Reliefpay

Release status · In preparation

Open-source, when it is actually open.

Open-source core in preparation. Fixed fees. NGO control. The deployable core is being prepared for an open-source release. The current repository is private and no public-source licence is in force yet.

Planned public core

A deployable system

The intended release includes the web and server application, Android shop application, database migrations, card protocol and tooling, tests, and public operating documentation.

Provisional licence

AGPL, after review

The target is AGPL-3.0-or-later for software and CC BY 4.0 for documentation. No licence applies publicly until the reviewed repository and licence files are released.

Sustainable service

Open code, paid operations

Organisations may self-host the released core. ReliefPay can still charge fixed fees for physical cards, supported readers, managed hosting, training and support.

What open will mean

Inspectable infrastructure.

The goal is to let humanitarian organisations inspect, self-host and improve the deployable core. A public repository will become the canonical core only after the release gates are complete; ReliefPay will not maintain a misleading public demo fork.

What open will never mean

  • No card keys, signing secrets or production credentials.
  • No beneficiary identities, PINs or transaction records.
  • No private correspondence, partner notes or business files.
  • No permission to imply ReliefPay endorsement or misuse the ReliefPay name and marks.

Publication gate

Source link withheld until ready.

There is deliberately no public repository link yet. Passing these checks—not a marketing date—changes the website to present-tense open-source wording.

  1. 01Publish an allow-listed repository without private business files, generated exports, credentials or deployment secrets.
  2. 02Complete dependency, copyright and licence review, then add the software and documentation licences.
  3. 03Pass secret and history scans, generate an SBOM, document the threat model and reproduce a clean-clone build.
  4. 04Add contribution, governance, support, security-disclosure, code-of-conduct and trademark policies.