TuxCare
TuxCare provides subscription-based rebootless Linux kernel patching (KernelCare), extended lifecycle security support for end-of-life open-source software (ELS), and vulnerability scanning (TuxCare Radar) to 2,300+ enterprise customers in healthcare, finance, and government.
- Company typePrivate
- Founded-
- HeadquartersPalo Alto, United States
- Headcount—
- GTM typeB2B
- OfferingSoftware
What TuxCare does
TuxCare Inc. is a privately-held open-source security company headquartered in Estero, Florida, that sells enterprise subscription services for rebootless Linux kernel patching and extended lifecycle support for end-of-life open-source software. Its flagship product, KernelCare Enterprise, applies CVE patches to running Linux kernels across 70+ distribution versions without requiring system reboots or maintenance windows; the LibCare add-on extends this capability to user-space shared libraries (OpenSSL, glibc), and KernelCare IoT addresses ARM64-based embedded devices via Azure IoT Hub integration. The Endless Lifecycle Support (ELS) portfolio provides SLA-backed CVE patching for out-of-support operating systems (CentOS, RHEL, Ubuntu, Debian, Alpine, Amazon Linux 2), language runtimes (PHP, Python, Node.js, Ruby, .NET, OpenJDK), libraries (Angular, Django, Bootstrap, Apache Commons), and applications (Tomcat, Kafka, Grafana, PostgreSQL), including transitive dependencies.
The business model is subscription-based, primarily per-server for KernelCare (starting at $35.40/server/year for Starter tier) and per-distribution for ELS and TuxCare Enterprise Support for AlmaLinux and Rocky Linux. Revenue is anchored in a recurring annual contract model with tiered pricing (Essential, Extended Security Updates, Enhanced, Custom), volume discounts, and bundle packaging including a FedRAMP-Ready bundle. Distribution combines direct enterprise field sales targeting regulated verticals (healthcare, finance/banking, government/public sector) with online self-service purchase, OEM and System Integration partner programs, and channel resellers. The company claims 2,300+ enterprise customers and serves logos including Dell, IBM, Cisco, HPE, UnitedHealth Group, DocuSign, Adyen, Telefonica, Rakuten, and Proofpoint. TuxCare is the founding sponsor of the AlmaLinux OS Foundation, maintains FIPS 140-3 validated modules and DISA STIG/CIS Benchmark authorship for AlmaLinux OS 9, and is a member of the Open Source Security Foundation (OpenSSF). The company operates without publicly disclosed funding rounds, suggesting a cash-flow-financed operating model.
TuxCare firmographics
Firmographics- Name
- TuxCare
- Legal name
- TuxCare Inc.
- Website
- https://tuxcare.com
- Company type
- Private
- Operating status
- Operating
- Short description
- TuxCare provides subscription-based rebootless Linux kernel patching (KernelCare), extended lifecycle security support for end-of-life open-source software (ELS), and vulnerability scanning (TuxCare Radar) to 2,300+ enterprise customers in healthcare, finance, and government.
- Ownership category
- akta.pro rank
TuxCare industry classification
Industry- Product category
- Linux Security & Patch Management
- NAICS
- Computer Systems Design and Related Services (5415), Custom Computer Programming Services (541511)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Programming Services (7371)
- akta.pro primary industry
- Code & Repository Security (Git Security, Code Integrity) (HDADACAG)
Keywords
Where TuxCare is headquartered
LocationHeadquarters
- HQ city
- Palo Alto
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
TuxCare business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Operations, Infrastructure
Revenue model
- Endless Lifecycle Support (ELS) Subscription: Annual subscription-based service providing ongoing CVE patches for end-of-life open-source software across operating systems, runtimes, libraries, and applications. Delivered through secure TuxCare-hosted repositories.
- KernelCare Enterprise: Annual subscription for rebootless kernel live patching. Tiered pricing (Starter, Standard, Enterprise) with pricing starting at $35.40 per year per server. Additional LibCare add-on for shared library patching at $19.50.
- TuxCare Enterprise Support (TES): Enterprise support subscription for AlmaLinux and Rocky Linux including security updates, 24/7 support, FIPS compliance, and rebootless patching options. Includes Essential, Extended Security Updates, Enhanced, and Custom support tiers.
- FedRAMP Bundle: Bundled solution for federal government cloud service providers combining FIPS 140-3 validated modules, rebootless patching, and continuous vulnerability scanning.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | KernelCare Starter - Entry-level rebootless kernel patching |
| Subscription | Annual | KernelCare Standard - Enhanced security with centralized management |
| Subscription | Annual | KernelCare Enterprise - Full-featured enterprise with dedicated support |
| Unit Pricing | Annual | LibCare Add-on - Live patching for OpenSSL and glibc |
| Subscription | Annual | TES Essential Support - Core security updates and stability |
| Subscription | Annual | TES Extended Security Updates - FIPS-validated long-term security |
| Usage-based | Pay-as-you-go | TES Enhanced Support - Pay-as-you-go expert access |
| Subscription | Annual | TES Custom Support - Tailored enterprise solutions |
Go-to-market motion2 records
Distribution channels5 records
Marketing channels8 records
TuxCare product offering
Product offeringCore offering
TuxCare provides rebootless live patching for Linux kernels and shared libraries through KernelCare and LibCare, and delivers Endless Lifecycle Support (ELS) — ongoing CVE patches for end-of-life open-source operating systems, runtimes, libraries, and applications. Its portfolio also includes TuxCare Radar (Linux vulnerability scanner with AI-assisted risk scoring), SecureChain for OSS (supply chain security), and TuxCare Enterprise Support (TES) for AlmaLinux and Rocky Linux with FIPS 140-3 and FedRAMP-ready bundles.
Product overview
TuxCare is an open-source security company offering a portfolio of cybersecurity solutions centered on rebootless kernel patching and extended lifecycle support for end-of-life open-source software. The core product suite includes KernelCare Enterprise (rebootless kernel patching) extended by LibCare (shared library patching) and KernelCare IoT (ARM64 device patching); TuxCare Enterprise Support (TES) for AlmaLinux and Rocky Linux; TuxCare Radar (vulnerability scanner eliminating false positives); Endless Lifecycle Support (ELS) covering OS, runtimes, libraries, and applications across 40+ technologies; SecureChain for OSS (supply chain security across npm/Maven/PyPI/Go/Rust/PHP); and Custom Kernel Development services. A FedRAMP-ready compliance bundle and security hardening add-ons round out the enterprise-focused portfolio.
Differentiator
Problem solved
Functional benefit
Brands
- KernelCare: Rebootless Linux kernel patching service supporting 60+ distribution versions without system reboots.
- LibCare
- KernelCare IoT
- TuxCare Radar
- SecureChain
- Endless Lifecycle Support (ELS)
Products and services
- KernelCare Enterprise Rebootless kernel security patching for Linux distributions that automatically applies CVE patches to running systems, eliminating reboots and maintenance windows across enterprise Linux estates.
- LibCare Rebootless live patching add-on for critical shared libraries including OpenSSL and glibc, extending KernelCare Enterprise to cover the last category of patching that still requires restarts.
- KernelCare IoT Rebootless live patching for ARM64-based connected IoT and embedded devices, integrated with Azure IoT Hub for fleet-scale deployment without taking devices offline.
- TuxCare Enterprise Support for AlmaLinux Enterprise-grade support subscription for AlmaLinux providing 16-year lifecycle coverage, FIPS 140-3 validated patches, and 24x7 expert support from the founding sponsor of AlmaLinux OS Foundation.
- TuxCare Enterprise Support for Rocky Linux Enterprise support subscription for Rocky Linux delivering 16-year lifecycle coverage, FIPS 140-3 compliance, and 24x7 expert support.
- TuxCare Radar Linux vulnerability scanner that eliminates false positives by recognizing both standard and KernelCare in-memory patches, with AI-assisted risk scoring that integrates with Qualys, Nessus, and OpenSCAP.
- Endless Lifecycle Support (ELS) Ongoing CVE patch delivery subscription for out-of-support open-source operating systems, runtimes, libraries, and applications, including transitive dependency coverage with SLA-backed rapid patch delivery.
- ELS for Operating Systems Security patch subscription for end-of-life Linux distributions including CentOS, Oracle Linux, Ubuntu, RHEL, Debian, Alpine Linux, and Amazon Linux 2.
- ELS for Runtimes CVE patch subscription for end-of-life language runtimes including PHP, Python, Node.js, Ruby, .NET, and OpenJDK.
- ELS for Libraries Security patch subscription for end-of-life JavaScript frameworks, Python libraries, and Java frameworks including Angular, React, Vue, Django, Flask, and Apache Commons.
- ELS for Applications Security patch subscription for end-of-life middleware and applications including PostgreSQL, MySQL, Apache Tomcat, Kafka, Grafana, OpenSearch, MinIO, MariaDB, and WildFly.
- SecureChain for OSS Software supply chain security service covering npm, Maven, PyPI, Go, Rust, and PHP ecosystems, verifying packages on install, scanning for malware, and providing continuous vulnerability patching from adoption through post-EOL.
- Custom Kernel Development and Maintenance End-to-end custom Linux kernel development, backporting, hardening, and rebootless security patching services for embedded, IoT, HPC, telecoms, and defense environments.
- FedRAMP Bundle for AlmaLinux Bundled compliance solution combining FIPS 140-3 validated modules, rebootless KernelCare patching, and continuous TuxCare Radar vulnerability scanning for cloud service providers serving US federal government.
Quantifiable outcome
- 5,000+ CVEs resolved in open-source products to date
- +5 more outcomes
Companies that use TuxCare
Customer profileNamed customers22 records
Segments5 records
Ideal customer profiles5 records
TuxCare technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration5 records
AI capability2 records
Feature6 records
TuxCare partnerships and signals
Strategic signalPartnerships
Six partnerships are on record, tiered flagship and core.
- Open Source Security Foundation (OpenSSF)flagshipTuxCare joined as new member organization during OpenSSF Community Day North America event. Active participant in efforts to address EU Cyber Resilience Act and secure open source software supply chains against evolving threats.
- Amazon Web ServicescoreEndless Lifecycle Support service expanded to include Amazon Linux 2 starting July 1, 2026, continuing security updates after AWS ends support for the operating system.
- TenablecoreTenable One Exposure Management platform now supports detection of TuxCare's KernelCare rebootless patching solution. Integration enables joint customers to identify fully patched Linux kernels and vulnerabilities already addressed by KernelCare, combining both security platforms to reduce exposure window for known CVEs.
- AlmaLinux OS FoundationflagshipContinued Platinum-level sponsorship renewal alongside CloudLinux. TuxCare is founding sponsor of AlmaLinux OS Foundation (501c6 non-profit). Provides enterprise security, lifecycle extensions, and support for community Linux distribution.
- CloudLinuxcoreJoint platinum-level sponsor with TuxCare for AlmaLinux OS Foundation. Long-time collaboration on open-source Linux security solutions.
- Microsoft AzurecoreAzure IoT Hub integration for KernelCare IoT enabling fleet-scale deployment of rebootless patching for ARM64-based connected IoT devices.
Scale indicators15 records
Recent moves6 records
Expansion highlights6 records
TuxCare competitors and assessment
Company assessmentEmerging players
- Sonatype: Sonatype's Nexus platform manages open-source component security across the same package ecosystems TuxCare SecureChain targets. Both companies position around proactive open-source dependency risk reduction for enterprise developers.
- Snyk: Snyk addresses software supply chain security and open-source vulnerability management, overlapping with TuxCare's SecureChain for OSS across npm, Maven, PyPI, Go, Rust, and PHP ecosystems. Both serve developer and security teams securing open-source dependencies.
Broad incumbents
- Oracle: Oracle offers KSplice for rebootless kernel patching on Oracle Linux and extended Premier Support for older Linux versions. TuxCare publishes a head-to-head comparison versus KSplice, confirming it as a direct competitor in live patching and EOL Linux support.
- SUSE: SUSE provides enterprise Linux (SLES) with extended general support and security patching that overlaps with TuxCare's ELS for OS. It competes in regulated industries and federal markets where TuxCare is also active.
- Canonical: Canonical bundles Livepatch for Ubuntu into Ubuntu Pro subscriptions, directly competing with KernelCare on rebootless patching. It also provides extended security maintenance for Ubuntu LTS releases, overlapping with TuxCare's ELS for OS offerings.
- Red Hat: Red Hat delivers RHEL with bundled kpatch live patching — a direct substitute for KernelCare — plus FIPS-validated modules and FedRAMP-ready offerings. It competes with TuxCare across enterprise Linux support, live patching, and federal compliance, but at vastly greater scale.
Others
- Tenable: Tenable's Tenable One Exposure Management platform now detects KernelCare-applied patches (integration partner) and competes more broadly in vulnerability management. It is a distribution partner for TuxCare Radar while also being a category competitor in vulnerability scanning.
- Qualys: Qualys integrates with TuxCare Radar to validate patch status and close false positives. It is a leading vulnerability management platform whose scanning workflows intersect with TuxCare's scanner and patching capabilities.
Direct peers
- CloudLinux: CloudLinux shares Platinum sponsorship of the AlmaLinux OS Foundation with TuxCare and offers competing enterprise Linux support and kernel-care products. It is the closest comparable because both companies monetize extended-support and security services around community Linux distributions.
- CIQ (Rocky Linux Enterprise Support): CIQ delivers enterprise support, security patching, and lifecycle extensions for Rocky Linux — a direct counterpart to TuxCare Enterprise Support for Rocky Linux. Both companies serve enterprises that migrated from CentOS to Rocky/AlmaLinux.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
TuxCare social profiles
Digital presenceTuxCare compliance and trust
Trust signalCompliance9 records
TuxCare financial estimates
Financial estimateRevenue estimate
Valuation estimate
TuxCare leadership team
Management profileNumber of profiles
Profiles3 records
TuxCare funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
TuxCare M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about TuxCare
What does TuxCare do?
TuxCare provides rebootless live patching for Linux kernels and shared libraries through KernelCare and LibCare, and delivers Endless Lifecycle Support (ELS) — ongoing CVE patches for end-of-life open-source operating systems, runtimes, libraries, and applications. Its portfolio also includes TuxCare Radar (Linux vulnerability scanner with AI-assisted risk scoring), SecureChain for OSS (supply chain security), and TuxCare Enterprise Support (TES) for AlmaLinux and Rocky Linux with FIPS 140-3 and FedRAMP-ready bundles.
Is TuxCare a public or private company?
TuxCare is a private company. It is classified as unknown and is currently operating.
When was TuxCare founded?
TuxCare was founded in -1.
Where is TuxCare based?
TuxCare is headquartered in Palo Alto, United States, in the North America region.
How does TuxCare make money?
Four revenue lines are on record. Endless Lifecycle Support (ELS) Subscription is the primary driver. The others are kernelCare Enterprise, tuxCare Enterprise Support (TES) and fedRAMP Bundle.
Who are TuxCare's main competitors?
Emerging players on record are Sonatype and Snyk. Broad incumbents are Oracle, SUSE, Canonical and Red Hat. Others are Tenable and Qualys. Direct peers are CloudLinux and CIQ (Rocky Linux Enterprise Support).
Does TuxCare have an API?
No public API is recorded for TuxCare.
What industry is TuxCare in?
TuxCare's product category is Linux Security & Patch Management. Its primary akta.pro industry code is HDADACAG, Code & Repository Security (Git Security, Code Integrity). Its NAICS code is 5415 and its SIC code is 7372.