Read the source, or use Cloud
DocKosha’s application is open source under AGPL-3.0-or-later for inspection and contribution. External self-hosting is not currently available because the mandatory DocYantra dependency is private; DocKosha Cloud is the available hosted product.
The short version
The source is public for reading and contribution, but external self-hosting is not currently available. DocKosha Cloud is the supported way to use the product today.
Read and contribute to the public source if
- You want to inspect the public DocKosha source under the AGPL-3.0-or-later license.
- You want to review the architecture and contribute improvements.
- You understand that external self-hosting is not currently available.
- You do not need external access to the private DocYantra dependency.
Use DocKosha Cloud if
- Operating the stack is not how your team wants to spend its week.
- You want upgrades, backups, deliverability, and custom-domain certificates handled for you.
- You want the DocYantra processing path already operated inside Cloud.
- You would rather pay a subscription than carry an on-call rotation.
What a future self-hosting path would involve
These are maintainer reference notes for a possible future self-hosting path, not instructions or an offer available today.
Upgrades and migrations
Backups you have actually restored
Object storage and its bill
Email deliverability
Custom-domain infrastructure
Secrets and transport security
Availability and monitoring
Legal and regulatory duties
The repository ships public source and maintainer reference material. It does not currently ship an externally runnable deployment or DocYantra access.
What is available today
There is one supported route today: DocKosha Cloud. The source is public for review and contribution; a runnable external route is not currently available.
| Concern | Public source (runtime unavailable) | DocKosha Cloud |
|---|---|---|
| Upgrades and migrations | Future operator reference only; external runtime unavailable today. | Applied by DocKosha; nothing for you to schedule. |
| Database and backups | Future operator reference only; external runtime unavailable today. | Managed and backed up as part of the service. |
| Object storage | Future operator reference only; external runtime unavailable today. | Included in the plan's storage allowance. |
| Email deliverability | Future operator reference only; external runtime unavailable today. | Sent over DocKosha's sending domain, which we maintain. |
| Custom domains | Future operator reference only; external runtime unavailable today. | Configured in the app on paid plans. |
| TLS and secret rotation | Future operator reference only; external runtime unavailable today. | Managed by DocKosha. |
| Monitoring and on-call | Future operator reference only; external runtime unavailable today. | DocKosha's. |
| Support | No external self-hosting support is currently available. | Commercial support and service-level agreements are paid artifacts, available through Cloud or a separate agreement. |
| DocYantra engine | Unavailable to external users while the private DocYantra dependency remains internal. | Already running; no separate key to buy. |
| What it costs | Future operator reference only; no external runtime is available today. | A subscription; the plan tiers are on the pricing page. |
What the Cloud product provides
These are the product guarantees available through DocKosha Cloud.
Safety-critical capability stays in the DocKosha application
Watermarks are burned into the delivered bytes
Screenshot protection is a deterrent, and we say so
Conversion fails closed, never degraded
What the public source and Cloud product include
DocKosha source is published under AGPL-3.0-or-later. The Cloud product provides the hosted feature set, including:
- Custom domains and white-label branding
- User groups and group-based access rules
- Advanced analytics: per-page dwell, country, media sections, exports
- Versioning retention policies
The capability matrix also names later roadmap items such as SSO/SAML and MFA enforcement; those are not shipped, so treat them as roadmap rather than as something you are buying.
DocYantra is the private mandatory direct `0.0.26` dependency for the validated Office and PDF path. Enterprise terms require a separate signed agreement and do not imply engine access; see pricing for that path.
Source publication does not create a deployment
The public repository is available for review and contribution, but it is not currently an externally runnable deployment.
What source publication does and does not provide
- Telemetry and marketing analytics are opt-in and environment-gated. Leave their variables unset and those integrations are inert.
- External users do not receive private DocYantra package access, tokens, SDKs, APIs, or engine licenses.
- The public repository is not an externally runnable distribution today; there is no external installation to count.
- The claim is meant to be checked rather than trusted: grep the source for DocKosha-owned endpoints, then read
env.examplefor every configurable network boundary.
Cloud is different, and here is exactly how
DocKosha Cloud is a hosted service we operate, so it runs viewer and product analytics under consent:
- Consent is regional. Visitors in the EU, EEA, and UK — and any visitor whose region cannot be determined — get nothing until they explicitly opt in.
- Elsewhere, analytics default to granted with a straightforward opt-out.
- A Global Privacy Control signal always wins, whatever the region says.
- Raw IP addresses are never stored by the current application.
The security page covers the rest of what Cloud does with data.
Pick the path that fits your week
Read and contribute to the repository under AGPL-3.0-or-later, or use DocKosha Cloud for the available hosted product. Enterprise terms require a separate signed agreement and do not grant DocYantra engine access.