New in v1.1.0The mobile app is out of Beta and included in every edition — iOS and Android, signed in to your own instance.Read the announcement

Platform Platform overviewSee it in actionAI SearchAI AssistantAI Connectors & MCPIntegrationsQuality LoopAdministration & SecurityMobile app
Solutions IT & Platform teamsCompliance & Data ProtectionDevelopersAgencies & Partners
Sovereignty
References
Pricing
Resources Trust CenterEU AI ActSecurity & disclosureFree toolsOpen source & open coreDocumentation ↗API reference ↗GitHub ↗ReferencesBlogChangelog
Company AboutPartnersContact
Search See it live Book a demo
Product

RAGSuite is now open source: the Community Edition is public

The RAGSuite Community Edition is public on GitHub under Apache 2.0, with an install CLI on npm. Three commands and it runs on your own infrastructure — no sales call, no trial gate, no phone-home.

PRODUCT :9191 liveApache 2.0 ragsuite.de
Jürgen Pietschmann
Jürgen Pietschmann AI Consultant
Published21 August 2026 Updated11 September 2026 Read7 min Product

The RAGSuite Community Edition is public. The source is at github.com/ragsuite/RAGSuite under Apache 2.0, the install CLI is on npm as @ragsuite/ragsuite, and you can have it running on your own server in the time it takes to read this post.

That is the whole announcement. What follows is why it matters more than a repository going from private to public usually does.

The claim and the proof are now the same thing

Every sovereign-AI vendor says the same words. Self-hosted. Your data never leaves. No lock-in. We have said them too, on this website, for months.

The problem with those words is that they are unfalsifiable in a sales conversation. A buyer in a regulated organisation cannot verify “your data never leaves” from a slide. They can ask for a DPIA, read an architecture diagram, and take a vendor’s word for the part that matters — which is what the code actually does when it holds their documents.

Opening the source changes the nature of the claim. You no longer have to believe that RAGSuite does not phone home. You can read the code, run it on a host with no outbound route, and watch. That is a materially different conversation to have with a Datenschutzbeauftragter, a Betriebsrat, or an auditor — and it is the one we would rather be in.

Three commands

bash
npm install -g @ragsuite/ragsuite@latest
ragsuite init      # native by default — add --docker to use Compose
ragsuite start

The web UI comes up on localhost:9191, the API on localhost:9090 with its reference at /docs. ragsuite doctor checks your prerequisites first if you would rather look before you leap, and ragsuite stop shuts the stack down without touching your database.

You need Node 18 or newer, plus PostgreSQL and Redis — RAGSuite is a real platform with real state, and we would rather tell you that up front than discover it together at step four. Native is the default because it is the mode most teams end up running in production; Docker is one flag away if you prefer it.

No account. No trial key. No form in front of the download.

What is open, and what is not

We run an open-core model and it is worth being precise about the line, because “open source” is used loosely enough in this market to be nearly meaningless.

The open-core line What is open and what is commercialCOMMUNITY · APACHE 2.0The practitioner platformthe full ingestion pipelineconnectors & MCP · Gmail, n8nAI Search · AI Assistant · widgetsevery LLM provider, incl. local OllamaREST API · webhooks · basic audit · 2FAunlimited users, unlimited projectsENTERPRISE · /ee DIRECTORYThe governance layerSSO / SAML / OIDCRBAC across orgs, teams and usersfull audit logs, compliance exportsCompare Modelsdeep query tracingadvanced analyticsMulti-user collaboration is not in the paid tier.
The line is drawn once and stated plainly: the platform a team actually runs is Apache 2.0, and what the commercial edition adds is the governance layer — SSO, RBAC and full audit exports.

Open, under Apache 2.0 — the full pipeline: website crawl and document upload, the entire connector and MCP ecosystem including Gmail and n8n, AI Search, the AI Assistant, embeddable widgets with a citation on every answer, every LLM provider including local Ollama, the REST API and webhooks, basic audit, 2FA, and unlimited users and unlimited projects.

Commercial, in a separate /ee directory — the governance layer an organisation needs once AI stops being an experiment: SSO/SAML/OIDC, RBAC across organisations, teams and users, full audit logs with compliance exports, Compare Models, deep query tracing and advanced analytics.

Note what is not in the paid tier: multi-user collaboration. A great many open-core products cap the free edition at one administrator, which turns “free” into “demo”. We removed that cap deliberately. Community is a platform a team can actually run, not a lead magnet with the useful parts removed.

We also do not charge an SSO tax. SSO and RBAC sit in the base paid edition, not in a bespoke “contact us” tier above it. For a product that sells on compliance, putting the security features behind the most expensive door would be an odd thing to do.

The part we are quietly proudest of

Enterprise activation is offline. Your vendor emails you a signed key and an encrypted bundle; you drop them into the install root and run ragsuite activate. The platform validates them locally.

Activation without a licence server Offline activation, step by step01Delivered by emaila signed key and anencrypted bundle02Dropped into placeinstall root, thenragsuite activate03Validated locallyon your own host —no server to callNo licence server appears anywhere in that sequence.When a key expires, the deployment degrades back to Community.It never locks you out, and it never deletes your data.
Enterprise unlocks from a file on disk rather than a call to a server — which is why an air-gapped deployment is the product working normally, not a special edition or a services engagement.

There is no licence server in that sequence. Nothing calls home to check whether you are still a paying customer — which means an air-gapped deployment is not a special edition or a services engagement, it is just the product working the way it was built to work. When a key expires, the deployment degrades gracefully back to Community. It never locks you out, and it never deletes your data.

That design costs us something. It means we cannot see usage, so we cannot run the usage-triggered sales motion that most of this industry runs on. We think that is the correct trade for a product whose entire proposition is that it does not watch you.

Where this goes next

The repository is the beginning of the work, not the end of it. Documentation lives at docs.ragsuite.de, with the REST API reference alongside the install and configuration guides. Issues and pull requests are open — contributions come in under a CLA so the project stays cleanly licensable — and the security policy is published for anyone who finds something they should tell us about privately.

If you run a regulated workload in the DACH region and you have been waiting to see the code before taking us seriously: it is there. Read it first. That was always the point.

Frequently asked questions

What exactly is open source — all of it?

The Community Edition is, under Apache 2.0: the full ingestion pipeline, the connector and MCP ecosystem, AI Search, the AI Assistant, widgets, every LLM provider including local Ollama, the REST API, and unlimited users and projects. Enterprise features — SSO/SAML/OIDC, RBAC, full audit and compliance exports, Compare Models, deep query tracing, advanced analytics — live in a separate /ee directory under a commercial licence. Open core, stated plainly: the practitioner platform is open, the governance layer is paid.

What do I need to run it?

A Linux, macOS or WSL2 host with Node 18 or newer, plus PostgreSQL and Redis. The CLI checks prerequisites for you with ragsuite doctor. It runs natively by default, or under Docker if you pass --docker to ragsuite init. The web UI comes up on port 9191 and the API on 9090.

Does it phone home?

No. There is no telemetry, and Enterprise capabilities unlock with a signed offline key rather than a call to a licence server. That is a deliberate architectural constraint, not a setting — and now that the source is public, it is one you can verify rather than take on trust.

Can I use it commercially without paying?

Yes. Apache 2.0 permits commercial use, modification and redistribution. The Enterprise Edition is what you buy when you need the governance layer — SSO, RBAC, full audit exports — not permission to use the platform.

Sources & further reading

  1. RAGSuite on GitHub — the Community Edition source, Apache 2.0
  2. @ragsuite/ragsuite on npm — the install CLI
  3. Apache License 2.0 — the Community Edition licence
  4. RAGSuite — pricing — Community / Enterprise Edition

← All posts