The OffVendor Lock-in Index
157 commercial products scored on the five dimensions that decide how hard leaving actually is. Higher = harder to leave. Compiled by the same editorial process as our migration guides; scoring rules and caveats are published below.
The ten hardest products to leave
Composite of all five dimensions, 0–100. The bar is the score; the note says why.
- Ingest pricing plus a decade of SPL searches, dashboards, and correlation content that no converter translates.
- SAP HANA Databases 85Memory-based pricing, certified hardware, and inseparability from the SAP application estate make this among the deepest locks in enterprise IT.
- The largest integration content library in the segment is exactly what makes leaving it a full playbook rewrite.
- PL/SQL depth, audit exposure, and per-core economics are the textbook lock-in case; ora2pg and managed converters are mature but the code surface is the long pole.
- CyberArk Identity & Access 80Vaults, connectors, and privileged-access policy weave so deeply that migration is a multi-quarter programme.
- Per-action metering punishes successful automation, over Python playbooks locked inside a proprietary editor.
- Self-learning models you cannot inspect, export, or reproduce; the TAP infrastructure, at least, is vendor-neutral.
- BTEQ scripts and decades of warehouse logic are among the heaviest proprietary surfaces in the index.
- Mule flows are an integration programming model, not just gateway config; exits are rewrites.
- Proprietary catalog and format plus decades of enterprise entrenchment; the retention tail is the lock.
How to read the heatmap
Each cell is scored 1 (minimal friction) to 5 (severe friction): 12345 The composite normalizes the five scores to 0–100.
Virtualization
| Product | L | D | P | E | X | Lock-in |
|---|---|---|---|---|---|---|
| VMware vSphere | 5 | 3 | 4 | 4 | 2 | 65 |
| Subscription-only per-core bundles maximized repricing power, but virt-v2v-class tooling and several credible destinations keep the exit path well trodden. | ||||||
| XenServer (Citrix Hypervisor) | 3 | 2 | 3 | 3 | 1 | 35 |
| XCP-ng is a near drop-in fork that reads the same VM formats, one of the cheapest exits in enterprise IT. | ||||||
Databases
| Product | L | D | P | E | X | Lock-in |
|---|---|---|---|---|---|---|
| SAP HANA | 5 | 4 | 5 | 5 | 3 | 85 |
| Memory-based pricing, certified hardware, and inseparability from the SAP application estate make this among the deepest locks in enterprise IT. | ||||||
| Oracle Database | 5 | 4 | 5 | 5 | 2 | 80 |
| PL/SQL depth, audit exposure, and per-core economics are the textbook lock-in case; ora2pg and managed converters are mature but the code surface is the long pole. | ||||||
| IBM Db2 | 4 | 4 | 4 | 4 | 3 | 70 |
| Deep mainframe-era integration and thinner third-party migration tooling than Oracle's exit ecosystem. | ||||||
| Microsoft SQL Server | 4 | 3 | 4 | 4 | 2 | 60 |
| T-SQL, SSIS, and Windows coupling hold workloads in place even though the data itself exports cleanly. | ||||||
| MongoDB | 3 | 3 | 4 | 3 | 3 | 55 |
| SSPL licensing and a proprietary query API mean the friction is in the application layer, not the data export. | ||||||
| Redis | 3 | 3 | 3 | 4 | 2 | 50 |
| The SSPL/RSAL relicensing is the pressure; the Valkey fork keeps the exit unusually short for a commercial database. | ||||||
Backup & DR
| Product | L | D | P | E | X | Lock-in |
|---|---|---|---|---|---|---|
| Veritas NetBackup | 4 | 5 | 4 | 4 | 3 | 75 |
| Proprietary catalog and format plus decades of enterprise entrenchment; the retention tail is the lock. | ||||||
| Rubrik | 4 | 5 | 4 | 3 | 4 | 75 |
| Appliance-plus-SaaS model and proprietary snapshot chains make partial exits particularly awkward. | ||||||
| Commvault | 4 | 5 | 4 | 3 | 3 | 70 |
| Same retention-tail dynamic, with a broad proprietary feature surface on top. | ||||||
| Veeam Backup & Replication | 3 | 5 | 3 | 2 | 3 | 55 |
| Old backups stay readable only by the product that wrote them, so retention obligations keep it installed for years after you switch. | ||||||
| Acronis Cyber Protect | 3 | 4 | 3 | 3 | 3 | 55 |
| Per-workload pricing over archives that read back mainly through Acronis, the familiar backup retention tether. | ||||||
Monitoring
| Product | L | D | P | E | X | Lock-in |
|---|---|---|---|---|---|---|
| Splunk | 4 | 4 | 5 | 4 | 3 | 75 |
| Years of SPL queries, dashboards, and detection content are the real migration, not the log data. | ||||||
| Dynatrace | 4 | 4 | 4 | 3 | 3 | 65 |
| OneAgent and Davis automation are genuinely differentiated, which cuts both ways: harder to replicate on open stacks. | ||||||
| Datadog | 4 | 4 | 4 | 3 | 2 | 60 |
| Usage-based billing plus non-exportable metric history; OpenTelemetry makes the go-forward pipeline portable even though the past stays behind. | ||||||
| New Relic | 4 | 4 | 4 | 3 | 2 | 60 |
| Agent footprint and historical telemetry retention keep renewals sticky; OTel-based stacks are a viable destination. | ||||||
| Cisco AppDynamics | 4 | 4 | 4 | 3 | 2 | 60 |
| Agent footprint and Cisco-ecosystem coupling keep renewals sticky; OpenTelemetry is the credible go-forward exit. | ||||||
| SolarWinds | 3 | 3 | 3 | 3 | 3 | 50 |
| Moderate on every axis; the migration is mostly re-instrumenting checks rather than untangling proprietary depth. | ||||||
Storage & SAN
| Product | L | D | P | E | X | Lock-in |
|---|---|---|---|---|---|---|
| NetApp ONTAP | 4 | 3 | 4 | 4 | 2 | 60 |
| Data moves with host-side copy, but SnapMirror-era workflows and ONTAP features rarely translate one-to-one. | ||||||
| Dell PowerStore | 4 | 3 | 3 | 3 | 2 | 50 |
| Standard block/file semantics keep the exit conventional: migrate LUNs, re-point hosts, retire. | ||||||
| Pure Storage FlashArray | 4 | 3 | 3 | 3 | 2 | 50 |
| Evergreen subscription economics are the retention mechanism more than any technical barrier. | ||||||
| HPE Alletra | 4 | 3 | 3 | 3 | 2 | 50 |
| As with most SANs, the friction is operational cutover risk rather than data captivity. | ||||||
Operating Systems
| Product | L | D | P | E | X | Lock-in |
|---|---|---|---|---|---|---|
| Windows Server | 4 | 3 | 4 | 4 | 3 | 65 |
| AD, IIS, and MSSQL coupling make this an application re-platforming exercise, not an OS swap. | ||||||
| SUSE Linux Enterprise | 3 | 2 | 2 | 2 | 2 | 30 |
| zypper-to-dnf and SUSE-specific management tooling add friction that plain RHEL clones don't have. | ||||||
| Red Hat Enterprise Linux | 3 | 1 | 2 | 2 | 1 | 20 |
| Workloads are portable Linux; migrate2rocky/almalinux-deploy make the conversion nearly mechanical. | ||||||
| Oracle Linux | 3 | 1 | 2 | 2 | 1 | 20 |
| RHEL-compatible base means the same near-mechanical conversion paths apply. | ||||||
| CentOS Linux | 1 | 1 | 1 | 1 | 1 | 0 |
| EOL ended the product rather than locking anyone in; the forced move is easy, just mandatory. | ||||||
Identity & Access
| Product | L | D | P | E | X | Lock-in |
|---|---|---|---|---|---|---|
| CyberArk | 5 | 4 | 5 | 4 | 3 | 80 |
| Vaults, connectors, and privileged-access policy weave so deeply that migration is a multi-quarter programme. | ||||||
| Microsoft Entra ID | 4 | 5 | 4 | 4 | 3 | 75 |
| Credential material plus conditional-access policy depth plus Microsoft 365 gravity is a three-layer bind. | ||||||
| SailPoint | 4 | 4 | 5 | 3 | 3 | 70 |
| Bespoke certification and provisioning workflows resist mechanical translation to any other governance engine. | ||||||
| Okta | 4 | 5 | 3 | 3 | 3 | 65 |
| Password hashes generally cannot be exported, so every migration forces a user re-enrollment or reset wave. | ||||||
| Ping Identity | 4 | 4 | 4 | 3 | 3 | 65 |
| Long-lived federation configs and bespoke policy trees accumulate into the real switching cost. | ||||||
| ForgeRock | 4 | 4 | 4 | 3 | 3 | 65 |
| Heavily customized identity journeys resist mechanical translation to any other engine. | ||||||
| JumpCloud | 4 | 4 | 3 | 3 | 3 | 60 |
| Directory, SSO, and device data consolidated in one cloud, so leaving unwinds several services at once. | ||||||
Cybersecurity
| Product | L | D | P | E | X | Lock-in |
|---|---|---|---|---|---|---|
| Splunk Enterprise Security | 5 | 4 | 5 | 5 | 4 | 90 |
| Ingest pricing plus a decade of SPL searches, dashboards, and correlation content that no converter translates. | ||||||
| Palo Alto Cortex XSOAR | 5 | 4 | 5 | 4 | 4 | 85 |
| The largest integration content library in the segment is exactly what makes leaving it a full playbook rewrite. | ||||||
| Splunk SOAR (Phantom) | 5 | 4 | 5 | 3 | 4 | 80 |
| Per-action metering punishes successful automation, over Python playbooks locked inside a proprietary editor. | ||||||
| Darktrace | 5 | 4 | 5 | 3 | 4 | 80 |
| Self-learning models you cannot inspect, export, or reproduce; the TAP infrastructure, at least, is vendor-neutral. | ||||||
| IBM QRadar SIEM | 4 | 4 | 5 | 3 | 4 | 75 |
| AQL rules, custom DSMs, and the offense workflow are three separate rebuilds, on appliances with their own refresh cycle. | ||||||
| Secureworks Taegis (Sophos) | 4 | 4 | 4 | 3 | 5 | 75 |
| Platform and analyst service are separable, but replacing 24x7 coverage is a staffing project, not a procurement one. | ||||||
| Fortinet FortiSIEM | 4 | 4 | 4 | 4 | 3 | 70 |
| EPS licensing over FortiSIEM-specific rules and parsers, woven into the Fortinet fabric it assumes. | ||||||
| OpenText ArcSight | 4 | 4 | 5 | 2 | 4 | 70 |
| ESM correlation content and the SmartConnector estate are the least portable combination in the SIEM market. | ||||||
| Swimlane | 4 | 4 | 5 | 2 | 4 | 70 |
| Low-code applications built in the platform have no export path at all; the build effort is the lock. | ||||||
| Cisco Secure Endpoint | 4 | 3 | 4 | 4 | 3 | 65 |
| Deep ties to the Cisco security ecosystem and Smart Licensing complicate an otherwise conventional agent migration. | ||||||
| CrowdStrike Falcon | 4 | 4 | 4 | 3 | 3 | 65 |
| Detection history and tuned policies live in the vendor cloud; a switch resets institutional memory. | ||||||
| SentinelOne | 4 | 4 | 4 | 3 | 3 | 65 |
| Same cloud-resident telemetry dynamic as its main rival; agents swap easily, the tuning doesn't. | ||||||
| Palo Alto Cortex XDR | 4 | 4 | 4 | 3 | 3 | 65 |
| Two meters at once, endpoints and ingested data, over BIOC and XQL content that has no export path. | ||||||
| Exabeam | 4 | 4 | 4 | 3 | 3 | 65 |
| UEBA models do not export, and the LogRhythm merger means the roadmap itself may force a product-line move. | ||||||
| LogRhythm (Exabeam) | 4 | 4 | 4 | 3 | 3 | 65 |
| The Exabeam merger put two overlapping SIEM lines together, so even staying may mean a migration. | ||||||
| Microsoft Sentinel | 5 | 3 | 4 | 4 | 2 | 65 |
| Per-gigabyte ingest is the pressure, but log data exports cleanly and partial exits (tiering high-volume sources out) genuinely work. | ||||||
| CrowdStrike Falcon Complete | 4 | 4 | 3 | 3 | 4 | 65 |
| Managed detection layered on Falcon: the tuning stays in the vendor cloud and the coverage stops with the contract. | ||||||
| Arctic Wolf | 4 | 4 | 3 | 2 | 5 | 65 |
| The exit is a hiring plan: multi-year minimums over a concierge model where the provider holds the operational knowledge. | ||||||
| Rapid7 MDR | 4 | 4 | 3 | 3 | 4 | 65 |
| Layered on the Insight platform, so leaving the service usually means reconsidering the platform too. | ||||||
| Deepwatch | 4 | 4 | 4 | 2 | 4 | 65 |
| Co-managed on a SIEM you often license separately, so two contracts and one squad's knowledge all move at once. | ||||||
| ReliaQuest GreyMatter | 4 | 4 | 4 | 2 | 4 | 65 |
| A platform layered over your own tools, with detections and automations that live in GreyMatter and stay there. | ||||||
| LevelBlue (AT&T Cybersecurity / USM Anywhere) | 4 | 4 | 4 | 2 | 4 | 65 |
| USM Anywhere correlation plus a managed service, on a product line freshly spun out of AT&T into LevelBlue. | ||||||
| NTT Data Security (MSSP) | 4 | 4 | 4 | 2 | 4 | 65 |
| Global-MSSP scale with multi-year terms and platform-resident telemetry across regions and tools at once. | ||||||
| Vectra AI | 4 | 4 | 4 | 3 | 3 | 65 |
| Licensed by monitored IPs, so estate growth is billed automatically, over scoring models that stay with the vendor. | ||||||
| ExtraHop Reveal(x) | 4 | 4 | 4 | 3 | 3 | 65 |
| Throughput-based licensing means faster links cost more to watch, with triggers written in a platform-specific model. | ||||||
| Cisco Secure Network Analytics | 4 | 3 | 4 | 4 | 3 | 65 |
| Flow licensing plus deep coupling to Cisco networking and ISE; the network estate is the real tether. | ||||||
| Qualys VMDR | 4 | 4 | 4 | 3 | 3 | 65 |
| QID-keyed findings, an installed cloud-agent estate, and a long list of separately licensed modules to unpick one by one. | ||||||
| Mandiant Advantage | 4 | 5 | 3 | 3 | 3 | 65 |
| A research subscription rather than software; by design there is little portable to take on exit. | ||||||
| Recorded Future | 4 | 5 | 3 | 3 | 3 | 65 |
| You are buying a research corpus, not software, so by design there is nothing meaningful to take with you. | ||||||
| Gurucul | 4 | 4 | 4 | 2 | 3 | 60 |
| The proprietary risk-analytics models are the product, so leaving means rebuilding detection logic from scratch. | ||||||
| Securonix | 4 | 4 | 4 | 2 | 3 | 60 |
| Identity-based licensing decouples cost from log volume, and the UEBA models that justify the price cannot leave. | ||||||
| Fortinet FortiSOAR | 4 | 3 | 4 | 3 | 3 | 60 |
| Playbooks and connectors are platform-specific, and the best value assumes the rest of the Fortinet fabric. | ||||||
| Tines | 4 | 3 | 4 | 3 | 3 | 60 |
| Stories export as Tines JSON, which nothing else executes; tier limits do the rest of the work. | ||||||
| Bitdefender MDR | 4 | 3 | 3 | 3 | 4 | 60 |
| Sold as an uplift on GravityZone, so the endpoint and service decisions are deliberately bundled together. | ||||||
| Trustwave | 4 | 4 | 3 | 2 | 4 | 60 |
| Long MSSP contracts with platform-resident telemetry; the response knowledge is the provider's, not yours. | ||||||
| eSentire | 4 | 4 | 3 | 2 | 4 | 60 |
| Contractual response authority and multi-signal coverage entangle several tools in one service agreement. | ||||||
| Sophos MDR | 4 | 3 | 3 | 3 | 4 | 60 |
| Sold as an uplift on an endpoint licence, so the service and the product decisions are bundled together on purpose. | ||||||
| Alert Logic (Fortra) | 4 | 4 | 3 | 2 | 4 | 60 |
| Platform-resident log retention plus Fortra's repeated portfolio repackaging is an awkward combination at renewal. | ||||||
| Ontinue ION | 4 | 3 | 3 | 3 | 4 | 60 |
| MDR delivered on Microsoft Defender and Sentinel, so leaving is bound up with the Microsoft-stack decision. | ||||||
| Gigamon ThreatINSIGHT | 4 | 3 | 4 | 3 | 3 | 60 |
| Detection tied to Gigamon's visibility fabric, so the tap and packet-broker estate is the real tether. | ||||||
| Trellix Network Detection | 4 | 3 | 4 | 3 | 3 | 60 |
| FireEye-heritage appliances on their own refresh cycle, with sandboxing detections that do not export. | ||||||
| Wiz | 4 | 3 | 4 | 3 | 3 | 60 |
| Per-workload cloud pricing over a findings graph and policy engine that live entirely in the Wiz platform. | ||||||
| Trellix EDR | 4 | 3 | 4 | 3 | 2 | 55 |
| ePolicy Orchestrator gravity across the McAfee and FireEye estates is the sunk cost more than the agent itself. | ||||||
| Symantec Endpoint Security | 4 | 3 | 3 | 3 | 3 | 55 |
| Broadcom-era licensing pressure meets an older, less entangled agent estate. | ||||||
| Google Security Operations (Chronicle) | 4 | 3 | 4 | 2 | 3 | 55 |
| YARA-L detection content and the UDM schema are the programme you write; retention economics keep you writing it there. | ||||||
| D3 Security (Smart SOAR) | 4 | 3 | 4 | 2 | 3 | 55 |
| Low-code playbooks built in the platform have no export path; MSSP-tier licensing adds its own complexity. | ||||||
| Torq | 4 | 3 | 4 | 2 | 3 | 55 |
| Execution-based pricing scales with success, and SaaS-only delivery rules out running it anywhere else. | ||||||
| Expel | 3 | 4 | 3 | 2 | 4 | 55 |
| Sits on tools you already own, which softens the platform lock; the analyst coverage is still the hard part to replace. | ||||||
| Red Canary | 3 | 4 | 3 | 2 | 4 | 55 |
| Detection engineering as a service: the content is theirs, and the EDR underneath is yours, which makes a partial exit possible. | ||||||
| Critical Start | 4 | 3 | 3 | 2 | 4 | 55 |
| The tuning registry that makes full alert resolution affordable is the provider's asset, not yours. | ||||||
| Proficio | 4 | 3 | 3 | 2 | 4 | 55 |
| ProSOC playbooks and tuned detections are the provider's asset, so a switch resets that institutional knowledge. | ||||||
| Fidelis Network | 4 | 3 | 4 | 2 | 3 | 55 |
| Throughput-licensed sensors with proprietary deep-session inspection that has no open equivalent. | ||||||
| Tenable Vulnerability Management | 4 | 3 | 3 | 4 | 2 | 55 |
| Per-asset metering counts ephemeral cloud instances too; scanning ports out easily, VPR prioritisation does not. | ||||||
| Fortinet FortiEDR | 4 | 3 | 3 | 3 | 2 | 50 |
| Best value assumes the wider Security Fabric, which is the coupling that makes leaving more than an agent swap. | ||||||
| Check Point Harmony Endpoint | 4 | 3 | 3 | 3 | 2 | 50 |
| Infinity Portal-resident policy and logs, priced on the assumption you stay inside the Infinity platform. | ||||||
| Carbon Black (Broadcom) | 4 | 3 | 3 | 3 | 2 | 50 |
| Broadcom packaging pressure on a sensor estate that is comparatively easy to swap, with watchlists as the sunk cost. | ||||||
| Cybereason | 3 | 4 | 3 | 2 | 3 | 50 |
| The MalOp investigation model is specific to the platform, and vendor-continuity questions add their own urgency. | ||||||
| Trend Micro | 3 | 3 | 3 | 3 | 3 | 50 |
| Moderate across the board; policy porting is the bulk of the work. | ||||||
| Rapid7 InsightIDR | 4 | 3 | 3 | 3 | 2 | 50 |
| Metered on assets and users at once, with value that assumes you buy the rest of the Insight suite. | ||||||
| Binary Defense | 3 | 3 | 3 | 2 | 4 | 50 |
| A people business more than a platform one, which makes the contract easier to leave and the coverage harder to replace. | ||||||
| Pondurance | 3 | 3 | 3 | 2 | 4 | 50 |
| Analyst-led coverage that ends with the contract; the exit is an insourcing question more than a data one. | ||||||
| Ivanti Neurons for RBVM | 4 | 3 | 3 | 3 | 2 | 50 |
| Per-asset licensing with platform-specific prioritization, on a broad and consolidating Ivanti estate. | ||||||
| Rapid7 InsightVM | 4 | 3 | 3 | 3 | 2 | 50 |
| Remediation workflow and risk scores live in the Insight platform; the scan results themselves are portable. | ||||||
| Anomali | 4 | 3 | 3 | 2 | 3 | 50 |
| Retro-hunt history against past telemetry is the differentiator, and it is precisely the part that cannot be exported. | ||||||
| Bitdefender GravityZone | 3 | 3 | 3 | 3 | 2 | 45 |
| Strong prevention on an easy console; XDR and MDR are uplifts, and the agent estate swaps without much drama. | ||||||
| Sophos Intercept X | 3 | 3 | 3 | 3 | 2 | 45 |
| Mid-market packaging with MDR sold as an uplift; the endpoint layer itself moves without much drama. | ||||||
| Devo | 4 | 3 | 3 | 2 | 2 | 45 |
| Ingest pricing plus a platform-specific query language; the raw log data itself leaves cleanly enough. | ||||||
| Stellar Cyber Open XDR | 3 | 3 | 4 | 2 | 2 | 45 |
| Bundling SIEM, NDR, and UEBA into one Open XDR platform makes a partial exit awkward by design. | ||||||
| Sumo Logic | 4 | 3 | 3 | 2 | 2 | 45 |
| Credit-based consumption on a platform whose searches and dashboards are proprietary but whose data leaves easily. | ||||||
| Rapid7 InsightConnect | 3 | 2 | 4 | 3 | 2 | 45 |
| Workflows live in a hosted designer and assume the Insight platform, but the automation scope is usually modest. | ||||||
| Blackpoint Cyber | 3 | 3 | 3 | 2 | 3 | 45 |
| MSP-channel MDR with a narrow, fast-response scope, which keeps the practical exit surface small. | ||||||
| ThreatQuotient | 4 | 3 | 3 | 2 | 2 | 45 |
| STIX helps the indicators leave; the scoring, workflow, and integrations are configured in-platform and do not. | ||||||
| EclecticIQ | 4 | 3 | 3 | 2 | 2 | 45 |
| STIX-friendly at the data layer, with the analyst-workbench enrichment history kept inside the platform. | ||||||
| ESET PROTECT | 3 | 3 | 3 | 2 | 2 | 40 |
| Among the least entangled commercial endpoint products here, with an on-prem console that keeps data local. | ||||||
| ThreatConnect | 4 | 2 | 3 | 2 | 2 | 40 |
| STIX 2.1 export makes the intel graph genuinely portable; playbooks and computed confidence scores are what stay behind. | ||||||
| Huntress | 2 | 3 | 2 | 2 | 3 | 35 |
| Deliberately narrow scope and monthly pricing make this one of the easier managed services to leave. | ||||||
| Corelight | 3 | 2 | 1 | 2 | 1 | 20 |
| Packaged open Zeek: the logs, scripts, and analytical model are already portable, which makes this the softest lock in the category. | ||||||
IaC & Secrets
| Product | L | D | P | E | X | Lock-in |
|---|---|---|---|---|---|---|
| HashiCorp Vault | 3 | 3 | 3 | 3 | 2 | 45 |
| OpenBao forked the engine, but secrets migration and re-auth of every consumer still need a careful runbook. | ||||||
| Puppet Enterprise | 3 | 2 | 3 | 3 | 2 | 40 |
| The DSL and module estate is the sunk cost; the managed nodes themselves move easily. | ||||||
| HashiCorp Terraform | 3 | 2 | 3 | 2 | 1 | 30 |
| The BSL relicense triggered OpenTofu, a state-compatible drop-in fork, about as clean as exits get. | ||||||
Containers & PaaS
| Product | L | D | P | E | X | Lock-in |
|---|---|---|---|---|---|---|
| Cloud Foundry (Tanzu AS) | 3 | 3 | 4 | 3 | 3 | 55 |
| The cf-push developer contract has no exact open equivalent, so the migration is a workflow change, not just a platform swap. | ||||||
| Red Hat OpenShift | 4 | 2 | 4 | 3 | 2 | 50 |
| Manifests are mostly portable Kubernetes, but Routes, Operators, and S2I builds need untangling first. | ||||||
| VMware Tanzu | 4 | 2 | 3 | 3 | 2 | 45 |
| Broadcom-era pricing meets a workload layer that is largely standard Kubernetes underneath. | ||||||
| Mirantis Kubernetes Engine | 3 | 2 | 2 | 2 | 2 | 30 |
| Swarm-to-Kubernetes conversion is well understood and the container images themselves are already portable. | ||||||
Data Warehouse
| Product | L | D | P | E | X | Lock-in |
|---|---|---|---|---|---|---|
| Teradata | 5 | 4 | 5 | 4 | 3 | 80 |
| BTEQ scripts and decades of warehouse logic are among the heaviest proprietary surfaces in the index. | ||||||
| Databricks | 4 | 4 | 5 | 3 | 2 | 65 |
| Delta and Unity Catalog keep raw data portable while notebooks, jobs, and DBU economics pull workloads deeper in. | ||||||
| Azure Synapse / Fabric | 4 | 3 | 4 | 4 | 2 | 60 |
| Tables export cleanly; T-SQL extensions, pipelines, and the Microsoft data-estate gravity do the holding. | ||||||
| Snowflake | 4 | 3 | 4 | 3 | 2 | 55 |
| COPY-to-Parquet keeps raw data portable while credits pricing, Snowpark, and tasks pull workloads deeper in. | ||||||
| Google BigQuery | 4 | 3 | 4 | 3 | 2 | 55 |
| Easy table export contrasts with slot economics and SQL extensions that accumulate in every pipeline. | ||||||
| Amazon Redshift | 4 | 3 | 4 | 3 | 2 | 55 |
| UNLOAD to S3 keeps data portable; dialect quirks and AWS integration do the holding. | ||||||
CI/CD & DevOps
| Product | L | D | P | E | X | Lock-in |
|---|---|---|---|---|---|---|
| Atlassian Bamboo | 4 | 3 | 4 | 3 | 3 | 60 |
| Data-center licensing changes plus plan configs that predate pipeline-as-code conventions. | ||||||
| GitHub Actions | 3 | 2 | 4 | 4 | 2 | 50 |
| Workflows and Marketplace actions are GitHub-specific, and the SCM gravity around them is the real hold. | ||||||
| GitLab (Premium/Ultimate) | 3 | 2 | 3 | 2 | 2 | 35 |
| Git history moves trivially; CI definitions and merge-request workflow are the translation work. | ||||||
| CircleCI | 3 | 2 | 3 | 2 | 2 | 35 |
| YAML pipelines translate readily; the exit is mostly re-plumbing secrets and runners. | ||||||
| Jenkins | 1 | 2 | 3 | 3 | 2 | 30 |
| Open source with no vendor to lock you in; teams leave over Groovy pipeline sprawl and maintenance burden instead. | ||||||
Load Balancers / ADC
| Product | L | D | P | E | X | Lock-in |
|---|---|---|---|---|---|---|
| F5 BIG-IP | 5 | 3 | 5 | 4 | 3 | 75 |
| iRules are a full programming environment; estates carry years of traffic logic no converter fully translates. | ||||||
| Citrix NetScaler ADC | 4 | 3 | 4 | 3 | 3 | 60 |
| Content-switching policies and rewrite rules need manual re-expression in any destination. | ||||||
| A10 Thunder ADC | 4 | 3 | 4 | 3 | 3 | 60 |
| aFleX scripting mirrors the F5 dynamic at somewhat smaller scale. | ||||||
| Kemp LoadMaster | 3 | 2 | 3 | 2 | 2 | 35 |
| Simpler feature surface keeps conversions to HAProxy/NGINX comparatively contained. | ||||||
Switches & Routers
| Product | L | D | P | E | X | Lock-in |
|---|---|---|---|---|---|---|
| Cisco Catalyst / Nexus | 4 | 2 | 4 | 4 | 3 | 60 |
| Configs convert, but an IOS-certified operations culture is the stickiest asset in the rack. | ||||||
| Juniper Networks | 4 | 2 | 4 | 3 | 3 | 55 |
| Junos policy language and automation tooling embed deeply into network operations. | ||||||
| Arista Networks | 3 | 2 | 3 | 3 | 3 | 45 |
| EOS's Linux foundations and standard protocols keep the surface more portable than most. | ||||||
Firewalls
| Product | L | D | P | E | X | Lock-in |
|---|---|---|---|---|---|---|
| Palo Alto Networks | 5 | 3 | 4 | 4 | 3 | 70 |
| Panorama-managed policy estates and per-feature subscriptions concentrate both cost and switching effort. | ||||||
| Fortinet FortiGate | 4 | 3 | 4 | 3 | 3 | 60 |
| FortiOS feature breadth means rulebase conversion is rarely the whole story. | ||||||
| Check Point | 4 | 3 | 4 | 3 | 3 | 60 |
| Decades-old rulebases with layered admin conventions resist clean mechanical export. | ||||||
| Sophos Firewall (XG) | 3 | 3 | 3 | 3 | 3 | 50 |
| Central-managed policy plus endpoint synchronisation in Sophos Central; a conventional rulebase-rebuild exit otherwise. | ||||||
| SonicWall | 3 | 3 | 3 | 2 | 3 | 45 |
| Smaller-estate deployments keep the practical exit surface manageable. | ||||||
Message & Streaming
| Product | L | D | P | E | X | Lock-in |
|---|---|---|---|---|---|---|
| IBM MQ | 5 | 4 | 4 | 4 | 3 | 75 |
| Forty years of enterprise integration patterns assume MQ semantics that open brokers only approximate. | ||||||
| TIBCO EMS | 5 | 4 | 4 | 4 | 3 | 75 |
| Private-equity-era pricing on a broker woven through legacy middleware estates. | ||||||
| Solace PubSub+ | 4 | 4 | 4 | 3 | 3 | 65 |
| Appliance heritage and proprietary topic semantics make like-for-like replacement uncommon. | ||||||
| Confluent Platform | 4 | 3 | 4 | 3 | 2 | 55 |
| MirrorMaker 2 moves topics to open Kafka; ksqlDB, connectors, and Schema Registry are the sticky extras. | ||||||
AI & LLMs
| Product | L | D | P | E | X | Lock-in |
|---|---|---|---|---|---|---|
| Azure OpenAI | 4 | 5 | 4 | 3 | 2 | 65 |
| The same model captivity plus Azure networking, identity, and compliance integration on top. | ||||||
| Amazon Bedrock | 4 | 5 | 4 | 3 | 2 | 65 |
| The models are swappable; the surrounding AWS identity, networking, and service integration is what keeps you. | ||||||
| OpenAI GPT | 4 | 5 | 4 | 2 | 2 | 60 |
| Prompts port easily but fine-tuned models cannot leave the platform, and behavior parity on open weights needs re-evaluation from scratch. | ||||||
Cloud Migration
| Product | L | D | P | E | X | Lock-in |
|---|---|---|---|---|---|---|
| Amazon Web Services | 4 | 4 | 5 | 4 | 3 | 75 |
| Egress economics and hundreds of proprietary services make gravity, not any single contract, the lock. | ||||||
| Microsoft Azure | 4 | 4 | 5 | 4 | 3 | 75 |
| Microsoft licensing bundles reach beyond the cloud itself into identity and productivity estates. | ||||||
| Google Cloud | 4 | 4 | 4 | 3 | 3 | 65 |
| Slightly thinner proprietary surface than its rivals, with the same data-gravity fundamentals. | ||||||
VDI & EUC
| Product | L | D | P | E | X | Lock-in |
|---|---|---|---|---|---|---|
| Citrix DaaS / Virtual Apps & Desktops | 5 | 3 | 4 | 4 | 3 | 70 |
| Post-acquisition repricing on a product whose admin skill set is a career specialty of its own. | ||||||
| Omnissa Horizon (VMware Horizon) | 4 | 3 | 4 | 3 | 3 | 60 |
| The Omnissa transition adds vendor uncertainty to an already specialized stack. | ||||||
API Management
| Product | L | D | P | E | X | Lock-in |
|---|---|---|---|---|---|---|
| MuleSoft Anypoint | 5 | 4 | 5 | 4 | 3 | 80 |
| Mule flows are an integration programming model, not just gateway config; exits are rewrites. | ||||||
| Google Apigee | 4 | 3 | 4 | 3 | 3 | 60 |
| Proxy bundles export, but policy semantics and Google Cloud integration need re-architecture elsewhere. | ||||||
| Kong Enterprise | 3 | 2 | 3 | 2 | 1 | 30 |
| Declarative config and an OSS core underneath make the enterprise-to-OSS step unusually short. | ||||||
Methodology, caveats, and how to cite this
The index is an editorial assessment by the OffVendor Editorial Team, produced with the same process as our migration methodology: public licensing terms, vendor documentation, commonly reported customer experience, and first-hand knowledge of the migration tooling for each product.
Each product is scored 1–5 on the five dimensions above; the composite is the normalized sum. Scores describe the typical mid-size enterprise deployment, your contract, version, and architecture can move any score in either direction. These are general, commonly reported considerations, not statements of fact about any vendor's current terms, and they are not legal or procurement advice. Products are re-scored when licensing or ownership changes materially (Broadcom/VMware and HashiCorp/BSL both triggered re-scores).
You are welcome to cite or reproduce individual scores with attribution and a link: "OffVendor Lock-in Index 2026, offvendor.com/lock-in-index". Spotted a score you can argue with evidence? Email hello@offvendor.com, the index improves through corrections.