Self-hosting with an enterprise contract

DevGuard Enterprise.
In your data center.

Platform and data stay in your data center. On top, you get what professional operation of a security-critical application requires: contractually agreed response times, vetted updates straight from the publisher and a fixed contract partner who is reachable and acts when it matters.

Built on open standards

CycloneDXVEXCSAFSARIF

Three operating models

  1. 1SaaSWe run DevGuard for you. You need no infrastructure of your own and start without any installation effort.
  2. 2Self-hostingOpen source under AGPL-3.0, with no license fees. Setup, updates and troubleshooting are entirely in your hands.
  3. Self-hosting with an enterprise contractPlatform and data stay with you. Setup, support and maintenance are covered by contract.

Our stance

Security is a dimension of software quality.

Modern software consists largely of components that were not built inside your own organization. Whoever ships that software is still responsible for them. The Cyber Resilience Act and the NIS-2 implementation have turned this standard into a duty of proof: detect known vulnerabilities, assess them, fix them and document the process.

The tools that do this are mostly proprietary and rarely come from Europe. Above all, the same vulnerability in the same component is assessed again in every organization – the same triage work, repeated thousands of times.

The evidence that regulators, auditors, market surveillance and customers ask for becomes a by-product of development – not a documentation task after the fact.
Across the entire lifecycle
From blocking malicious packages before download, through SCA, SAST, secret, IaC and container scanning in the pipeline, to continuous monitoring of shipped releases.
Open source, open standards
Developed under AGPL-3.0 on SBOM (CycloneDX), VEX, CSAF and SARIF. Assessments can be shared across organizational boundaries as VEX statements.
Recognized and built in Germany
An OWASP Foundation Incubation Project, developed by L3montree GmbH in cooperation with the openCode team at Germany's Center for Digital Sovereignty (ZenDiS).

What the enterprise contract covers

Setup, support and maintenance in one contract.

An enterprise contract bundles three critical aspects into one comprehensive service package. We do not just roll out DevGuard – we align it with the way your teams already work.

Initial setup

Together we review your target architecture, deploy DevGuard via our Helm chart and connect it to your CI/CD pipelines, SSO/OIDC and issue trackers. This includes a best-practice check of your pipelines and guided onboarding for your team.

Support with defined service levels

You get a fixed allowance of support hours, binding response times and clear escalation paths. You escalate to a team that knows your installation, not to a public issue tracker.

Maintenance

We keep your installation current with vetted updates and, depending on your package, guide upgrades through breaking changes. The contract also establishes a formal supplier relationship with the publisher, which simplifies your supplier assessment.

Packages

Packages at a glance

Four tiers – from running DevGuard without a contract to Mission Critical for large enterprises, the public sector and critical infrastructure. Choose the service level that matches how critical your operation is.

Enterprise Advanced

Mid-sized and large companies, regulated industries, up to 300 repositories

Request a quote
Service levels
Service hours1Business days, 9 am–6 pm
On-call1Not included
Response time within service hours2Up to 8 h
Resolution time3Up to 10 business days
ChannelsPlus chat (Matrix) and phone
Priority supportNot included
Senior engineer accessNot included
Allowance
Support hours per year480 h
of which with a named contact420 h
On-site days per year (Germany)51
Maintenance
Updates and upgradesAs Standard, plus guided major upgrades through breaking changes
Guided upgrade windowsDuring regular service hours

Get your quote in an introduction call or by email.

Enterprise packages are billed annually in advance as a subscription; other models are possible by arrangement. The annual fee covers support, service levels and maintenance. Initial setup is billed once, separately.

Included in every package

Verify instead of trust.

The provenance, components and vulnerability status of every DevGuard release are documented. That is the basis for adding DevGuard itself to your supplier management.

Reproducibly built, hardened images

DevGuard ships as a bit-for-bit reproducible container image with a minimized attack surface. Its origin and build process are attested via SLSA provenance and independently verifiable with cosign.

An SBOM for every release

Every artifact comes with a CycloneDX SBOM as an attestation, so you can prove at any time which components your installation consists of.

VEX-based CVE handling

We assess vulnerabilities in DevGuard and its dependencies and publish the result as a VEX statement. For every CVE, you get a clear statement on whether you are affected instead of a raw scanner finding.

More on reproducible builds

Additional services

Beyond your allowance.

Beyond the allowance included in your package, further services are available. Hour packages booked in advance come at a discount compared to individual billing.

Support and consulting hours
Billed individually or as a pre-booked package of 35 or 80 hours, usable for 24 months from purchase.
On-site days
Additional days for architecture and roadmap alignment, training or rollout support, plus travel expenses.
Emergency call-outs
Call-outs outside service hours for packages without Mission Critical, billed per started two hours.

Custom development

If you need functionality beyond DevGuard's standard scope, we build it for you – per person-day or at a fixed price after a prior effort estimate.

As an open-source project, we contribute the features we build back into the main version of DevGuard. No separately maintained special version emerges, and you carry no fork maintenance costs.

By commissioning the work, you agree to its publication under AGPL-3.0; we do not grant exclusive usage rights. Confidential data and configurations of your organization are never published.

FAQ

Frequently asked questions about DevGuard Enterprise

What organizations want to clarify before signing an enterprise contract – from why a service package makes sense to supplier assessment under NIS-2.

Your contact

The right package for your organization.

For every question about DevGuard Enterprise – from choosing the right package and service levels to pricing and setup in your data center. You can book a first conversation directly online.

Frédéric Noppe
Frédéric NoppeCOO, L3montree GmbHrequests@devguard.org