PostGIS Project
postgis.net · 2 vendors
Resilience scores
- Digital Sovereignty: 0
- Digital Resilience: 7
- Financial Resilience: 7
Technology vendors
- Canonical Ltd. — Technology — United Kingdom
- Pair Networks — United States
- PostgreSQL Project — Technology — United States
- and 3 more
Services catalogue
1 service in catalogue across 1 category; runs on 2 sub-vendors.
- PostGIS
Insights
Last updated 2026-06-18 · revision 5
2 direct vendors, 10 subvendors
Direct vendors by controlling owner country (sample)
- United States: 2
Subvendors by controlling owner country (sample)
- Denmark: 1
- United States: 5
- Belgium: 1
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
The PostGIS Project exhibits a very high level of migration readiness, largely driven by the open-source nature and portability of its core product. PostGIS is an extension for PostgreSQL, a database platform that is highly compatible with cloud-native environments, containerization, and microservices architectures across all major cloud providers. The project's 'Total Vendors: 0' is a critical factor, indicating no commercial vendor lock-in, which eliminates complex contract negotiations or proprietary system migrations. The project's own infrastructure leverages modern, portable tools like Git (with multiple hosts) and Hugo for its website, facilitating potential migration of these operational components. There are no mandatory data localization requirements applicable to the PostGIS project itself, simplifying deployment across different geographies. Challenges for migration readiness are primarily related to the project's non-commercial structure and regulatory gaps. The absence of traditional financial stability means a large-scale, funded migration of its own infrastructure would rely on community effort or OSGeo funding. Furthermore, the 'Assessment Required' status for GDPR and ISO 27001, particularly concerning contributor data hosted on OSGeo infrastructure, could introduce complexities if the project needed to migrate its operational data to environments with stricter compliance requirements. Some older components in the internal tech stack (Trac, Mailman, DocBook XML) might require more effort to migrate compared to fully modern, containerized services.
Compliance
3 in-scope frameworks identified; showing 3.
Open Source License Compliance — Compliant
PostGIS is distributed under the GNU General Public License v2.0 (GPL-2.0). As the originating project, PostGIS itself is the licensor and is inherently compliant with its own license terms. The risk is Low because the project controls its own licensing and actively publishes source code. The primary license compliance risk lies with downstream users and distributors of PostGIS, not the project itself.
Evidence: https://postgis.net/development/source_code/, https://postgis.net/
GDPR (source) — Assessment Required
PostGIS is an open-source software project with no commercial operations, no SaaS offering, and no known direct collection or processing of EU/EEA personal data on behalf of users. The project website (postgis.net) may collect minimal visitor data (e.g., server logs, analytics), which could technically implicate GDPR if EU/EEA residents visit the site. However, as a non-commercial open-source project under OSGeo, the scale and sensitivity of any personal data processing is extremely limited. Risk is Low because: (1) no personal data products or services are offered; (2) the software itself is a tool that end-users deploy in their own environments; (3) no evidence of large-scale EU personal data processing by the project itself. The primary GDPR risk would be limited to website visitor data and contributor/mailing list data.
Evidence: https://postgis.net/, https://postgis.net/community/mailinglists/, https://postgis.net/community/conduct/
Export Control — Assessment Required
Open-source geospatial software may be subject to US Export Administration Regulations (EAR) depending on cryptographic components and distribution channels. PostGIS includes or interfaces with cryptographic libraries through PostgreSQL. However, open-source software with publicly available source code generally qualifies for EAR exemptions (EAR99 or License Exception TSU). Risk is Low because: (1) PostGIS is not a military or dual-use technology in the traditional sense; (2) open-source exemptions typically apply; (3) no evidence of controlled technology classification.
Evidence: https://postgis.net/development/source_code/
Financials
Three-year financials
- null:
- null:
- null:
Financial Resilience Score: 7/10
PostGIS is not a commercial entity and therefore has no revenue, EBIT, equity, or treasury of its own. As an open-source project governed by the PostGIS Project Steering Committee under the OSGeo Foundation umbrella (a US 501(c)(4) non-profit), it cannot be assessed via traditional financial-resilience metrics. Instead, resilience must be judged via institutional, contributor, and ecosystem factors. On those dimensions, PostGIS demonstrates strong resilience. The project has been in continuous development since 2001 and is the de facto standard spatial extension for PostgreSQL, embedded in nearly every major Linux distribution, cloud database service (AWS RDS, Azure, GCP, Crunchy Bridge, EDB, Neon, Supabase), and GIS toolchain (QGIS, GeoServer, MapServer, ArcGIS). Its GPLv2+ license and distributed committer base mean no single sponsor failure would end the project. Key risks include the absence of a central treasury to fund full-time maintainers, dependence on sponsoring employers to allocate engineering time, key-person concentration around a small group of committers (Paul Ramsey, Regina Obe, Sandro Santilli, Darafei Praliaskouski), and value capture by hyperscalers who monetize PostGIS-as-a-service without proportionate upstream funding. There are also no service-level guarantees absent third-party commercial support. On balance, PostGIS's longevity, multi-sponsor contributor model, deep ecosystem integration, and strong network effects support a moderately high resilience score, tempered by the structural funding and key-person risks inherent to volunteer-driven open-source projects.
Key strengths: Continuous development since 2001 (>20 years of longevity), De facto standard spatial extension for PostgreSQL, Bundled in all major cloud database offerings (AWS RDS, Azure, GCP, Crunchy Bridge, EDB, Neon, Supabase), Multi-sponsor contributor model diversifies funding risk (Crunchy Data, Cleverelephant, Kontur, CARTO, Boundless/Planet, OpenGeo, Oslandia), GPLv2+ license ensures project survival independent of any single sponsor, Strong network effects via thousands of public-sector GIS deployments, Governance via PostGIS Project Steering Committee under OSGeo Foundation (US 501(c)(4))
Risk factors: No central treasury — cannot directly fund full-time maintainers, Dependence on sponsoring employers to allocate engineering time, Key-person concentration among small group of core committers (Paul Ramsey, Regina Obe, Sandro Santilli, Darafei Praliaskouski), Hyperscaler value capture without proportional upstream funding, No service-level guarantees absent third-party commercial support, No standalone financial statements or audited accounts
Revenue by geography
- Asia: 0%
- Europe: 0%
- Latin America: 0%
- North America: 0%
Revenue by product/service
- Commercial support & consulting: 0%
- Managed cloud database services: 0%
Workforce by country
- Italy: 0
- Canada: 0
- France: 0
- United States: 0
- Belarus/Germany: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.