PostgreSQL Global Development Group

United States · www.postgresql.org · 29 vendors

The PostgreSQL Global Development Group is a worldwide community of developers and volunteers that maintains PostgreSQL, a powerful, open-source object-relational database system. It uses and extends the SQL language, known for its reliability, data integrity, robust feature set, and extensibility. The group formed in 1997, following the release of PostgreSQL Version 6.0.

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 1 category; runs on 29 sub-vendors.

Insights

Last updated 2026-08-11 · revision 11

29 direct vendors, 230 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 5/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

The core product, PostgreSQL, is open-source and highly portable across various operating systems and cloud environments, which is a significant advantage for any migration involving the database itself. The organization's internal tech stack already includes cloud components such as Amazon Web Services (AWS) and Fastly CDN, indicating existing familiarity and experience with cloud infrastructure, which can ease a transition. However, the internal infrastructure is a hybrid model, combining cloud services with bare-metal hosting (Rackspace), suggesting that a full migration to a purely cloud-native or containerized environment would require significant re-architecture and effort. A major impediment to migration readiness is the numerous "Assessment Required" statuses in the regulatory environment, specifically for GDPR, SOC2, and ISO 27001, as well as for data residency requirements. These necessitate detailed assessments and potential remediation efforts, adding considerable complexity, cost, and time to any migration project. The absence of financial data (revenue, growth) makes it impossible to determine the organization's capacity to fund a potentially large-scale migration. Finally, the "Vendor Lock-in Risk" is "Unknown," and the contradictory "Total Vendors: 0" makes it difficult to assess the level of dependency on existing service providers. If there is significant reliance on specific vendors (e.g., Rackspace for bare-metal), this could create lock-in challenges during migration.

Compliance

5 in-scope frameworks identified; showing 3.

CPRA — Assessment Required

The California Consumer Privacy Act (CCPA) as amended by CPRA applies to for-profit businesses meeting certain thresholds. PGDG is a non-profit/community organization and likely does not meet the 'for-profit business' threshold for CCPA applicability. However, PGDG collects personal data from California residents (website visitors, community members) and uses Google Analytics. The risk is Medium-Low: PGDG likely falls outside CCPA's scope as a non-commercial entity, but this has not been formally assessed. Other US state privacy laws (Virginia VCDPA, Colorado CPA, Texas TDPSA, etc.) similarly target for-profit commercial entities. A formal legal assessment is recommended to confirm exemption status.

Evidence: https://www.postgresql.org/about/policies/privacy/, https://www.postgresql.org/about/donate/

SOC 2 (source) — Assessment Required

SOC 2 (System and Organization Controls 2) is a voluntary framework relevant to service organizations that store, process, or transmit customer data in cloud or hosted environments. PGDG operates postgresql.org infrastructure including user account systems, mailing list services, package repositories, and community platforms that store user data. While PGDG is not a commercial cloud service provider, it does operate shared infrastructure services used by a global developer community. The risk is Medium because: (1) PGDG has no SOC 2 certification, which may be a concern for enterprise organizations that rely on PGDG infrastructure (e.g., package downloads, security advisories); (2) The absence of SOC 2 is common for non-commercial open-source organizations but represents a maturity gap; (3) PGDG's Sysadmin Team (PGInfra) manages significant public infrastructure without publicly documented security controls. However, since PGDG does not sell services commercially, the business impact of non-certification is lower than for commercial SaaS providers.

Evidence: https://www.postgresql.org/about/governance/sysadmin/, https://www.postgresql.org/support/security/, https://www.postgresql.org/about/governance/

Open Source Software Supply Chain Security — Assessment Required

US Executive Order 14028 (Improving the Nation's Cybersecurity, May 2021) and the NIST Secure Software Development Framework (SSDF / SP 800-218) establish requirements for software supply chain security, particularly for software used by US federal agencies. PostgreSQL is widely deployed in US government systems and critical infrastructure. While PGDG itself is not directly regulated by EO 14028 (which targets federal contractors), the SSDF and related CISA guidance increasingly influence expectations for open-source software maintainers. Risk is Medium because: (1) PostgreSQL is used extensively in US federal government systems, creating indirect pressure for SSDF alignment; (2) PGDG's release signing, vulnerability disclosure, and development practices are scrutinized under supply chain security frameworks; (3) Non-compliance with SSDF best practices could affect PostgreSQL's acceptability in US government procurement.

Evidence: https://www.postgresql.org/support/security/, https://www.postgresql.org/about/governance/

Financials

Three-year financials

Financial Resilience Score: 7/10

PostgreSQL Global Development Group (PGDG) is not a corporate entity but an unincorporated open-source project with no revenue, EBIT, equity, or employees. Traditional financial resilience metrics do not apply. However, the project itself demonstrates strong operational resilience as an ongoing concern through its diversified corporate contributor base (EDB, Crunchy Data, Microsoft, AWS, Google, Fujitsu, NTT, VMware/Broadcom, Cybertec, Percona), permissive licensing that encourages broad commercial adoption, and 35+ years of continuous development since 1986. The project benefits from a strong ecosystem economics model where PostgreSQL-based commercial businesses have created a multi-billion-dollar market that reinvests developer resources upstream. Governance stability is high with a long-standing Core Team and Committer group, and release cadence has been reliably annual for over a decade. Associated non-profits (US PostgreSQL Association, PostgreSQL Europe, JPUG) have combined budgets well under USD 1 million per year, funding community infrastructure through donations and conference sponsorships. Key risks include no central budget for emergency work, dependence on donations/sponsors for infrastructure, occasional trademark and governance disputes, and contributor concentration where a handful of committers do a large share of code review. Enterprises cannot sign support contracts directly with PGDG, requiring third-party vendor relationships.

Key strengths: Diversified corporate contributor base with no single-sponsor risk, Permissive PostgreSQL License encourages broad commercial adoption, 35+ years of continuous development since 1986, Multi-billion-dollar commercial ecosystem reinvests into upstream project, Stable governance with long-standing Core Team and Committer group, Reliable annual release cadence sustained for over a decade, #1 most-used database in Stack Overflow Developer Surveys 2023 and 2024, DB-Engines DBMS of the Year multiple times (2017, 2018, 2020, 2023)

Risk factors: No central budget to fund emergency work such as major security incidents, Infrastructure funding depends on donations and sponsors via regional non-profits, Occasional trademark and governance disputes, Contributor concentration - handful of committers do large share of code review, Not a counterparty - enterprises cannot sign support contracts with PGDG directly, Loss of key individual committers would slow releases

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report