Every firm that runs the same open source pays, separately, to keep it safe — forking, patching or buying support for identical CVEs. OSERA replaces that recurring single-firm "fork tax" with one openly governed programme. The numbers behind the thesis are on the home page.
Not a vendor and not a buyers' club — an open ecosystem. Institutions that run open source meet the technology firms with deep upstream expertise that maintain it. No single firm sits in the middle.
FINOS neutral governance · open standards · per-project funding pools
Incubated in financial services — open to any regulated enterprise, anywhere in the world. Sovereign by design: no single vendor, and no single country, controls the fix.
One effort, three constituencies — each with a clear reason to take part.
AI hasn't changed which vulnerabilities exist; it has changed how fast known ones are weaponised. And regulation now makes timely remediation a duty, not a choice.
Automation weaponises a published CVE in hours — but the same fix is still re-created, forked or bought firm by firm.
Supervisors increasingly treat third-party and open source risk as systemic and auditable.
Vulnerability-reporting duties from Sep 2026; full vulnerability-handling obligations from Dec 2027.
Akrites coordinates upstream security response; OSERA helps regulated enterprises operationalize remediation downstream.
The upstream security response layer: coordinated vulnerability disclosure, remediation and upstreaming so fixes can reach open source projects responsibly.
The downstream operationalization layer: prioritization, standards, validation, back-patch sponsorship, vendor alignment, and rollout patterns for regulated enterprises.
Financial institutions fund and govern the alliance. Tech vendors join the working groups and bid to maintain. And because the source is open, anyone can build it themselves.