Chainloop Open Source
Our vision is to automate trust for Software Supply Chain, helping companies make faster decisions, reduce security risks, achieve compliance, and save time and money. Software releases and audits will take hours rather than weeks.
Trusted Software Supply Chain
Evidence Store
Chainloop’s Open Source Metadata Evidence Store allows you to easily collect, attest, sign, and distribute your Software Supply Chain metadata, SBOMs, VEX, SARIF files, QA reports, and more.
With Chainloop, SecOps teams can, for each step in their SDLC, declare and enforce what pieces of evidence must be collected and what to do with them by leveraging third-party integrations such as Dependency-Track for SBOM analysis or a blob storage/OCI registry.
On the other hand, developer teams do not need to become security experts. The attestation crafting tool will guide them with guardrails and a familiar developer experience.
You can think of Chainloop as an API for your organization’s Software Supply Chain that both development and SecOps teams can use to interact effectively.
That way SecOps teams now have control over their organization’s Software Supply Chain security compliance, observability and standardization implementation efforts.
Block
With
Confidence
Effortlessly implement control gates and raise security or compliance exceptions to the entire organization. Empower teams to confidently enforce security and compliance measures.
Instrument
Your Software Delivery
Enable visibility into your software supply chain by implementing monitoring, alerting, and SLOs.
Meet
Developers
Where they are
We offer native integrations with multiple CI/CD and SCM platforms like GitHub, GitLab, Jenkins, Dagger, and more. With Chainloop, developers get a jargon-free process to comply with the SecOps team's requirements. No need to learn in-toto, signing, SLSA, OCI, APIs, credentials, nada :)
Enterprise
Ready Features
Chainloop’s was born with Enterprise features in mind. From customizable Federated content addressable store to Role Base Access Control or Single Sign On.
SLSA
in a Box
Supply Chain Levels for Software Artifacts (SLSA) defines standards and controls to prevent tampering and improve the integrity of your Software Supply Chain. With Chainloop, you can reach SLSA v1.0 Build Level 2 by leveraging your own content addressable storage, the Sigstore suite, and the in-toto attestation format.
Declarative and Versioned
Contracts
Operators have full control over what metadata must be received as part of the attestation and the environment where these workflows must be executed. This enables an easy and maintainable way of propagating and enforcing requirements downstream to your organization.
Growing Number Of
Integrations
Chainloop offers a pluggable integrations framework that operators can use to extend Chainloop functionality by setting up third-party integrations on your attestation metadata. Integrations can range from notifications via a Slack message, storing the attestation to an AWS S3 blob storage, or sending a Software Bill Of Materials (SBOMs) to a third-party service, such as Guac or Dependency-Track.
Use
Your Cloud
Chainloop is cloud agnostic. We simplify deployment on AWS, Azure, and Google Cloud with support for multiple cloud managed services.
Use Cases
SOFTWARE DELIVERY VISIBILITY
Gain comprehensive visibility across all your workflows.
AUTOMATED COMPLIANCE
Automate compliance with our declarative contracts.
SUPERCHARGED COLLABORATION
Collaborate seamlessly with all your teams
on software delivery.
ENTERPRISE EVIDENCE STORE
Gather and centralize software supply chain metadata and pieces of evidence for SOC 2.
SBOM AND *VEX
Operationalize SBOMs software bill of materials.
OPEN SOURCE CONSUMPTION
Consume Open Source in a trustworthy way.
VULNERABILITY MANAGEMENT
Simplify vulnerability management for enhanced security.
Control Gates
Establish control gates and connect automated and human-driven processes.
Upcoming
Chainloop Platform
Frequently asked questions.
Is Chainloop Open Source?
Yes, Chainloop source code has been Open Sourced and can be found here! 🎉
Can I run my own instance of Chainloop end to end?
Yes, please refer to this guide.
I am using neither GitHub Actions nor GitLab, can I still use Chainloop?
Yes, Chainloop is runner agnostic, which means that you can run the attestation anywhere, including your laptop! That said, there are benefits for using one of our supported runner types. We plan on supporting more CI vendors so your is not supported yet, please contact us with your preference and we will get back to you.