Open-source strategy
Open foundations. Governed integration. A clear exit path.
CLIP integrates proven open-source capabilities through stable product boundaries, documented interfaces and exact-version security and license review.
CLIP · Supply-chain flow
Illustrative view- 01Source
- 02Review
- 03Build
- 04Attest
- 05Sign
- 06Internal registry
- 07Deploy
Nothing reaches a deployment without passing every stage.
Why open source
Four reasons that survive procurement review.
Sovereignty
Core functions operate without dependency on public Internet or foreign software-as-a-service, which is a hard requirement for disconnected deployments.
Transparency
Source availability lets a security authority inspect what it is accepting rather than trusting a description of it.
Interoperability
Open standards and documented interfaces keep data portable and prevent lock-in to opaque formats.
Skills reuse
Practitioners train on tools they will encounter operationally, so capability transfers out of the classroom.
Capability categories
Candidate components by capability.
This records intended direction, not an approved bill of materials. Neutral text labels only — no partner logos and no implication of endorsement.
Structured learning
Open edXExercise control
INJECT MUNIInfrastructure
OpenStackKubernetesKubeVirtSecurity analytics
WazuhOpenSearchNetwork visibility
ZeekSuricataArkimeDigital forensics
VelociraptorTimesketchAutopsySecure development
ForgejoTektonHarborTrivyObservability
OpenTelemetryPrometheusGrafana
Not an approved bill of materials
Foundation systems
Two systems CLIP builds on rather than replaces.
Rebuilding what already works well would add cost and risk without adding capability.
Open edX
Structured learning system of recordRemains authoritative for course enrolment, delivery and completion. CLIP integrates identity context, launch, completion and result synchronisation without creating circular authority over those records.
INJECT MUNI
Tabletop and exercise-control foundationRemains the authoritative source for tabletop scenario and inject state in the MVP. CLIP exchanges exercise, participant, inject and status context while preserving that authority.
CLIP adds the unified experience, identity, policy, competency, range-orchestration, telemetry and evidence layer around these systems.
Adoption gates
Nine gates before a component enters a baseline.
Every gate must be satisfied for the exact version in use. Passing for one release does not carry forward to the next.
- 01Exact version and sourceThe specific release and repository, never a floating tag.
- 02Licence and distribution modelReviewed against the intended deployment and redistribution model.
- 03SBOM and vulnerabilitiesComponent inventory with a known-vulnerability assessment.
- 04Maintainer and community healthActivity, governance and end-of-life outlook.
- 05Offline installation planReproducible install from an internal mirror, no public-Internet dependency.
- 06Security hardeningA documented hardened configuration, not upstream defaults.
- 07Backup and recoveryBackup, restore and migration procedures that have been tested.
- 08Integration contract and ownershipA named owner and a defined interface boundary.
- 09Exit strategyA data-export path and a viable replacement route.
Licence families
Licence obligations shape architecture.
Licence review happens against the exact release used, including transitive dependencies, fonts, icons and copied assets. An SPDX identifier alone is not approval.
Permissive
MIT, Apache-2.0, BSD, ISC. Retain notices; few architectural constraints.
Weak copyleft
MPL-2.0, LGPL. File- or library-level obligations on modification and distribution.
Strong copyleft
GPL, AGPL. Network and distribution obligations require architecture and legal review.
Mixed or component-specific
Distributions bundling many licences. Inventory the exact image or release.
Legal review is required
Supply chain
From upstream source to running deployment.
- 01SourceExact version, pinned by digest.
- 02ReviewSecurity, licence and community health.
- 03BuildIsolated, reproducible pipeline.
- 04AttestProvenance and SBOM generated.
- 05SignArtifact and image signatures.
- 06DeployFrom the internal registry only.
In sequence: An upstream source is reviewed, built in an isolated pipeline, attested with provenance, signed, published to an internal registry and only then deployed — with each step producing retained evidence.
Contribution and partnership
Working with the communities we depend on.
Depending on open-source projects creates an obligation toward them. These are the ways that obligation is met in practice.
Upstream contribution
Fixes and improvements developed for CLIP are offered upstream where the project accepts them.
Scenario and content sharing
Approved scenarios and detection content can be shared subject to classification and releasability rules.
Research collaboration
Governed datasets and reproducible environments for academic and institutional research.
Integration partnership
Documented interfaces for organizations building adjacent capability.
Discuss a partnership.
Whether you maintain a component we use, build adjacent capability or want to collaborate on content — we would like to hear from you.