Extended Security Lifecycle

We backport security fixes to the exact Keycloak version you run up to three years after its release. Upgrade on your own schedule without staying exposed.

A critical CVE can be a nightmare. That's our job, not yours.

25+ CVEs

with a high or critical score in Keycloak so far in 2026

48h

average time to patch

1 to 3 years

of coverage

Plan your upgrades in advance and don't let CVEs dictate your priorities.

Every version you run stays covered for up to three years after its release. You can see exactly when yours expires and plan the jump months ahead, not the day a CVE drops.
Timeline of Keycloak versions 26.5 to 26.8 from 2026 to 2029:  Keycloak community open source version covers only three months on average, while Cloud-IAM Extended Security Lifecycle keeps each version covered for up to three years.

Pricing built around your setup.

Every deployment is different, so we price yours around what you actually need. Tell us about your project.

Get a quote

Everything you need

Patched fast

Our average time to assess, reproduce, test and fix CVEs is 48h.

Painless
The security patches are delivered on your deployment as soon as they are validated, with no upgrade required or downtime.
Audit trail
For each patch, we provide you with an attestation detailing when you were exposed, and when you stopped being, so you get all the information needed for your auditors.
Guaranteed coverage
We guarantee your version stays secure for up to three years.

Frequently Asked Questions

Can’t find your answer? Need any help?

Contact us

Does Keycloak offer an LTS version?

Community Keycloak does not offer an LTS release. Only the latest community version is actively maintained, so older versions eventually reach end of life (EOL) and stop receiving upstream security patches. Cloud-IAM Extended Security Lifecycle bridges that gap by backporting fixes for qualifying critical and high-severity CVEs to the Keycloak version you already run.

Do I need to host with Cloud-IAM?

Today, yes. If you’d be interested in accessing patched Keycloak versions outside of Cloud-IAM, please contact us.

How is this different from my SLA?

The SLA guarantees uptime and support response. The Extended Security Lifecycle guarantees security fixes on a version you choose instead of just on the latest release.

What exactly counts as a covered CVE?

Critical and high CVEs (CVSS score of 7.0 or higher) affecting Keycloak core on your covered version. Performance issues and feature bugs follow the standard support path.