Open Source Software is a founding principle of Defense Unicorns because we believe vendor lock is harmful to national security.
Three Problems with Vendor-Locked Systems
1. Modernization Nightmares
When a mission adopts a closed-source, proprietary solution from a single vendor, it sets the stage for future problems, depending on how the initial contract was written. While that new system may be fit for purpose at the start, when it’s time for an upgrade or renewal, the pain begins.
- The vendor can raise prices to unreasonable levels for new capabilities or continued support.
- The vendor controls whether or not to allow integration with other systems.
- The military is at the mercy of the vendor’s timelines to deliver results.
That single vendor has the leverage. This often results in long delays, increased costs to U.S. taxpayers, and modernization efforts stalling out altogether, so the military falls behind in capability.
2. Security Vulnerabilities
When a new vulnerability or exploit is discovered in proprietary software, the military has to rely on the vendor to disclose and patch the issue in a timely manner. Hopefully, there’s an SLA in place to enforce expediency, but that’s not always the case.
Open source software puts control in the hands of its users, giving them the freedom and permission to fix problems and implement additional features (and, hopefully, share those updates with the community). More importantly, open source software provides transparency into any vulnerabilities that do exist, unlike proprietary software, where closed-source vendors can choose to hide bugs and other problems.
3. Expiring License Keys
- Murphy’s 1st Law: “Anything that can go wrong will go wrong.”
- Murphy’s 2nd Law: “The moment you need mission-critical software the most is the moment its license key will expire.”
The worst thing that can happen when using proprietary software is its license key expiring at a critical moment in military operations, blocking warfighters from the tools they need to execute their mission.
It can take days, weeks, and even months to fix the situation. When the fight’s on, your software can’t fail!

How Defense Unicorns Kills Vendor Lock
Defense Unicorns publishes the foundation of its Unified Defense Stack (UDS) platform as Free Open Source Software (FOSS), releasing updates with new features and patches about every two weeks. Check out UDS Core on GitHub: https://github.com/defenseunicorns/uds-core
Releasing our core platform as FOSS means that missions adopting UDS as their software delivery platform are not bound to Defense Unicorns. Missions are free to use UDS Core, with or without Defense Unicorns, and will continue to receive the regular updates we publish. If Defense Unicorns disappeared tomorrow, the software would continue to freely exist. This ensures continuity of operations.
Additionally, other system integrators and software vendors are free to use our open source tools to deliver their solutions, and we encourage them to do so! We’re building critical products to support national security, and it’s in our collective best interests as a nation that others leverage our work rather than reinvent the wheel.
The only way Defense Unicorns is going to vendor-lock you is by our team being so gosh-darn amazing to work with that you couldn’t imagine yourself anywhere else! 😉
Our “Open Core” Business Model
What we truly love and are passionate about is open source technologies that advance the mission. However, open source still requires funding, so we have commercial products that enable us to support your mission directly while allowing us to improve the open source ecosystem and deliver more for the common good.
To balance our open source principles with business realities, Defense Unicorns has adopted an “Open Core” business model in which we make all essential components of UDS open source to ensure mission continuity, while offering dedicated support and premium features through paid licenses.
Our commercial product licenses for UDS Enterprise and UDS Fleet include:
- Unicorn engineer support with 24/7 coverage for critical events
- Near-zero CVE and FIPS-validated container images
- Cybersecurity compliance artifacts (SCTM, SBOM, diagrams, etc.)
- Additional product features to simplify how to build, package, deploy, and manage applications with UDS, such as UDS Connect and UDS Command. These make software installations and updates accessible to every warfighter
All of those commercial product features are available under annual licenses; however, for Government end users, we provide a perpetual license to the last delivered version if you decide to stop using Defense Unicorns.
As a Government customer, if your license expires, you can continue using the last version of our commercial software before the expiration date. There are no technical restrictions in place, like expiring license keys. When your license expires, you simply lose access to future updates, upgrades, maintenance, and support. However, you will continue to benefit from the ongoing maintenance of our open source foundation regardless.
Why the APGL-3.0 License?
We’ve chosen to use the AGPL-3.0 license for the open source parts of UDS, such as UDS Core, because it protects both Defense Unicorns and, more importantly, our mission heroes in the US Government.
AGPL-3.0 is a free copyleft license which allows anyone to use and modify UDS for their needs; however, they must share those modifications back with the community. This accomplishes two things:
- Eliminate vendor lock by making UDS open source
- Prevent other companies from taking UDS and turning it into their own proprietary, vendor-locked products
We’re Open Source Contributors First
Like most modern software, we built UDS on the shoulders of open source giants. But at Defense Unicorns, we’re not just a consumer of OSS, we are first and foremost proactive contributors to the open source community!
Our commitment to open source means the tools we build are available individually and free of vendor-lock risk. For example, Zarf is open source, free to use, and maintained by the Zarf community, with no proprietary dependencies and no requirement to continue using a specific vendor. Our donation of Zarf to OpenSSF, while remaining Zarf’s primary maintainer group, demonstrates our strong commitment to the open source ethos. Another example is Pepr, the Kubernetes middleware framework from Defense Unicorns, which is available on GitHub and can be adopted, modified, and maintained by mission owners independently of our services.
Finally, in addition to building new projects, we also contribute back upstream to major open source projects, including Kubernetes, Helm, Istio, Keycloak, Sonarqube, Archivista, Renovate, Atmos, Kairos, ChainLoop, and more. We do that by proactively hiring engineers who are maintainers of those open source projects to become Defense Unicorns. When there’s a critical bug or new feature needed in upstream software, the warfighter isn’t stuck waiting and hoping for a fix. We can fix it.
Defense Unicorns is committed to eliminating vendor lock through Open Source Software that ensures data independence for the US military and its allies.





