The Linux enclave backend is written against documented tool behaviour and has never been executed. We will not ship an encrypted-storage implementation nobody has run.
The backend and its LUKS2 enclave exist but have never been executed on a real Linux host. Unreleased until they have been.
It will not run unlicensed. That is the point.
Vault-OS binds itself to this machine’s TPM, system UUID and MAC at activation. An unlicensed copy installs, boots, builds its enclave and stops — so you can evaluate everything up to the point where a contract starts.