Kiteworks' Strategic Response to CentOS End-of-Life with Seal Security

At a glance
- Company: Kiteworks, a California-based technology company that secures sensitive content communications across email, file sharing, managed file transfer, web forms and APIs.
- Challenge: Red Hat ended support for CentOS images in June 2024, leaving dozens of critical vulnerabilities with no upstream fix and putting FedRAMP compliance at risk.
- Alternative considered: Migrating to a different Linux distribution, a project of more than six months with a high risk of breaking changes.
- Result: All CentOS-related vulnerabilities patched within days, FedRAMP compliance maintained, and critical vulnerability scans passed.
The backdrop
Kiteworks faced a significant challenge when Red Hat announced that support for CentOS images would end in June 2024. Some third-party libraries were already lacking security updates, and Kiteworks' systems were accumulating dozens of critical vulnerabilities without a viable fix.
A security bottleneck
Maintaining FedRAMP compliance was crucial for Kiteworks, and it became difficult once Red Hat withdrew support. Kiteworks used a scanning solution and a prioritization tool, but these only identified problems without offering fixes. The only viable option seemed to be migrating to a different Linux distribution, a process that would take more than six months and risk breaking changes.
Customer confidence at risk
The loss of support heightened customer concerns about security, since many customers had strict federal requirements for vulnerability risk. Kiteworks was spending significant resources to meet those requirements and was stuck in a cycle of putting out fires to stay compliant.
The turning point with Seal Security
Seal Security integrated with Kiteworks' source code repository and became part of the software build process, giving Kiteworks centralized governance and patching. In the next deployment cycle, customers' vulnerability requirements were met for the first time without Kiteworks spending time on remediation.
The results
- All CentOS-related vulnerabilities were patched within days.
- FedRAMP compliance was maintained.
- Kiteworks passed critical vulnerability scans, protecting customer trust and business continuity.
- Immediate open source security risks were mitigated.
- The team gained the flexibility to plan and test a migration to another Linux distribution on its own timeline, without the risk of disruptive changes.
Conclusion
With Seal Security, Kiteworks navigated the CentOS end of life without an emergency migration. The development team could focus on innovation and growth, while the security team managed vulnerabilities with confidence, kept the company compliant and maintained customer trust.
Sharing this with your team? Download the case study as a PDF to pass along internally.
See it on your own stack
Seal Security backports security fixes into the open source versions you already run, across application dependencies, containers and Linux distributions, with no upgrade required.
See Seal on your stack
Get a walkthrough of how Seal backports security fixes into the open source versions you already run, with no upgrade and no code changes.
Book a demoChat with an expert
