
Work Here?
Work Here?
Work Here?
Azul Systems provides enterprise OpenJDK-based Java solutions designed to boost performance and security for cloud applications. Its product offerings include a Java platform licensed to customers, 24/7 support, and migration services that help organizations move from Oracle JDK to Azul with minimal downtime. Azul’s platform integrates with existing Java technologies and supports IoT and big data workloads, delivering low-latency, stable applications across millions of installations. The company differentiates itself by focusing on open Java implementation for enterprises, serving many Fortune 100 companies, and employing highly experienced Java engineers to ensure reliable operation and expert guidance. Azul’s goal is to help businesses run faster, more secure Java in the cloud, with easy migration, strong support, and scalable performance across diverse workloads.
We're working on gathering enough insights on this company, check back soon!
Industries
Data & Analytics
Consulting
Enterprise Software
Company Size
501-1,000
Company Stage
Series F
Total Funding
$177.7M
Headquarters
Sunnyvale, California
Founded
2002
See people who can refer or advise you
Health Insurance
Paid Vacation
Paid Holidays
Remote Work Options
Employee Referral Bonus
EWE AG cuts Java licensing costs by 60% after migrating from Oracle to Azul Core. German energy leader standardizes Java environment across 100+ applications and tens of thousands of desktops, eliminating Oracle licensing burden. SUNNYVALE, Calif. - June 23, 2026 - Azul, the trusted leader in enterprise Java for today's AI and cloud-first world, today announced that EWE AG, one of Germany's leading energy and infrastructure companies, has cut its Java licensing costs by 60% by migrating from Oracle Java to Azul Core - standardizing its fragmented Java environment across more than 100 applications and tens of thousands of desktop endpoints in the process. EWE AG provides critical infrastructure and energy services to more than two million customers. Java is deeply embedded across its operational and end-user systems, many of which support essential daily processes and cannot be easily replaced. Ensuring stability and consistency across this environment is central to business continuity. Over time, however, EWE's Java landscape became increasingly fragmented, with multiple versions and distributions in use across the organization. Legacy systems, including some still dependent on Java 6, which Oracle stopped supporting in December 2018, added further complexity. This environment created additional overhead for packaging, deployment, support and governance, while new Java instances continued to be introduced through incoming applications, increasing the need for standardization. In addition, EWE, as an operator of critical energy infrastructure serving more than 2 million customers, is subject to the German BSI Act (BSIG) and its KRITIS framework, which requires operators of critical infrastructure to implement and demonstrate appropriate technical and organizational measures to ensure the security and availability of their IT systems. The situation was further impacted when Oracle changed its Java licensing model in January 2023. What had previously been a manageable cost structure quickly became a significant budget concern. "When Oracle Java changed the licensing metric, we realized it would become far more expensive for us," said Sacha Massarra, license manager at EWE AG. "That was the moment we decided to move to an alternative." Evaluating options in a highly fragmented environment As EWE assessed its options, it weighed the trade-offs between unsupported OpenJDK distributions and commercially supported platforms. While free OpenJDK variants were available, EWE determined they would introduce substantial internal operational burden, particularly around patch management, version control and support escalation across a highly distributed environment. Given the scale and criticality of its systems, the organization required a stable, enterprise-supported Java platform. "In a corporate environment, switching to a Java platform without support is not really an option," said Massarra. EWE selected Azul Core based on its enterprise support model, compatibility across legacy and modern Java environments, and ability to support older versions such as Java 6. The company also cited faster vendor responsiveness and a clearer path toward enterprise-wide standardization. Phased migration enables controlled rollout across the enterprise EWE implemented a phased migration approach, beginning with small rollout waves of approximately 50 to 200 devices. This allowed teams to validate application behavior early and identify issues before broader deployment. As confidence increased, larger migration waves followed until the rollout was completed across the organization in approximately eight to nine months. "If you reduce twenty different Java packages down to one, the internal support effort drops significantly," said Gerold Frilling, Solution Architect at EWE AG. "Azul's support was fast, structured, highly competent and very uncomplicated. There was no problem that wasn't immediately addressed." Results: simplified operations, standardized environment, and reduced cost For EWE AG, the migration delivered both operational and financial outcomes, simplifying its Java estate while reducing cost and complexity across IT operations. Key results include: * Standardized Java environment across the enterprise, consolidating multiple distributions into a single supported standard across more than 100 applications and tens of thousands of endpoints, reducing complexity for IT operations, packaging, and support teams. * 60% reduction in Java licensing costs, compared with the projected multi-million-euro cost of remaining on Oracle Java, achieved under a five-year agreement. * Low-risk, phased migration across the organization, with even the most complex application migrations completed in approximately four hours. * Improved operational efficiency and support experience, with EWE citing Azul's responsiveness, technical competence and ease of collaboration throughout the migration process. * Reduced environmental and compute overhead, supporting EWE's broader sustainability objectives as an energy provider focused on efficiency and resource optimization. "Nobody needs Oracle Java anymore. If you need support, the clear answer is: switch to Azul," said Massarra. "EWE AG's transformation demonstrates the operational impact of Java fragmentation at enterprise scale," said James Johnston, vice president of EMEA at Azul. "By consolidating a highly distributed Java estate under a single supported platform, they significantly reduced complexity across critical systems while also lowering costs and improving operational control. This type of standardization is becoming increasingly important as enterprise Java environments grow more diverse and distributed." How much can enterprises save by migrating from Oracle Java to Azul Core? Savings vary based on environment size and complexity. In EWE AG's case, Java licensing costs were reduced by 60% after migrating from Oracle Java to Azul Core. The company standardized more than 100 applications across tens of thousands of endpoints, replacing a projected multi-million-euro Oracle cost structure with a predictable five-year agreement. Can large enterprises migrate from Oracle Java without disrupting operations? Yes. EWE AG completed its migration in approximately eight to nine months using a phased rollout approach. Initial waves of 50 to 200 devices enabled early validation before scaling across the enterprise. Even complex applications were migrated in approximately four hours. Why choose a commercially supported OpenJDK distribution over a free alternative? Free OpenJDK distributions typically lack enterprise support, structured patching and service-level guarantees. EWE AG evaluated these options but determined that managing updates and support internally across a fragmented environment - including legacy Java 6 systems - would create significant operational overhead. Azul Core provides enterprise-grade support and compatibility across both legacy and modern workloads. About Azul Azul is the trusted leader in enterprise Java for today's AI and cloud-first world. Its open source-based Java platform empowers organizations to optimize the entire Java lifecycle to accelerate performance, strengthen security, reduce licensing and cloud costs, and boost developer productivity. Azul powers mission-critical systems for 36% of the Fortune 100, 50% of the Forbes Top 10 World's Most Valuable Brands, and the world's top 10 financial trading companies. Learn more at azul.com and follow @azulsystems.
Azul addresses the Java runtime security blind spot autonomous AI can now exploit. Azul | Published 18 June 2026 Launches free JVM vulnerability risk assessment to give enterprises estate visibility before AI threat actors find the gaps Azul today launched a free JVM vulnerability risk assessment to address the blind spot that autonomous AI exploitation tools are increasingly able to find. With mean time to exploit (MTTE) collapsing from months to days or hours, the unmanaged Java estate has become an urgent enterprise security vulnerability. Azul's assessment gives DevOps and SecOps teams complete visibility into the hidden risks embedded in the runtime of their Java estate before threat actors get there first, and is designed to complement the broader security, licensing and compliance solutions and services delivered by Azul's trusted partners. The Threat Landscape Has Transformed For most of Java's enterprise history, a sophisticated exploit required a sophisticated attacker. Zero-day discovery and weaponisation were largely the domain of nation-states and elite offensive security teams. The barrier was expertise - deep JVM knowledge, reverse engineering, and months of painstaking technical effort. That barrier has collapsed. Anthropic's Claude Mythos demonstrates that AI can autonomously uncover previously unknown vulnerabilities and generate working exploit paths at scale - without human expertise. What once required deep, specialised expertise can now be accomplished with little more than an advanced AI model and an API key. The result is an expanding population of potential attackers. MTTE - once measured in months - can now collapse to days or hours. Meanwhile, most enterprises still patch non-critical Common Vulnerabilities and Exposures (CVEs) on a "best effort" basis, leaving extended windows of exposure between vulnerability disclosure and remediation. For large, complex Java estates with legacy versions in production, embedded or unmanaged JVMs and incomplete runtime visibility, that gap is a critical security and compliance liability. The JVM Vulnerability Risk Assessment - See Everything, Prioritize What Matters Azul's JVM vulnerability risk assessment is available at no cost, direct from Azul and via select Azul partners. In a single engagement, organisations receive: * Executive-ready security dashboard: A visual summary of the entire Java estate, broken down by risk tier, publisher and Java version - designed for CxO-level consumption and board reporting. * Risk-by-version breakdown: Identification of the specific Java versions driving the highest exposure, so remediation effort can be directed where it matters most rather than spread uniformly. * Key Risk Indicators (KRIs) for AI-driven exploits: Visibility into which JVMs carry active Known Exploited Vulnerability (KEV) exposure - the highest-priority threat class recognised in the U.S. government's CISA KEV catalog - as well as which instances are end-of-life or running below the current patch baseline. * Prioritised remediation roadmap: Concrete next steps ranked by impact, including which workloads to patch first, which to migrate off unsupported runtimes, and how to address extended support needs for legacy environments that cannot be immediately modernised. "Through our strategic partnership with Azul, we significantly reduced our security risk level with our Java applications and Java-based infrastructure, which certainly helps me sleep better at night," said Jenny Nelson, head of ICT & Digital at Newcastle City Council. "In addition, the benefits of switching to Azul Core as our JVM are clear. Our Java estate is now consistent, standardized, easier to maintain, and has brought a level of simplicity that's a huge benefit to our organization." The assessment is purpose-built for the risk environment AI-driven attackers have created: one in which the gap between assumed security posture and actual security posture is measured not in audit findings, but in active exploits. Why Security Patch Velocity is the Frontline Defense Java's quarterly updates are the primary mechanism by which known vulnerabilities are remediated. But in an environment where autonomous AI systems continuously discover new vulnerabilities or chain together previously known CVEs into exploits, the pace of standard patch deployment is no longer sufficient on its own. Azul's enterprise Java platform addresses this challenge through a multi-layered approach designed for large, complex Java estates: * Stable Critical Patch Updates (CPUs): Quarterly, production-safe patches containing only current CVE fixes. Azul Core is the only OpenJDK distribution which provides security-only updates, intended for immediate deployment without disrupting live environments. * Out-of-cycle emergency fixes: As vulnerabilities are discovered which demand immediate remediation, Azul provides security-only emergency fixes, collaborating with the Java community to help ensure safe delivery. * Full-stack visibility: Azul surfaces every JVM instance across the enterprise estate, including embedded and unmanaged runtimes that standard asset discovery typically misses - closing the gaps before they can be exploited. The zero-day problem remains the hardest frontier. No scanner, SIEM (Security Information and Event Management), or EDR (Endpoint Detection and Response) platform can detect a vulnerability that has not yet been disclosed. Against unknown exposure, organisations maintaining a fully current Java estate are materially harder to exploit as they continuously remove outdated runtimes and previously exposed attack surfaces from production, minimising the footprint that agentic AI exploits can target. Elevated Stakes for Regulated Enterprises Organisations in financial services, healthcare, utilities and government face a compounding challenge. They operate some of the largest and most complex Java estates in existence, and they face the strictest regulatory obligations. Frameworks including PCI-DSS, SOX, HIPAA, DORA, NERC CIP and FedRAMP all require demonstrable visibility into deployed software versions, timely vulnerability remediation and documented patch history. Autonomous AI exploitation tools do not distinguish between regulated and unregulated targets. But the consequences of a breach in a regulated environment - and the burden of demonstrating adequate security posture to auditors - make estate visibility and rapid CPU deployment not merely a best practice but a compliance requirement. "Anthropic's Mythos has shown that AI can now discover and weaponise vulnerabilities on its own - including flaws that survived decades of human review. That's the real lesson for every CISO: the deep expertise that used to stand between attackers and your software estate is no longer a barrier," said Scott Sellers, co-founder and CEO of Azul. "The unpatched JVM is already a growing liability, not a future one. Azul's JVM vulnerability risk assessment was created to help security leaders find and close that exposure before AI-driven attackers can exploit it." Azul's JVM vulnerability risk assessment maps JVM exposure, KEV risk and patch gaps across the entire enterprise Java estate and delivers a concrete remediation roadmap to close them. The assessment can be utilised as a standalone vulnerability analysis specific to a Java runtime estate or can be augmented into existing security, licensing and compliance solutions and services offered by Azul partners. How do I find unmanaged or embedded JVMs across my enterprise Java estate? Azul's JVM vulnerability risk assessment surfaces every JVM instance across your environment - including embedded and unmanaged runtimes that standard asset discovery misses - and delivers a prioritised remediation roadmap to close the gaps. How do I know which Java versions in my environment are the highest security risk? Azul's JVM vulnerability risk assessment breaks down your estate by risk tier, Java version and publisher, and identifies which JVMs carry active Known Exploited Vulnerability (KEV) exposure from the CISA KEV catalog. What's the best way to reduce the attack surface autonomous AI tools can exploit in my Java environment? Azul continuously removes outdated runtimes and closes patch gaps across the entire Java estate - including legacy and unmanaged JVMs - minimising the footprint autonomous AI exploitation tools can target. Why are Critical Patch Updates (CPUs) important? A CPU contains only security fixes, applied on top of the previous, field-stabilised release. That sets these updates apart from the Patch Set Updates (PSUs) that all other OpenJDK builds provide. PSUs bundle security updates, new features and bug fixes - typically measured in the hundreds - that demand far more testing before they can be safely deployed in production. Azul Core is the only OpenJDK distribution which provides CPUs, allowing teams to deploy urgent security fixes rapidly, with much lower risk of regression. Why are unpatched Java environments a growing security liability? Autonomous AI tools have collapsed mean time to exploit from months to days or hours, making unpatched JVMs and unmanaged runtimes an urgent liability - underscored by how quickly Mythos-class capability escaped its intended containment. Maintaining a current Java estate with full visibility is now the primary defence. About Azul Azul is the trusted leader in enterprise Java for today's AI and cloud-first world. Its open source-based Java platform empowers organizations to optimize the entire Java lifecycle to accelerate performance, strengthen security, reduce licensing and cloud costs, and boost developer productivity. Azul powers mission-critical systems for 36% of the Fortune 100, 50% of the Forbes Top 10 World's Most Valuable Brands, and the world's top 10 financial trading companies. Learn more at azul.com and follow @azulsystems.
Find jobs on Simplify and start your career today
We're working on gathering enough insights on this company, check back soon!
Industries
Data & Analytics
Consulting
Enterprise Software
Company Size
501-1,000
Company Stage
Series F
Total Funding
$177.7M
Headquarters
Sunnyvale, California
Founded
2002
Find jobs on Simplify and start your career today