Skip to content
Gelhaus Solutions
Apps Services Security Contact
EN DE
Apps / GOpenCNR / GOpenCNR terms

GOpenCNR terms

What membership of GOpenCNR gives you and what it does not, how allocated space stays with you and returns to the registry, how members are restricted and can challenge it, and what is public.

Last updated 1 October 2026 Auf Deutsch lesen →

On this page

  1. What GOpenCNR is
  2. These terms and the other documents
  3. Becoming a member
  4. What you get
  5. Space is allocated, never owned
  6. Keeping your space
  7. Using GOpenCNR
  8. No service level
  9. Your abuse contact
  10. What may be restricted, and how it is decided
  11. Emergency suspension
  12. What is public
  13. When membership ends
  14. Your content, your account and these clauses
  15. Changes to these terms
  16. Everything else

This applies alongside the general terms of service and privacy policy. Where they differ on a point about GOpenCNR specifically, this page wins.

What GOpenCNR is

GOpenCNR, the Gelhaus Open Community Network Registry, is a registry-run private overlay network. One registry allocates globally unique private IPv6 space, IPv4 space on request and autonomous system numbers (ASNs) to its members, and the network routes between them over WireGuard and BGP through hubs, encrypted end to end between the members' agents. It works alongside the internet: your internet connection stays as it is, and GOpenCNR adds a private network between members. Gelhaus Solutions operates the registry at cnr.gplatform.org, its RPKI and its own hub, as Tier 0.

Traffic between members passes through hubs: Tier 0's own, certified hubs run by other operators under the hub operator agreement, and community hubs that members pick for themselves and that carry open routes only. Audited members may also carry other members' open routes under the transit operator agreement. Hub and transit operators may be based anywhere except in a country subject to EU sanctions, and each answers for its own local law. A certified hub operator, and an audited transit operator, handles members' data for us as our processor under its agreement; one based outside the EU or EEA, and outside a country with an adequacy decision, also signs the EU standard contractual clauses. The public network map shows each hub's country. Certified operators run only hubs in the shared network, and none of them may charge you for GOpenCNR traffic. Dedicated or private hubs are run only by Tier 0, on its own servers, under the enterprise terms.

These terms and the other documents

Your G Open account, the one account for GOpenCDR, GOpenCNR and GOpenCSR, is governed by the GOpenCSR terms and the GOpenCSR acceptable use policy, which you accepted at sign-up together with the general terms of service. These terms and the GOpenCNR acceptable use policy are added when you become a GOpenCNR member, and you accept both at that step. Every router you connect also comes under the network participation agreement, and a member who joins during the beta accepts the beta participation agreement as well.

The general terms carry warranty, the limits of liability, the governing law and everything else that is not particular to GOpenCNR. What we process about you is in the GOpenCNR privacy notice, and what the network sees of your traffic is in GOpenCNR and the secrecy of telecommunications. The provider is Gelhaus Solutions, whose details are in the legal notice.

Where two of these documents speak to the same point, the one written for the role in question wins on that point, and an agreement signed by both sides wins over anything published here. A document signed by one role binds nobody else: a member is not a party to the hub operator agreement and cannot be held to anything in it.

GOpenCNR is governed under the shared part of the governance charter, which binds all three products, and the GOpenCNR charter rider. The GOpenCNR Registry Council sets network policy, the GOpenCNR Community Council creates address pools and may release quarantined space early, and the GOpenCNR Operators Council looks after hub and transit matters.

Becoming a member

People aged 16 or over and verified organisations (companies, associations, public bodies and registered groups) may hold space in GOpenCNR. If you are under 18, you need the consent of a parent or guardian, as the GOpenCSR terms set out (Sections 107 and 108 BGB). An organisation is verified under the organisation verification terms: a registered entity with a DNS TXT record and a register extract, an unregistered group or a public body with the DNS TXT record alone. The record is checked again every day. If it or the domain is gone for 30 days, the organisation shows as not verified: what it holds keeps working, but it gets nothing new until it is verified again.

Joining is by invitation. An invitation is for one email address, works once and is valid for 30 days, and every invitation names a member, or Tier 0, who vouches for you. Your voucher is named on any case against you for 12 months. That does not make the voucher liable for what you do; it puts on record who brought you in. Each member may vouch a limited number of times, and the account shows the limit.

No tunnel comes up for you until your account has a verified email address and a passkey and somebody has vouched for you, and, where you join for an organisation, until the organisation has passed verification.

When you become a member, you give your legal name and your country. They are used for sanctions screening, seen by Tier 0 only, never public and never in RDAP, and kept while you hold resources and for 12 months after. An organisation is screened by its verified name and country. Every holder is screened against the EU consolidated financial sanctions list when it becomes a holder, and every day after.

A possible match places holds at once: no new names or addresses and no transfers out, while what already exists keeps working. These holds are automated decisions within the meaning of Art. 22 GDPR: the name and country are compared with the list, near matches included, and a match places the holds without anybody deciding. They are permitted because they are needed to perform the contract and to comply with the EU sanctions regulations (Art. 22(2)(a) and (b) GDPR), with the safeguards of Art. 22(3) GDPR: a person at Tier 0 reviews every match, and you may ask for a person to look at it, give your view and contest the decision, at contact@gplatform.org. Tier 0 then either clears the match, recording why, or confirms it under the four-eyes principle, which blocks the holder's names and addresses together.

Only you and Tier 0 know that a review exists. Anybody else sees only that something "cannot be added right now". No screening outcome tied to a holder is written to the transparency log; the joint transparency report counts them, and nothing more. The GOpenCSR terms and the GOpenCNR privacy notice describe the screening in full.

You become a member when you accept these terms and the acceptable use policy and sign your first space. GOpenCSR records which versions you accepted, and when, by their identifiers in the document archive.

What you get

  • IPv6 space: a /56 for a person or a /48 for an organisation, from fdc0:0900::/24, placed so that it can grow where it is.
  • IPv4 space, on request: a /29 from 10.113.0.0/16, or from a further pool when that one is full or collides with your own network. 198.18.0.0/15 is used only if you opt in, because some proxy tools treat it specially, and 240.0.0.0/4 is an opt-in experimental pool that Windows refuses.
  • One ASN from AS4223000000 to AS4223009999.
  • A name under the GOpenCDR TLD gnet for your devices and services, free of charge. It counts toward no standing in GOpenCDR.
  • A reverse zone for each allocation, created with it and either hosted for you or delegated to your nameservers.
  • A hosted router, created when you join, so that a first phone or laptop can connect at once.
  • Alerts when a prefix of yours is hijacked, leaked, invalid or withdrawn.
  • Closed prefixes on request, reachable only by an audience you choose. The prefix, your handle, its origin ASN and its ROA are public like those of any prefix; only its reachability is closed, and the audience and the routes to it stay private. Tier 0 approves each request under the four-eyes principle. Closed prefixes are free for every member: money buys capacity and service, never safety.

Larger allocations and further ASNs need a written justification, which Tier 0 reviews under the four-eyes principle against thresholds set by policy. Wherever these terms name the four-eyes principle, an approval that Tier 0 gives alone, while it is one person, is flagged as decided alone. Address pools are created only by a motion of the GOpenCNR Community Council. An organisation may delegate parts of its space to sub-holders, with roles of their own.

You may also bring an ASN you already hold: a dn42 ASN with a signature from its dn42 maintainer key, a public ASN with an RPKI Signed Checklist or a token in its RIR's aut-num object. Such an ASN is recorded, never allocated: GOpenCNR records that you hold it, and it stays held where it was assigned. The proof is checked again from time to time, and while it has lapsed, routes with that origin are refused.

Space is allocated, never owned

An allocation gives you the right to use the space and the ASN in GOpenCNR for as long as you keep it up and keep these terms. Addresses and ASNs are allocated, never owned and never sold. An allocation is not your property, and because these are private ranges, it gives you no claim against anybody who uses the same addresses outside GOpenCNR.

The right belongs to the holder. It moves to another holder only by transfer: both holders consent by signing it, Tier 0 reviews it, and it is recorded in the transparency log. A transfer is never made for payment. Both holders confirm that no money or goods change hands, and Tier 0 declines a transfer that is a sale.

Keeping your space

Reconfirm once every 12 months. One click is enough, and one reconfirmation covers everything the holder holds. If it does not arrive in time:

  1. Grace, 30 days. Your routes stay. Reconfirming restores everything as it was.
  2. Redemption, 30 days. The hubs refuse your routes, but the space stays yours. Reconfirming restores it.
  3. Reclaim. When redemption ends, the space is reclaimed and rests in quarantine for 3 months before anybody else can have it. A motion of the GOpenCNR Community Council may release it earlier. Announcements of quarantined space are dropped.

Space never announced for 12 months is warned about too, and reclaimed 90 days after the warning unless you announce it.

We write to the address of your account before each step. Grace and redemption begin on their dates without anybody deciding; reclaiming space is approved by Tier 0 under the four-eyes principle.

Using GOpenCNR

Commercial use is allowed. You may connect your company's sites, run services for other members and charge for your own services. Reselling GOpenCNR itself, meaning its addresses, transit or tunnels, needs Tier 0's agreement.

There is no exit to the public internet. GOpenCNR never carries traffic between the internet and other members. The hubs forward a packet only where its source and its destination both lie inside GOpenCNR's ranges or a named interconnect, and drop and count everything else. You may still expose your own service on your own internet uplink, outside GOpenCNR. The interconnects with dn42 and NeoNetwork carry open prefixes only. Routing between GOpenCNR and the public internet is offered only under terms of its own: the hosted ASN and public pool terms and the licensed exit operator terms.

Fair use. Each hub limits each member to 100 Mbit/s sustained, with bursts capped at 200 Mbit/s. The limit is raised on request, and bulk traffic belongs on a direct peering session.

What the hubs see. Between two agents, a hub forwards ciphertext. Hubs keep per-member counters, fine-grained for 90 days and then as daily totals until 12 months, and no records of your traffic. The secrecy of telecommunications binds us and every hub operator.

You sign your own changes. Every change to your objects is signed by you: in the browser with a passkey in the signing step on csr.gplatform.org, or by automation with an Ed25519 key you registered under a passkey. Each signed change is recorded in the transparency log, and its receipt is its log entry with an inclusion proof. You are told of every change to your objects, including changes Tier 0 makes. If a key is compromised, revoke it: the portal lists every change it signed, and the objects it signed stay frozen until you sign them again.

Routers and devices. Each router you enrol comes under the network participation agreement. Devices connect through your own router or your hosted router, and each shows how it is protected.

The API at csr.gplatform.org/api/cnr/v1 is used under the GOpenCSR API terms.

No service level

No service level applies. No availability, capacity, response time or restoration time is owed, whatever the status page, the network map or anybody says. When GOpenCSR or the transparency log is down, accepted changes wait and are logged when it returns, and routers keep running on their last signed bundle. A hub that cannot load fresh data keeps its last good filters and never opens up. Help is available through the portal, the community channels and contact@gplatform.org, with no response time owed.

Your abuse contact

Every holder has a public abuse relay address in GOpenCSR, which forwards reports to the holder. Keep it delivering to somebody who acts, and answer within the times the acceptable use policy sets: you act first on anything reported about your space, and Tier 0 steps in only when you do not.

Tier 0 does not police content. You answer for what you run and host on your addresses. A report of unlawful use goes through the case system to you, and a holder who ignores a well-founded report can be restricted, as an upstream provider would restrict a customer.

What may be restricted, and how it is decided

This section is also the information Art. 14 of the Digital Services Act requires. It applies with the general terms of service, which set out in full how we restrict, suspend and end, and adds what is particular to GOpenCNR.

What can happen. Under the sanctions ladder, a holder can be warned; have its max-prefix limit reduced; have its routes suppressed at the hubs; be depeered from all of Tier 0's nodes; and have an allocation reclaimed. In an emergency, an allocation can be suspended at once, so that the hubs refuse its routes. A possible sanctions match places the holds described above. A sanction may cover a holder's names in GOpenCDR and its addresses in GOpenCNR together.

On what grounds. Abuse as the acceptable use policy defines it, a breach of these terms or of the network participation agreement, a binding order of a court or a competent authority, and a confirmed match on the EU sanctions list. We do not judge content or speech at the network layer. A holder is not restricted because of what a service on its addresses says, unless it ignores a well-founded report of unlawful use, or a court or an authority orders us to act.

Who decides, and how. Every report becomes a case in GOpenCSR's one case system, run under the abuse and sanctions policy. The holder acts first, and Tier 0 steps in when the holder has not acted within the times the acceptable use policy sets. A person at Tier 0 decides every step of the ladder, under the four-eyes principle. Each step is an action in the case that the holder is told of, and each step lasts at least 7 days before the next; only an emergency suspension acts faster. Monitoring, the collector's alerts and the hubs' counters find candidates and never decide on their own.

Some things happen without anybody deciding, because they follow from rules rather than from a judgement: the hubs refuse routes that break the routing rules; they drop a leaking member's closed routes and sessions at once when a closed route appears outside its audience; they hold a session that flaps 6 times in 15 minutes for 15 minutes; and they limit traffic above fair use. Grace and redemption also begin on their dates, and a possible sanctions match places its holds until a person at Tier 0 has reviewed it.

What you are told. You get a statement of reasons no later than when a measure takes effect: what was done, why, under which rule and on which facts, whether it followed a report, our own findings or an automatic check, how long it lasts, and how to challenge it. Before your membership is suspended or ended on these grounds, you are told what is intended and why, you can respond, and Tier 0 decides again in the light of your response. Tier 0 acts before hearing you, and hears you afterwards, only in the cases the general terms name, as in an emergency suspension below; even then, the statement of reasons reaches you no later than when the measure takes effect. Where the law forbids telling you, you are told as soon as it no longer does. Every step of the ladder and every emergency measure is recorded in the transparency log; a screening outcome never is.

How to challenge it. Reply to the notice, or write to contact@gplatform.org, within six months. The GOpenCNR Registry Council hears the appeal, or, where what led to the decision happened in another product, the Registry Council of that product; the statement of reasons names which. The person who took the decision does not vote on it. As long as Tier 0 holds the council's seats, Tier 0 reviews the appeal itself and says so in its answer. A measure stays in place while the appeal is heard, and the answer gives reasons. The courts remain open to you whatever the outcome.

Points of contact. For authorities, and for anyone using GOpenCNR, the single point of contact under Arts. 11 and 12 DSA is contact@gplatform.org, in English or German. Abuse reports go to abuse@gplatform.org.

Emergency suspension

Where one of the cases in which the general terms let us act first cannot wait for the steps above, such as an active attack on the network or on others, malware or phishing, or a threat to life or limb, Tier 0 may act at once. An emergency measure only suspends or tightens, never loosens. It is recorded in the transparency log, you receive a statement of reasons no later than when it takes effect and are heard afterwards, and you may challenge it as above. It lapses after 90 days unless it is reaffirmed, and after one year at the latest.

What is public

Some things are public by design, and it is worth knowing which before you join:

  • Registry data. For each allocation: the holder's handle (a person's name only if they choose it), the prefix, its size and dates, whether it is open or closed, the origin ASN and the abuse relay address. It is served through the portal, RDAP (with admin and tech contacts redacted), RPSL and an IRR server, whois on port 43, NRTMv4, dn42-format exports, and a signed export with a change journal that is also published as a read-only git repository. A closed prefix is public like any other; only its reachability is closed. The public history is kept for good: past states of the registry, the change journal and the git copy. If you withdraw your name as your handle, it leaves current pages, interfaces and later export states; past states keep it, and a request to remove it from the history is weighed case by case under Arts. 17 and 21 GDPR. The registry data policy says what may be seen and by whom. Your endpoints, the members of your audiences, and your legal name and country are never public.
  • RPKI. The ROAs and ASPA objects made from the registry are published in the RPKI repository at cnr.gplatform.org.
  • The transparency log at csr.gplatform.org/tlog holds every registry change with its holder's signature, and the events of Tier 0, of operators and of governance. Audiences and endpoints appear in it only as hashes, each with a random salt that only the holder and accepted peers receive, with the receipt, so that they can check the entry and nobody can guess what lies behind it. It holds no email address, no name, no screening outcome and none of the addresses your routers and devices connect from. An entry in it cannot be removed, because removing one would break every checkpoint signed after it.
  • The looking glass shows open routes to everyone. Members also see the closed routes of the audiences they are in.
  • The network map shows the hubs, each hub's country, how many members each serves and their aggregate health, never an endpoint address.
  • The route collector publishes MRT dumps of open routes every 15 minutes, kept for 2 years.

When membership ends

You may return space, unenrol routers or end your membership at any time in the portal. We may end your membership on the grounds and in the way set out above, or without giving reasons, with at least four weeks' notice by email, as the general terms allow for a free service. If we stop offering GOpenCNR altogether, we tell you at least 60 days ahead, as they set out. Closing your G Open account ends what you hold as a person; what an organisation holds stays with the organisation. Allocations also end when redemption runs out, when unused space is reclaimed, when your membership ends, and through a decision under the sections above.

Space you return, like reclaimed space, rests in quarantine for 3 months. Routers are unenrolled and their keys revoked, and your hosted router is switched off. After your membership ends, you can have your data exported for 30 days, as the general terms set out, by writing to contact@gplatform.org. Data about a resource that is not public is deleted 12 months after the resource ends; the public history of the registry and the entries in the transparency log stay. What we keep afterwards, and for how long, is in the privacy notice.

Your content, your account and these clauses

The general terms of service set out in full the licence you give us to your content, how we may move your account between our own sign-in services, how new terms come into force, and how we restrict, suspend and end. This section adds only what is particular to GOpenCNR.

Your content. You keep all rights in what you submit. In GOpenCNR, the licence covers the registry objects you create and sign (allocations, ASNs with their ASPA providers, routes, the services you declare, reverse zones and delegations to sub-holders), the justifications and requests you write, your routers' and devices' public keys and endpoints, and what your agent reports: health reports, other telemetry and measurement results. It is used only to run GOpenCNR. For that purpose only, we may sublicense it to:

  • IONOS SE, which hosts the registry, Tier 0's hub, the route collector, the RPKI repository and our mail server for us;
  • GOpenCSR and GOpenCDR, our own products: GOpenCSR for signing, cases and the transparency log, GOpenCDR for your name under gnet and your reverse zones;
  • the hub and transit operators that carry your traffic and routes, the witnesses that cosign the transparency log, and anyone mirroring the public registry or the log, to serve and verify it;
  • a successor of the business and companies affiliated with Gelhaus Solutions, as the general terms set out.

Showing your content where GOpenCNR shows it (registry data to the public, your endpoint to a peer you accepted, a closed route to its audience, open routes to the networks GOpenCNR is interconnected with) is part of running the service and gives nobody a licence. Nobody receives a licence to your content for their own purposes.

What is permanent. These are permanent records, and this is your notice of it before you submit them: the public history of the registry (its past states, the change journal and the git copy), every entry in the transparency log, the MRT dumps the route collector publishes, and the RPKI objects published in the repository. For them the licence has no time limit: you allow us, and anyone mirroring or verifying the record, to copy and publish them as part of it, as the general terms set out. We keep published MRT dumps for 2 years. How a name you withdraw as your handle is treated is set out under "What is public" above. What is never public, such as your endpoints, your audiences and what your agent reports, is never a permanent record.

Your account. Your G Open account is kept by GOpenCSR and governed by the GOpenCSR terms. The move between our own sign-in services that the general terms allow is, for your account, the move of sign-in to GPlatform SSO, set out in the sign-in transition terms. Your space, your routers and their keys stay in GOpenCNR, and the move does not touch them.

GOpenCNR membership is free of charge. So when new terms come, the general terms' rule for free services applies: if you have not accepted the new version when the six weeks' notice is over, your use of GOpenCNR is restricted until you accept, in the way the general terms set out. The restriction does not itself end anything you hold: your allocations and routes stay in place, and your routers keep running. While it lasts, though, you cannot reconfirm your space, so a yearly reconfirmation that falls due goes through grace and redemption as usual, as "Keeping your space" describes. If you, or an organisation you act for, have a paid order with us, such as under the enterprise terms, your use is never restricted this way: you stay on the version you accepted until we end the paid contract at its next ordinary end date, as the general terms set out.

Changes to these terms

These terms change only as the general terms set out under "New versions of these terms". A material change is emailed to your address at least six weeks before it takes effect, and at your next sign-in you are asked to accept the new version, which is shown to you in full and linked in the document archive. A new version applies to you only once you accept it. What applies if you have not accepted it when the six weeks are over is set out under "Your content, your account and these clauses" above. Every version stays in the document archive, so the version you accepted stays readable.

Everything else

Warranty, service levels and the limits of our liability are as set out in the general terms of service, which govern GOpenCNR and are not restated here. GOpenCNR is provided free of charge, and for what is given away, liability is limited to intent and gross negligence (Section 521 BGB). The enterprise offer and the public-internet offers have terms of their own: the enterprise terms and order form, the hosted ASN and public pool terms, the LIR sponsorship agreement and the licensed exit operator terms.

Gelhaus Solutions

Self-hosted applications, and the platform that hosts them for the people who would rather not.

Site

  • Apps
  • Security
  • Writing
  • Contact
  • Sitemap

GHub

  • GAdvisory
  • GControl
  • GPlatform Control
  • GPlatform SSO
  • GPlatform Billing

Legal

  • Impressum
  • Privacy
  • Terms
  • Data processing
  • Withdrawal
  • Report content

Elsewhere

  • egelhaus@ennogelhaus.de
  • @egelhaus
  • @egelhaus
© 2026 Enno Gelhaus Built and shipped in Germany