GOpenCNR hub operator agreement
The terms on which a certified operator runs a hub in GOpenCNR's default pool, covering certification, forwarding without inspection, closed routes, hosted routers, the operator's role as our processor for members' data, its own legal duties, and what running a hub earns and what it does not.
This agreement
This agreement is between Gelhaus Solutions, as Tier 0 of GOpenCNR, and the person or organisation that runs a certified hub, the operator. It takes effect when the operator signs it in the GOpenCNR portal for a named hub and Tier 0 certifies that hub, and it then covers every certified hub the operator runs. Publishing it here is not an offer: a hub is certified only under a signed copy of the version current at the time.
The GOpenCNR terms, the acceptable use policy and the network participation agreement bind the operator as a member, as they bind everyone else. The GOpenCNR charter rider gives the operator its council seat. Warranty, liability and law are governed by the general terms of service.
Community hubs are not covered by this agreement. A community hub runs under automated conformance and the network participation agreement: members pick it by name, it never joins the default pool, and it carries open routes only.
What a certified hub is
A hub forwards members' traffic between WireGuard tunnels and runs one BGP session per member, with itself as the next hop. A certified hub is in GOpenCNR's default pool, so members' agents may choose it on their own. It may carry closed routes, and it may host members' routers. It peers with Tier 0's hubs over eBGP under the operator's own ASN.
Certified operators run hubs in the shared network only, and for free. Paid dedicated or private hubs are run only by Tier 0, on its own servers; an operator offers none under this agreement or on GOpenCNR's behalf.
Certification
- Conformance. The hub passes GOpenCNR's automated conformance checks, which test among other things that its filters match the registry, that closed routes reach only their audiences, and that drops are counted and reported. GOpenCNR probes it continuously.
- Three failed probe rounds in a row take the hub out of the default pool, automatically. Members who picked it by name stay on it.
- Yearly remote audit and spot checks. Tier 0 audits the hub remotely once a year and may check it at other times. The operator cooperates with both and gives the information they need.
- The rules for conformance and certification are set by the GOpenCNR Operators Council.
- Losing certification. A hub that fails its audit, or whose operator breaks this agreement, may lose its certification. The operator is told why and may challenge the decision as it would a sanction under the abuse and sanctions policy.
Forward only
The hub forwards. It does not look.
- No inspection. The operator does not inspect, analyse, alter or divert members' traffic, and lets nobody else do so. Between members with agents, the hub carries the inner WireGuard layer as ciphertext and sees only which two routers exchange packets, how large they are and when.
- No traffic records. The hub keeps counters, per member, of bytes, packets and drops by reason, and the state of its sessions. It keeps nothing else about traffic: no flow records, no packet captures, no record of who talked to whom.
- Flow sampling is Tier 0's alone. It happens only inside an open case, for at most 7 days, at 1 in 1,000 packets, and records source, destination, port and size, never content. The operator never samples of its own accord.
- The secrecy of telecommunications. The operator, and every person it lets near the hub, commits in writing to keep the secrecy of telecommunications under Section 3 TDDDG, wherever they are, before they get access. The operator keeps those commitments and shows them in the audit. GOpenCNR and the secrecy of telecommunications sets out what the secrecy covers in GOpenCNR.
Routes
- Closed routes only for their audiences. The hub exports a closed route only to the sessions of the audience's members, and forwards packets into closed space only from audience sources. It never sends a closed route anywhere else.
- Leaks are cut at once. When a closed route arrives from outside its audience, the hub drops the leaking member's closed routes and sessions on its own, a case opens and the holder is told. Nobody confirms a cut, and the operator does not undo one.
- Anti-spoofing and no exit. Each tunnel accepts only sources inside the member's registered space. The hub never carries traffic between the internet and members: traffic leaves it only towards GOpenCNR's ranges or a named interconnect.
Generated configuration only
- The registry is the truth. Every filter, session, tunnel and firewall rule on the hub is generated from registry state and delivered in a signed bundle with a serial number, and a lower serial is refused. The operator changes nothing by hand and adds nothing beside what is generated.
- The limits come with it. Max-prefix (8 by default), the flap hold-down (6 flaps in 15 minutes hold a session for 15 minutes) and fair use (100 Mbit/s sustained per member, with a 200 Mbit/s burst cap, raised on request) are generated with everything else.
- Staged rollout. Hub changes reach a canary hub first and are rolled back when a hub's health regresses. The operator's hub takes its place in that rollout.
- Fail closed. A hub that cannot load fresh data keeps its last good filters and never opens up. The operator does not work around that.
- Maintenance. Before planned work, the operator uses graceful maintenance, which moves members to another hub before the hub drains (RFC 8326).
Software, keys and the host
- Signed releases only. The hub runs the GOpenCNR agent in hub mode, in signed releases only. The operator installs a release marked as a security release within 14 days, as every member must for its agent, and otherwise stays within the supported window: an agent keeps working for 12 months after a newer bundle schema ships.
- Enrolment. The hub enrols with a single-use token that is valid for 24 hours. Its agent key is made on the host, and every request it makes is signed, bound to its body and valid for 60 seconds. The operator keeps the key and the token secret.
- The host. The operator keeps the hub's host patched, gives access to it only to the people who need it, and logs that access.
- Licence. We grant the operator a free, non-exclusive, non-transferable licence to install and run the agent in hub mode, and the configuration it renders, on systems the operator controls, for as long as this agreement lasts and only to run the hub. The agent is proprietary. The operator does not modify it, pass it on or reverse engineer it beyond what Sections 69d and 69e of the German Copyright Act allow.
Hosted routers
A certified hub may host members' routers. A member chooses the hub for its hosted router, and the nearest one is suggested. This clause governs every hosted router on the operator's hubs.
- Where they run. Each hosted router runs on the hub as a network namespace with its own WireGuard interface and firewall, generated from the registry like everything else.
- What the operator holds. The hub terminates the tunnels of the member's devices and holds the hosted router's inner keys, so that it can encrypt onward, end to end, to other members' agents. Between a device's tunnel and the inner layer, the member's traffic is in plain text on the hub. That is why the duties under "Forward only" apply here most of all.
- Keys are born on the hub. A hosted router's keys are made on the hub's host and sealed in its TPM where the hardware allows. They never leave the hub. When the hub is rebuilt or moves, new keys are made and the member's device configs are reissued.
- Counters only. The operator sees how many hosted routers and devices its hub carries and how much traffic each moves, never the traffic itself.
- The label. Devices on a hosted router show "encrypted to <operator>, end to end from there", with the operator's name. The operator accepts being named in that label.
- Closed prefixes. A hosted router counts as an agent router, so its member may use closed prefixes through it, and the hub then holds inner keys for those audiences. They are used for nothing but forwarding.
Cases, leaks and security incidents
- Cases. Abuse is handled in the one case system in GOpenCSR, under the abuse and sanctions policy. The operator answers Tier 0's questions on a case without undue delay, from the counters and session state its hub keeps, and passes any abuse report it receives about a member to abuse@gplatform.org.
- Leaks. The operator helps Tier 0 find out how a leak came about, and keeps what its hub recorded about it until the case is closed.
- Security incidents. The operator reports to Tier 0 without delay, at contact@gplatform.org, every security incident: any suspected compromise of the hub, its host, its agent key or the keys of hosted routers, and anything that disrupts the hub or affects members' traffic. Tier 0 reports such incidents to the Bundesnetzagentur and the BSI under Section 168 TKG, within 24 hours, 72 hours and one month, and needs the operator's report to do so.
- Requests from authorities that concern GOpenCNR members or their traffic go to Tier 0, as the data protection section says, and are counted in the joint transparency report.
Sanctions and emergencies
The sanctions ladder of the abuse and sanctions policy applies to the operator and its hubs as it does to any holder: a warning, reduced max-prefix, routes suppressed at the hubs, depeering from all Tier 0 nodes, and reclaiming the allocation. Each step lasts at least 7 days before the next. For a hub, depeering ends its sessions with Tier 0's hubs.
Tier 0's emergency suspension applies to hubs too, in the cases where the general terms of service let us act first, such as an attack on the network or on others, malware, a match on a sanctions list or a binding order of a court or an authority. It takes effect at once, may only suspend or tighten, never loosen, and lapses after 90 days unless it is reaffirmed, after one year at the latest. The operator receives the statement of reasons no later than when it takes effect, unless the law forbids telling it, is heard afterwards, and may appeal within six months to the GOpenCNR Registry Council, as the abuse and sanctions policy describes. The courts remain open.
No fees, either way
- Neither side pays the other anything. The operator runs its hubs at its own cost.
- The operator does not charge members for GOpenCNR traffic, for a hosted router, or for anything else GOpenCNR provides through its hub.
- What the operator gets in return is standing in GOpenCNR's governance, described below, and nothing else.
The council seat
- The operator's group holds one ex officio seat on the GOpenCNR Operators Council, exercised by its representative, for as long as it runs a certified hub.
- It casts one ballot in elections to the GOpenCNR Registry Council, through its designated voter.
- After 90 days in the hub role, it may also vote in elections to the GOpenCNR Community Council.
- An operator group that also runs audited transit still counts once: one seat and one ballot.
The charter rider sets out what those councils decide.
Data protection: the operator as our processor
For members' data, the operator is our processor under Art. 28 GDPR. It forwards members' traffic and runs hosted routers on our behalf, and Gelhaus Solutions is the controller, as the GOpenCNR privacy notice describes. This section is the agreement Art. 28(3) GDPR requires.
- Subject matter and duration. Running the operator's certified hubs for GOpenCNR's members, for as long as this agreement lasts.
- Nature and purpose. Forwarding members' traffic; terminating their tunnels and BGP sessions; for hosted routers, terminating the tunnels of members' devices and encrypting onward; filtering and counting as the generated configuration says; and reporting counters, session state and health to GOpenCNR. Nothing else.
- Kinds of data. Members' public keys, prefixes, ASNs and sessions; the addresses their tunnels come from; counters per member; for hosted routers, the member's devices and their keys; and members' traffic while it passes through the hub.
- Data subjects. Members, the people who use their routers and devices, and anyone whose communication crosses the hub.
- Our instructions only. The operator processes members' data only on our documented instructions: this agreement, the signed bundles the registry generates, and what Tier 0 instructs in writing in a case. That covers transfers to a third country too. Where the law that applies to the operator requires other processing, the operator tells us before it acts, unless that law forbids it. If it believes an instruction infringes data protection law, it tells us at once.
- No disclosure of its own accord. The operator discloses members' data to nobody, authorities included. A request from an authority goes to Tier 0. Where the law that applies to the operator compels it to disclose, it tells us first, unless that law forbids it.
- Confidentiality. Everyone the operator lets process members' data, or lets near the hub, is bound to confidentiality and has committed in writing to the secrecy of telecommunications, as "Forward only" sets out.
- Security. The operator takes the measures Art. 32 GDPR requires, and at least those this agreement sets: generated configuration only, signed releases, hosted routers' keys born on the hub and sealed in its TPM where possible, a patched host with access limited and logged, and no traffic records.
- Sub-processors only with our authorisation. The operator engages another processor, including the provider of a server or a data centre the hub runs in, only with our prior written authorisation, specific or general. Under a general authorisation it tells us in advance of every intended addition or replacement, so that we can object. It binds each sub-processor by contract to the same obligations and remains liable to us for it.
- Assistance. The operator passes every request from a data subject to us without undue delay and answers none itself, and helps us meet our duties under Arts. 32 to 36 GDPR, breach notices and data protection impact assessments included.
- Breaches. The operator tells us of a personal data breach without undue delay, at contact@gplatform.org, with what Art. 33(3) GDPR asks for as far as it knows it, so that we can notify the supervisory authority and, for telecommunications data, the Bundesnetzagentur and the BfDI under Section 169 TKG.
- At the end. When this agreement ends, the operator deletes all members' data, the keys of hosted routers included, unless a law requires it to keep them, and confirms the deletion to us in writing. There is nothing to return: the registry holds what GOpenCNR needs.
- Audits. The operator makes available everything we need to show that this section is kept, and allows and contributes to audits, inspections included, by us or by an auditor we mandate. The yearly remote audit and the spot checks are such audits.
- Outside the EU and the EEA. An operator established outside the EU and the EEA, in a country without an adequacy decision, signs the EU standard contractual clauses with us, module 2 (controller to processor), as part of this agreement. Where the clauses and this agreement conflict, the clauses prevail. The privacy notice tells members.
- The operator's own logs. The operator is a controller in its own right only for the logs of its own infrastructure, its hosts and its network. It gives the information the law requires for them and keeps no record of members' traffic in them.
- What GOpenCNR keeps. GOpenCNR keeps the counters a hub reports in detail per member for 90 days, then only as daily totals per member up to 12 months, and telemetry and health reports for 12 months.
- Endpoint addresses and audience memberships are never made public.
Where the operator may run, and its own legal duties
- Its own notification. Tier 0's notification to the Bundesnetzagentur covers the network Tier 0 operates, not the operator's. Where the operator's activity needs a notification of its own (Section 5 TKG), the operator files it and meets the duties that come with it.
- Outside Germany, the operator answers for its own local law, including any telecommunications notification or licence it requires.
- Never in a sanctioned country. A certified hub may run anywhere except in a country subject to EU sanctions. Like every holder, the operator is screened against the EU consolidated financial sanctions list from the moment it first became a holder, and every day after.
- Each hub's country is public. The public network map shows the country every hub runs in. An operator outside the EU and the EEA, in a country without an adequacy decision, signs the standard contractual clauses as the data protection section sets out.
Ending the agreement
- The agreement runs without a fixed term.
- Either side may end it with three months' notice, without giving reasons. The operator gives notice in the portal or by email to contact@gplatform.org. Before a hub stops, graceful maintenance moves its members, and the hosted routers on it move to another hub, with their device configs reissued.
- Either side may end it at once for cause. For Gelhaus Solutions, cause includes the hub losing its certification and a breach not remedied after notice.
- Gelhaus Solutions may suspend a hub at once only as an emergency suspension under "Sanctions and emergencies".
- When the agreement ends, the hub's credentials are revoked, the licence ends, the operator's ex officio seat ends unless its group still runs audited transit, and the operator deletes what it holds about members, the keys of hosted routers included, and confirms the deletion in writing. What we keep about the operator afterwards, and for how long, is in the GOpenCNR privacy notice.
Everything else
No service level applies, in either direction. Warranty and liability, including the cap for businesses, are as set out in the general terms of service; for what is given away, liability is limited to intent and gross negligence (Section 521 BGB). German law applies, and where the operator is a merchant, the courts at Gelhaus Solutions' seat have jurisdiction. A material change to this agreement, including one the GOpenCNR Operators Council makes on the topics the fence allows, is emailed to the operator at least six weeks before it takes effect, and at its next sign-in the operator is asked to sign the new version in the portal, which is shown in full and linked in the document archive, without a list of what changed. A new version applies to the operator only once it signs it. Until then, the version it signed stays in force until the agreement ends as "Ending the agreement" sets out, and the operator is not restricted for not signing.