# OSSeva — Enterprise Open Source Assurance

> CVE-patched runtimes, architectural assurance, and managed operations for the enterprise OSS stack. One vendor for the OSS stack you actually run.

OSSeva is a division of a global enterprise consulting firm. We are one of only two commercial entities — alongside Broadcom — offering CVE remediation for community RabbitMQ versions. Our expertise covers the full enterprise open-source stack: RabbitMQ, Kafka, Spring, PostgreSQL, Redis, Node.js, .NET, and more.

## The Problem

Enterprise organizations depend on open-source runtimes — RabbitMQ, Kafka, Spring Framework, PostgreSQL — that reach end-of-life without a plan. When community support ends, CVE patches stop. Commercial vendors like Broadcom (VMware Tanzu) charge 4× renewal prices. No single vendor covers the full OSS stack.

## Services

### OSSeva Patch
CVE remediation for community-EOL OSS runtimes. Drop-in signed builds delivered quarterly or out-of-cycle for CVSS 9.0+ vulnerabilities. Signed via GPG and Sigstore. Compatible with Artifactory, Nexus, Harbor. No per-core pricing.

### OSSeva Assure
Architectural review, configuration audit, reference architectures, and compliance documentation. SOC 2, HIPAA, PCI DSS, ISO 27001, FedRAMP-aligned attestations produced by engineers who have run these systems at Fortune-scale.

### OSSeva Operate
24/7 managed operations with ≤15-minute P1 incident response SLA. Named engineers. Full MSP coverage without runtime lock-in.

## Trust Signals

- 14 CVEs disclosed and patched (maintained public directory)
- ≤ 15 minute P1 incident response (contractual SLA)
- 10+ years on RabbitMQ and Spring before it was mainstream
- 13 supported OSS runtimes: Kafka, PostgreSQL, Spring, RabbitMQ, ActiveMQ Artemis, Apache Pulsar, Redis, GemFire, Tomcat, Node.js, .NET, Spring Security, Spring Boot

## Supported Technologies

| Runtime | Supported Versions |
|---|---|
| RabbitMQ | 3.11 – 4.x |
| Apache Kafka | 2.8 – 3.7 |
| PostgreSQL | 11 – 16 |
| Spring Framework | 5.2 – 6.1 |
| Spring Boot | 2.7 – 3.x |
| Spring Security | 5.x – 6.x |
| ActiveMQ Artemis | 2.x |
| Apache Pulsar | 2.10 – 3.x |
| GemFire | 9.x – 10.x |

## Solutions

- **Exit Broadcom Tanzu**: Migration support for organizations exiting VMware Tanzu at renewal
- **Exit Confluent**: Kafka migration from Confluent to community or alternative managed
- **Spring Continuation**: EOL Spring Framework and Spring Boot continuation support
- **PostgreSQL EOL**: PostgreSQL version continuation past community EOL dates
- **For CISOs**: Compliance documentation, audit evidence packages, and security attestations
- **For Platform Engineering**: Infrastructure-layer support for the OSS runtimes you operate

## Comparison

OSSeva vs. EOL-binary specialists (e.g. HeroDevs, OpenLogic):
- OSSeva: patches + architecture + managed operations + compliance documentation under one contract
- EOL-binary specialists: patched software only, no MSP, no architecture review

OSSeva vs. Broadcom Tanzu:
- OSSeva: community OSS at community pricing, with commercial-grade support
- Broadcom Tanzu: proprietary runtimes with per-core licensing

## Pricing

All pricing is custom — contact sales. No prices are listed on this site. Discovery call required.

## Contact

- Website: https://www.osseva.io
- Discovery call booking: https://www.osseva.io/contact
- CVE Feed (RSS): https://www.osseva.io/api/vulnerabilities/rss

## About

OSSeva is a division of a global enterprise consulting firm. Our founders ran one of the world's largest RabbitMQ consultancies before building OSSeva to address the OSS support gap created by Broadcom's Tanzu acquisition.

No authentication required to access public content on this site.
