Public Sector

Secure software supply chains.For the public sector, at every level.

DevGuard is the open-source platform for vulnerability management, software bills of materials and supply chain integrity - developed in Europe and in production across German public administration.

The European and German flags in front of the Bundesrat building in Berlin
640+

projects on openCode used DevGuard as of August 2026.

Transparency, evidence and independence. At every level.

Public administration has to account for the software it operates. DevGuard turns that obligation into an automated and auditable process - without introducing another proprietary dependency in the process.

Know every component in operation.

Every build produces a software bill of materials, so the components behind a service are documented rather than assumed - including the dependencies no one selected deliberately.

Produce evidence, not assurances.

Findings, decisions and justifications are recorded as the work happens, so reporting obligations and audits draw on a record that already exists instead of one assembled afterwards.

Remain independent of any vendor.

DevGuard is open source and built on open standards. It can be self-hosted, audited and extended by the administration itself, and the data never has to leave your own infrastructure.

Innovation

Innovation for more secure software - for and by the public sector.

The capabilities below were developed together with public sector teams and are in production today. Each one builds on open standards, so results stay comparable and portable between administrations.

12 findingsFiltersCVE-2024-30940.03s

Situational awareness

A live picture of which vulnerabilities affect which services, across every repository, container image and SBOM in the organisation.

SBOM · SARIFOne gate

Quality gates on open standards

Release criteria are defined against open standards and can be enforced in the pipeline, so a build that fails them does not reach production.

Proxy
Proxy active12 480 packages

Prevention at the point of entry

A dependency proxy screens packages before they reach a build, so known-vulnerable versions are stopped on the way in.

CRABSI TR-03183CycloneDX

Compliance that can be tracked

Obligations from the Cyber Resilience Act and the BSI technical guidelines are integrated to be tracked, with their status tracked per project over time.

Elastic capacityEU regions

Built for the scale of administration

A single installation serves hundreds of projects and teams, with tenancy, roles and reporting that follow how public administration is actually organised.

62% utilised
12k SBOMs
48k CVEs

Aggregated data, sharper decisions

Findings from every project are consolidated and prioritised, so teams work through what is genuinely exploitable instead of a raw vulnerability count.

Success stories

Already in production across public administration

DevGuard secures the software supply chain of the platform German public administration publishes its own open source on it.

ZenDiS
Federal Ministry for Digital Transformation and Government Modernisation
ZenDiS · on behalf of the BMDS

openCode

openCode is the open-source platform of German public administration, operated by the Zentrum für Digitale Souveränität (ZenDiS) on behalf of the Federal Ministry for Digital Transformation and Government Modernisation (BMDS). DevGuard provides vulnerability management and software bills of materials for the projects hosted there.

640+projects on openCode used DevGuard as of August 2026.
View DevGuard on openCode
DevGuard schafft es durch moderne Software-Security-Konzepte unseren Entwicklern und Nutzern auf openCode einen benutzerfreundlichen Einstieg in die Best Practices des Schwachstellenmanagements zu ermöglichen, ohne dabei Abstriche in der Enterprisefähigkeit zu machen.
Julian Schauder
Julian SchauderDevSecOps & Development Lead · ZenDiS GmbH
ZenDiS
ZenDiS

openCode badge programme

The badge programme on openCode uses DevGuard to verify how projects handle their vulnerability management. It turns established practice into a visible, comparable signal — so administrations can judge at a glance whether a project is worth reusing.

Open the badge programme
Open Source in der öffentlichen Verwaltung erfordert eine sichere und transparente Software-Lieferkette. L3montree hat uns durch Fachwissen und eine schnelle technische Umsetzung dabei unterstützt, unsere Software-Plattform openCode in diese Richtung weiterzuentwickeln.
Leonhard Kugler
Leonhard KuglerGeschäftsführer · ZenDiS GmbH

Collaboration

Built together with the public sector

The DevGuard maintainers work closely with ZenDiS and the BSI so the platform matches what public administration actually needs - from sovereign hosting to reporting and evidence.

ZenDiS
Joint work on evolving the openCode platform towards a secure and transparent software supply chain.
BSI
Exchange on security requirements and need-fit for public administration.
DevGuard maintainers
Requirements from public sector projects flow directly back into the open-source product.

Digital sovereignty

Secure supply chains keep the state able to act

Public administration depends on software it can audit, rebuild and maintain itself. A verifiable software supply chain is what turns open source into long-term digital sovereignty - and that is exactly the layer DevGuard secures.

„Mit ‚DevGuard‘ wird Entwickelnden außerdem ein Tool an die Hand gegeben, das Sicherheits-Features direkt mit in die Entwicklung einfließen lässt.“
Leonhard Kugler, Geschäftsführer, Zentrum für Digitale Souveränität der Öffentlichen Verwaltung (ZenDiS) — Behörden Spiegel special publication “Digitale Souveränität in Aktion”, p. 27

Talk to the team behind DevGuard.

Whether you are evaluating DevGuard for a single project or for an entire agency, we are glad to walk through requirements, hosting options and how other administrations operate it today.