Why Steward

The operational half of Open Source Software (OSS) governance, for the teams who can't staff it.

An OSS Program Manager does community work, strategic alignment, and mentorship — judgment calls software won't make. Steward does the rest: evaluate every Pull Request (PR) across nine dimensions, score the contributor, surface supply-chain risk, and produce a markdown report someone can paste into a review or share with their board.

The category problem

"AI PR review" is a saturated market with the wrong buyer.

The AI PR-review category is well-funded, has distribution, and reviews the diff well — typically at $24–30 per developer per month. Steward will lose head-to-head on PR-review polish. We don't try.

The interesting question isn't "who reviews PRs best" — it's "who answers the question every OSS maintainer asks first: is this contributor real?" That question has structural answers no diff-scoring tool can produce. It needs reputation signal accumulated across thousands of repos, not another LLM pass over the patch.

And the buyer isn't an engineering manager spending a dev-productivity budget. It's a head of OSS staring at a calendar full of triage, or a founder who knows the team should be doing this work and isn't.

The wedge

Score the contributor, not just the diff.

Contributor reputation is the one capability where Steward beats both the AI PR-review category and a human OSS Program Manager. A Program Manager judges contributors with experience and intuition — slow, idiosyncratic, expensive. Steward judges them with reproducible signal across thousands of repos — available the moment the PR opens, on every contributor, for every repo under governance.

This is the hook. Once a maintainer trusts the reputation lens, the rest of the nine-dimension evaluation — risk, supply chain, scope alignment, governance math — lands as "the same kind of signal, applied to the rest of what matters."

Who Steward is for

Teams without an OSS Program Manager — by capacity, budget, or stage.

The buyer who actually converts is a Commercial Open Source Software (COSS) team without a dedicated program manager:

  • A Series A–C startup with a public OSS surface — their core product or a critical open dependency — and 3–25 engineers, all of whom would rather build than triage.
  • A COSS-tier company that knows it should have an OSS Program Manager but hasn't budgeted one.
  • An established OSS project under a sponsoring company where the maintainers are doing the Program Manager work in their margins.

The buyers who don't convert quickly:

  • Companies that already have a dedicated OSS Program Manager team. Steward doesn't replace them, and selling "augmentation" against an existing role is a slower motion.
  • Casual single-maintainer projects without revenue. Community tier ($0) is for them — but they're not the conversion path to paid.

Not just for OSS

Most of what Steward does carries to private repos — and for some buyers, harder.

The OSS framing leads the marketing because reputation-on-drive-by-PRs is the sharpest wedge against the AI PR-review category. Reputation matters less inside a company you control — you already know your engineers' track record — but the rest of what Steward does applies cleanly to private codebases, and for some buyers (compliance leads, engineering leadership) it's the stronger pull:

  • Policy-as-code instead of Slack-thread rules. governance.pxf ships with the repo, gets code-reviewed when it changes, and applies uniformly across PRs without someone manually re-stating "we don't take direct deps in core/" every quarter.
  • Supply-chain enforcement doesn't care whether the manifest is public. License gates, pinning, mission-drift, and the alternatives gate (manual + behavioral + Large Language Model (LLM)) apply identically — a proprietary monolith with 400 npm packages has the same liability surface as an OSS library.
  • Contributor License Agreement (CLA) / Developer Certificate of Origin (DCO) covers internal Intellectual Property (IP) chain hygiene — contractor onboarding, joint-venture code, acquisition diligence. Per-commit enforcement catches the "one automated-dependency- update commit was authored by a bot in a human-author PR" case cleanly.
  • Service Organization Control 2 (SOC2) shaped audit-bundle export with the 12-month default, 5-year cap, 50k-event truncation flag. Most OSS projects don't need this; most compliance-driven private companies need it badly.
  • Multi-repo fleet dashboard + bulk-apply templating gives one ProjectManager surface across 30 internal repos — replaces "let's update CODEOWNERS in every repo" tickets with one fan-out.
  • Single Sign-On (SSO) via OpenID Connect (OIDC) at the Business tier — Okta, Azure AD, Keycloak, Google Workspace — for internal Identity Provider (IdP) integration where most OSS-tier customers wouldn't bother.

One product, both audiences. The OSS framing is the wedge that explains why we exist as a category; the internal-engineering use case is the wider door once you're inside.

What we deliberately don't do

The framing has to survive contact with someone who knows the role.

"Replace your OSS Program Manager" is a frame that survives a 30-second elevator pitch and breaks on the first conversation with a buyer who actually understands what a PM does. We don't use it.

Steward is strongest at operational triage. It's partial in contributor relations and risk. It's absent in community building, strategic alignment, and governance-policy authorship. A buyer should walk in knowing Steward fills the operational gap — freeing the staff engineers and founders from doing that work themselves — not believing it will run the program for them.

One product, two surfaces

Caliper is the wedge. Steward is the product.

Caliper is a Go static-analysis Model Context Protocol (MCP) server, distributed publicly under Business Source License (BSL) 1.1. Free for non-production and under-threshold commercial use; paid commercial use bundled into every Steward tier. It's the cheap deterministic gate that keeps Steward's LLM bill from getting out of hand — and it's the developer-tooling wedge that lands in AI coding agents and funnels users toward Steward when they need governance across the rest of their portfolio.

There is no standalone paid Caliper SKU. Companies that want Caliper for production buy Steward, and the bundle gives them the commercial license plus the hosted governance product. One paid product, one buyer.

If this is you

Start where it fits.

Pricing has the four-tier ladder; the compare page covers how Steward sits next to the AI PR-review and static-analysis markets. Or jump straight to a conversation.