
OpenSSL Library is critical infrastructure — the cryptography that secures much of the internet. A company stewarding something like that shouldn't answer only to itself, so the Corporation is governed by Members: individuals from the OpenSSL community who elect its Board and hold its leadership to account. They are the Corporation's keepers, not its owners — no shares, no profit, only responsibility.


Members elect the Board of Directors. The Board manages the Corporation and appoints its officers, who run the business day to day. So the people ultimately in charge of OpenSSL's commercial arm answer to a group whose only stake is the health of the OpenSSL Corporation itself.
Membership is by invitation, not application. Any individual who supports the organization's purpose may be nominated; new Members are admitted by the existing Members, approved by the Board, and affirm the Articles of Incorporation and By-Laws. Deliberately, this keeps membership in the hands of people the community already trusts.
The OpenSSL Project's commercial work (this Corporation) and its community-facing sister, the OpenSSL Software Foundation, are two independent organizations that deliberately do not share members: no individual may be a Member of both at the same time. Each is accountable to its own membership, so neither controls the other — a separation both organizations chose together.
The formal definition of membership is in Article IV of the By-Laws. Any individual supportive of the organization's purpose may be nominated; applicants are admitted by a quorum of Members, approved by the Board, and affirm the Articles of Incorporation and By-Laws. No individual may serve as a Member of the Corporation while simultaneously holding membership in the OpenSSL Software Foundation. The Members collectively elect the Board of Directors, which manages the Corporation and appoints its officers.
Open a ticket. Scope a FIPS submission. Pressure-test a post-quantum migration. Talk to the engineering team that wrote the code.