The Solution

One pooled fix instead of many private ones.

Every firm that runs the same open source pays, separately, to keep it safe — forking, patching or buying support for identical CVEs. OSERA replaces that recurring single-firm "fork tax" with one openly governed programme. The numbers behind the thesis are on the home page.

An open, two-sided platform

End users and tech producers, in one neutral venue

Not a vendor and not a buyers' club — an open ecosystem. Institutions that run open source meet the technology firms with deep upstream expertise that maintain it. No single firm sits in the middle.

End users · demand

Everyone who runs the software

  • Banks, insurers & market infrastructure
  • Fintechs
  • Regulated enterprises beyond finance
  • Technology providers to the sector
Resilient, compliant OSS at a fraction of single-firm cost — with a General tier sized for banks of all sizes.
Meet the Members →

The open, governed platform

FINOS neutral governance · open standards · per-project funding pools

IP & antitrustConfidentialityOpen standardsUpstream-first
Explore the workstreams →
Tech producers · supply

Firms with upstream expertise

  • Upstream specialists
  • OSS maintainers
  • Security & remediation firms
  • SIs & consultancies
Reach the whole sector through one neutral channel — no lock-in.
Meet the Contributing Vendors →

Incubated in financial services — open to any regulated enterprise, anywhere in the world. Sovereign by design: no single vendor, and no single country, controls the fix.

The value

What each actor gets

One effort, three constituencies — each with a clear reason to take part.

FSIs · end users
  • Pay a fraction of single-firm cost
  • A flexible funding model — pooled & per-project; pay for what you depend on
  • A venue you already trust: IP, antitrust, confidentiality
  • DORA / NIS2 / CRA readiness, with evidence built in
  • Remediation stays open & portable — no lock-in
Become an OSERA member →
OSS & tech vendors · producers
  • One neutral channel to the whole sector — no per-firm BD
  • Demand aggregated and funded through directed pools
  • Win on upstream expertise, not on lock-in
  • Reputation and contribution across the commons
  • Upstream-first — work that benefits everyone
Become a FINOS member →
Regulators
  • Shared, auditable remediation evidence
  • Reduces systemic third-party & open source risk
  • One point of engagement for the sector's OSS posture
  • Transparency — public forks, open standards
  • Aligned to DORA, NIS2 and the CRA
Why now

Patching is only half of the problem

AI hasn't changed which vulnerabilities exist; it has changed how fast known ones are weaponised. And regulation now makes timely remediation a duty, not a choice.

Exploitation has accelerated

Automation weaponises a published CVE in hours — but the same fix is still re-created, forked or bought firm by firm.

§

DORA & NIS2 are in force

Supervisors increasingly treat third-party and open source risk as systemic and auditable.

The EU CRA clock is running

Vulnerability-reporting duties from Sep 2026; full vulnerability-handling obligations from Dec 2027.

Part of the collective Linux Foundation security response

Complementary to Akrites, by design

Akrites coordinates upstream security response; OSERA helps regulated enterprises operationalize remediation downstream.

Akrites · Linux Foundation

The upstream security response layer: coordinated vulnerability disclosure, remediation and upstreaming so fixes can reach open source projects responsibly.

OSERA · FINOS

The downstream operationalization layer: prioritization, standards, validation, back-patch sponsorship, vendor alignment, and rollout patterns for regulated enterprises.

Pick your path in.

Financial institutions fund and govern the alliance. Tech vendors join the working groups and bid to maintain. And because the source is open, anyone can build it themselves.