCP credential and retiring a worker never need a license, and they never will. Keys you issued keep billing on your own provider account until someone cancels them, so charging for the off switch would turn a billing lapse into a security problem we caused. If a license lapses while keys are still live, Registry → Keys says how many there are and what they have spent, and every one of them is still revocable from that page.

Applying a license#

Your license is a single token. Paste it into Settings → License. It takes effect immediately, no restart. To extend, apply a fresh token the same way.

Any operator (owner or admin) can apply one. In the Console the tab is Platform → License; in the Workspace shell it's the gear icon → License.

No license server. Your license is verified locally against a built-in key. Nothing about your license is ever sent to damn.dev. There is no license server, no online activation, and no usage reporting tied to it, by design. The one message an instance does send is the anonymous install analytics ping: a random id and a version number, with its own off switch.

Source review under NDA#

The software ships as built artifacts; the source is not public. For teams deploying in sensitive or regulated environments, we make the full source available for private security review under NDA, so your security team can verify exactly what runs on your infrastructure before you trust it. Contact hello@damn.dev.

Your data is yours#

Whatever the license state, your content is yours: workspaces, agents, memories, skills, rules, and audit records are stored in open formats (markdown, JSON) and fully portable, with or without us.

Running it for you#

Prefer not to self-host? We also offer managed hosting, a dedicated server we provision and operate, where you stay the sole admin. See Install & deploy or talk to us.