Documentation index

Licensing and Entitlement

Server-Side Enforcement

The on-premise edition validates a signed license on the server before protected operations. Browser code cannot grant a license, change employee limits, or self-attest payment.

Trial and Paid Activation

  1. Sign in to the Project X IT client portal and complete MFA when required.
  2. Open Billing and review the server-calculated amount.
  3. Select an enabled hosted provider such as PayPal, Square, Stripe, or Authorize.Net.
  4. Complete checkout on the provider's site. Project X IT does not receive card, CVV, routing, or bank-account fields.
  5. Wait for the portal to confirm the signed provider webhook, invoice, amount, and currency.
  6. Request the 30-day trial or contracted on-premise license.
  7. Download license.json and store it as a read-only secret.
  8. Mount it at /run/secrets/projectxit-workbench-license.json.
  9. Confirm the local server reports the expected customer, validity dates, modules, and employee limit.

ACH, wire, purchase-order, and provider exceptions require an approved reconciliation before license issuance.

License Contents

The signed file identifies the license, customer, employee limit, optional MSSP managed-customer limit, modules, effective and expiration dates, grace period, support date, optional deployment fingerprint, signer key ID, payload hash, and digital signature.

Project X IT retains the private signing key. The customer installation receives only the public verification key.

Protected Operations

The server checks license state before connector creation and sync, CSV/XLSX import, scanner import, collector-token issuance, evidence upload, report generation, quantitative risk package generation, MSSP workspace creation, and protected API access.

Read-only access may remain available during a contractual grace period so the customer can export data and renew.

Employee Volume

The default unit is active canonical employees. Service accounts, shared accounts, application identities, and faceless enterprise applications do not count as employees, but they must still be discovered and mapped to owners.

Renewal and Capacity

Customer administrators monitor current volume and expiration in Billing. When usage approaches the licensed limit, renew or adjust the subscription before the limit is exceeded. Existing evidence remains readable when the server enters an approved grace state; new imports and synchronization may be restricted according to the contract.