Public OSPO, ten projects in the open.
What FlyttGo maintains, what FlyttGo sponsors, what FlyttGo contributes upstream — and the explicit boundary between OSS and proprietary in the platform stack. Open Source Programme Office policy public; quarterly contribution report shipped alongside the changelog.
- Maintained projects5
- Sponsored projects3
- Upstream contributions2
- OS.PR.01
Maintained projects
FlyttGo maintains the SDK, the reference MCP server, the policy-as-code library, the CLI, and the sigstore helpers. Each released under MIT or Apache-2.0; CI in GitHub Actions; CodeQL + Sigstore on every release.
- OS.PR.02
Sponsored projects
FlyttGo sponsors paid maintainer time on Sigstore Cosign, Open Policy Agent and CycloneDX CLI — three projects in the platform's critical-supply-chain path. Sponsorship is public, audit-trail-attached, and signed via OpenSSF Funding.
- OS.PR.03
Upstream contributions
FlyttGo engineers contribute spec feedback to MCP, OpenTelemetry, AsyncAPI and W3C VC working groups. Time-budgeted, public, and reflected on individual engineers' OSS-contribution profiles.
- OS.PR.04
OSPO policy
Open Source Programme Office policy: 10 % engineering time available for contributions; CLA-free upstream where the project allows; license-compatibility scan on every dependency; quarterly OSPO report.
Ten projects, three contribution shapes.
- flyttgo/sdk-typescriptMaintained
Official TypeScript SDK across the FlyttGo platform — auto-generated from OpenAPI 3.1 specs, ESM-first, tree-shakable.
TypeScript·MITOpen on GitHub - flyttgo/mcp-serverMaintained
Reference MCP server implementation exposing the platform tool registry. Used by Claude, Cursor, OpenAI Agents SDK.
TypeScript·Apache-2.0Open on GitHub - flyttgo/policy-as-codeMaintained
Open Policy Agent rego library covering the FlyttGo platform-policy API — admission controls, agent scopes, sovereign-region policies.
Rego·Apache-2.0Open on GitHub - flyttgo/cliMaintained
Command-line tool for workspace operations — workspace token issuance, deployment scaffolding, audit log export.
Go·MITOpen on GitHub - flyttgo/sigstore-helpersMaintained
Sigstore signing + verification helpers used internally on every release artefact; useful as a reference for SLSA L3 builds.
Go·Apache-2.0Open on GitHub - sigstore/cosignSponsored
Container-signing tool used across the FlyttGo release pipeline. FlyttGo sponsors maintainer time on the project.
Go·Apache-2.0Open on GitHub - open-policy-agent/opaSponsored
Open Policy Agent — used for admission policy across every FlyttGo deployment substrate. FlyttGo contributes upstream.
Go·Apache-2.0Open on GitHub - CycloneDX/cyclonedx-cliSponsored
CycloneDX SBOM tooling — generates the per-release SBOMs published at /sbom. FlyttGo contributes upstream.
C#·Apache-2.0Open on GitHub - modelcontextprotocol/specificationContributed
Model Context Protocol specification. FlyttGo contributes spec feedback + interop test coverage from production.
Markdown·MITOpen on GitHub - opentelemetry-io/otepsContributed
OpenTelemetry Enhancement Proposals. FlyttGo contributes telemetry-schema feedback for cross-tenant observability.
Markdown·Apache-2.0Open on GitHub
Where the line sits, surface by surface.
| Surface | Position |
|---|---|
| Platform modules (Transify, Workverge, Civitas, EduPro, Identra, Payvera, Ledgera, Marketplace) | Proprietary |
| TypeScript SDK + CLI | Open · MIT |
| Reference MCP server | Open · Apache-2.0 |
| Policy-as-code (OPA rego library) | Open · Apache-2.0 |
| OpenAPI 3.1 specifications | Open · CC-BY 4.0 |
| Audit envelope schema (CloudEvents 1.0) | Open standard · adopted upstream |
| Sigstore signing tooling | Sponsored upstream |
| OpenTelemetry exporters | Open · upstream |
| Sovereign-cluster bootstrapper | Proprietary · partner-shared under MNDA |
| AI weights + retraining pipelines | Proprietary · disclosed in AIBOM |
Open source touches every other trust artefact.
OSS posture is a procurement signal. The four pathways below take a security or developer review from this manifest into deeper engagement.
- OS.00
Open standards
33 standards across 6 interop categories — what every OSS project here implements.
OS.00 · 33 standards - SB.00
SBOM registry
Per-release CycloneDX 1.6 SBOM — exposes every OSS dependency in production.
SB.00 · 8 modules - TC.00
Trust artefacts
Vulnerability disclosure policy, supply-chain provenance, OSPO compliance posture.
TC.00 · 8 artefacts - CB.00
Open scoping
Five-step intake routes an OSS-led discussion under CT.01 platform architecture session.
CT.01 · CB.00