Add agentic-AI future readiness and scoped CRA supply-chain messaging#206
Add agentic-AI future readiness and scoped CRA supply-chain messaging#206brianamarie wants to merge 7 commits into
Conversation
New File Governance CheckNo added markdown files detected. Doc Coverage CheckNo new markdown docs detected. Manual waiver commands (maintainers)
Waiver JSON is stored in a hidden PR comment ( Triggered by |
Messaging Smart Suggestions
Only auto-apply suggestions at high confidence with reviewer approval. Triggered by |
Messaging Impact Check
postgres-cost-claim (BLOCKING)PostgreSQL cost/TCO claims usually impact shared value proof messaging. Required review files:
Suggested additional scan:
licensing-or-open-source-claims (BLOCKING)License and open source positioning changes are cross-cutting. Required review files:
Suggested additional scan:
offering-name-or-tier-change (WARN)Offering naming updates should stay aligned across offering pages. Required review files:
Suggested additional scan:
product-messaging-module-touch (WARN)Product messaging modules often need checks against company framing and shared pillars or offerings. Required review files:
Suggested additional scan:
Manual waiver commands (maintainers):
Waiver state is stored in Triggered by |
| - **Extended Lifecycle Support (ELS):** When database versions reach End of Life (EOL), Percona experts help teams plan upgrades, align CVE backports to their risk window, and move to supported releases. Expert Support covers Extended Lifecycle Support (ELS) for MySQL and MongoDB, grounded in published release and lifecycle policy. | ||
| - **Kubernetes operator planning:** Architecture and cutover plan review for databases on Kubernetes (topology, storage, backups, PMM integration); the customer platform team executes install and Day-2 runbooks, with expert validation at key gates. | ||
| - **Operator production escalations:** SLA-backed incident response and advisory troubleshooting for failover, backup and recovery, replication, and upgrade failures on customer-run operator clusters. | ||
| - **CVE triage at scale:** Automated scanning and broader project indexing have increased published CVE volume across open source ecosystems ([Linux Foundation 2026 CRA Awareness and Readiness Report](https://www.linuxfoundation.org/research/cra-readiness-2026)). Percona experts help customers prioritize database-layer findings against exploitability and their supported release line, align fixes to published CVE advisories and backport policy, and avoid panic patching or unnecessary downtime when noise exceeds real risk. |
There was a problem hiding this comment.
@andrey-glazkov is this section all right to add for support and a high CVE scenario?
There was a problem hiding this comment.
I like that we narrow the scope to the databases here!
janwieremjewicz
left a comment
There was a problem hiding this comment.
To me this reads bad. Hard to understand and not sure what it says at many times. I spent a lot of time reading this and often failed to make sense of it. Too often did I feel as if reading legalese.
|
|
||
| - **Who Expert Support is for:** Teams with capable DBAs or SREs who manage their own databases but want reliable expert escalation for production issues, architectural questions, and review of planned changes. | ||
| - **Problems Expert Support solves:** Outages and other urgent incidents, replication or high availability failures, performance regressions, uncertain upgrade or migration plans, lifecycle and EOL transition risk, and hard architectural questions. | ||
| - **Problems Expert Support solves:** Outages and other urgent incidents, replication or high availability failures, performance regressions, uncertain upgrade or migration plans, lifecycle and EOL transition risk, CVE overload when scanning volume outpaces internal triage capacity, and hard architectural questions. |
There was a problem hiding this comment.
I'm not 100% sold on the fact that improvements we introduce with CVEs for databases is enough to justify this change. scanner noise is still going to be an issue.
There was a problem hiding this comment.
I would simplify this to: "CVE volume that outpaces internal triage capacity"
| - **Extended Lifecycle Support (ELS):** When database versions reach End of Life (EOL), Percona experts help teams plan upgrades, align CVE backports to their risk window, and move to supported releases. Expert Support covers Extended Lifecycle Support (ELS) for MySQL and MongoDB, grounded in published release and lifecycle policy. | ||
| - **Kubernetes operator planning:** Architecture and cutover plan review for databases on Kubernetes (topology, storage, backups, PMM integration); the customer platform team executes install and Day-2 runbooks, with expert validation at key gates. | ||
| - **Operator production escalations:** SLA-backed incident response and advisory troubleshooting for failover, backup and recovery, replication, and upgrade failures on customer-run operator clusters. | ||
| - **CVE triage at scale:** Automated scanning and broader project indexing have increased published CVE volume across open source ecosystems ([Linux Foundation 2026 CRA Awareness and Readiness Report](https://www.linuxfoundation.org/research/cra-readiness-2026)). Percona experts help customers prioritize database-layer findings against exploitability and their supported release line, align fixes to published CVE advisories and backport policy, and avoid panic patching or unnecessary downtime when noise exceeds real risk. |
There was a problem hiding this comment.
I like that we narrow the scope to the databases here!
| - Cloud-native operations: The Percona Operator for PostgreSQL automates deployment, scaling, and failover in Kubernetes environments, delivering consistent governance and portability across any cloud. | ||
| - Platform portability: Percona Distribution for PostgreSQL ships packages for current Ubuntu LTS releases, including Ubuntu 26.04 on AMD64 and ARM64, so teams can standardize database deployments on their long-term support platform images without retooling the stack. | ||
| - AI and analytics readiness: Teams run embeddings and vector search on PostgreSQL using pgvector packaged with other tested distribution components ([third-party components](https://docs.percona.com/postgresql/18/third-party.html)), avoiding a separate AI-only datastore for many workloads. Percona Expert Support includes advisory guidance for pgvector and pgvectorscale production tuning; pgvectorscale is not packaged in Percona Distribution for PostgreSQL. | ||
| - AI and analytics readiness: Teams run embeddings and vector search on PostgreSQL using pgvector packaged with other tested distribution components ([third-party components](https://docs.percona.com/postgresql/18/third-party.html)), avoiding a separate AI-only datastore for many RAG and agent retrieval workflows. Percona Expert Support includes advisory guidance for pgvector and pgvectorscale production tuning; pgvectorscale is not packaged in Percona Distribution for PostgreSQL. |
There was a problem hiding this comment.
I don't understand why "other tested distribution components" not simply "other components" or "other distribution components".
There was a problem hiding this comment.
TBH reading the whole sentence I would simplify:
thanks to extensions like pgvector teams successfully run AI workloads on PostgreSQL instead of having to learn, deploy and manage a separate AI-only datastore for RAG and agent retrieval workflows.
feels (to me at least) more natural, human written, not AI and robotic...
| - **AI and analytics affect business competitiveness:** Real-time and AI-driven workloads demand unified data access, but fragmented systems slow response and inflate both latency and cost per transaction. | ||
| - **Downstream costs:** Cloud bills, tool licensing, and staff hours add up on one side; downtime, security gaps, and lost productivity on the other. The average data breach now costs $4.88M ([IBM](https://www.ibm.com/think/insights/cost-of-a-data-breach-2024-financial-industry)), with outage costs in the automotive industry exceeding $2.3M per hour ([Siemens, 2024](https://web.archive.org/web/20260208082933/https://blog.siemens.com/2024/07/the-true-cost-of-an-hours-downtime-an-industry-analysis/)). | ||
| - **AI and analytics affect business competitiveness:** Real-time and AI-driven workloads demand unified data access, but fragmented systems slow response and inflate both latency and cost per transaction. | ||
| - **Private fork maintenance tax:** Teams that fork open source database components to control patches internally carry recurring integration and merge labor every release cycle. Industry research estimates roughly $258,000 in labor per release cycle for organizations maintaining private open source forks at scale ([Linux Foundation 2026 CRA Awareness and Readiness Report](https://www.linuxfoundation.org/research/cra-readiness-2026)), a hidden people cost that often exceeds license savings. |
There was a problem hiding this comment.
This finding I believe should be more visible. VERY good framing!
There was a problem hiding this comment.
What about combining this with sustainable founding of open source?
| - **Inefficient resource consumption:** Proprietary DBaaS tiers often enforce sizing floors and support bundles that lead to consistent under-utilization and higher long-term spend. At the same time, efforts to reduce cost by scaling down too aggressively can cause underprovisioning, resulting in degraded performance or unexpected downtime. | ||
| - **AI and analytics affect business competitiveness:** Real-time and AI-driven workloads demand unified data access, but fragmented systems slow response and inflate both latency and cost per transaction. | ||
| - **Downstream costs:** Cloud bills, tool licensing, and staff hours add up on one side; downtime, security gaps, and lost productivity on the other. The average data breach now costs $4.88M ([IBM](https://www.ibm.com/think/insights/cost-of-a-data-breach-2024-financial-industry)), with outage costs in the automotive industry exceeding $2.3M per hour ([Siemens, 2024](https://web.archive.org/web/20260208082933/https://blog.siemens.com/2024/07/the-true-cost-of-an-hours-downtime-an-industry-analysis/)). | ||
| - **AI and analytics affect business competitiveness:** Real-time and AI-driven workloads demand unified data access, but fragmented systems slow response and inflate both latency and cost per transaction. |
There was a problem hiding this comment.
Too short and lacking in essence:
- Link to some example, case studies, success stories?
- What do we offer to help?
I am afraid that the fragmented data is something beyond of reach of our services. Do we have any offering regarding consulting on data architecture level across the company for such AI and analytical use cases? I am afraid I am missing the point and value of this :/
|
|
||
| - **RAG on PostgreSQL:** Store embeddings alongside relational data for retrieval workflows without a separate vector database contract. Percona packages pgvector in documented PostgreSQL builds; Percona Expert Support includes advisory guidance for pgvector production tuning. Percona focuses on PostgreSQL performance, scalability, and security for vector workloads, not embedding-model or LLM application design. | ||
| - **Vector search on Valkey:** Serve low-latency similarity search for AI retrieval tiers on the same operational model as other supported engines. Percona Expert Support and PMM cover Valkey and Redis alongside PostgreSQL and other engines in customer-controlled deployments. | ||
| - **Governed retrieval for agent workflows:** Agent pipelines that combine embeddings, relational context, and operational state need governed, low-latency retrieval on infrastructure the customer controls. Percona packages pgvector for PostgreSQL, supports vector search on Valkey, and provides PMM observability plus audit-capable distributions for mixed-engine estates. Percona focuses on database performance, security, and vector retrieval for these workloads, not agent orchestration or LLM application design. |
There was a problem hiding this comment.
the opening with governed retrieval does not match what follows as the description of the value. There is exactly zero information about governance or inspection (auditing) of such governance rules enforcement.
| - **Fragmented control policies:** Security enforcement differs across platforms: one engine's encryption standard or retention policy rarely matches another's, creating audit gaps and inconsistent governance. One survey flagged legal and geopolitical dependencies (46%) and cybersecurity incidents (42%) as key drivers for IT sovereignty initiatives ([HMS](https://www.analytical-software.de/en/it-sovereignty-in-practice/)). | ||
| - **Unverified supply chains:** Only about 20% of organizations generate software bills of materials (SBOMs), leaving most without full traceability into the software they depend on ([arXiv, 2025](https://arxiv.org/pdf/2503.15021)). | ||
| - **Unverified supply chains:** Only about 20% of organizations generate software bills of materials (SBOMs), leaving most without full traceability into the software they depend on ([arXiv, 2025](https://arxiv.org/pdf/2503.15021)). Under the EU Cyber Resilience Act, manufacturers placing products on the EU market must exercise active due diligence on third-party and open source components, yet many still passively wait for upstream fixes or maintain private forks that complicate audit trails. | ||
| - **CVE noise and triage overload:** Published CVE volume across major open source projects rose sharply in early 2026, driven in part by broader automated scanning and AI-assisted analysis ([Linux Foundation 2026 CRA Awareness and Readiness Report](https://www.linuxfoundation.org/research/cra-readiness-2026)). Manufacturers face more findings to evaluate, not necessarily more exploitable risk, which makes credible prioritization and documented remediation paths more valuable than reactive panic patching. |
There was a problem hiding this comment.
This is true. But databases are but one source of these CVEs. We would need to prove that a big chunk of this noise is coming from databases or that the noise from other sources hides the potential real threats that come rarely but may be missed in the databases and point to this as a value. Otherwise that's not something that reads as an understandable value to me.
| - **Lock-in through tooling:** Vendor-specific APIs and managed encryption layers limit portability and make it costly to adapt to new regulatory or business needs. Many firms cite vendor dependency and lack of portability as strategic risks. Adopters of sovereign or independent infrastructure cite freedom from vendor lock-in and stronger strategic control as key benefits ([PureStorage](https://www.purestorage.com/company/newsroom/press-releases/data-sovereignty-emerges-as-critical-business-risk-in-new-geopolitical-era-in.html)). | ||
| - **Fragmented control policies:** Security enforcement differs across platforms: one engine's encryption standard or retention policy rarely matches another's, creating audit gaps and inconsistent governance. One survey flagged legal and geopolitical dependencies (46%) and cybersecurity incidents (42%) as key drivers for IT sovereignty initiatives ([HMS](https://www.analytical-software.de/en/it-sovereignty-in-practice/)). | ||
| - **Unverified supply chains:** Only about 20% of organizations generate software bills of materials (SBOMs), leaving most without full traceability into the software they depend on ([arXiv, 2025](https://arxiv.org/pdf/2503.15021)). | ||
| - **Unverified supply chains:** Only about 20% of organizations generate software bills of materials (SBOMs), leaving most without full traceability into the software they depend on ([arXiv, 2025](https://arxiv.org/pdf/2503.15021)). Under the EU Cyber Resilience Act, manufacturers placing products on the EU market must exercise active due diligence on third-party and open source components, yet many still passively wait for upstream fixes or maintain private forks that complicate audit trails. |
There was a problem hiding this comment.
Shouldn't we then mention that we do provide SBOMs then?
| - **US extraterritorial access risk:** Teams that cannot rely on US hyperscaler control planes need hosting they choose, including non-US infrastructure, because US law can compel technology companies to hand over stored data regardless of server location. Percona does not host customer data; customers run the stack on infrastructure that matches their jurisdictional requirements. | ||
| - **Multi-tenant platform isolation:** Shared platforms must separate tenants or business units without control-policy drift. Percona Operators support Kubernetes namespaces, network policies, and RBAC so isolation stays consistent across MySQL, PostgreSQL, and MongoDB-compatible workloads. | ||
| - **EU software supply chain compliance:** Teams shipping products with digital elements into the EU must determine whether they are manufacturers under the Cyber Resilience Act and exercise due diligence on open source dependencies, including databases. Private forks add audit burden and recurring integration labor; passive reliance on upstream security fixes does not meet active vulnerability-management expectations. Percona develops and sustains supported database software with public CVE handling and documented lifecycles. Customers remain responsible for their product as manufacturer; Percona helps on the database tier with inspectable software, PMM security findings, and Expert Support for prioritized remediation. Percona does not certify full product CRA compliance. | ||
| - **Compliance-driven private forks:** Some teams maintain private forks of database components as a short-term compliance workaround. Industry research estimates roughly $258,000 in labor per release cycle to maintain private open source forks at scale ([Linux Foundation 2026 CRA Awareness and Readiness Report](https://www.linuxfoundation.org/research/cra-readiness-2026)). Supported engagement with sustained upstream distributions reduces divergent codebase debt and strengthens the supply chain evidence manufacturers need. |
There was a problem hiding this comment.
Carrying own patches is costly and raises the risk of delayed CVE fixes coming from minor upstream releases is what I read. But the way it's written is not clear enough to me. Value is hidden :/
| Sovereignty is not only where data sits. It is who can operate your databases and whether you can keep running under supplier or jurisdictional change. Percona delivers software, Expert Support, and Expert Consulting and Services that help teams exercise **data**, **operational**, and **technological** sovereignty across MySQL, MariaDB (Community), PostgreSQL, MongoDB-compatible, Valkey, and Redis. The primary risk is **concentration and continuity risk**: single-provider dependency when teams cannot prove residency, access control, or exit paths. | ||
|
|
||
| Across industries, governance, compliance, and hardening requirements are expanding, from GDPR, HIPAA, and PCI-DSS to DISA's STIG guidelines used in public-sector and defense environments. At the same time, hyperscaler ecosystems make it difficult for enterprises to verify what "secure" really means inside managed services. [UNCTAD's overview of data protection and privacy legislation worldwide](https://unctad.org/page/data-protection-and-privacy-legislation-worldwide) documents how many jurisdictions have adopted formal regimes, which enterprises increasingly pair with sovereign-cloud or regional-control strategies. National frameworks beyond Europe, including India's DPDP Act and Brazil's LGPD, add distinct residency and access rules ([Forcepoint global data protection laws, 2026](https://www.forcepoint.com/blog/insights/tracking-global-data-protection-laws-2026)). A majority of organizations prioritize data sovereignty in infrastructure decisions, with strong regional weight in Europe, Middle East, and APAC ([Thales Global Data Threat Report](https://cpl.thalesgroup.com/data-threat-report)). | ||
| Across industries, governance, compliance, and hardening requirements are expanding, from GDPR, HIPAA, and PCI-DSS to the EU Cyber Resilience Act (CRA) for products with digital elements sold in Europe, and DISA's STIG guidelines used in public-sector and defense environments. At the same time, hyperscaler ecosystems make it difficult for enterprises to verify what "secure" really means inside managed services. [UNCTAD's overview of data protection and privacy legislation worldwide](https://unctad.org/page/data-protection-and-privacy-legislation-worldwide) documents how many jurisdictions have adopted formal regimes, which enterprises increasingly pair with sovereign-cloud or regional-control strategies. National frameworks beyond Europe, including India's DPDP Act and Brazil's LGPD, add distinct residency and access rules ([Forcepoint global data protection laws, 2026](https://www.forcepoint.com/blog/insights/tracking-global-data-protection-laws-2026)). A majority of organizations prioritize data sovereignty in infrastructure decisions, with strong regional weight in Europe, Middle East, and APAC ([Thales Global Data Threat Report](https://cpl.thalesgroup.com/data-threat-report)). |
There was a problem hiding this comment.
Read this 3 times. I see a problem and a trend but not the point. Not sure how this bullet fits. Is this to describe the reality? I feel what we want to say is that there is a growing trend to adopt hybrid or on-prem solutions and we can help there, but it's missing here.
| - **Extended Lifecycle Support (ELS):** When database versions reach End of Life (EOL), Percona experts help teams plan upgrades, align CVE backports to their risk window, and move to supported releases. Expert Support covers Extended Lifecycle Support (ELS) for MySQL and MongoDB, grounded in published release and lifecycle policy. | ||
| - **Kubernetes operator planning:** Architecture and cutover plan review for databases on Kubernetes (topology, storage, backups, PMM integration); the customer platform team executes install and Day-2 runbooks, with expert validation at key gates. | ||
| - **Operator production escalations:** SLA-backed incident response and advisory troubleshooting for failover, backup and recovery, replication, and upgrade failures on customer-run operator clusters. | ||
| - **CVE triage at scale:** Automated scanning and broader project indexing have increased published CVE volume across open source ecosystems ([Linux Foundation 2026 CRA Awareness and Readiness Report](https://www.linuxfoundation.org/research/cra-readiness-2026)). Percona experts help customers prioritize database-layer findings against exploitability and their supported release line, align fixes to published CVE advisories and backport policy, and avoid panic patching or unnecessary downtime when noise exceeds real risk. |
There was a problem hiding this comment.
"avoid panic patching or unnecessary downtime when noise exceeds real risk."
The "noise exceeds real risk" reads a bit overly AI-generated to me.
I think the sentence reads the same if this is dropped.
| - **Multi-database vendor consolidation:** One relationship for database support across engines reduces duplicate fees, conflicting SLAs, and slow handoffs when incidents cross systems. Percona consolidates agreements for Expert Support, ExpertOps, and consulting across MySQL, MariaDB (Community), PostgreSQL, MongoDB-compatible environments, Valkey, and Redis so teams coordinate renewal, escalation, and scope in one place. | ||
| - **Reduce cloud spend:** Customers ask how to reduce cloud spend when DBaaS minimum tiers, bundled markup, and sizing floors outpace actual use. Managed database services can cost several times more than comparable workloads on VMs or Kubernetes. Percona Experts use PMM, Operators, and rightsizing on customer-chosen infrastructure to align capacity with utilization and lower managed-service premiums. | ||
| - **Database workload tuning and rightsizing:** Neglected databases accumulate poor indexing, inefficient queries, and oversized instances, especially when generalist cloud or DevOps teams operate DBaaS without deep database expertise. Percona Experts tune workloads and rightsize instances so teams save on infrastructure whether they stay on DBaaS or run self-managed stacks. Performance gains often let teams scale down instance sizes without sacrificing service levels. | ||
| - **Private fork labor vs supported upstream:** Maintaining private forks of database components to control security patches internally consumes engineering hours every release cycle that do not scale with product growth. Supported Percona distributions, public CVE advisories, and Expert Support for backport alignment offer a lower long-term labor path than sustaining divergent codebases, especially as software supply chain regulations raise documentation and due diligence expectations. |
There was a problem hiding this comment.
Maintaining private forks of database components to control security patches internally consumes engineering hours every release cycle that do not scale with product growth.
"do not scale with product growth" does not make a ton of sense in this context. I'd go with something like "...engineering hours every release cycle that compound as upstream divergence widens".
Extend future-readiness positioning with McKinsey-backed agentic AI context and governed-retrieval use cases, with light PostgreSQL and PMM alignment. Add CRA, CVE triage, and private-fork copy in security, cost, and Expert Support pillars where buyer situations are specific, without changing company-level why-percona framing. Co-authored-by: Cursor <cursoragent@cursor.com>
Keep EU Cyber Resilience Act messaging in problem bullets and use cases rather than the opening regulatory list on the SSC page. Co-authored-by: Cursor <cursoragent@cursor.com>
6af294f to
8e08e93
Compare
|
Hey all, thank you for the feedback. I've pushed a few commits to update the PR to match it:
If a particular sentence still reads badly, point me at it and I’ll fix the wording. (Reminder that downstream assets are not written verbatim from messaging, and typically use the organization level plugins available through Claude.) Thank you again! |
Tighten future-readiness copy to the database layer, rename the agent retrieval use case, and simplify Expert Support CVE and PostgreSQL AI wording. Deduplicate CRA and private-fork themes across pillars; keep fork cost as a single uncommon manufacturer use case. Add McKinsey agentic URL to lychee CI exclusions. Co-authored-by: Cursor <cursoragent@cursor.com>
Drop redundant CRA certification line from EU supply chain use case. Co-authored-by: Cursor <cursoragent@cursor.com>
Markdown hygiene auto-fixApplied safe markdown hygiene fixes and pushed one bot commit to this PR branch. Fixed files:
Triggered by |
thefactremains
left a comment
There was a problem hiding this comment.
Comment only. The MySQL-relevant content checks out.
Not approving yet on mechanical state: the branch is CONFLICTING and CI is red, with Links (lychee) and impact-check both failing. Ask: rebase on main to clear the conflict and get both checks green, then I will approve.
| - Cloud-native operations: The Percona Operator for PostgreSQL automates deployment, scaling, and failover in Kubernetes environments, delivering consistent governance and portability across any cloud. | ||
| - Platform portability: Percona Distribution for PostgreSQL ships packages for current Ubuntu LTS releases, including Ubuntu 26.04 on AMD64 and ARM64, so teams can standardize database deployments on their long-term support platform images without retooling the stack. | ||
| - AI and analytics readiness: Teams run embeddings and vector search on PostgreSQL using pgvector packaged with other tested distribution components ([third-party components](https://docs.percona.com/postgresql/18/third-party.html)), avoiding a separate AI-only datastore for many workloads. Percona Expert Support includes advisory guidance for pgvector and pgvectorscale production tuning; pgvectorscale is not packaged in Percona Distribution for PostgreSQL. | ||
| - AI and analytics readiness: With pgvector and other distribution components (see [third-party components](https://docs.percona.com/postgresql/18/third-party.html)), teams run RAG and agent retrieval on PostgreSQL they already operate instead of standing up a separate AI-only datastore. Percona Expert Support includes advisory guidance for pgvector and pgvectorscale production tuning; pgvectorscale is not packaged in Percona Distribution for PostgreSQL. |
There was a problem hiding this comment.
Just inputting for readability.
| - AI and analytics readiness: With pgvector and other distribution components (see [third-party components](https://docs.percona.com/postgresql/18/third-party.html)), teams run RAG and agent retrieval on PostgreSQL they already operate instead of standing up a separate AI-only datastore. Percona Expert Support includes advisory guidance for pgvector and pgvectorscale production tuning; pgvectorscale is not packaged in Percona Distribution for PostgreSQL. | |
| - AI and analytics readiness: pgvector is packaged and tested as part of the distribution's third-party components, so teams can run embeddings and vector search for RAG and agent retrieval directly on PostgreSQL, no separate AI-only datastore required. Percona Expert Support advises on tuning pgvector and pgvectorscale for production; pgvectorscale itself isn't packaged in the distribution. |
Summary
security-sovereignty-compliance.mdwith CRA due diligence, CVE noise, EU manufacturer use cases, and compliance-driven private-fork context. Add private-fork labor cost tocost-optimization.mdwhere fork maintenance is the buyer problem. Extend Expert Support with CVE overload and triage-at-scale scenarios (Linux Foundation CRA readiness report).future-readiness-ai.mdwith McKinsey April 2026 stats and governed-retrieval positioning; light alignment in PostgreSQL and PMM messaging. Scope boundary unchanged: database performance, security, and vector retrieval, not agent orchestration or LLM design.why-percona.md. Private-fork and CVE stewardship stay in pillars and offerings where the situation is specific, not at company-level positioning.Why we're doing this
Enterprise buyers are moving from GenAI pilots toward agentic workflows, but scaling is stalling on data foundations, not models. McKinsey reports that most organizations experimenting with agents have not scaled them, with data limitations cited as the primary blocker. That reinforces Percona's existing future-readiness thesis: AI value depends on governed, portable database infrastructure teams already operate, not proprietary AI SKUs or parallel ungoverned data silos.
In parallel, EU Cyber Resilience Act pressure and rising CVE noise are pushing manufacturers toward active due diligence on open source dependencies, including databases. That work belongs in security, cost, and Expert Support messaging where the buyer situation is specific, not in top-level company positioning.
Primary impact
Future readiness positioning is the main audience for this change. The McKinsey-backed agentic AI context, governed-retrieval use case, and light PostgreSQL/PMM alignment give field and web teams current buyer language and proof points for why dependable database estates matter as autonomy increases.
CRA and CVE additions are secondary: they support compliance and supply-chain conversations in the security pillar and Expert Support offering without shifting core company framing in
why-percona.md.Made with Cursor