Open source, AGPL-3.0
Osiris's core, backup, restore and the audit log, is AGPL-3.0 on GitHub; the archive and multi-tenant layers Business and Service Provider add are planned as separate proprietary modules, not a smaller version of the same code.
Osiris's core is licensed AGPL-3.0: freely usable, inspectable and modifiable software, including the Community edition, which is free of charge for one organization with no mailbox limit and no licence key at all, and the AGPL-3.0 code already released cannot be withdrawn, whatever happens to this project later.
What's public today
The repository atgithub.com/lcsfls/osirisholds the licence and project description today. Osiris is in closed beta and development currently happens in a private repository; the source code itself ships with the first public release, not before. That's stated plainly here rather than left to be assumed from a link that looks further along than it is. See how Osiris is built for the full account of the development process this code goes through.
Why AGPL-3.0, specifically
AGPL closes the loophole plain GPL leaves open for network software: a provider running a modified Osiris as a service has to publish those modifications too, not just installations they physically hand someone a copy of. For a self-hosted backup and archive tool, aimed partly at service providers running it for clients, that matters more than it would for a desktop app.
What the paid editions actually add (and don't)
Business and Service Provider unlock additional features with a signed, offline Ed25519 licence key: the archive layer built for German GoBD requirements, multi-tenancy, provider reporting and the white-label option once it ships. That key is a fair-play mechanism, not DRM: it does not phone home, does not expire your access to a version you already have, and never limits restore. Restore is never limited by edition, in any version. Seepricing for exact terms, including what happens after the 12 months of included updates end (nothing functional: the software keeps running).
Getting your data back without Osiris at all
Open source extends past the application code to the data itself: the chunk-store format is open and documented, and a small standalone tool restores from it even with no Osiris server running, so open source here also means you can get your own backup back even in the worst case, not just read the code. Seeexit costs and vendor lock-in for why that specific guarantee is worth having in writing.
Frequently asked
Is Osiris really open source, or open core with a locked-down free tier?
AGPL-3.0 for the core, and the free Community edition already includes full Microsoft 365 and IMAP backup, non-destructive restore, a simple archive with search, and the audit log, with no mailbox limit and no licence key required. Business and Service Provider add a signed, offline licence key that unlocks additional features (the archive layer built for German GoBD requirements, multi-tenancy) on the same codebase, not a smaller version of the same feature.
Where's the code?
github.com/lcsfls/osiris holds the licence and project description today. Osiris is currently in closed beta and development happens in a private repository; the source code itself ships with the first public release. That's stated here plainly rather than implied further along than it is.
Is the licence key a form of DRM?
No. It doesn't call home, doesn't expire your access, and never limits restore. Restore is never limited by edition or licence in any version of Osiris. It's a fair-play mechanism that unlocks Business/Service Provider features once, offline, against a signed Ed25519 key; nothing about it can remotely disable the software.