Leadership - 2026-08-23 - 4 min read

I Said Closed Source Isn't a Moat. Here's What I Keep Closed Anyway.

The line between what to open-source and what to keep closed isn't about secrecy as a moat — build-time artifacts get more valuable by being public, while a runtime platform stays closed until switching-cost gravity, not hidden code, gives it real defensibility.

Open SourceMoatOrvenaPlatform Strategy

Originally published on LinkedIn on August 23, 2026.

Last post I argued that if secrecy is doing the load-bearing work in your defensibility story, you don't have a moat, you have a head start. A fair reader would turn that around on me: then why is half of what I build closed? Orvena's source is public. The writing is public. The multi-tenant platform I'm building underneath — the part designed to make money — is not. If closed source isn't a moat, what exactly am I doing?

The answer is a rule, and I think the rule is more useful than any individual call it produces.

Everything I build gets sorted by one question: is this a build-time artifact or a runtime service? Build-time artifacts — reference skeletons, scaffolds, the worldview writing, a containment runtime you run on your own machine — get more valuable by being public. Their whole job is to be seen, argued with, and trusted, and you can't earn trust with a repo nobody can read. Runtime services are different in kind: a platform where a tenant's schema is stored as data, where their records accumulate, where the APIs grow at execution time around what they've built — that's where someone else's working life ends up living. Anything with that runtime smell goes on the closed side. Not because the code is precious, but because the business, if it ever works, works there.

Here's the part I want to be precise about, because it's where the last post and this one have to agree. The closed side's defensibility — if it ever earns that word — will not come from the source being hidden. It will come from switching cost: tenants whose data, schemas, and integrations have grown into the platform. That kind of gravity is model-neutral; it doesn't erode when the next frontier model ships. And today it does not exist. I have one internal tenant, whose real data runs tenant-isolated on the platform. That proves tenants can grow here. It proves nothing about whether anyone will pay to. Zero external paying tenants means the closed side is currently an option, not a moat, and I make myself use that word.

So why not open it anyway, by my own argument? Because a head start isn't a moat, but it isn't worthless either. Until the gravity exists, the head start is the only asset that side of the line owns, and giving it away buys nothing: what's blocking adoption isn't that people can't read the source, it's that they don't yet know or trust the thing exists. That problem is solved on the public side — the runtime you can inspect, the benchmarks with their caveats attached, these posts — not by donating the one asset the commercial side has before it can defend itself. Openness where openness compounds; reserve where reserve is the only thing you've got.

The line itself is written down, dated, and versioned, like the rest of what I've shown in this series. It comes with a working rule anyone can apply to their own stack, and with a condition under which the line stops meaning what I think it means — if the first ten buyer conversations say they'd rather own a copy of the code than rent a hosted platform, then the closed side isn't a moat in waiting, it's inventory, and I'd have to treat it that way. That would be the market telling me something, not a defeat. I've also gone the other direction: I parked an open-source project this year when the premise it was betting on didn't survive contact with reality. The rule cuts both ways or it isn't a rule.

Four posts ago I said the scarce thing is judgment you can inspect. This is what that looks like applied to my own business: not "open good, closed bad," and not the reverse — a boundary with a reason, a date, and the terms on which I'd move it.

Working on something like this?

I help teams ship AI-native systems — architecture, governable autonomy, and the evidence discipline to back them. One conversation is enough to see whether it fits.

Discuss fit