OpenSecOps.org
  • Home
  • Foundation
  • SOAR
  • Blog

Blog

JEFF BARR MENTIONS FOUNDATION & SOAR

28/4/2025

0 Comments

 
Jeff Barr, Vice President & Chief Evangelist at Amazon Web Services, has mentioned OpenSecOps Foundation & SOAR on LinkedIn:
​
Full post and comments here:
​
  • www.linkedin.com/posts/jeffbarr_i-am-sitting-at-the-airport-waiting-for-my-activity
Picture
0 Comments

Our Full Transition to Open Source

9/4/2025

0 Comments

 
Picture

​Embracing Transparency and Community

Today, we're excited to announce a significant milestone for OpenSecOps: the complete transition of our platform to open source. This decision represents our commitment to transparency, community collaboration, and ensuring the long-term viability of these security tools.

Why Open Source?

Our journey towards open source began with several components already freely available on GitHub. The success of these tools – like our serverless log aggregation system and  SSO configuration utilities – showed us the value of community engagement and transparent development.

As economic conditions shifted in 2024, particularly affecting the specialised technical consulting market, we faced important decisions about the future of these security-critical platforms. After careful consideration of what would best serve our existing customers and the broader AWS security community, the path forward became clear: complete open source was the answer.

Ensuring Continuity Through Transparency

​The primary motivation behind our open source transition is straightforward: ensuring continuity and security for organisations that depend on these tools.

By open-sourcing our entire platform:
  • Organisations will always have access to the source code running their security infrastructure
  • The community can inspect, verify, and contribute to the security of the platform
  • Long-term viability is guaranteed regardless of market conditions
  • Security benefits from the collective expertise of the AWS community

Security-First Open Source

Unlike many open source projects that prioritise rapid feature development, our approach is distinctly security-focused:
​
  • Rigorous contribution guidelines that emphasise security above all else
  • Stringent review process for all proposed changes
  • Zero tolerance for security compromises in any contribution
  • Controlled evolution to protect existing production deployments​​

This security-first governance model reflects the reality that OpenSecOps components are deployed in financial services and other security-sensitive environments where stability and security are non-negotiable requirements.

What's Now Available

​Our complete platform is now open source, including:
​
  • OpenSecOps Foundation: Our enterprise-grade AWS infrastructure implementation with centralised logging, SSO configuration, and stringent security best practices and protections
  • OpenSecOps SOAR: Our security orchestration platform with automated incident response, forensic capabilities, automatic remediation of security issues, and AI-powered reporting
  • Comprehensive Documentation: Installation guides, technical design specifications, and standard operating procedures

Everything is provided under the Mozilla Public License 2.0, offering both openness and appropriate protections. The MPL 2.0 licence was carefully chosen because it doesn't restrict users in how they implement or deploy the software, whilst ensuring that modifications to the original code remain open source. This means organisations can freely integrate OpenSecOps into their environments without licensing concerns or restrictions on their own proprietary systems.

How to Get Started

Getting started with OpenSecOps is straightforward:
  1. Explore our repositories on https://github.com/OpenSecOps-Org,
  2. Follow our detailed installation guides for step-by-step deployment instructions,
  3. ​Implement powerful security automation in your AWS environment.

​Looking Forward

Going open source is just the beginning. We're committed to:
  • Maintaining our security-first governance approach
  • Expanding documentation for different stakeholders
  • Building a community of security-focused contributors
  • Continuing to innovate in cloud security automation

​In Conclusion

The open source model offers the ideal path forward for these security platforms. It ensures transparency, continuity, and community engagement whilst maintaining the high security standards that our users require.

We believe that security tools should be accessible, transparent, and community-driven. By embracing open source, we're creating a foundation for more secure AWS environments across all organisations, regardless of size or industry.

Join us on this journey as we build a more secure cloud future together.
0 Comments

Open Source

8/5/2024

0 Comments

 
Picture
We see open source as a strength. It's no secret that part of our offerings is open source, written by us or other reputable developers. For instance, here's the new version of our serverless log aggregation system:

https://github.com/OpenSecOps-Org/Foundation-control-tower-log-aggregator

The log aggregator is part of OpenSecOps Foundation and will massage your AWS log files to cut your log file storage costs in half, amongst other things. 

Suppose you use it with our open-source multi-account log aggregator, (https://github.com/OpenSecOps-Org/Foundation-CloudWatch2S3). In that case, you have a complete solution for automatically collecting CloudWatch logs from all accounts in an AWS organization and storing them centrally in a consistent format and structure along with all system logs. 

Best of all, it costs you absolutely nothing.

You'll find all our open-source offerings here.

Why do we do this? Because we like to get the initial complexities out of the way so we can assist our clients with the architecture that really matters. Thus, OpenSecOps Foundation has no license fee; we only charge for the time it takes us to install it. Now that's a value proposition you might want to consider.

P.S.: Apart from our open source, you'll like our proprietary security aspects too, which include fully text-based configuration and a battle-tested system to prevent any escalation of privileges, amongst other things. Full details here.
0 Comments

    Archives

    April 2025
    August 2024
    May 2024

    Categories

    All
    AI
    AWS Security Hub
    ML
    OpenSecOps Foundation
    OpenSecOps SOAR
    Open Source

    RSS Feed

Search

Contact:
[email protected]
Source code:
https://github.com/OpenSecOps-Org

Subscribe to our mailing list

Powered by Buttondown.

  • Home
  • Foundation
  • SOAR
  • Blog