SlideShare a Scribd company logo
1 of 13
Download to read offline
Starting big, enabled by open source
Martin von Willebrand, Founder
Mindtrek, 3.10.2023
https://www.doubleopen.org/
1. What is Double Open?
Service for software composition analysis (SCA) with open source tools
➢ Open source compliance (available now)
○ Analyze, download, scan, evaluate, report
➢ Software Bill of Materials (available now)
○ Analyze, download, scan, evaluate, report
➢ Vulnerability scanning (not yet)
2
https://www.doubleopen.org/
2. What is the delivery / business model?
● Open source tool that can be installed in-house and integrated into CI/CD
○ Available now - setup project required
○ Data via API - augments the tool with trusted data
■ Available now
■ Coming: free tier, registered tier, paid tier + pay-as-you-go, enterprise tier
○ Support tickets
● Full Software-as-a-Service offering with no in-house installations needed
○ Coming
3
https://www.doubleopen.org/
3. SCA Market
- Software composition analysis (SCA)
- Security analysis, open source compliance, sboms
- Cloud-based and on-premises solutions
- Total of ~1,5B annually, expected to grow to rapidly, forecasts to 4B@2025
- Synopsys 0,5B (of 5B)
- Veracode ? (0,5B of 6,5B)
- Mend 0,1B
- Currently typical revenue per client size 100-500k/year. One-off projects are
smaller.
- DO appraisal: current market players have mostly very large customers,
around ~2000-5000 continuous clients, and then one-off project customers on
top of that
4
https://www.doubleopen.org/
4. Market Opportunity for scalable SaaS/API SCA
- All businesses are becoming software driven
- IoT, cloud, automotive, healthcare, manufacturing, retail
- European Comission: 95% are using digital technologies
- Cyber Resilience Act will further drive growth for SCA
- Number of businesses in Europe: 23M (Eurostat 2022)
- 1,5M of the companies are larger than 10 persons.
- 150.000 are fast growing companies
- Internationally 10x
- Addressable market globally around 1,5M companies
- 100x+ of current SCA clientele
- 20.000 euro /year for 75.000 customers (5%) means 1,5B in revenue
5
https://www.doubleopen.org/
5. DO Value proposition for clients
● Services outcome for clients
○ Compliant software all the time, automated
○ Reduced manual work and costs, faster time to market
○ Higher productivity, clear process to solve arising questions
○ Tech and legal issues solved in tandem
○ Minimized risk & increased and confidendent OSS usage
○ Growing OSS competence
● Services
○ Open source tooling as SaaS or on-premises
○ License data, tech curation etc. over API
○ Tech and legal support services for
■ Projects for taking the tools and improved processes into use
■ Solving tickets in using the processes and tools
6
OSS quality with
license compliance,
without vulnerabilities
Automate,
because you
can!
https://www.doubleopen.org/
Customer testimonials
Petteri Kivimäki, CTO, Nordic Institute for Interoperability Solutions, NIIS:
“With the help of Double Open, our third-party open-source component usage is now compliant all
the time, and we have significantly reduced both the time needed in open-source compliance and
the related administrative headaches.”
7
https://www.doubleopen.org/
6. Where is DO now?
- Background in open source compliance collaboration at HH Partners.
Spinned off to own company, Double Open Oy, August/September 2023
- Pilot references from Vaisala, NIIS (and Validos members)
- Existing revenue
- Many collaboration partners, multiple leads in Finland, Sweden, Germany etc.
- Two sw developers, CEO deal pending, operative advisors, strategic partner
- Pre-seed funding of about 150k (not closed)
- How can we be so far already now?
8
https://www.doubleopen.org/
7. Open source building blocks
- ORT:
- “A suite of tools to automate software compliance checks.”
- Adopters such as Bosch, HERE Technologies, Porsche
- Attempts to cover the whole process
- ScanCode Toolkit
9
https://www.doubleopen.org/
7. Open Source Building Blocks, ORT
10
https://www.doubleopen.org/
8. Double open business model analysis
Value: Automated and integrated software compliance
Rare: High quality compliance data API
Inimitability: Compliance data creation via curation service, co-creation in
curation, reinforced by brand
Organized: SaaS and API management
Open everything we can, to maximise demand for our API.
11
https://www.doubleopen.org/
9. What’s in open source business models?
● Search for a scalable open source business model
○ Key business is not in hours or projects sold
● Focus on value created at client. Look beyond your software offering.
○ Software is always part of a process at the client. The client needs also other services.
○ Google open sourced a lot, but it’s business is in data, data understanding and leverage.
○ Red Hat is reasonably pure open source, but makes its business on signed and certified
binaries.
● Do not focus on software installation, or delivery projects, or customization
projects. May be required, but better to off-load to others.
● Brand? Data? Community? Add-ons by third parties?
Open everything you can to maximise demand for your scalable service.
12
Thank you

More Related Content

Similar to How open source empowers startups to start big, with case Double Open Oy

[Social innovation challenge][pitching]
[Social innovation challenge][pitching][Social innovation challenge][pitching]
[Social innovation challenge][pitching]
Ann Lam
 
Scandinavia
ScandinaviaScandinavia
Scandinavia
jaromik
 
SII IT Services
SII IT ServicesSII IT Services
SII IT Services
jaromik
 
AIT-Portfolio - thomas
AIT-Portfolio - thomasAIT-Portfolio - thomas
AIT-Portfolio - thomas
Thomas Russell
 

Similar to How open source empowers startups to start big, with case Double Open Oy (20)

Web Venture Development Outsourcing
Web Venture Development OutsourcingWeb Venture Development Outsourcing
Web Venture Development Outsourcing
 
Be informed overview
Be informed overviewBe informed overview
Be informed overview
 
DevOps as a Service - our own true story with a happy ending (JuCParis 2018)
DevOps as a Service - our own true story with a happy ending (JuCParis 2018)DevOps as a Service - our own true story with a happy ending (JuCParis 2018)
DevOps as a Service - our own true story with a happy ending (JuCParis 2018)
 
Ecotech Presentation.pdf
Ecotech Presentation.pdfEcotech Presentation.pdf
Ecotech Presentation.pdf
 
BitCraft 2017 general presentation
BitCraft 2017 general presentationBitCraft 2017 general presentation
BitCraft 2017 general presentation
 
arago - NOAH19 Berlin
arago - NOAH19 Berlinarago - NOAH19 Berlin
arago - NOAH19 Berlin
 
ArabNet Beirut - Keynote: Open Banking - To be or not to be? by Open Bank Pr...
ArabNet Beirut  - Keynote: Open Banking - To be or not to be? by Open Bank Pr...ArabNet Beirut  - Keynote: Open Banking - To be or not to be? by Open Bank Pr...
ArabNet Beirut - Keynote: Open Banking - To be or not to be? by Open Bank Pr...
 
Keynote: Open Banking - To be or not to be? by Open Bank Project by ArabNet B...
Keynote: Open Banking - To be or not to be? by Open Bank Project by ArabNet B...Keynote: Open Banking - To be or not to be? by Open Bank Project by ArabNet B...
Keynote: Open Banking - To be or not to be? by Open Bank Project by ArabNet B...
 
[Social innovation challenge][pitching]
[Social innovation challenge][pitching][Social innovation challenge][pitching]
[Social innovation challenge][pitching]
 
AdminCamp 2018 - ApplicationInsights für Administratoren
AdminCamp 2018 - ApplicationInsights für AdministratorenAdminCamp 2018 - ApplicationInsights für Administratoren
AdminCamp 2018 - ApplicationInsights für Administratoren
 
Scandinavia
ScandinaviaScandinavia
Scandinavia
 
SII IT Services
SII IT ServicesSII IT Services
SII IT Services
 
1C Partner Presentation
1C Partner Presentation1C Partner Presentation
1C Partner Presentation
 
Python in the Financial Industry The universal tool for end-to-end developme...
Python in the Financial Industry  The universal tool for end-to-end developme...Python in the Financial Industry  The universal tool for end-to-end developme...
Python in the Financial Industry The universal tool for end-to-end developme...
 
ITMAGINATION - competences, facts, technologies, clients
ITMAGINATION - competences, facts, technologies, clientsITMAGINATION - competences, facts, technologies, clients
ITMAGINATION - competences, facts, technologies, clients
 
GNS: Your IT outsourcing provider
GNS: Your IT outsourcing providerGNS: Your IT outsourcing provider
GNS: Your IT outsourcing provider
 
openGPSoC
openGPSoCopenGPSoC
openGPSoC
 
I nearshore
I nearshore I nearshore
I nearshore
 
Ever it onepager
Ever it onepagerEver it onepager
Ever it onepager
 
AIT-Portfolio - thomas
AIT-Portfolio - thomasAIT-Portfolio - thomas
AIT-Portfolio - thomas
 

More from Mindtrek

More from Mindtrek (20)

What the AI revolution means for Open Source, Open Tech and Open Societies
What the AI revolution means for Open Source, Open Tech and Open SocietiesWhat the AI revolution means for Open Source, Open Tech and Open Societies
What the AI revolution means for Open Source, Open Tech and Open Societies
 
Data balance sheets laying foundations for sustainable and ethical use of data
Data balance sheets laying foundations for sustainable and ethical use of dataData balance sheets laying foundations for sustainable and ethical use of data
Data balance sheets laying foundations for sustainable and ethical use of data
 
Towards data responsibility - how to put ideals into action
Towards data responsibility - how to put ideals into actionTowards data responsibility - how to put ideals into action
Towards data responsibility - how to put ideals into action
 
Täytä velvollisuudet ja hyödynnä mahdollisuudet – käytännön työkaluja regulaa...
Täytä velvollisuudet ja hyödynnä mahdollisuudet – käytännön työkaluja regulaa...Täytä velvollisuudet ja hyödynnä mahdollisuudet – käytännön työkaluja regulaa...
Täytä velvollisuudet ja hyödynnä mahdollisuudet – käytännön työkaluja regulaa...
 
Datatalouden ja tekoälyn regulaatio – missä mennään?
Datatalouden ja tekoälyn regulaatio – missä mennään?Datatalouden ja tekoälyn regulaatio – missä mennään?
Datatalouden ja tekoälyn regulaatio – missä mennään?
 
Green ICT Tools for Sustainable Digitalization
Green ICT Tools for Sustainable DigitalizationGreen ICT Tools for Sustainable Digitalization
Green ICT Tools for Sustainable Digitalization
 
Future-proof digitalization is on full speed – are you on board?
Future-proof digitalization is on full speed – are you on board?Future-proof digitalization is on full speed – are you on board?
Future-proof digitalization is on full speed – are you on board?
 
How to (Help to) Save Our Planet with Green Coding
How to (Help to) Save Our Planet with Green CodingHow to (Help to) Save Our Planet with Green Coding
How to (Help to) Save Our Planet with Green Coding
 
National Library of Finland - open source solutions in the development of nat...
National Library of Finland - open source solutions in the development of nat...National Library of Finland - open source solutions in the development of nat...
National Library of Finland - open source solutions in the development of nat...
 
The Case for Open Source in the Public Sector
The Case for Open Source in the Public SectorThe Case for Open Source in the Public Sector
The Case for Open Source in the Public Sector
 
KEYNOTE: From Lutece to CiteLibre, City of Paris' commitment to open source
KEYNOTE: From Lutece to CiteLibre, City of Paris' commitment to open sourceKEYNOTE: From Lutece to CiteLibre, City of Paris' commitment to open source
KEYNOTE: From Lutece to CiteLibre, City of Paris' commitment to open source
 
Freedom & Functionality – A Startup Approach to Open Source & Innovation for ...
Freedom & Functionality – A Startup Approach to Open Source & Innovation for ...Freedom & Functionality – A Startup Approach to Open Source & Innovation for ...
Freedom & Functionality – A Startup Approach to Open Source & Innovation for ...
 
Sustainable Open Source; Balancing Business and Community
Sustainable Open Source; Balancing Business and CommunitySustainable Open Source; Balancing Business and Community
Sustainable Open Source; Balancing Business and Community
 
Empowering Employment: The Swedish Public Employment Service’s digital transf...
Empowering Employment: The Swedish Public Employment Service’s digital transf...Empowering Employment: The Swedish Public Employment Service’s digital transf...
Empowering Employment: The Swedish Public Employment Service’s digital transf...
 
KEYNOTE: How to automate the world the open source way
KEYNOTE: How to automate the world the open source wayKEYNOTE: How to automate the world the open source way
KEYNOTE: How to automate the world the open source way
 
"Perspectives from the EU level" by Henna Virkkunen
"Perspectives from the EU level" by Henna Virkkunen"Perspectives from the EU level" by Henna Virkkunen
"Perspectives from the EU level" by Henna Virkkunen
 
"Sand battery and other new energy concepts by Vatajankoski" by Pekka Passi
"Sand battery and other new energy concepts by Vatajankoski" by Pekka Passi"Sand battery and other new energy concepts by Vatajankoski" by Pekka Passi
"Sand battery and other new energy concepts by Vatajankoski" by Pekka Passi
 
"Finnish National Rural Network: Support framework for Smart Villages" by Sal...
"Finnish National Rural Network: Support framework for Smart Villages" by Sal..."Finnish National Rural Network: Support framework for Smart Villages" by Sal...
"Finnish National Rural Network: Support framework for Smart Villages" by Sal...
 
"Smart Villages in Finland" by Marianne Selkäinaho
"Smart Villages in Finland" by Marianne Selkäinaho"Smart Villages in Finland" by Marianne Selkäinaho
"Smart Villages in Finland" by Marianne Selkäinaho
 
"Animating Smart Village Strategies in Ireland: Opportunities and Outcomes" b...
"Animating Smart Village Strategies in Ireland: Opportunities and Outcomes" b..."Animating Smart Village Strategies in Ireland: Opportunities and Outcomes" b...
"Animating Smart Village Strategies in Ireland: Opportunities and Outcomes" b...
 

Recently uploaded

Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Victor Rentea
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 

Recently uploaded (20)

Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Simplifying Mobile A11y Presentation.pptx
Simplifying Mobile A11y Presentation.pptxSimplifying Mobile A11y Presentation.pptx
Simplifying Mobile A11y Presentation.pptx
 
Introduction to use of FHIR Documents in ABDM
Introduction to use of FHIR Documents in ABDMIntroduction to use of FHIR Documents in ABDM
Introduction to use of FHIR Documents in ABDM
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
 
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
 
AI in Action: Real World Use Cases by Anitaraj
AI in Action: Real World Use Cases by AnitarajAI in Action: Real World Use Cases by Anitaraj
AI in Action: Real World Use Cases by Anitaraj
 
Six Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal OntologySix Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal Ontology
 
Less Is More: Utilizing Ballerina to Architect a Cloud Data Platform
Less Is More: Utilizing Ballerina to Architect a Cloud Data PlatformLess Is More: Utilizing Ballerina to Architect a Cloud Data Platform
Less Is More: Utilizing Ballerina to Architect a Cloud Data Platform
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Vector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptxVector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptx
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelMcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 

How open source empowers startups to start big, with case Double Open Oy

  • 1. Starting big, enabled by open source Martin von Willebrand, Founder Mindtrek, 3.10.2023
  • 2. https://www.doubleopen.org/ 1. What is Double Open? Service for software composition analysis (SCA) with open source tools ➢ Open source compliance (available now) ○ Analyze, download, scan, evaluate, report ➢ Software Bill of Materials (available now) ○ Analyze, download, scan, evaluate, report ➢ Vulnerability scanning (not yet) 2
  • 3. https://www.doubleopen.org/ 2. What is the delivery / business model? ● Open source tool that can be installed in-house and integrated into CI/CD ○ Available now - setup project required ○ Data via API - augments the tool with trusted data ■ Available now ■ Coming: free tier, registered tier, paid tier + pay-as-you-go, enterprise tier ○ Support tickets ● Full Software-as-a-Service offering with no in-house installations needed ○ Coming 3
  • 4. https://www.doubleopen.org/ 3. SCA Market - Software composition analysis (SCA) - Security analysis, open source compliance, sboms - Cloud-based and on-premises solutions - Total of ~1,5B annually, expected to grow to rapidly, forecasts to 4B@2025 - Synopsys 0,5B (of 5B) - Veracode ? (0,5B of 6,5B) - Mend 0,1B - Currently typical revenue per client size 100-500k/year. One-off projects are smaller. - DO appraisal: current market players have mostly very large customers, around ~2000-5000 continuous clients, and then one-off project customers on top of that 4
  • 5. https://www.doubleopen.org/ 4. Market Opportunity for scalable SaaS/API SCA - All businesses are becoming software driven - IoT, cloud, automotive, healthcare, manufacturing, retail - European Comission: 95% are using digital technologies - Cyber Resilience Act will further drive growth for SCA - Number of businesses in Europe: 23M (Eurostat 2022) - 1,5M of the companies are larger than 10 persons. - 150.000 are fast growing companies - Internationally 10x - Addressable market globally around 1,5M companies - 100x+ of current SCA clientele - 20.000 euro /year for 75.000 customers (5%) means 1,5B in revenue 5
  • 6. https://www.doubleopen.org/ 5. DO Value proposition for clients ● Services outcome for clients ○ Compliant software all the time, automated ○ Reduced manual work and costs, faster time to market ○ Higher productivity, clear process to solve arising questions ○ Tech and legal issues solved in tandem ○ Minimized risk & increased and confidendent OSS usage ○ Growing OSS competence ● Services ○ Open source tooling as SaaS or on-premises ○ License data, tech curation etc. over API ○ Tech and legal support services for ■ Projects for taking the tools and improved processes into use ■ Solving tickets in using the processes and tools 6 OSS quality with license compliance, without vulnerabilities Automate, because you can!
  • 7. https://www.doubleopen.org/ Customer testimonials Petteri Kivimäki, CTO, Nordic Institute for Interoperability Solutions, NIIS: “With the help of Double Open, our third-party open-source component usage is now compliant all the time, and we have significantly reduced both the time needed in open-source compliance and the related administrative headaches.” 7
  • 8. https://www.doubleopen.org/ 6. Where is DO now? - Background in open source compliance collaboration at HH Partners. Spinned off to own company, Double Open Oy, August/September 2023 - Pilot references from Vaisala, NIIS (and Validos members) - Existing revenue - Many collaboration partners, multiple leads in Finland, Sweden, Germany etc. - Two sw developers, CEO deal pending, operative advisors, strategic partner - Pre-seed funding of about 150k (not closed) - How can we be so far already now? 8
  • 9. https://www.doubleopen.org/ 7. Open source building blocks - ORT: - “A suite of tools to automate software compliance checks.” - Adopters such as Bosch, HERE Technologies, Porsche - Attempts to cover the whole process - ScanCode Toolkit 9
  • 11. https://www.doubleopen.org/ 8. Double open business model analysis Value: Automated and integrated software compliance Rare: High quality compliance data API Inimitability: Compliance data creation via curation service, co-creation in curation, reinforced by brand Organized: SaaS and API management Open everything we can, to maximise demand for our API. 11
  • 12. https://www.doubleopen.org/ 9. What’s in open source business models? ● Search for a scalable open source business model ○ Key business is not in hours or projects sold ● Focus on value created at client. Look beyond your software offering. ○ Software is always part of a process at the client. The client needs also other services. ○ Google open sourced a lot, but it’s business is in data, data understanding and leverage. ○ Red Hat is reasonably pure open source, but makes its business on signed and certified binaries. ● Do not focus on software installation, or delivery projects, or customization projects. May be required, but better to off-load to others. ● Brand? Data? Community? Add-ons by third parties? Open everything you can to maximise demand for your scalable service. 12