The RAGSuite Community Edition is public. The source is at github.com/ragsuite/RAGSuite under Apache 2.0, the install CLI is on npm as @ragsuite/ragsuite, and you can have it running on your own server in the time it takes to read this post.
That is the whole announcement. What follows is why it matters more than a repository going from private to public usually does.
The claim and the proof are now the same thing
Every sovereign-AI vendor says the same words. Self-hosted. Your data never leaves. No lock-in. We have said them too, on this website, for months.
The problem with those words is that they are unfalsifiable in a sales conversation. A buyer in a regulated organisation cannot verify “your data never leaves” from a slide. They can ask for a DPIA, read an architecture diagram, and take a vendor’s word for the part that matters — which is what the code actually does when it holds their documents.
Opening the source changes the nature of the claim. You no longer have to believe that RAGSuite does not phone home. You can read the code, run it on a host with no outbound route, and watch. That is a materially different conversation to have with a Datenschutzbeauftragter, a Betriebsrat, or an auditor — and it is the one we would rather be in.
Three commands
npm install -g @ragsuite/ragsuite@latest
ragsuite init # native by default — add --docker to use Compose
ragsuite start
The web UI comes up on localhost:9191, the API on localhost:9090 with its reference at /docs. ragsuite doctor checks your prerequisites first if you would rather look before you leap, and ragsuite stop shuts the stack down without touching your database.
You need Node 18 or newer, plus PostgreSQL and Redis — RAGSuite is a real platform with real state, and we would rather tell you that up front than discover it together at step four. Native is the default because it is the mode most teams end up running in production; Docker is one flag away if you prefer it.
No account. No trial key. No form in front of the download.
What is open, and what is not
We run an open-core model and it is worth being precise about the line, because “open source” is used loosely enough in this market to be nearly meaningless.
Open, under Apache 2.0 — the full pipeline: website crawl and document upload, the entire connector and MCP ecosystem including Gmail and n8n, AI Search, the AI Assistant, embeddable widgets with a citation on every answer, every LLM provider including local Ollama, the REST API and webhooks, basic audit, 2FA, and unlimited users and unlimited projects.
Commercial, in a separate /ee directory — the governance layer an organisation needs once AI stops being an experiment: SSO/SAML/OIDC, RBAC across organisations, teams and users, full audit logs with compliance exports, Compare Models, deep query tracing and advanced analytics.
Note what is not in the paid tier: multi-user collaboration. A great many open-core products cap the free edition at one administrator, which turns “free” into “demo”. We removed that cap deliberately. Community is a platform a team can actually run, not a lead magnet with the useful parts removed.
We also do not charge an SSO tax. SSO and RBAC sit in the base paid edition, not in a bespoke “contact us” tier above it. For a product that sells on compliance, putting the security features behind the most expensive door would be an odd thing to do.
The part we are quietly proudest of
Enterprise activation is offline. Your vendor emails you a signed key and an encrypted bundle; you drop them into the install root and run ragsuite activate. The platform validates them locally.
There is no licence server in that sequence. Nothing calls home to check whether you are still a paying customer — which means an air-gapped deployment is not a special edition or a services engagement, it is just the product working the way it was built to work. When a key expires, the deployment degrades gracefully back to Community. It never locks you out, and it never deletes your data.
That design costs us something. It means we cannot see usage, so we cannot run the usage-triggered sales motion that most of this industry runs on. We think that is the correct trade for a product whose entire proposition is that it does not watch you.
Where this goes next
The repository is the beginning of the work, not the end of it. Documentation lives at docs.ragsuite.de, with the REST API reference alongside the install and configuration guides. Issues and pull requests are open — contributions come in under a CLA so the project stays cleanly licensable — and the security policy is published for anyone who finds something they should tell us about privately.
If you run a regulated workload in the DACH region and you have been waiting to see the code before taking us seriously: it is there. Read it first. That was always the point.
Frequently asked questions
What exactly is open source — all of it?
The Community Edition is, under Apache 2.0: the full ingestion pipeline, the connector and MCP ecosystem, AI Search, the AI Assistant, widgets, every LLM provider including local Ollama, the REST API, and unlimited users and projects. Enterprise features — SSO/SAML/OIDC, RBAC, full audit and compliance exports, Compare Models, deep query tracing, advanced analytics — live in a separate /ee directory under a commercial licence. Open core, stated plainly: the practitioner platform is open, the governance layer is paid.
What do I need to run it?
A Linux, macOS or WSL2 host with Node 18 or newer, plus PostgreSQL and Redis. The CLI checks prerequisites for you with ragsuite doctor. It runs natively by default, or under Docker if you pass --docker to ragsuite init. The web UI comes up on port 9191 and the API on 9090.
Does it phone home?
No. There is no telemetry, and Enterprise capabilities unlock with a signed offline key rather than a call to a licence server. That is a deliberate architectural constraint, not a setting — and now that the source is public, it is one you can verify rather than take on trust.
Can I use it commercially without paying?
Yes. Apache 2.0 permits commercial use, modification and redistribution. The Enterprise Edition is what you buy when you need the governance layer — SSO, RBAC, full audit exports — not permission to use the platform.
Sources & further reading
- RAGSuite on GitHub — the Community Edition source, Apache 2.0
- @ragsuite/ragsuite on npm — the install CLI
- Apache License 2.0 — the Community Edition licence
- RAGSuite — pricing — Community / Enterprise Edition