| Fully open source (MIT) | Yes | Partial (OSS core, paid features) | No (Elastic 2.0, source-available) | Partial (Outpost OSS, core platform closed) | No | Yes |
| Self-hosted | Yes | Yes | Yes | Partial (Outpost self-hosted, platform SaaS) | No (Managed) | Yes |
| No vendor per-message pricing (self-hosted) | Yes (self-hosted; infra only) | No | Yes (self-hosted) | No | No | Yes (your infra only) |
| Infra complexity (core deps) | PostgreSQL only | PostgreSQL (+ Redis for HA) | PostgreSQL + Redis | SaaS | Managed | Varies |
| Job queue backend | PostgreSQL (River) | Redis-backed queue/workers | Background workers + Redis | Managed | Managed | Varies |
| Webhook signing | Dual HMAC-SHA256 + Ed25519 | HMAC-SHA256 | HMAC-SHA256 | HMAC-SHA256 | X.509 signature (not HMAC) | Manual |
| Security model for secrets | Envelope encryption with per-record DEKs | Encrypted at rest (service-managed keys) | Deployment-dependent (no built-in envelope hierarchy) | Vendor-managed encryption | Vendor-managed encryption | Manual |
| Payload transformation | Go templates per subscription (37 functions, incl. structural + arithmetic) | Varies by edition/plan | Yes (JS transform) | Yes (JS transform) | No | Manual |
| Per-webhook rate limiting | Leaky bucket (DB-backed) | Available (details vary) | Yes | Yes | Regional quotas | Manual |
| Delivery semantics | At-least-once + explicit idempotency model | At-least-once + retries | At-least-once + retries | At-least-once + replay | At-least-once | Varies |
| Delivery health model | State machine (healthy/degraded/unhealthy) | Endpoint status | Circuit breaker | Dashboard metrics | CloudWatch | Manual |
| Error classification | 10 protocol-aware categories with retryability flags | Basic status and error reporting | Success/failure | Categorized | CloudWatch | Manual |
| Bulk retry/re-push | Deterministic snapshot-based (up to 10K) | Not in OSS | Manual retry | UI retry | No | Manual |
| Idempotent ingestion | Built-in dedup with idempotency keys | Application-level (no OSS ingest dedup) | Event IDs | Dedup available | Message dedup (5min) | Manual |
| REST / OpenAPI API | Yes (OpenAPI 3.1 spec) | Yes (REST) | Yes (REST) | Yes (REST) | No | Manual |
| Event schema validation | Soft validation (warns, never rejects; server-side check on test pushes) | JSON Schema defs (not enforced) | No | Filters (not schema) | No | Manual |
| Prebuilt integration recipes | Yes (Slack, Discord, PagerDuty, ntfy, ClickHouse, Twilio, SendGrid — one YAML, rendered server-side) | Limited | Limited | Yes (integrations) | Limited destinations | Manual |
| Inbound ingestion (verify provider signatures) | Yes (sparrow-sources: Stripe, GitHub, cron schedules) | Yes (Ingest product) | Yes (incoming webhooks) | Yes (core feature) | No | Manual |
| Non-HTTP delivery (email, object storage, OTLP) | Yes (sparrow-sinks: SMTP, S3/MinIO, OTLP logs) | Limited | Limited | Limited | SNS-native targets | Manual |
| Self-monitoring alerts | Built-in system events (webhook health, delivery failure) + opt-in email alerts | Operational webhooks | Alert configs | Issue alerts | CloudWatch alarms | Manual |
| CLI tooling | Yes (push, tail, local listen, apply recipes, debug templates) | Yes | Yes | Yes (localhost tunnels) | AWS CLI | Manual |
| Web dashboard | Embedded SvelteKit | Included | Included | Included | Console | No |
| Tracing & metrics | OpenTelemetry (traces + metrics + logs, job-level propagation) | Logging | Prometheus metrics | Dashboard | CloudWatch | Manual |
| SSRF protection | Built-in (private IPs, redirects) | Built-in controls (plus proxy best practices) | Built-in controls / IP filtering | Managed | N/A | Manual |
| Client SDKs | 3 (Go, Python, TypeScript) | Broad coverage | Multiple | Multiple | All AWS SDKs | 0 |
| Consumer app portal | Yes (embeddable, token-scoped) | Yes (embeddable) | Yes (Portal Links) | Yes (Outpost/managed) | No | No |
| Multi-region / HA story | PostgreSQL-native HA + stateless workers | Vendor/infra-managed | Vendor/infra-managed | Vendor-managed | Global managed service | Manual |
| Multi-tenant SaaS mode | No (single-tenant focus) | Yes | Yes | Yes | Yes | Manual |