Open Source DAM: Build From Scratch, Build on Nuxeo, or Buy?
We've heard a lot of our clients and prospects talk about software being democratized. A good team can build its own DAM or ECM on tried, tested, and trusted hosted services, shaped to its own workflow and ontology. MongoDB, Kafka and OpenSearch in front of a scalable, searchable repository, with the features we need and nothing we don't.
These are statements from large financial institutions, media companies, and insurers - our typical clients at Maretha Solutions. They are risk averse, and they carry a long list of security and compliance requirements for good reason.
We think they are right that the path is closer than ever. Code is cheaper to write than it has ever been, and tools like Claude Code and Codex have multiplied the pace of a skilled team. Our certified Anthropic architects help automate Nuxeo LTS upgrades for many teams, cutting project timelines by 10x or more.
But "build from scratch" is a narrower choice than it sounds. The stack a technical team wants to build is usually the stack Nuxeo already runs on, and Nuxeo is open source. So the question should not necessarily be to build or buy. It is which four paths fits your ontology, your governance, and your compliance list and the team you will still have in year ten. This is how we help clients decide, and where Maretha Solutions fits in.
The stack you'd build is the stack you'd buy
Nuxeo is MongoDB for the document store, Kafka for streams and bulk processing, Elasticsearch or OpenSearch for search, and S3 for binaries. That is the from-scratch shopping list, item for item.
Our own demo environment runs exactly this: MongoDB 8, OpenSearch 2 and S3 on Docker Compose. Our https://demo.maretha.io is public - let us know if you want a login to give it a test drive.
So a team starting from scratch will likely go with a similar tested and proven architecture. It is choosing to rewrite everything that sits between those services and a working repository: the content model, security, versioning, audit, renditions, workflow, and the rest of the checklist. The stack is the easy part. Nuxeo has been building the part above it for nearly twenty years, and we have been working inside it since 2007. It is what all modern content repositories are based on - even those claiming to be "AI Native" - which they are, and which Nuxeo is as well.
Is Nuxeo open source?
Yes. The Nuxeo Platform source is public on GitHub under the Apache 2.0 license. You can build it, run it and change it.
What Hyland sells is everything that makes an enterprise comfortable running it: LTS releases with hotfixes, Nuxeo Studio for configuration, support with an SLA, Nuxeo Cloud if you would rather not host, and a roadmap you can plan around. We covered the current roadmap from Hyland CommunityLIVE in this post.
That split is the whole decision. If your organization needs a vendor to call at 2 a.m., needs hotfixes without owning the build pipeline, or needs a security questionnaire answered by a company with a logo, the subscription is the price of those things. If you have acess to a team that already knows Kafka and OpenSearch and patches them on its own schedule, open source Nuxeo is a viable and real option.
Four ways to get a DAM
Every client conversation we have about DAM lands on one of four paths. The names matter, because "build" and "buy" each cover two of them. Gartner calls the category content services platforms. Our clients say DAM and ECM, so we will too.
- From scratch on primitives. Managed MongoDB, Kafka, OpenSearch and S3, with your team writing the repository, the APIs and the UI above them. Full control, and full ownership of everything. This is what people mean by a headless DAM when they build it themselves.
- Open source Nuxeo, self-run. The same primitives plus the platform code, built and operated by you, with no subscription cost. You get the content model, security, versioning, audit, renditions and workflow on day one.
- Nuxeo with a Hyland subscription. The same platform, self-hosted or on Nuxeo Cloud, with LTS builds, Studio, support. This is where most of our regulated clients land.
- A commercial cloud platform. Orange Logic for enterprise DAM, Vertesia for governed processes with agents in the loop, Sanity for headless structured content. Fastest to value when the product's model fits in well with yours.
The layer above the stack
Whatever path you pick, this is the list you have to cover before a media organization, bank, or an insurer will put production content in it.
- Content model with schemas, facets and versioning
- Permissions with inheritance, and security policies that override them
- Audit log on every change, queryable and exportable
- Retention and legal hold
- Renditions: thumbnails, PDF, video transcoding, Office conversion
- Metadata extraction: EXIF, IPTC, XMP, OCR
- Full-text search that respects permissions on every hit
- Workflow for review and approval
- Bulk operations that survive restarts across hundreds of millions of documents
- Blob storage abstraction with more than one backend and a CDN in front
- SSO through SAML or OIDC
- Rights, embargoes and expiry on assets
Then the part that isn't a feature at all. A security review board wants evidence: SOC 2 and PCI-DSS artifacts, pen test findings and their remediation, disaster recovery with a stated RPO and RTO, encryption at rest and in transit with key management they can audit. Build from scratch and your team produces it, and keeps producing it every year.
That is the hidden cost of an in-house build. Not writing the features but proving them.
Three clients, three answers.
A bank with a security review board. The board does not care how elegant the stack is. It wants a vendor's SOC 2 report and someone to hold accountable. That lands on the Hyland subscription or a commercial platform, with custom work on top for the parts the bank actually cares about.
An insurer with retention rules. Retention and legal hold are not optional and not simple. Building them from scratch and defending them in an audit is the single best argument against the first path for this client.
A media company with a custom ontology at volume. Tens of millions of assets, a taxonomy nobody else has, and a platform team or service provider that has the experience needed to run containerized services. These are the clients where open source Nuxeo or a focused from-scratch build is a serious conversation, and where AI coding tools change the math.
What AI coding tools change, and what they don't
Claude Code and Codex cut the cost of writing custom code on every one of the four paths. The gain is largest on the two where you write the most: from scratch and open source Nuxeo. Boilerplate, integrations, admin screens and the tests around them now land in a fraction of the time they took just two years ago.
Three things did not get cheaper. Knowing what to build. Producing the required evidence around it. Support and monitoring from a skilled ops team.
So AI moves the line. It does not erase it. It makes "a thin core on managed services" viable for teams that could not have staffed it two years ago. It does not make the internal review board go away. We are an Anthropic partner and we use these tools on every engagement, which is exactly why we are careful about what we claim for them.
How Maretha helps
We work on all four paths, and we do not have a platform to sell you. Our partners page says it plainly: we match the platform to the problem instead of forcing one stack onto every project.
- Deciding. An architecture assessment, or a second opinion on a plan you already have. We tell you which path fits your ontology, your compliance list and your team, and we show the work. See Advisory and Enablement.
- Building. New builds, migrations and the add-ons that fill the platform's gaps. We have worked on Nuxeo since 2007, carried billions of documents into it, and keep 325+ add-ons running in production. We are a Hyland partner, an Orange Logic Solution Partner and a Vertesia consulting partner. See Platform Engineering and the Maretha Marketplace.
- Running. If you don't have an answer to "who patches it in year six?" We run, patch, upgrade and tune the platform so your team does not have to. See Platform Operations.
- AI Document intelligence, search and agents that make it to production and hold up there. All of our certified AI engagments are purposely simple. We agree the target and the acceptance criteria up front, and you pay on delivery - after all the criteria is met or exceeded. See AI engineering.
- Public tooling. The tools we build for our own work live in Maretha Labs. Try our free agent builder for any Nuxeo work you may need Maretha Studio
FAQ
Is Nuxeo open source?
Yes. The Nuxeo Platform source is on GitHub under the Apache 2.0 license. Hyland sells LTS releases, hotfixes, Nuxeo Studio, support and Nuxeo Cloud on top of it.
Can you build a DAM with open source tools?
Yes, and the stack is settled: MongoDB, Kafka, OpenSearch and S3, which is also what Nuxeo runs on. The real work is not the stack. It's the content model, permissions, audit, retention, renditions, workflow and the compliance evidence around it.
What is a headless DAM?
A DAM that exposes its repository through APIs and leaves the user interface to you, so the same assets serve a website, an app and a print workflow. Nuxeo runs headless. A from-scratch build on managed services is headless by definition. We can give you starting point for an Angular based WebUI for free in Maretha Studio right now.
Should a bank build or buy a DAM?
Usually buy, or build on top of a supported platform, because infosec needs an accountable party. Build the parts that are specific to the bank on top.
How long does it take to build a DAM from scratch?
Longer than the stack suggests, because the stack is a week and the layer above it is the project. We've implemented bespoke platforms in six months with the help of Claude code. On Nuxeo the same scope is a matter of weeks, because the platform layer already exists.
Where to start
If you are having this conversation inside your company, the fastest way to settle it is to put your ontology, your compliance list and your team on one page and score the four paths against them. We do that with our long standing clients and prospective clients in a short assessment.
Work with Maretha
Working through a content platform challenge?
Bring your platform, constraints and questions. Let us help you work through the approach.
Discuss your project ↗