Forking Cal.com to closed source (Interview)

Summary of Forking Cal.com to closed source (Interview)

by Changelog Media

1h 54m•September 3, 2026

Overview of Forking Cal.com to closed source (Interview)

In this Changelog interview, Pierre Ricklefs (Cal.com co-founder) argues that AI has fundamentally changed the risk profile of open source. His core thesis: commercial open source projects that handle sensitive data are now easier to attack, harder to maintain, and increasingly overwhelmed by AI-generated noise. As a result, Cal.com is forking its own codebase internally, keeping a public community edition, but moving the sensitive production/commercial parts private under a new cal.diy identity.

Why Cal.com is changing

Pierre says the old assumptions behind open source security no longer hold:

  • AI has lowered the skill floor for both contributors and attackers
    • A “16-year-old can vibe hack a power station” is the same kind of shift as vibe coding apps.
    • Security research and exploitation are now much easier to automate.
  • Open source maintainers are drowning in AI-generated slop
    • Cal.com’s PR queue is flooded with low-quality, often duplicated, AI-written pull requests.
    • Security inboxes are also overloaded with AI-generated vulnerability reports, many of which are hallucinated.
  • Open source is now easier to attack than before
    • Pierre cites security researchers who say public repos are roughly 5–10x easier to hack than private ones.
    • The visibility of source code, function calls, and implementation details makes black-box defenses less effective.

Cal.com’s new model

Cal.com is not “going closed source” in the absolute sense. Instead, it is splitting the product into two paths:

  • Public/community edition
    • Remains open source.
    • Rebranded as cal.diy.
    • Intended for self-hosting, experimentation, and non-production use.
  • Private commercial fork
    • The production code powering Cal.com’s SaaS will be forked internally.
    • Sensitive areas like:
      • authentication
      • database access
      • encryption
      • middleware / backend logic
    • will be rewritten or hidden from public view.

Pierre emphasizes that this is meant to reduce attack surface, not to abandon open source entirely.

The broader open source problem in the AI era

A major theme of the conversation is that AI changes the economics and culture of open source:

  • PR review is harder
    • AI-generated pull requests often look polished at first glance, making human review more difficult.
    • Maintainers can no longer rely on obvious quality signals.
  • Quality can recursively degrade
    • If sloppy AI code lands in a project, future agents may learn from that bad code and reproduce worse patterns.
  • Contribution incentives are distorted
    • Some people now use agents to spray PRs across repositories in hopes of looking employable.
    • The result is less meaningful contribution and more noise.
  • The old “open source is more secure” argument is weaker
    • Pierre says that used to be true, but no longer is for software with real data, real customers, and real attack value.

GitHub, agents, and the changing meaning of code

The interview expands into what all of this means for GitHub and software collaboration:

  • GitHub may need a new identity
    • If code becomes increasingly machine-generated and unreadable, GitHub may become more like a distribution platform than a code-review hub.
  • Agentic contributions blur intent
    • There’s a difference between a human asking an agent to research something and an agent autonomously opening PRs on external repos.
  • Current tooling is behind the curve
    • Pierre argues GitHub should provide better first-party guardrails for who can contribute and under what conditions.
  • MIT/AGPL/source available distinctions may matter less than execution
    • The real issue is not just licensing, but how much sensitive runtime code is exposed.

Cal.com’s business and growth

Despite the security concerns, Cal.com is doing well commercially:

  • Around $7M ARR at the time of the interview, with strong month-over-month growth.
  • The business is high-margin because it is not burning AI tokens.
  • Pierre notes that many AI startups are growing top-line revenue while losing more money than they make.
  • Cal.com’s growth is attributed to:
    • product quality
    • high customer trust
    • steady shipping
    • strong demand for scheduling and rescheduling tools

Product feedback and a concrete issue discussed

Adam, the host, raises a real product pain point around rescheduling:

  • He wants the calendar owner to be able to reschedule directly within the same UI.
  • Current behavior sometimes forces an admin override or extra steps.
  • Pierre agrees it’s annoying and says it’s on his list to fix.
  • This becomes a good example of Cal.com’s product philosophy: listen to customers, simplify workflows, and keep refining UX.

Notable takeaways

  • “Open source is not dead, but it’s changing.”
  • Commercial open source projects that handle sensitive data are now high-value targets.
  • AI has dramatically reduced the cost of both contribution and exploitation.
  • The future may favor a split model: public community code + private production fork.
  • For Cal.com, the goal is to preserve open source values while protecting customers and the business.

Practical recommendations from the episode

Pierre’s advice to other commercial open source companies:

  • Run AI-assisted security scans and measure the real blast radius.
  • Reassess whether your public repo should expose production-critical code.
  • Consider making auth, database, and encryption layers private.
  • Keep a community edition if it serves self-hosters and hobbyists.
  • Don’t assume public code is automatically safer anymore.

Final sentiment

The episode is thoughtful but uneasy: Pierre is not cheering for closed source, he’s reacting to a changed reality. His position is essentially that if a company processes sensitive customer data, the old open-source-by-default model may now create unacceptable risk. Cal.com’s move is framed as a defensive adaptation, not a rejection of open source philosophy.