24 Open Core, Honest Business
A book about trust that ended at engineering would be incomplete. The trust layer is not just an architecture; it is a business proposition, and it deserves an honest business model — one where what is free, what is paid, and why can be stated in a paragraph without embarrassment.
The model that fits is open core: the kernel is open; the difficult, boring, regulated value around it is commercial.
24.1 What stays open, and why
The engines — comparison machinery, renderers, derivation code — are open because openness is strategically correct for them. Open kernels get audited by strangers, hardened by users, and trusted by procurement (“we can read the code” is a real line item in regulated buying). Openness also aligns with the product’s own thesis: a trust layer whose internals are opaque is asking you to extend exactly the kind of unverifiable confidence it exists to eliminate.
There is a subtler reason. In a market where the artisanal alternative is expensive manual labor, an open kernel that automates even eighty percent of the pain is a public good that creates the market. Every team that adopts the open comparator is a team that has stopped doing comparison by hand — and a prospect for the paid layer above it. Open source, here, is not charity; it is distribution.
24.2 What is sold, honestly
The paid layer is everything the ecosystem cannot copy cheaply, each item answering a real budget line:
- The validation package, maintained. Traceability matrix, qualification runs, deviation log — kept current with every release, re-executable by the customer. (Principle Five as a SKU.)
- Delivery into the customer’s environment. The appliance form: the kernel plus deployment, identity integration, and the operational hardening that regulated IT demands. (Principle Nine, invoiced.)
- Support and accountability. A channel with response times and names. Regulated organizations buy accountability the way others buy features; “who answers at 2 a.m. before the filing” is a legitimate product.
- The catalog as a service. Continuous qualification across releases, if the customer would rather consume than operate.
Note what is not on the list: the code itself, features held hostage, open-core bait-and-switch where the “open” version is quietly crippled. Those patterns buy a quarter of revenue and cost the benefit of the doubt — the one asset this entire book argues is the point.
24.3 Pricing against the alternative
The honest anchor for pricing is not competitor list prices but the cost of the manual status quo: weeks of double programming per submission, audits that consume quarters, findings that cost filings. A product that provably removes most of that is worth a visible fraction of it. Anchoring there also keeps the vendor honest — the value story is quantified in the customer’s own labor, not in adjectives.
And the reciprocity rule for an open-core trust product: the open kernel must always be genuinely useful alone. The moment the free tier exists only as a demonstration of what paying unlocks, the product’s central claim — that it generates trust rather than performs it — collapses.
The test. Ask any open-core vendor: “Name the boundary between free and paid, and tell me one useful thing I can accomplish today, in production, on the free side.” If the boundary is evasive or the free side is a demo, the business is renting trust back to the community that built its credibility.