> Do you mean as in auditable?
Auditable is part of it I suppose; but no, that's not what I meant. I meant security in the sense of "do I feel safe that I'm not going to get burned by it?" Specifically, if something goes wrong or I need to self host or it needs to get forked, can the problem be fixed? Security in the sense of "am I tying myself to a service where I have no control?" It's less about fear of getting hacked and more about fear of a service turning into <insert-basically-any-number-of-proprietary-saas-services-from-the-past-few-years-here>.
Source available would be a harder sell for me but depending on the terms not an impossible sell. I do use some source available products, but not a ton of them. My main question when I'm looking at a SaaS service is "what are the situations where I'll suddenly lose access to this?"
Free for non-commercial use only works if it's a product where I absolutely know for certain that I'm not ever going to use it commercially (and I don't just mean selling hosting as a service; if I'm building any product at all that depends on it, I need to know really clearly in the license that I'm allowed to do so). Otherwise, I don't have that sense of security. But there are products I use where that's fine. If it is a purely personal thing where I'm not going to use it as a business, I wouldn't necessarily drop a product over a source available license I guess.
I pay for and I use Aseprite commercially and Aseprite is source-available. But Aseprite is not a SaaS service, and its license explicitly allows me to modify and self-compile it for internal use even commercially. The risks are not very high for me, now that I've bought the thing I'm basically allowed to do whatever with it. If I have to commercially license the product on a continual basis to use it commercially then yeah the auditability is nice, but otherwise I don't really see what the difference is with a proprietary product. If the company gets bought out Google and your product gets canceled or turned into a mess or merged into another Google product, I'm still going to be in the same situation where I won't be able to do anything about it and where I won't be able to self-host.
That's more of what I was trying to get at when I talked about lack of security.
---
I guess the TLDR is that if a SaaS product is actually OSS, my thought is:
- as an individual I'm willing to potentially consider paying for hosting if it's cheap enough, and as company I would pretty much always pay for hosting unless there's a strong reason for me to care about the data storage or customizations.
If it's source available, my thought is:
- as an individual I'm willing to consider paying for hosting depending on my usage, but as a company I'm probably not touching it.
I would only consider using a source-available SaaS product if I'm very confident that my usage is never going to be subject to the restrictions in the license. Note the phrase "using" there; there are some SaaS products that I avoid even though it would be free to use them. For example, I'm never going to choose to build a product I control on top of MongoDB if I can help it; even though I wouldn't have to pay for hosting to do so. Getting back to my original comment, there are two parts to selling SaaS:
1. Convincing me to use the product in the first place
2. Convincing me to pay for hosting
The first step is the hard part, the second step is the easier part. If I feel comfortable using it, it's not that hard to convince me to pay for hosting. For the most part, I do not want to self-host most of my software; I want that to be someone else's problem. But I'm never going to get to the "pay for hosting" step if I don't feel comfortable using it.
At its best, SaaS should make me feel like I'm getting rid of a dependency, that there's a part of my infrastructure I don't need to worry about because someone else is handling it. At its worst, SaaS introduces a new dependency because it means that I can lose access at any time and that any infrastructure I build around having access can be rendered useless at any time. At its best, SaaS makes my infrastructure more robust by delegating responsibility, at its worst it makes my infrastructure more fragile because it introduces another point of potential failure if the service goes away or becomes unusable.
And the license is very often the biggest thing that determines which of those scenarios is the case for a given service.