// HTTP4K ENTERPRISE EDITION

Production-grade peace of mind. Minus the enterprise theatre.

Long-term support, supply-chain security, priority help from the people who actually wrote the code, and every Pro module - one subscription for teams running http4k where it really counts.

// WHAT'S IN THE BOX

Six guarantees, one subscription.

Up to 24 months peace of mind

Guaranteed security and critical updates for the LTS stable release channel, including source access, allowing you to focus on feature delivery.

Supply chain security

SLSA Level 2 provenance, signed SBOMs, and cosign signatures for every artifact, verified at build time with http4k Verify.

Never wait for a release

Early access to all http4k features and fixes through maven.http4k.org every 1-2 weeks, rather than the quarterly cadence on Maven Central (from 1 October 2026).

Access to priority support

The http4k team are here on Slack and Email to guide you through any issues or questions.

Pro modules

A growing collection of commercially licensed, battle-tested modules built from real-world enterprise delivery.

License reporting

Signed, per-module license reports delivered with every artifact - ready for audit and regulatory review.

// COMPLIANCE, HANDLED TODAY

Supply chain security is the whole point.

Security teams, customers and auditors increasingly want evidence that the components in a build are the ones their authors published. The EU Cyber Resilience Act brings vulnerability reporting obligations from 11 September 2026, and machine-readable SBOMs and due diligence over integrated components from December 2027. http4k Enterprise Edition delivers the evidence today.

SLSA Level 2 provenance

Tamper-evident build provenance on every artifact. SLSA L3 on request.

CycloneDX SBOMs

Machine-readable software bills of materials, signed.

Signed licence reports

Per-module licence compliance reports, audit-ready.

Cosign signatures

Cosign signatures with trusted Sigstore timestamps.

FrameworkStatusWhat http4k EE provides
EU Cyber Resilience ActReporting from Sep 2026, full requirements Dec 2027CycloneDX SBOMs, signed artifacts, provenance and a published vulnerability disclosure policy
Customer due diligenceOngoingEvidence to answer security questionnaires and vendor reviews without a scramble
NIST SSDF (PW.4 / PS.3)Industry benchmarkSecure development practices, provenance, third-party component verification
PCI DSS 4.0.1Mandatory for cardholder dataRequirement 6.3.2 inventory of third-party software components

http4k Verify - one line of build config validates signatures, SBOMs and provenance for every http4k dependency, automatically, before your code compiles.

Explore Verify →
Full technical detail →
// COMPARE EDITIONS

Same core. More assurance as you grow.

CommunityFree · Apache 2.0ProPer module / seatEnterpriseSubscription
Full open-source core
Supported http4k versionsv6v6v4, v5, v6
Minimum Java versionJava 21Java 21Java 8 (v4/5), 21 (v6)
Pro modules-A la carte✓ all
Supply chain & license provenance, Verify plugin--
Priority supportGitHub issuesGitHub issues✓ Slack, Email
Guaranteed support term--✓ up to 24 months
Source code accessPublicPublic✓ + LTS
Get started →View Pro →Talk to us →
// LONG-TERM SUPPORT

A predictable LTS cadence, aligned to the JDK.

Major versions track the JDK's two-year LTS cycle. As each new Community major ships, the previous one rolls into a 24-month Enterprise LTS programme - so you upgrade on your schedule, not ours.

// THE FINE PRINT

Enterprise FAQ

What evidence do we receive with each artifact?

Every artifact in the http4k Enterprise Repository ships with an SBOM, build provenance, a signed licence report and cosign signatures. None of it is published to Maven Central, which carries PGP signatures only. The supply chain security page has the detail.

Are we locked in to http4k Verify, or can we check the artifacts ourselves?

You can check them yourself. The signing keys are published openly and every artifact verifies with standard cosign tooling. http4k Verify makes it a build step rather than something somebody remembers to do.

Does an Enterprise subscription make us CRA compliant?

No, and be wary of any vendor claiming their product does. The Cyber Resilience Act places obligations on the manufacturer putting a product on the EU market, not on a library in your dependency tree. What we give you is evidence for the part that concerns us: due diligence over an integrated component under Article 13(6). The rest stays yours.

What is happening with Maven Central, and is the Community Edition going away?

No. The Community Edition stays free, stays Apache-2.0 and stays on Maven Central. From 1 October 2026, Sonatype’s publishing limits mean releases reach Central approximately quarterly rather than every 1-2 weeks. maven.http4k.org is unaffected. We keep the current position on the distribution and release channels page.

How do our teams get access, and what has to change in our build?

Credentials for maven.http4k.org are issued when your subscription starts. It is a repository declaration in your build or your Artifactory equivalent, and coordinates and version numbers are unchanged, so nothing else moves. See the Enterprise Repository reference.

How long are LTS versions available, and what do they receive?

http4k Community releases major versions on a delayed cadence aligned to the JDK’s two-year LTS cycle. As each new major ships, the previous one enters the http4k EE LTS programme for 2 years, receiving security and high priority bug fixes together with source access. The schedule above shows the current timeline.

What support is available to Enterprise subscribers?

Email and Slack, answered by the people who wrote the code. That covers the LTS releases and the mainline, and questions about using http4k as well as defects in it.

Can I request specialised features for the http4k EE LTS versions?

For stability, LTS versions carry security and bug fixes only. Get in touch with a feature request and we will either prioritise it for the mainline release or work with you on a custom build.

Let's talk about your deployment.

Tell us about your stack and compliance needs and we'll tailor a subscription - including LTS timelines outside the standard schedule.

scarf