The Control Plane
for Trusted Software Delivery
Our vision is to automate trust for Software Supply Chain, helping companies make faster decisions, reduce security risks, achieve compliance, and save time and money. Software releases and audits will take hours rather than weeks.
Discover
The Chainloop Platform
Implement
Policy as Code
with Ease
Automate and streamline compliance and security management. Create a central repository and manage all your policies effectively across various domains, including cloud infrastructure, DevSecOps tools, security, and compliance.
Track Compliance with a Centralized Dashboard
Stay on top of your compliance efforts with a clear, centralized dashboard. It gives you an easy way to see how your products and teams are meeting security and compliance standards.
SLSA
in a Box
Supply Chain Levels for Software Artifacts (SLSA) defines standards and controls to prevent tampering and improve the integrity of your Software Supply Chain. With Chainloop, you can reach SLSA v1.0 Build Level 2 by leveraging your own content addressable storage, the Sigstore suite, and the in-toto attestation format.
Declarative and Versioned
Contracts
Operators have full control over what metadata must be received as part of the attestation and the environment where these workflows must be executed. This enables an easy and maintainable way of propagating and enforcing requirements downstream to your organization.
Enforce Quality Control Gates
Implement quality control gates and effortlessly add them to all your CI/CD pipelines to ensure your software meets security and compliance standards. Adding quality control for your SBOMs and other metadata has never been easier.
Curated Library of Open Source Tools
Our curated library of open-source DevSecOps tools is continuously updated, so you don’t have to worry about maintaining, downloading, or updating them yourself. Use tools like Syft, ZAP, Trivy, and more across all your CI/CD pipelines.
Leverage Open Source for Flexibility
Chainloop's core components, including the evidence store and control plane, are open source, offering flexibility and avoiding vendor lock-in—key requirements for many organizations.
Build Your
Single Pane Of Glass
Create a centralized view of your entire Software Development Life Cycle (SDLC). Integrate various CI/CD and DevSecOps services across any cloud or platform. Consolidate software delivery metrics in one dashboard to simplify oversight and minimize distractions.
Trust Our Chainloop Platform
Chainloop is built with security in mind, and our platform is SOC2 Type 2 certified. As we continue to grow, we’ll be adding more certifications to ensure the safety and compliance of our platform. You can trust Chainloop with your most critical operations.
Get Context With
Chainloop Trust Hub
Chainloop helps you better understand your software development process by creating a single source of truth for all your supply chain events and metadata. You can link essential data points like team information, pipelines, and manual or automated workflows to get a complete picture of the process. Chainloop enables you to democratize this information in your organization so you can make better decisions. For example, you can confidently block a software artifact to ensure compliance or security.
Block
With
Confidence
Effortlessly implement control gates and raise security or compliance exceptions to the entire organization. Empower teams to confidently enforce security and compliance measures.
Instrument
Your Software Delivery
Enable visibility into your software supply chain by implementing monitoring, alerting, and SLOs.
Meet
Developers
Where they are
We offer native integrations with multiple CI/CD and SCM platforms like GitHub, GitLab, Jenkins, Dagger, and more. With Chainloop, developers get a jargon-free process to comply with the SecOps team's requirements. No need to learn in-toto, signing, SLSA, OCI, APIs, credentials, nada :)
Enterprise
Ready Features
Chainloop’s was born with Enterprise features in mind. From customizable Federated content addressable store to Role Base Access Control or Single Sign On.
Trusted Software Supply Chain
Evidence Store
Chainloop’s Open Source Evidence Store allows you to easily collect, attest, sign, and distribute your Software Supply Chain metadata, SBOMs, VEX, SARIF files, QA reports, and more.
With Chainloop, SecOps teams can, for each step in their SDLC, declare and enforce what pieces of evidence must be collected and what to do with them by leveraging third-party integrations such as Dependency-Track for SBOM analysis or a blob storage/OCI registry.
On the other hand, developer teams do not need to become security experts. The attestation crafting tool will guide them with guardrails and a familiar developer experience.
You can think of Chainloop as an API for your organization’s Software Supply Chain that both development and SecOps teams can use to interact effectively.
That way SecOps teams now have control over their organization’s Software Supply Chain security compliance, observability and standardization implementation efforts.
Growing Number Of
Integrations
Chainloop offers a pluggable integrations framework that operators can use to extend Chainloop functionality by setting up third-party integrations on your attestation metadata. Integrations can range from notifications via a Slack message, storing the attestation to an AWS S3 blob storage, or sending a Software Bill Of Materials (SBOMs) to a third-party service, such as Guac or Dependency-Track.
Use
Your Cloud
Chainloop is cloud agnostic. We simplify deployment on AWS, Azure, and Google Cloud with support for multiple cloud managed services.
Use Cases
SOFTWARE DELIVERY VISIBILITY
Gain comprehensive visibility across all your workflows.
AUTOMATED COMPLIANCE
Automate compliance with our declarative contracts.
SUPERCHARGED COLLABORATION
Collaborate seamlessly with all your teams
on software delivery.
ENTERPRISE EVIDENCE STORE
Gather and centralize software supply chain metadata and pieces of evidence for SOC 2.
SBOM AND *VEX
Operationalize SBOMs software bill of materials.
OPEN SOURCE CONSUMPTION
Consume Open Source in a trustworthy way.
VULNERABILITY MANAGEMENT
Simplify vulnerability management for enhanced security.
Control Gates
Establish control gates and connect automated and human-driven processes.
Frequently asked questions.
Is Chainloop Open Source?
Yes, Chainloop source code has been Open Sourced and can be found here! 🎉
Can I run my own instance of Chainloop end to end?
Yes, please refer to this guide.
I am using neither GitHub Actions nor GitLab, can I still use Chainloop?
Yes, Chainloop is runner agnostic, which means that you can run the attestation anywhere, including your laptop! That said, there are benefits for using one of our supported runner types. We plan on supporting more CI vendors so your is not supported yet, please contact us with your preference and we will get back to you.