Chainguard
Chainguard builds secure-by-default container images, libraries and VMs to secure the open source software supply chain for engineering teams.
Chainguard builds secure-by-default container images, libraries and virtual machine images, with the stated aim of securing the open source software supply chain for engineering teams. Founded in 2021, the company works across software supply chain security, container security, vulnerability management and zero-CVE hardening, secure build pipelines and cloud-native infrastructure including Kubernetes.
Its product line comprises Chainguard Container Images, described as the largest catalog of minimal, zero-CVE container images; Chainguard Libraries and Chainguard VMs, both secure-by-default; and Chainguard Factory, a continuously operating build system that builds and updates thousands of artifacts. The company says its approach eliminates around 1,000 hours of engineering toil per year per customer, and that customers have used it to achieve FedRAMP High authorization. Its stated position is that engineering teams should not have to choose between speed, security and scalability.
The four founders - Dan Lorenc, Kim Lewandowski, Matt Moore and Ville Aikas - built foundational open source projects including Kubernetes, Sigstore and Distroless at Google. Chainguard describes itself as mission-driven around the phrase "the safe source for open source", serious about the mission and playful about everything else, with a commitment to verifiably secure code and open source stewardship. The company serves software development and DevSecOps teams, cloud-native engineering organisations and the government and public sector.