Support · mod_pagespeed 2.1
Support from the engineers who build mod_pagespeed 2.1
The software is open source under the Apache License 2.0 and does the same thing with or without a subscription. A subscription decides who answers when something breaks and, from Priority up, which repository your packages come from.
What a subscription buys
- channel: direct
- Tickets and email go to the engineers who build the product. Nobody in between.
- response: by severity
- Agreed response times on CET business days, per severity level, stated in your quote.
- security updates: SLA-backed
- Advance notice and a delivery window you can hold us to.
- scope: deployment or organization
- One production deployment in a declared server band, or a whole organization.
Subscriptions are governed by the support terms together with the terms of service.
Three tiers
Tiers differ in fleet size and in which repository your packages come from. The software is the same in all three.
Standard support
up to 5 production servers
- Ticket and email channel to the engineers who build the product
- Configuration, upgrade and incident help
- Advance notice of security updates
- One onboarding configuration review
Priority support
Recommendedup to 25 production servers
- Everything in Standard
- Hardened builds through the subscriber repository
- Upgrade rehearsal on request
- Quarterly review call
Enterprise
unlimited servers and sites, one organization
- Everything in Priority
- A named engineer
- Custom build targets (distributions, nginx versions)
- Backport commitments and pre-notification of security advisories
- Master agreement, purchase order and invoice
- Roadmap input and consulting days
Pricing on request: published once agreements with current customers close; early subscribers keep their quoted rate for three years. Response targets by severity are stated in your quote.
For your security team
Hardened builds
Every build of mod_pagespeed 2.1 comes from the same source. Hardened builds differ in how they are built and delivered, never in what they do. They are included in Priority and Enterprise.
What ships today, for everyone
-
The apt and yum repositories at
packages.modpagespeed.comare GPG-signed (RSA 4096, fingerprintDF00 E296 BE91 41CE A541 1346 F50D 6054 F107 12A0); apt and dnf verify what they install against that key. -
Every release asset on GitHub is listed in a
SHA256SUMSfile published with the release. -
An SPDX 2.3 SBOM for the 2.1 line, with a VEX document, is published in the
sbom/directory of the source tree. - The container images on GHCR are signed with keyless cosign and carry an SBOM attestation and build provenance; the verify commands are in the deployment guide.
What the subscriber repository adds
- Packages built through a hardened build pipeline.
- Security updates ahead of the public release.
- Enterprise adds custom build targets.
Hardened artifacts carry the same Apache License 2.0 as the standard packages. A subscription covers access to the repository, not a different license.
Ask about hardened buildsVerify what you install today
Four lines: fetch the repository key, check its fingerprint, pin apt to it, and check the checksums of anything downloaded from a release page.
curl -fsSL https://packages.modpagespeed.com/pubkey.gpg -o modpagespeed.asc
gpg --show-keys --with-fingerprint modpagespeed.asc # expect DF00 E296 BE91 41CE A541 1346 F50D 6054 F107 12A0
gpg --dearmor < modpagespeed.asc | sudo tee /usr/share/keyrings/modpagespeed.gpg > /dev/null # apt: deb [signed-by=/usr/share/keyrings/modpagespeed.gpg] ...
sha256sum --check --ignore-missing SHA256SUMS # release assets downloaded from GitHub
On dnf, the repository file sets gpgcheck=1 against the same key.
Hosting partner program
For providers running mod_pagespeed 2.1 across a multi-tenant fleet: Priority-level support for your second- and third-line team, plus cPanel/EA4 and distribution-channel upkeep. One agreement per provider, unlimited hosted domains.
The partner program →Consulting
When the question is your site rather than the software, We-Amp's consulting practice takes over: a fixed-price performance and configuration audit delivered as a written report, and longer engagements on caching and reverse-proxy infrastructure.
Consulting at we-amp.com →Already a customer?
IISpeed and mod_pagespeed 1.x license holders move to mod_pagespeed 2.1 at no cost, and paid terms are honored to expiry. To transfer a license or renew into a support subscription, use the contact form with the topic “IISpeed license transfer” and include the order number or the email address the license was bought under.
How to reach us
The contact form, or email info@we-amp.com. We reply within one business day (CET). Vulnerability reports go to security@modpagespeed.com under the security policy, never to the commercial address.
Support questions
Does a subscription change what the software does?
No. Every install runs the same software under the Apache License 2.0, with every optimization enabled by configuration, not by a plan. A subscription changes who answers when you need help, and for Priority and Enterprise, which repository your packages come from.
Who answers a ticket?
The engineers who build mod_pagespeed 2.1. There is no first-line desk in front of them: the person reading your ticket can read the code path behind it.
When do you answer?
On CET business days. There is no 24x7 desk. Response targets by severity, including any out-of-hours terms for Enterprise, are stated in your quote.
How do security updates reach me?
Everyone gets security fixes as regular releases through the channel they installed from, listed under Security in the release notes. Subscribers get advance notice, with a delivery window stated in their quote. Priority and Enterprise subscribers receive the update through the subscriber repository before the public release.
What counts as a production server?
A server that serves production traffic with the module or the optimizer worker. You declare the band (up to 5, up to 25, or more) when you ask for a quote; there is no metering and the software never reports a count.
What does "hardened" mean for the builds?
The same source, built through a hardened build pipeline and delivered through the subscriber repository, with security updates ahead of the public release. Enterprise adds custom build targets. The artifacts carry the same Apache License 2.0 as the standard packages. See hardened builds.
Can I verify the standard packages without a subscription?
Yes. The apt and yum repositories are GPG-signed, every release asset is listed in SHA256SUMS, and the SPDX SBOM is published in the source tree. The four-line recipe on this page checks the key and the checksums.
What happens if a subscription lapses?
Nothing happens to your deployment. The software keeps running and you keep upgrading from the public channels. Write to info@we-amp.com when you want to pick it up again.