Glossary
Comprehensive glossary of cloud-native, Kubernetes, and software distribution terminology
Air-Gapped Network Definition: Complete Security Guide for 2026
Understanding air-gapped systems, networks, and environments, and how to distribute software to them
BYOC (Bring Your Own Cloud): Complete Guide
Complete guide to BYOC (Bring Your Own Cloud): what it means, how it works, BYOC vs SaaS vs self-hosted, architecture, benefits, challenges, and when to use BYOC for software distribution and data services.
Common Vulnerabilities and Exposures (CVE)
Understanding CVEs: What they are, how they work, and their critical role in cybersecurity and vulnerability management.
Coordinated Vulnerability Disclosure (CVD): Now Mandatory Under the CRA
What coordinated vulnerability disclosure is, and why the Cyber Resilience Act makes a CVD policy and a reporting contact mandatory for manufacturers.
Cyber Resilience Act (CRA): What It Is and Who Must Comply
The EU Cyber Resilience Act explained: scope, deadlines, manufacturer obligations, and penalties for software and hardware vendors.
Docker Registry & Container Registry Explained (2026)
Complete guide to container registries and Docker registries: what they are, how they work, public vs private registries, OCI compliance, security best practices, and choosing the right registry for CI/CD, software distribution, and air-gapped deployments.
Helm Chart
Understanding Helm charts, their role in Kubernetes package management, and how they simplify the process of deploying, managing, and scaling applications
Independent Software Vendor (ISV) - Complete 2026 Guide
Learn what ISV (Independent Software Vendor) means, see ISV examples like Salesforce & Adobe, understand ISV partners, certification, and how ISVs distribute software across cloud, on-premises & air-gapped environments.
Kubernetes
Understanding the Kubernetes platform, its architecture, and its role in modern application deployment
On-Premises Definition
Understanding on-premises (on-prem) deployment for software vendors and enterprises in 2026
Open-Source Software Steward: The CRA's Light-Touch Category
What an open-source software steward is under the Cyber Resilience Act, which obligations apply, and why the category matters for open-core companies.
Product with Digital Elements: The CRA's Core Definition
What counts as a product with digital elements under the Cyber Resilience Act, and why standalone software qualifies on its own.
Remote Data Processing Solution: The CRA's SaaS Boundary
How the Cyber Resilience Act defines remote data processing solutions, and when a cloud service becomes part of a regulated product.
SaaS Definition
Understanding the Software as a Service deployment model definition and explanation
Security Update vs Functionality Update: The CRA Distinction
Why the Cyber Resilience Act requires security updates to be delivered separately from feature updates, and what that means for release engineering.
Self-Hosted Software
Understanding the self-hosted (self-managed) software deployment model, and how vendors support self-hosted customers with a distribution platform
Software Bill of Materials (SBOMs)
Discover what SBOMs are, their importance, and their role in software security supply chains.
Software Distribution Platform: Complete Guide (2026)
Complete guide to software distribution platforms: what they are, vendor-to-customer vs IT admin tools, key features, distribution methods for on-premises, air-gapped, BYOC, and self-hosted customer deployments.
Software Entitlement
A software entitlement defines what a customer is permitted to access. Learn how entitlements work for ISVs shipping on-prem, VPC, and air-gapped software.
Software License Management
Find out what Software License Management is, why it is important, and how to track software licenses effectively.
Support Period (CRA): The 5-Year Floor Explained
The Cyber Resilience Act support period: the minimum 5 years of vulnerability handling, the 10-year update availability rule, and the engineering consequences.
Vulnerability Scanning
Understanding how vulnerability scanning identifies security weaknesses, its types, benefits, and role in a comprehensive security strategy