Vigil Core, free and open source under Apache-2.0
The free edition is the whole monitor.
Both editions are 1.30.0, cut from one commit.
Vigil Core is real free software under Apache-2.0: all forty of Core's check types behind a registry, adaptive intervals down to two seconds and to 500 ms for HTTP, JSON-query and TCP, the condition engine, incidents with failure windows in seconds, as many status pages as you like, public, private or password-protected, with subscribers, four team roles, the audit page and the observation ledger. Every release is cut by stripping the commercial code out and running the whole suite, the migrations and a live smoke test against what is left. No license key, no telemetry, no expiry, and no cap on monitors, members or retention. What follows is the mechanism that keeps the two editions in lockstep, because the mechanism is the part worth checking.
Both editions are cut from one commit.
Commercial code is marked in place in one canonical repository. A script strips those markers to produce Core, and the same script runs in the build gate and the publish job, so the two editions cannot disagree about what Core is.
Against the paid edition
Everything the commercial edition has and Core lacks is something Uptime Kuma also lacks, with one exception: Kuma has maintenance windows and Core does not. Core has the check-type registry and all forty types, adaptive intervals, failure windows measured in seconds, the two-second scheduler floor and the 500 ms plane for HTTP, JSON-query and TCP, the condition engine, the ledger, the audit page, status-page subscribers and password-protected pages.
Core has no team-size cap. A 100-member limit inherited from a library default was removed, with a test that builds a 132-member organization and fails if either half of the fix is dropped.
In lockstep
Each Vigil Core release is cut from the same commit as the commercial release with the same number. If Core's version number ever lags, the mechanism is broken and you can see it from the outside. What the license commits to ↗ is written down and dated.
Exactly what is in each edition today.
As it stands right now. If a row is in Core, it is in Core forever. The free edition is not a funnel with a timer on it.
Three walls. If you never hit one, stay free.
Stated in advance so the decision is yours rather than a surprise four weeks in.
The multi-tenant wall
Core runs one organization per install. Fine for a team watching its own systems. If you monitor for clients and each needs their own workspace, with data one client's login cannot reach, you would be running one install per client, which is when the commercial edition's multi-tenancy pays for itself immediately.
The recovery wall
Core tells you something is down. It does not act on it. Automatic recovery, verify the failure, call your restart hook with a signed payload, verify the fix, hold the alert while it tries. Is the commercial edition's reason to exist. If a human is going to run the same restart command anyway, that loop is what you are buying.
The on-call wall
Core reaches you, by email or any of the 25 native provider types. It has no concept of whose turn it is. The commercial edition decides which of us it reaches, in what order, and what happens when nobody answers: rotations, escalation ladders with per-step delays, acknowledgement that stops the ladder, and SMS or voice through your own Twilio account. The second name on the rota is the moment this matters.
If none of these walls apply to you, Core is the right answer.
Open source as evidence.
An unknown company asking $149 for software you cannot inspect is asking for trust it has not earned. Publishing the engine under a real license answers that, and it costs the seller something.
Core is the checker, the incident state machine, the status page and the role system: the parts you would need to read to judge whether the paid edition is competent. Reading them is the point.
Since 1.11.0 the line between the editions is drawn in one place: everything the commercial edition has that Core does not is something Uptime Kuma does not have either, with one exception: Kuma has maintenance windows and Core does not. The paid edition charges for many client organizations, on-call rotas, probes inside networks nothing external can reach, and a system that acts on a failure. Monitoring capability stays free.
The rules Sikur holds its products toAsked by people deciding whether to trust this.
No. Nothing is gated behind a license key, there is no telemetry, nothing expires and no feature stops working after a while. Core runs one organization, and it has no on-call, escalation or automatic recovery; the edition split is written out in full on this page. If Core as it stands is all you need, that is the intended outcome.
Almost nothing. Keep the license and NOTICE file with copies you pass on, say what you changed, and do not use the Vigil name to imply we endorse your fork. That is the whole of it. You may modify Core, keep the changes private, run it for clients and even sell it, with no copyleft obligation of any kind. Core was AGPL-3.0 until July 2026, which asked more: modifying it and serving that version over a network required publishing your changes. That requirement is gone.
For features that matter at agency scale: automatic recovery, many client organizations in one install, on-call rotations with SMS and voice. Check types are not on that list and will not be; every check type ships in both editions. Core was AGPL-3.0 until July 2026, which gave the commercial license a second job, lifting the copyleft obligation. Core is Apache-2.0 now, so that reason is gone.
Yes. Since 1.11.0 both editions are cut from one tree and share one migration lineage, so Core → commercial is exactly what it should be, a license change plus additive migrations, with your monitors, incidents and history untouched. An install still on Core 1.0.x predates that lineage and needs a hand-assisted step first; write before upgrading and it gets planned. The upgrade guide covers taking updates after you have customized the code.
Core is Apache-2.0 and already published, so it cannot be withdrawn. You can fork it, run it and modify it regardless of what happens to the company. A commercial license covers every version its holder already has, and there is no license server that could switch anything off.