Exposure discovery EU-developed

OpenCVE

Tracks published vulnerabilities for selected vendors and products, with CVE filtering, subscriptions, notifications and shared remediation tracking for security teams.

By Amber Security / OpenCVE project · France

EU-developed

The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.

At a glance

Recorded facts
Response workflow
Exposure discovery
Developer or maintainer
Amber Security / OpenCVE project
Recorded country
France
Product model
Source available
Deployment
Self-hosted / SaaS
Software license
BUSL-1.1
Upstream status
Active
Evidence class
EU-developed

What the sources establish

Origin note

OpenCVE identifies Amber Security SAS as its publisher; the French company describes OpenCVE as its own vulnerability-monitoring solution and lists its registered office in Lille.

Reported capabilities

  • Vendor and product CVE subscriptions
  • Risk filtering and notification workflows
  • Docker deployment or hosted Cloud service

Scope and limits

The current Community code uses Business Source License 1.1, not an open-source license. Its additional grant restricts commercial security monitoring and alerting services for third parties; separate commercial terms may be needed. The inspected license names a 2030-08-14 change date to Apache-2.0 for that version. The hosted Cloud service has separate commercial terms; Cloud-only features are not assumed to be included in Community. This tracks disclosed CVEs and does not scan assets for vulnerabilities.

Inspect the research evidence 7 source observations
  1. identity / capabilities

    The upstream README describes a vulnerability-intelligence application with vendor/product subscriptions, CVE filters, notifications and team workflows; it separates Community from Cloud features.

    Read source
  2. origin

    OpenCVE names its two creators and identifies the publisher as Amber Security SAS.

    Read source
  3. origin / country

    Amber Security describes creating its OpenCVE solution and gives its French SAS registration and Lille office. This establishes the French publisher/steward, not every contributor location.

    Read source
  4. license

    Actual LICENSE text is Business Source License 1.1 with an additional-use restriction on providing commercial security monitoring and alerting services to third parties. It explicitly is not an open-source license; the inspected version changes to Apache-2.0 on 2030-08-14.

    Read source
  5. deployment

    Current installation documentation describes a complete Docker stack and directs users to OpenCVE Cloud as the hosted option.

    Read source
  6. license / deployment

    The official service agreement governs subscription-based SaaS access and limits customer rights; the hosted service is not covered by a blanket open-source grant.

    Read source
  7. maintenance

    The upstream changelog records version 3.1.0 on 2026-08-14 with API and access-control changes. Release activity is not a support guarantee.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Put the tool in context.

Scope exposure discovery, validate vulnerability findings, prioritize affected assets and verify remediation. Practical guidance with documented European tools.

From vulnerability finding to verified remediation