All offers

Retainer

Open Source

Open Source Operations & Maintenance

Open source carries your platform — and we carry the open source: maintaining it, upstreaming your fixes, and standing behind the components you depend on, as maintainers, not a support desk.

Duration

12 months, rolling

Usual next step

Platform Operations Partnership

The problem

Your critical path runs through open source you do not employ anyone to maintain. That is not a criticism, it is the normal state of a modern platform. It becomes a problem in three predictable ways.

A CVE lands in a component nobody owns, and the fix takes three weeks because nobody knows the codebase. A project you depend on goes quiet, and there is no plan. Your engineers write a patch, carry it as a fork because upstreaming it is work nobody has time for, and two years later that fork is technical debt that blocks every upgrade.

Regulation is now catching up with all three. The Cyber Resilience Act and NIS2 both assume you can answer questions about the software you ship and run.

What you get

  • Named component coverage. We agree the components that matter to you and we cover them: security response, upgrade support, compatibility validation, and deep-dive help when something breaks.

  • Upstream contribution. Your fixes and features go upstream, by us, properly. Your fork count goes down and your upgrade path stays open.

  • Maintainership where it counts. For components where we hold maintainer or contributor standing, you get a direct line into the project rather than a queue.

  • Security response. Advisory monitoring for your covered components, impact assessment for your specific usage rather than a generic severity score, and remediation support.

  • Supply chain evidence. SBOM generation and validation, provenance, and license position for your covered components, in the form your compliance function needs.

  • Long-term support paths. Where a project moves faster than you can, or slower, we work out and maintain the answer.

  • Open source strategy. Governance, contribution policy, inner source, and foundation engagement, for organizations that want to participate rather than only consume.

Why us

We are not reselling someone else’s support contract. We maintain and contribute to projects in the cloud native ecosystem, we hold governance roles in the foundations that steward them, and we publish our own tooling. When we say we can get a fix upstream, it is because we do that as a matter of routine.

How it works

An annual, rolling agreement with a defined component scope, a response commitment, and an included capacity for upstream work and deep dives. Reviewed quarterly, with the component scope adjustable as your platform changes.

Who it is for

Organizations running business-critical workloads on open source infrastructure, especially in regulated sectors where the Cyber Resilience Act, NIS2, or DORA make the “who maintains this” question a formal one.

Interested?

Write to us about where you are and what you want to decide. We will get back with a scope, a price, and an honest recommendation on whether this offer suits you.