Stay on your version. Stay protected.

Extended Security Lifecycle backports security fixes to the exact Keycloak version you run. No forced upgrade, no maintenance scramble, with proof for your auditors.

CVEs patched. Without the upgrade.

A new Keycloak CVE lands. Our team backports the fix to the version you run; not the latest one and hands you the proof. You choose when to upgrade. Once a year is fine.

100+

clusters patched in under 24h

0

forced upgrades

1

attestation per patched CVE

1 year

min coverage per version

Backported fixes

Critical and high CVEs patched on the exact version you run, no major upgrade, no downtime.

Proof for every CVE

A downloadable attestation for each fix — evidence of when you were exposed, and when you stopped being.

Patched fast

During the June 2026 CVE wave, more than 100 clusters were updated in under 24 hours.

Up to 3 years per version

Each Keycloak version is covered for up to three years. You pay for our availability, we act the moment a CVE lands.

Pricing built around your setup. Short and confident

Every deployment is different, so we price yours around what you actually need. Tell us about your project.

Get a quote
Who it's for

For teams that can't just upgrade

Regulated sectors, frozen release calendars, heavy customization. If upgrading Keycloak takes a committee, Extended Security Lifecycle keeps you protected in the meantime.
Pinned major versions

Your release calendar is yours. Upgrade once a year or when you decide.

Regulated industries

Banking, public sector, healthcare already sold to a major French financial institution.

Heavy customization

Extensions and themes that turn every Keycloak upgrade into a project.

Distinct from your SLA
The SLA keeps your Keycloak running. Extended Security Lifecycle keeps it safe without moving it.
Availability-based model

You pay for our readiness, not a constant workload. We act when a CVE lands.

Compliance-ready proof

Attestations you can attach to audits aligned with the Cyber Resilience Act.

Frequently Asked Questions

Can’t find your answer? Need any help?

Contact us

Do I need to host with Cloud-IAM?

Today it covers Cloud-IAM-maintained versions. Contact us if you’d be intereted in coverage beyond Cloud-IAM hosting is on the table for a second phase.

How is this different from my SLA?

The SLA guarantees uptime and support response. Assurance guarantees security fixes on a version you choose not to move, a separate, dedicated contract.

What exactly counts as a covered CVE?

Critical and high CVEs (cover vulnerability score equal and over 7) affecting Keycloak core on your covered version. Performance issues and feature bugs follow the standard support path.