Governance and working group
The open licence, the public working group, the initiator and first maintainer, the hand-over clause, and how forking keeps versions and maintainers accountable.
No single party owns this standard, can change its normative core, or can withdraw it. Four mechanisms make that true and verifiable: the open licence anyone can build on, the public working group, the separation of specification from implementation, and the clause that transfers stewardship.
Licence
The protocol and its specifications are published under an open, royalty-free licence with an irrevocable patent non-assertion covenant; the reference implementation, including its state machines, is licensed source-available under the Business Source License 1.1, which converts to the Apache-2.0 open-source licence two years after each version's release and whose additional use grant makes self-hosting free for everyone, governments included. You are free to implement them, fork them, and run them without charge or permission. There is no registration requirement and no fee for self-hosting. The full texts are on the licence page. The licence exists to make neutrality verifiable in practice, not dependent on a commercial relationship.
The source code of this website is licensed under the MIT licence, so the site itself can pass to a future steward without relicensing. The MIT grant covers the website code only: the specification texts follow the protocol licence above, and it conveys no rights to the SDX Protocol name or marks.
Working group
The standard is developed in public, and anyone can join the working group: organisations, implementers, and domain experts who want to review the specification, propose changes, or help define taxonomies. Domain taxonomies belong to the working-group members who propose and ratify them, not to one party; a group can join an existing taxonomy effort or start a new one where a field needs its own shared meaning. The normative core cannot be changed unilaterally. There is no central gatekeeper.
Initiator and first maintainer
mintBlue is the initiator and first maintainer of the base protocol. The model is the one open infrastructure has used for decades: a founding organisation maintains the work while the community forms, and the standard itself stays open and implementable by anyone.
The initiator is not the owner. The maintainer role is temporary and transferable. The normative core is separate from any reference implementation, and the specification cannot be changed by one party acting alone. Those three constraints are part of the governance design, which is why a single initiator does not undermine the neutrality of the standard. The current role is practical stewardship: keeping the first version coherent and preparing the work for transfer as participation grows.
Hand-over clause
Stewardship passes to the working group once at least three parties are actively implementing the protocol, participating in working-group discussions, and ratifying taxonomy changes. That clause was built into the governance model from the start, not added after the fact.
Version 1 does not claim an independent foundation, committee, or not-for-profit body. Neutrality in V1 rests on three things that exist today (an open working group anyone can join, the separation between specification and implementation, and the built-in transfer clause), plus the open, royalty-free licence.
The intended end state is a step beyond the working-group hand-over: stewardship housed in an independent steward-owned or not-for-profit entity that owns the standard and commissions maintenance, so that neutrality no longer depends on any commercial party, including the initiator. That structure is in development. This page will name the entity and its statutes when they exist; nothing about the current transfer conditions changes until then.
Versions and forks
The base layer is deliberately minimal. It fixes how data is addressed, exchanged, and verifiably recorded, and nothing else: it contains no decision that binds a participant to one provider, one implementation, or one domain's way of working.
Domain taxonomies do evolve. A working group can publish a new version of its taxonomy at any time, and adopting it is each participant's own decision, coordinated with the counterparties they exchange with. Versions are explicit, so parties always know which agreement a given exchange follows, and nobody is upgraded by someone else's timetable.
Because everything is open, anyone who disagrees with a choice can fork a taxonomy, or the specification itself, and take their own path. A fork carries exactly as far as others choose to adopt it. That is not a weakness of the model; it is the check that keeps every maintainer honest, including the first one.
A fork has one natural boundary: the public audit layer. Exchange mechanics, encryption choices, and domain taxonomies can all be revised or replaced, but as long as every party keeps anchoring to the same audit layer, every exchange stays verifiable across versions and forks, and everyone stays accountable to the same record. Splitting the record itself is the one move that breaks this. Earlier attempts at shared record-keeping that forked their audit trails ended up rebuilding exactly the disconnected silos they set out to remove.
Open and paid
The protocol, its specifications, and its state machines are all free. Everything needed to build, host, and operate an interoperable implementation is source-available and free to self-host: an organisation can run the full stack itself, commission an implementation from another party, or test compatibility against the public rules. There is no licence fee for self-hosting, no activation requirement, and no required integration with any managed service. The one case the reference implementation's licence prices is operating it as a hosted service for third parties; those terms are public, fixed and identical for every licensee, on the licence page.
The paid route is managed provisioning: a provider operates an implementation for organisations that do not want to run the infrastructure themselves, with one-click set-up, operational scale, and service-level commitments. Any conforming provider can offer this; the initiator is simply the first to do so. Paying for provisioning does not buy access to the protocol, control over the specification, or permission to participate. The choice is the same one organisations know from other open infrastructure: run the open software yourself, or pay someone to operate it with guarantees. The standard is identical in both cases.
Join the working group
If you are building on this standard, or evaluating whether to, the working group is the place to raise questions, follow new versions, and take part in taxonomy work for your field. Leave a note below and you will hear from the maintainer as the working group takes shape. One entry point keeps early conversations in one place, with an optional line for the areas that interest you, and per-domain channels can be added as participation grows.
What this adds beyond eDelivery and AS4
How the protocol compares with the EU's four-corner messaging infrastructure, what AS4 does better, and when each is the right choice.
Licence
The open, royalty-free licence for the specification texts and test vectors, with a patent non-assertion covenant, and the Business Source License 1.1 with FRAND terms for the reference implementation.