OSRAMP

Open Source Risk and Asset Management Platform
ControlPlane
controlplane.io | September 2025
Platform Overview

ControlPlane’s Open Source Risk and Asset Management Platform (OSRAMP) provides automated supply chain governance by securely managing the ingestion of Open Source Software (OSS) and other third-party artefacts. Acting as a centralised gatekeeper, OSRAMP mitigates systemic risks introduced by dependencies from public ecosystems, ensuring only trusted, verified, and policy-compliant components enter an organisation’s internal systems.

Incorporated operational models for enterprise vulnerability assessment to safely deploy mitigations or address unpatched vulnerabilities. OSRAMP ensures business continuity and enables safe mitigation deployment with continuous protection for unpatched OSS components.

Backed by 250 years of cloud native expertise and born from collaboration with the world’s most targeted financial services organisations. Assured by our world-leading SMEs in supply chain, open source and cloud native security, and distributed systems.

The Problem: Unmanaged OSS Risk
Modern software development relies heavily on OSS, but direct ingestion introduces significant attack vectors expanding your organisation's attack surface.
Unsafe Sources
Insufficient Integrity
Dependency Risk
High-Risk Pipelines
Hidden Dependencies
Incomplete Governance
How OSRAMP Works: Secure Ingestion Pipeline
1
Request
Developer requests OSS package
2
Analysis
SBOM, scan, patch, verify
3
Policy
Approve, reject, or flag
4
Delivery
Trusted internal registry
Business Impact

OSRAMP transforms OSS risk from an unmanaged liability into a controlled, auditable process whilst maintaining developer velocity.

Days→Hours
Zero-Day Response
100%
Asset Visibility
SLSA L3
Provenance

Security response times are reduced through automated patching and VEX workflows, ensuring sustained compliance and operational resilience.

Comprehensive asset graphing enables the instant identification and remediation of affected workloads across your entire estate.

Key Security Controls
Verify trusted sources only
Automated vulnerability management
Consistent integrity checks
Transitive dependency visibility
Least privilege build pipelines
Policy-as-code governance
Technology Foundation
Built on CNCF standards and battle-tested open source: SLSA L3 provenance, in-toto attestation, Sigstore verification, integrated with leading vendors and your existing tooling, and hardened Kubernetes deployment via Flux CD reference architectures.
SLSA L3 SLSA L3
in-toto
Sigstore Sigstore
OPA OPA
Kubernetes Kubernetes
Flux Flux
SBOM
VEX
Operational Model & Responsibilities

OSRAMP operates on a shared responsibility model that enables collaboration between teams.

First-Party Code Authors: The process is transparent. Request packages from internal registry; OSRAMP securely handles backend fetching and validation

Security Teams: Manage base images, organisational policy, and incident response. Track risk with comprehensive dashboards and VEX documents

Platform Teams: Manage middleware pipelines, shared services, and operational availability for the platform

Application Teams: Responsible for first-party code and dependencies, consuming secure artefacts provided by the platform

Defence-in-Depth: From Detection to Automated Remediation

OSRAMP doesn’t just detect vulnerabilities — it fixes them.

With automated patching that backports and regression tests secure fixes, vulnerabilities are remediated within the ingestion pipeline itself.

Comprehensive asset graphing enables instant identification of affected workloads across your entire estate, ensuring sustained compliance and operational resilience.

Get Started with OSRAMP

Contact us to learn how OSRAMP can transform your open source supply chain security and reduce risk across your organisation.

Address
London, NYC, Melbourne, Auckland