Kiko Fernandes-Reyes, Ericsson

Erlang and Elixir are programming languages that run on the BEAM virtual machine — a VM that has been battle-tested for 40 years and is used by companies such as WhatsApp, Ericsson, Klarna, Kivra, and Telia. Therefore, it is important to ensure that the ecosystem rests on a solid foundation that organizations can rely on.

How, then, can companies place their trust in these open-source projects? And are they ready for the upcoming Cyber Resilience Act?

In this talk, we will show how Erlang/OTP and the Erlang Ecosystem Foundation (EEF) collaborate to foster public trust in the ecosystem. We will outline the security- and compliance-focused best practices they follow, explain how they report and analyze vulnerabilities, and describe their process for issuing VEX statements.


Open Source Security Foundation
OWASP Foundation
Open regulatory compliance working group (ORCWG.ORG)