Skip to main content
S

Stacklok

Stacklok provides a supply chain security platform that ensures the integrity of source code repositories and open source dependencies by continuously enforcing security policies and verifying build environments. Their tools, Trusty and Minder, help developers assess supply chain risks and maintain secure software practices, reducing the likelihood of malicious code integration.

Seattle, United StatesFounded 2023401K+ followers
Updated 4 months ago

Funding

$17.3M raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.

Funding rounds are not available yet.

Founders

Product

Problem

Organizations face increasing threats from malicious code in open source dependencies, unsecured source code repositories, and compromised build environments, leading to potential secrets leakage, unauthorized code changes, and supply chain attacks. Current methods often lack continuous enforcement of security policies across the software development lifecycle.

Solution

Stacklok provides a supply chain security platform that enables organizations to proactively manage and mitigate risks throughout the software development lifecycle. The platform offers tools to continuously enforce security policies, verify build environments, and assess the supply chain risk of open source packages. By integrating with existing developer workflows, Stacklok helps developers make safer open source choices and allows security teams to maintain control through threat detection and automated remediation. The platform ensures the integrity of source code repositories and build artifacts, reducing the likelihood of malicious code integration and supply chain compromise.

Target Audience

The primary audience includes developers and security teams seeking to secure their software supply chain, as well as open source communities aiming to attest to their security practices.

Features

  • Trusty: A free web application that provides data and scoring on the supply chain risk of open source packages.
  • Minder: A supply chain security platform for building more secure software and attesting to security practices.
  • Policy enforcement across the software development lifecycle.
  • Integration with existing developer workflows and tools.
  • Automated remediation of inconsistencies.
  • Verification of build environment integrity and CI/CD workflows.
  • Operationalization of Sigstore for cryptographic signing and tamper-proofing of build artifacts.
This profile is AI-generated and may contain inaccuracies.