Skip to main content

Bitsea Announces OpenChain Security Assurance Services

Bitsea, a service provider specialized in software auditing and based in Germany, today announces support for the OpenChain Security Assurance Specification 1.1. They can help companies understand and adopt this standard for open source security in Germany and beyond. As a sister standard to OpenChain ISO/IEC 5230 – the international standard for open source license compliance – the OpenChain Security Assurance Specification 1.1 offers the same type of support for building a quality security assurance program.

“For over 10 years Bitsea has provided services to help organizations identifying hidden risks in software systems and managing their open source software supply chain,” says Dr. Andreas Kotulla, Founder and CEO of Bitsea. “Our services guide organizations to adopt and conform to both ISO 5230 OpenChain and OpenChain Security Assurance.”

“Bitsea has long been a provider of excellent reputation in the open source area,” says Shane Coughlan, OpenChain General Manager. “Their new services to support adoption of the OpenChain Security Assurance Specification 1.1 are a timely and useful contribution to the community in Germany and beyond. Open source security is a vital part of the global supply chain, and solid process management is key to addressing the ongoing challenges.”

About Bitsea

Big software systems are like a wild wide ocean of bits – our passion is to analyse and visualize software structure. We are keen to help our customers how to stabilize and optimize their systems. We assess software. We analyze, evaluate and optimize your development processes, software architecture and software design. We perform the technical due diligence for company takeovers. We reduce the economic risk by assessing open source components and ensure license compliance.

Our references include well-known Fortune 500 companies in communications, automotive, logistics, retail and aerospace industries. Highest standard for information security: We are VDA/ISA Tisax-certified since 2020. All data of our customers remain in Germany or, if required, in the territory of our customers. We are involved in the Bitkom Open Source working group. Bitsea is part of the OpenChain Community. We guarantee strictly confidential consulting in the context of technical due diligence for M&A activities. 

Learn more:

About the OpenChain Project

The OpenChain Project has an extensive global community that involves thousands of companies collaborating to make the supply chain quicker, more effective and more efficient. We work together to create trust between entities around open source. Our job is to increase trust in the open source supply chain. We do this by maintaining ISO/IEC 5230:2020, the International Standard for open source license compliance, and our Security Assurance Reference Specification. We also have a large global community where knowledge is shared to reduce friction and increase efficiency across all aspects of open source process management.

Learn more:

About The Linux Foundation

The Linux Foundation is the world’s largest non-profit connecting global technical experts, and providing them with a neutral and trusted platform to develop open source projects. Founded in 2000 as the home of the Linux Kernel, the Linux Foundation has grown to host hundreds of open source projects, with a community spanning 2,950+ members, 540,000+ contributing developers, and 19,000+ contributing companies.

Learn more: