First-party (closed, on our API)
The regulated primitives — identity/entity, money, comms, runtime, and the tool catalog. We’re the issuer / KYB-and-formation entity / carrier registrant. Forking the code doesn’t let you issue a card or form an LLC, because the moat is the operated regulated bundle and the per-tenant governance, not the SDK shape.Open (OSS on GitHub)
Cloud infrastructure (the Naive-managedcloud provisioner, with managed hosting as the upsell),
database, and custom modules. Anyone could run these; we host for
convenience. They compete with commodity hosted-backend platforms, so they are
complements and distribution, never the headline.
The litmus test
If we open-sourced this module, could someone run it without us?
- Yes → open module.
- No, because we’re the regulated counterparty → first-party.
What this means in practice
The SDK, CLI, templates, and skill onboarding are distribution, not
defensibility — the moat is the operated regulated bundle and the per-tenant
governance gateway.