Cal.com switches from open source to closed source over AI security threats
Key point
Cal.com has stopped disclosing its source, citing the rise of AI-driven vulnerability discovery.
Details
Cal.com is ending its 5-year run of open-source operation and switching to closed source.
The core reason is the rapid rise of AI-based security threats. In the past, exploiting vulnerabilities required time from a skilled attacker, but now AI can quickly analyze a codebase to find vulnerabilities and even generate exploits. The company judges that public code acts like a blueprint for attackers, creating greater risk to protecting customer data.
Rather than abandoning open source entirely, the company has released a separate community project called Cal.diy under the MIT License. This version is open to developers and hobbyist users and supports self-hosting. However, the main service's codebase has undergone major changes to its authentication and data-processing architecture, making it technically separate from Cal.diy.
Cal.com has also stated that this decision isn't a permanent end, and that it wants to return to open source once the security environment stabilizes. For now, its position is that mitigating security risk and protecting users comes first.
The comments section featured a lot of pushback against this decision.
- The argument that if AI has made vulnerability discovery easier, open source could actually help distribute the cost of auditing
- Suspicion that the real reason isn't security but rather protecting the business or preventing cloning/copying
- Conversely, a pragmatic view that for products with frequent commits, having to run the entire codebase through an LLM check every time could cause maintenance costs to surge
Ultimately, this case shows that the security realities of the AI era are changing the software distribution model itself.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.