Akrites
Akrites operates a Linux Foundation-hosted coordinated vulnerability disclosure initiative that runs a shared Security Incident Response Team for critical open source software, serving Premier, General, and Associate members including AWS, Google, Microsoft/GitHub, Anthropic, OpenAI, JPMorganChase, and Citi.
- Company typePrivate
- Founded2026
- Headquarters—
- Headcount—
- GTM typeB2B
- OfferingServices
What Akrites does
Akrites is a coordinated vulnerability disclosure (CVD) initiative operated under The Linux Foundation, launched on June 25, 2026, with a shared Security Incident Response Team (SIRT) that validates, deduplicates, and remediates vulnerabilities in critical open source software. It was founded by 22 organizations spanning hyperscale cloud providers (AWS, Google, Microsoft/GitHub, NVIDIA), AI labs (Anthropic, OpenAI), global banks (Citi, JPMorganChase), telecom operators (Ericsson, Vodafone), networking and security vendors (Cisco, Chainguard, Endor Labs, Sonatype, Zscaler, RapidFort), and open source foundations (Rust Foundation, with supporting endorsements from CNCF, LF Energy, OpenInfra, OpenJS, OpenSSF, and PyTorch Foundation). The problem Akrites targets is that AI-driven vulnerability discovery tools have shifted the cost of finding flaws from weeks to minutes, overwhelming upstream maintainers with duplicate reports and creating pre-patch disclosure risk; Akrites positions itself as a single coordinated front door so maintainers face one predictable partner instead of many independent reporters.
Akrites' core technology is a confidentiality-first CVD orchestration layer built on industry-standard security tooling — CVE, TLP 2.0, CWE, CVSS, EPSS, SSVC, VEX, and the VINCE case management platform — wrapped in hardened infrastructure (isolated secure enclaves, MFA-protected analyst workbenches via secure VMs, tamper-evident audit logs). Each finding follows a four-stage path: intake under TLP:RED, deduplication and severity validation, confidential remediation, and synchronized public disclosure with fixes flowing back to the original project namespaces. When a project lacks an active maintainer, Akrites acts as maintainer of last resort. Members may offer in-kind compute, AI resources, or licenses in place of cash dues, subject to annual Governing Board approval.
Akrites' commercial model is a three-tier membership consortium (Premier for critical infrastructure operators and dependent vendors; General for resource-constrained contributors; Associate for open source foundations at no cost), funded by foundation-level dues rather than per-seat licensing, with all members required to be current Linux Foundation members and to sign a participation agreement and NDA. Pricing is not publicly disclosed. Go-to-market is enterprise field sales through direct website inquiry, supplemented by the Linux Foundation's event and member network. Revenue is not publicly disclosed; Alpha-Omega, a directed fund of the Linux Foundation, provides seed funding for launch and initial operations. Akrites is structured as a nonprofit industry initiative under its parent rather than as a venture-backed or publicly traded entity.
Akrites firmographics
Firmographics- Name
- Akrites
- Legal name
- Akrites
- Website
- https://akrites.org
- Company type
- Private
- Founded year
- 2026
- Operating status
- Operating
- Short description
- Akrites operates a Linux Foundation-hosted coordinated vulnerability disclosure initiative that runs a shared Security Incident Response Team for critical open source software, serving Premier, General, and Associate members including AWS, Google, Microsoft/GitHub, Anthropic, OpenAI, JPMorganChase, and Citi.
- Ownership category
- akta.pro rank
Akrites industry classification
Industry- Product category
- Cybersecurity Coordination Services
- NAICS
- Computer Systems Design and Related Services (5415)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Software Supply Chain & Dependency Security (SBOM, Signing) (HDADACAD)
- akta.pro secondary industries
- Endpoint Vulnerability & Patch Management (HDADAEAH), Endpoint Security Managed Services (EDR/XDR) (BPAEADAH)
Keywords
Akrites business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Infrastructure
Revenue model
- Membership Dues: Foundation-level dues from Premier, General, and Associate members fund coordination operations including the neutral SIRT, secure workspace infrastructure, identity and audit infrastructure, Governing Board, and program management. Members may offer in-kind compute, AI resources, or licenses in lieu of dues, subject to annual Governing Board approval.
- Seed Funding: Alpha-Omega, a directed fund of the Linux Foundation, provides seed funding to support Akrites launch and initial operations.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Premier tier for critical infrastructure operators and vendors/platforms they depend on |
| Subscription | Annual | General tier for organizations wanting to help but unable to commit large engineering resources |
| Subscription | Annual | Associate tier for recognized open source foundations and projects at no cost |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels4 records
Akrites product offering
Product offeringCore offering
Akrites operates a shared Security Incident Response Team (SIRT) that runs a standardized Coordinated Vulnerability Disclosure (CVD) process for critical open source software. The SIRT provides a single confidential front door for members to report vulnerabilities; it validates, deduplicates, and triages findings, then coordinates remediation and patch creation with upstream maintainers using industry-standard frameworks (CVE, TLP 2.0, CWE, CVSS, EPSS, SSVC, VEX) and VINCE case management, culminating in synchronized public disclosure.
Product overview
Akrites is a coordinated confidential vulnerability remediation initiative for critical open source software, operated as a Linux Foundation project. It is not a product or platform in the traditional SaaS sense, but rather a membership-based industry coordination effort. Akrites provides a shared Security Incident Response Team (SIRT) that operates a standardized Coordinated Vulnerability Disclosure (CVD) process for member organizations. The service encompasses vulnerability intake and deduplication, confidential coordination with upstream maintainers, remediation support including patch creation in secure enclaves, and synchronized public disclosure. Membership tiers include Premier (critical infrastructure operators and vendors), General (organizations contributing resources), and Associate (open source foundations). The program is built on industry standards including CVE, TLP, CWE, CVSS, EPSS, SSVC, VEX, and uses VINCE as its coordination/case management platform.
Differentiator
Problem solved
Functional benefit
Products and services
- Coordinated Vulnerability Disclosure (CVD) Service A standardized confidential coordination service for vulnerability discovery, validation, deduplication, remediation, and synchronized disclosure across critical open source projects. Available to Premier and General members; operated by a shared neutral SIRT under The Linux Foundation.
- Premier Membership Membership tier for critical infrastructure operators and the vendors and platforms they depend on. Includes priority SIRT coordination and eligibility for Governing Board nomination. Requires current Linux Foundation membership and signed participation agreement and NDA.
- General Membership Membership tier for organizations that want to help but cannot commit large engineering resources. Includes participation in future forums and working groups, priority access to member briefings, and named participation in transparency reports. Requires current Linux Foundation membership.
- Associate Membership No-cost membership tier for recognized open source foundations and projects. Participants are invited by the Governing Board to coordinate with working groups subject to charter and confidentiality terms. Requires current Linux Foundation membership.
Quantifiable outcome
- Fewer than 5% of validated open source vulnerabilities were patched in recent months despite AI acceleration of discovery
Companies that use Akrites
Customer profileSegments4 records
Ideal customer profiles3 records
Akrites technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature5 records
Akrites partnerships and signals
Strategic signalPartnerships
25 partnerships are on record, tiered core and supporting.
- Amazon Web ServicescoreAWS is a founding member contributing engineering talent, security expertise, and funding. Committed to securing projects customers depend on and building shared infrastructure alongside the community. AWS VP and Distinguished Engineer Matt Wilson provided a supporting quote.
- AnthropiccoreAnthropic is a founding member. Deputy CISO Jason Clinton stated commitment to coordinating on findings and getting fixes upstream before exploitation.
- ChainguardcoreCEO and Co-founder Dan Lorenc is a founding member. Chainguard provides expertise on the software supply chain and the thin layer of upstream maintainers.
- CiscocoreCisco joins through its Outshift division with networking infrastructure, security expertise, and decades of open source contribution. SVP and GM Vijoy Pandey emphasized defenders cannot afford to lose and maintainers cannot run this alone.
- CiticoreCiti is a founding member committed to supporting the open-source ecosystem by helping build a framework that identifies and remediates vulnerabilities. CISO Al Tarasiuk leads Citi's participation.
- Endor LabscoreCEO and Co-Founder Varun Badhwar leads Endor Labs as a founding member. Contributed insight that fewer than 5% of validated open source vulnerabilities were patched in recent months despite AI acceleration.
- EricssoncoreEricsson joins as a Premier member contributing funding and talent. Chief Standardization Officer Per Beming emphasized no single organization can solve this alone.
- GooglecoreVP Security Engineering Heather Adkins represents Google as a founding member. Google brings long-standing commitment to open source security combined with industry-wide expertise.
- IBMcoreIBM Enterprise Security Executive Jamie Thomas leads IBM's participation as a founding member. IBM emphasizes ecosystem approach bringing community, technology providers, and enterprises together.
- JPMorganChasecoreCISO Pat Opet leads JPMorganChase's involvement as a founding member. Committed to measuring success in patch deployment, not publication, and supporting downstream operators.
- Microsoft and GitHubcoreAzure CTO, Deputy CISO and Technical Fellow Mark Russinovich leads Microsoft and GitHub participation as a founding member. Building on OpenSSF and Alpha-Omega experience, contributing expertise, resources, and AI technologies.
- NVIDIAcoreCSO David Reber represents NVIDIA as a founding member. Emphasized transparency and open collaboration are how cybersecurity community keeps infrastructure safe.
- OpenAIcoreOpenAI is a founding member contributing to coordinated effort to defend critical open source software against AI-enabled cyber threats.
- RapidFortcoreCEO Mehran Farimani leads RapidFort's participation as a founding member. Supports coordinated remediation that preserves integrity of original software and returns fixes to the commons.
- Red HatcoreCTO and SVP Global Engineering Chris Wright leads Red Hat's participation focusing on strengthening the upstream ecosystem through open collaboration to identify and patch vulnerabilities at the source.
- Rust FoundationcoreExecutive Director and CEO Rebecca Rumbul represents the Rust Foundation as a founding member. Looks forward to working with Akrites to develop security fit for the future.
- SonatypecoreCo-founder and CTO Brian Fox, also Steward of Maven Central, represents Sonatype as a founding member. Sees the dependency graph of the modern world and provides visibility into upstream vulnerabilities.
- VodafonecoreCyber & IT strategy and Architecture Director Paul Hopkins leads Vodafone's participation as a founding member. Committed both expertise and funding to unified industry-wide approach.
- ZscalercoreEVP and CSO Deepen Desai represents Zscaler as a founding member. Sees Akrites as helping turn AI speed into an advantage for the open source ecosystem.
- CNCF (Cloud Native Computing Foundation)supportingCNCF Executive Director Jonathan Bryce provided supporting statement. Open source cloud native infrastructure is operational backbone of modern production software; Akrites addresses coordination problem for large-scale remediation.
- LF EnergysupportingExecutive Director Alex Thornton stated support for industry coming together to improve security of open source software energy systems depend on. Projects operate in critical infrastructure from grid operations to EV charging networks.
- OpenInfra FoundationsupportingGM Thierry Carrez noted OpenStack community issued 20 security advisories in one quarter versus just two in all of 2025. Welcomes efforts helping critical open source infrastructure manage growing influx of findings upstream.
- OpenJS FoundationsupportingExecutive Director Robin Bender Ginn stated belief improving open source security is shared responsibility. Welcomes efforts strengthening relationship between industry and maintainers.
- OpenSSF (Open Source Security Foundation)supportingGeneral Manager Steve Fernandez stated rapid pace of AI-driven vulnerability discovery is new reality no single team can face alone. OpenSSF stands firmly in support of mission prioritizing health of shared open source projects.
- PyTorch FoundationsupportingExecutive Director Mark Collier stated open source foundations exist to create conditions for industry to do hard work together that no single organization can do alone. AI has fundamentally changed the math on vulnerability discovery.
Scale indicators2 records
Recent moves5 records
Expansion highlights5 records
Akrites competitors and assessment
Company assessmentBroad incumbents
- Sonatype: A founding member of Akrites and a long-established commercial incumbent in OSS dependency management and vulnerability intelligence. Operates Nexus and Maven Central infrastructure relevant to the same upstream security problem Akrites addresses, but as a broader commercial portfolio rather than a coordination consortium.
- Snyk: Established commercial incumbent in developer-first security, including open source vulnerability scanning and remediation guidance. Operates a much broader security platform than Akrites' narrow coordination focus, but competes for the same organizational budgets and attention.
- JFrog: Broad commercial platform covering software supply chain integrity, artifact management, and security scanning. Adjacent to Akrites' mission through its security and compliance offerings, but operates as a full enterprise platform rather than a coordination consortium.
Emerging players
- Chainguard: A founding member of Akrites specializing in secure, hardened container images and software supply chain integrity. Addresses adjacent parts of the same open source supply chain security problem Akrites targets through coordination rather than productization.
- Endor Labs: A founding member of Akrites focused on OSS dependency security and reachability analysis. Contributed the sub-5% patch-rate statistic used in Akrites' launch narrative. Operates in adjacent commercial OSS security space with potential overlap on remediation prioritization.
Direct peers
- Alpha-Omega Project: A directed Linux Foundation fund focused on improving OSS supply chain security, providing seed funding directly to Akrites. Closest institutional analog as a coordinated, LF-hosted effort targeting the same upstream vulnerability remediation problem with overlapping member base.
- OpenSSF (Open Source Security Foundation): Sister Linux Foundation initiative also focused on improving open source software security. Akrites' open letter explicitly references OpenSSF support, and both operate under the LF umbrella addressing supply chain and vulnerability challenges. OpenSSF's working groups (e.g., SLSA, Sigstore) are highly complementary — and potentially overlapping — with Akrites' CVD mission.
- Tidelift: Commercial subscription service that helps organizations manage open source dependencies, including coordinated remediation and maintenance support for upstream packages. Most direct commercial analog to Akrites' model of paying for collective open source security, though narrower in scope and commercially structured.
Others
- GitHub Security Lab: GitHub's research-focused OSS security initiative that discovers and responsibly discloses vulnerabilities in open source. Functions as a 'finder' upstream of Akrites' coordination flow rather than a direct competitor; explicitly mentioned as an integration partner class by Akrites.
- OSV.dev (Google): Google-operated open source vulnerability database and scanning infrastructure that feeds vulnerability intelligence into the same ecosystem Akrites coordinates. Functions as upstream data infrastructure rather than a direct peer, but materially shapes the operating environment.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
Akrites financial estimates
Financial estimateRevenue estimate
Valuation estimate
Akrites leadership team
Management profileNumber of profiles
Akrites funding detail
Funding detailFunding overview
Funding rounds1 record
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Akrites M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Akrites
What does Akrites do?
Akrites operates a shared Security Incident Response Team (SIRT) that runs a standardized Coordinated Vulnerability Disclosure (CVD) process for critical open source software. The SIRT provides a single confidential front door for members to report vulnerabilities; it validates, deduplicates, and triages findings, then coordinates remediation and patch creation with upstream maintainers using industry-standard frameworks (CVE, TLP 2.0, CWE, CVSS, EPSS, SSVC, VEX) and VINCE case management, culminating in synchronized public disclosure.
Is Akrites a public or private company?
Akrites is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was Akrites founded?
Akrites was founded in 2026.
How does Akrites make money?
Two revenue lines are on record. Membership Dues are the primary driver. The others are seed Funding.
Who are Akrites's main competitors?
Broad incumbents on record are Sonatype, Snyk and JFrog. Emerging players are Chainguard and Endor Labs. Direct peers are Alpha-Omega Project, OpenSSF (Open Source Security Foundation) and Tidelift. Others are GitHub Security Lab and OSV.dev (Google).
Does Akrites have an API?
No public API is recorded for Akrites.
What industry is Akrites in?
Akrites's product category is Cybersecurity Coordination Services. Its primary akta.pro industry code is HDADACAD, Software Supply Chain & Dependency Security (SBOM, Signing), with a secondary code of HDADAEAH, Endpoint Vulnerability & Patch Management. Its NAICS code is 5415 and its SIC code is 7370.