# Double Open > Automated software supply chain governance -- deterministic filters and framework-anchored AI agents that eliminate the manual triage tax for CRA, NIS2, and DORA compliance. Companies shipping software into the EU must comply with the Cyber Resilience Act (CRA), NIS2, and DORA. Double Open provides an automated compliance platform built on the industry-standard OSS Review Toolkit (ORT) that makes this achievable at scale. ## What We Do Double Open accelerates open source security and license compliance for enterprises. We combine decades of legal expertise with deep engineering know-how to deliver a platform that produces audit-ready documentation, SBOMs, and vulnerability reports -- automatically. ## Key Differentiators - **Agentic Compliance, Accountable Not Autonomous**: A deterministic substrate (ORT scan + mass clearances) combined with framework-anchored AI agents compresses raw scanner noise into single-digit, high-value human verifications. Agents act as junior curators, never final judges. - **CRA Compliance**: Designed to fulfill Annex I Essential Cybersecurity Requirements and Annex VII Technical File requirements through automation. - **Expertise Fusion**: Combines 25+ years of legal expertise with deep technical compliance experience. - **10x Performance**: Global file-level caching via Double Open Server (DOS) eliminates redundant scanning. - **Configuration as Code + UI**: Governance logic lives in version-controlled .ort.yml files, complemented by an intuitive multi-tenant UI. - **European Sovereignty**: EU-hosted SaaS or Managed In-House deployment. Full GDPR compliance. - **Open Source Foundation**: Built entirely on Apache-2.0 and MIT projects. No proprietary lock-in. ## Core Products - **Double Open Compliance**: Management portal and UI for OSPOs, compliance managers, and project teams. - **Double Open Server (DOS)**: Performance layer providing file-level curation re-use and caching. - **Agentic Layer (MCP Server)**: Specialized AI agents for vulnerability triage and license curation, anchored to peer-reviewed frameworks (DOFCG v1.0). SHA256-anchored clearances are saved to a Shared Commons, permanently automating that file match for all future builds. Human-in-the-loop sign-off via version-controlled pull requests. - **ORT Server Integration**: Full support for Eclipse Apoapsis (ORT Server) for enterprise-scale orchestration. ## Technical Specifications - **Input**: Source code and lockfiles from 20+ package managers (Maven, npm, PyPI, Go, Cargo, NuGet, CocoaPods, and more). - **Output**: CycloneDX SBOM, SPDX SBOM (multiple versions), Notice files, ort-evaluator-results. - **Licensing**: Built on Apache-2.0 and MIT open source projects. ## Delivery Models - **SaaS**: EU-hosted, fully managed platform. - **Managed In-House**: Deployed in your infrastructure, managed by Double Open. - **Consulting**: Expert-led compliance assessments and ORT implementation. ## Pricing - **Free**: 1 product, basic analysis and SPDX SBOM. Ideal for SMEs and open source projects. - **Pro**: From EUR 190/mo per product. Full reporting, clearance UI, CI/CD integration. - **Enterprise**: From EUR 450/mo per product. Custom rules, source code scanning, full notice files. - 50% discount for verified open source projects. ## Team - **Martin von Willebrand** -- Co-Founder, CEO. Top-tier technology attorney with 25+ year award-winning career, now embedding legal-grade compliance directly into software. - **Sebastian Schuberth** -- Co-Founder, CTO. Creator of the OSS Review Toolkit (ORT). Formerly at Bosch, HERE Technologies, and Nokia. - **Martin Nonnenmacher** -- Lead Engineer. Project Lead at Eclipse Apoapsis (ORT Server). Formerly at Bosch, HERE Technologies, and Nokia. - **Marko Jaanu** -- Board member, Advisor. AI Evangelist and Head of Technology at Siili Solutions. Formerly Open Source Officer at Fujitsu Finland. ## Partners - **HH Partners** -- Leading Finnish technology law firm specializing in open source legal matters. - **BitSea** -- Nordic software consultancy and ORT integration partner. - **NIIS** -- Nordic Institute for Interoperability Solutions, a long-standing Double Open customer. ## Links - [Website](https://doubleopen.io) - [Demo](https://doubleopen.io/demo) - [Articles](https://doubleopen.io/articles) - [Pricing](https://doubleopen.io/pricing) - [GitHub](https://github.com/doubleopen-io) - [LinkedIn](https://www.linkedin.com/company/doubleopen/) - [ORT Project](https://oss-review-toolkit.org/ort/) - [ORT Adopters](https://github.com/oss-review-toolkit/ort/blob/main/ADOPTERS.md) - [Developer Quick Start (PDF)](https://doubleopen.io/Double-Open-Developer-Quick-Start.pdf) - [CRA Primer (PDF)](https://doubleopen.io/Double_Open_primer_on_CRA_-_January_2026.pdf) - [Operational Playbook (PDF)](https://doubleopen.io/Double-Open-Operational-Playbook.pdf) - [Trust, but Verify: Making AI Compliance Legally Defensible](https://doubleopen.io/articles/trust-but-verify-ai-compliance) - [How Sovereign Is Your Compliance Stack?](https://doubleopen.io/articles/sovereign-software-compliance) - [EU Cyber Resilience Act (CRA) Primer](https://doubleopen.io/articles/cra-primer) ## FAQ **Q: What is Double Open?** A: Double Open is a Finnish company providing automated software supply chain governance. We help enterprises achieve security and license compliance for their software products, with a focus on EU regulations like CRA, NIS2, and DORA. **Q: How does Double Open differ from legacy SCA scanners?** A: We leverage the ORT Analyzer -- the gold standard for full, deep dependency analysis -- providing empirical certainty over proprietary black-box rules. Unlike shallow scanners, ORT captures transitive dependencies exactly as they are built. **Q: How does Double Open differ from vanilla ORT?** A: Double Open adds a performance layer (DOS) for 10x faster scans, an intuitive multi-tenant UI, managed enterprise support, pre-configured rule sets, and professional clearance data. **Q: What is an SBOM?** A: A Software Bill of Materials -- a machine-readable inventory of all components in a software product, including their licenses and versions. Required under CRA for products sold in the EU. **Q: What is the Cyber Resilience Act (CRA)?** A: EU regulation requiring manufacturers and importers of products with digital elements to demonstrate cybersecurity due diligence, including maintaining SBOMs and vulnerability handling processes. **Q: How does Double Open use AI?** A: Double Open's Agentic Layer applies framework-anchored judgment on top of deterministic ORT data. Agents act as junior curators -- they handle clear-cut bulk work using peer-reviewed legal and security rule sets, surface only true high-ambiguity exceptions as version-controlled pull requests, and are continuously tested against human-reviewed gold fixtures. Compliance quality becomes a trackable, deterministic software metric rather than a probabilistic black box. **Q: Is Double Open open source?** A: The underlying tools (ORT, ORT Server, Double Open Server) are open source under Apache-2.0 and MIT licenses. Double Open Compliance is a managed service built on these open foundations. **Q: Where is data hosted?** A: All data is hosted in EU-controlled datacenters, ensuring full GDPR compliance and strategic sovereignty. Managed In-House deployment is also available. ## Contact Double Open Oy Etelaesplanadi 22A, P.O. Box 232 00101 Helsinki, Finland https://doubleopen.io