Skip to content

The other ninety percent: how open-source companies actually make money

A plain-language companion to the draft working paper "Value Capture in Commercial Open Source: Services, Funding Paths, and the FLOSS Value Network (Europe, 2026)" (v0.4, July 2026). The paper carries the theory, the model, the proofs, and the caveats; this text carries the ideas.

Read the full draft working paper (PDF)

The short version. The public story of commercial open source in the 2020s is a story of licensing wars: Elastic, HashiCorp, and Redis pulling their code out of open source to stop cloud giants from reselling it, and the community forks that answered them. That story is real, and it concerns a small, loud slice of the sector. Most open-source companies never face a relicensing decision at all: they sell services around software they help maintain and do not own. The paper maps how those firms capture value, and finds that one early choice shapes everything downstream: where the money comes from. A self-funded firm and a venture-backed firm run different games on the same code, and the licensing drama lives almost entirely in the second game.

Free code, paid flow

The economic frame comes from the theory of FLOSS projects and open-source business models of Jullien, Viseur and Zimmermann (2025), which assembles a line of work running back through their own earlier papers to von Hippel. Its starting distinction: the software stock (the code as it sits in the repository) is free by construction, while the flow (the stream of versions that fixes security bugs, adds features, and keeps the software alive in a changing environment) is where value is created. Benefiting from the flow takes skills and participation, and organizations that lack the skills, or prefer to buy them, pay open-source companies to participate for them.

What those companies sell comes in three families, the "3A" services. Assurance is a guaranteed, security-maintained edition sold under contract: think of a public administration buying a supported version of an open-source infrastructure component. Adaptation is integration and customization: an open-source ERP fitted into a manufacturer's processes. Assistance is help with specifying needs, choosing solutions, training, and support: the services that carry a municipality onto an open-source platform.

The three have different cost structures, and the difference matters. Adaptation and assistance are sold as expert time: revenue arrives with the first client, and the business grows with hires, so it can be financed out of its own cash flow. Assurance at scale needs a "software factory" (build and test infrastructure, security handling, release management) that costs roughly the same for ten clients as for a thousand: the fixed cost has to exist before the subscribers do, so it calls for capital, accumulated surplus, or a foundation that mutualizes it.

The funding path decides the game

The paper's addition to the theory is one axis: the firm's funding path, formalized as patience. A firm living on its own revenue can weigh next year's returns almost like this year's. A venture-backed firm facing fund horizons and growth targets behaves, provably in the model, like an impatient firm: a revenue deadline acts exactly like a cut in how much the future counts.

Four results follow, each proved and machine-checked. First, how much a firm invests in the underlying project (code, maintenance, community work) rises with the square of its patience: halve the effective patience and contribution falls to a quarter. The patient service firms are the model's natural maintainers. Second, enclosure (relicensing the project away from open source to convert its users into product customers) pays only when two things hold at once: the firm is impatient enough, below a unique threshold, and converting users to a product today beats serving them today. Patient firms stay open even when the product margin is rich, because enclosure destroys the community asset whose returns arrive later. Third, a community capable of forking the project shrinks the region where enclosure pays: the credible fork is a tax on relicensing, paid in the revenue the fork would take away. Fourth, enclosure gets more tempting exactly when the service margin erodes (a hyperscaler's managed offering absorbing the revenue) and when the project's growth flattens with maturity.

That last pair is the timing of the real episodes. MongoDB relicensed in 2018; Elastic relicensed in 2021 and AWS launched the OpenSearch fork; HashiCorp relicensed in 2023 and the OpenTofu fork followed; Redis relicensed in 2024 and Valkey followed. Relicensing into ecosystems whose users could code drew forks; where users cannot rebuild the project, the deterrent is absent. The model reads these as consistency checks on its comparative statics, and assigns no probability to any particular fork.

What this means for Europe

The population a European open-source policy most wants to sustain is the self-funded service majority: the firms that keep contributing because their business model rewards patience. Two implications follow.

The Cyber Resilience Act attaches largely fixed compliance costs (secure development process, vulnerability handling, documentation, conformity assessment) to placing products on the EU market. A fixed cost is regressive in firm size: it lands hardest on the small firms and foundations at the sector's base. If the goal is a resilient European open-source sector, the mandate wants pairing with instruments that flatten that curve: mutualized compliance tooling, shared conformity infrastructure, clarity about the lighter regime for open-source stewards. The same regulation has an offset: the documentation and process artifacts it requires are, on the demand side, exactly what public and regulated buyers pay for as assurance, so the service majority can package compliance as a product. Which effect dominates, for which firms, is an empirical question the paper leaves open. No claim is made that the regulation delivers security to anyone.

The small print

The four results are theorems about a deliberately small two-period model, and the paper says precisely which sentences are theorems, which are interpretations (reading the discount parameter as the funding path, reading enclosure as relicensing), and which await data. The claim that the self-funded service majority carries most of the sector's employment and revenue is a hypothesis, motivated by the visible-vendor bias of the trade press and awaiting the survey designed to test it. Every proposition carries a written proof, a numeric cross-check against brute-force computation, and a Monte-Carlo robustness run; no firm-level estimate is reported anywhere in the paper.