Chainguard
Unicorn · $3.5BFounded 2021 · 745 employees on LinkedIn · 21 known investors
Find your way into Chainguard
616 people in our graph share verified history with the Chainguard team — schools, employers, funds. One of them is your warm intro.
Chainguard provides minimal, zero-CVE container images built from source with full build-time SBOMs, code signatures, and FIPS-validated cryptography to help vendors meet PCI DSS and other security compliance requirements. It targets engineering, security, and compliance teams handling cardholder data and other regulated software supply chains.
Also known as Chainguard, Inc.
Founders & leadership
Chainguard was founded in 2021 by Matt Moore, Dan Lorenc, and Ville Aikas.



Investors · 21
Also in the syndicate · 6
Funding
SEC filings, press & company announcements$356M disclosed across 1 of 6 rounds · 2023–2026
- $356MSeries DApr 2025 · 2 sources
IVP (lead), Kleiner Perkins (lead), Amplify, Datadog Ventures, Kerrest & Co., Lightspeed, Mantis, Redpoint, Salesforce Ventures, Sequoia, Spark
Source ↗ - Undisclosed amountSeries BNov 2023
Spark Capital (lead), Amplify Partners, Banana Capital, Sequoia Capital, The Chainsmoker’s Mantis VC
Source ↗
Source: company announcements and press reports — follow each round's link for the claim.
Valuation · disclosed
Disclosed eventsSource: SEC prospectus filings, and round valuations the company or its investors disclosed — follow each entry's link for the claim.
Company profile
researched Aug 2026Chainguard supplies open source software artifacts that are rebuilt from source, hardened and continuously updated so that customers can reduce vulnerabilities in their software supply chains. Its product lines span Chainguard Containers (minimal, distroless container images with a CVE remediation SLA), Chainguard Libraries (a guarded catalog of language libraries, including Java packages built from source), Chainguard VMs (virtual machine images rebuilt from source daily), Chainguard OS Packages, Chainguard Actions (CI/CD workflows), and Chainguard Agent Skills (a maintained catalog of hardened AI agent skills). All products are produced by what the company calls the Chainguard Factory, an internal build system described as SLSA L3-compliant and, in current messaging, "agentic," which the company says builds, patches, tests and hardens more than 13,000 packages and git repositories [0][3][6].
The company positions its offering around compliance and vulnerability management outcomes: images shipped with SBOMs and provenance attestations, FIPS-validated variants, and solution pages targeting FedRAMP, PCI DSS, CMMC 2.0, SOC 2, CRA, NIS2, HIPAA and Essential Eight requirements, as well as golden image programs and public sector buyers [0][3]. Chainguard also maintains a public documentation and training property, Chainguard Academy, with migration guides, courses, and product changelogs [2], and a public image directory at images.chainguard.dev where free and commercial images are browsable [3].
Chainguard's stated framing has shifted toward AI-era risk: the website argues that AI-accelerated code generation and AI-assisted attacks expand the open source attack surface, and the company has launched Athena, described as an industry coalition to protect open source software from AI attacks [0][7]. Named customers across sources include Anduril, ANZ Bank, Appian, Canva, Checkmarx, Cyera, GitLab, Hewlett Packard Enterprise, MAN Energy Solutions, Oceaneering International, Snap Inc., Snowflake, Univar Solutions, VPBank, Wiz and Booz Allen [5][6][7]."]
Founding story
Chainguard was co-founded by Dan Lorenc (CEO), Matt Moore (CTO) and Ville Aikas; the founding team had worked on open source infrastructure and security projects including Kubernetes, Sigstore and Distroless. In an April 2025 post, CEO Dan Lorenc wrote that the company had been started three years earlier, on the belief that security and innovation should go hand in hand [4][6][7].
Business model
Chainguard sells subscription access to catalogs of hardened open source artifacts (containers, libraries, VMs, OS packages, CI/CD actions, agent skills) to enterprises, with a free tier of selected public images and paid commercial/FIPS tiers; a pricing page and "Get started free" motion are published alongside enterprise sales [0][3]. Revenue is recurring: the company reports ARR figures rather than one-off license sales [6][7].
Recurring subscription revenue (annual recurring revenue) from enterprise customers, including enterprise license agreements such as the one signed with Booz Allen Hamilton; free tiers exist for a subset of images [3][6][7].
Traction
Chainguard reports 424,000+ engineering hours saved and 106,000+ CVEs remediated for customers, a catalog spanning roughly 2,950 projects, 331,754 versions, 657,642 images and over 1.37 billion build manifests, and a 4.7 G2 rating [0][3][4]. Financially, ARR grew from about $5 million to $40 million over fiscal year 2025 (a 7x increase), with a stated plan to exceed $100 million in ARR before the end of fiscal year 2026; container image count grew from 400 to 1,400 over that year and customers for the Containers product surpassed 150 [6][7]. In mid-2024 the company reported a 5x year-over-year increase in customer base and a 175% ARR increase in the first six months of that fiscal year [5].
Latest developments
Recent announcements include the launch of Athena, an industry coalition to protect open source software from AI attacks, with subsequent additions of new coalition members; availability through AWS Security Hub Extended as a supply chain partner; new product lines for OS Packages, Actions and AI Agent Skills; RHEL 9 and RHEL 10 RPM support in Chainguard OS and joining FINOS; partnerships with Upwind and Endor Labs; Gartner Magic Quadrant Leader recognition for Software Supply Chain Security; and an enterprise license agreement with Booz Allen Hamilton [0][6][7].
▸Full profile — market position, technology, go-to-market, geography, history, risks & controversies
Market position
Chainguard describes itself as the trusted/safe source for open source and was named a Leader in the inaugural 2026 Gartner Magic Quadrant for Software Supply Chain Security, according to its newsroom items; investors have described it as defining a new category in software supply chain security [6][7].
Rather than scanning and patching after the fact, Chainguard rebuilds open source from source in a controlled, SLSA L3-compliant factory and ships minimal images with a remediation SLA, aiming for near-zero CVE counts; the company cites averages of 97.6% CVE reduction, 85% attack surface reduction, and ~20-hour average remediation for critical CVEs [0][4].
Technology
Artifacts are rebuilt from source in the Chainguard Factory, described as SLSA L3-compliant, with daily rebuilds, minimal/distroless image construction, SBOMs and build provenance attestations, FIPS-validated cryptographic module variants, and GPU-optimized AI/ML images (e.g., PyTorch, TensorFlow, Conda, Kafka). The company reports the Factory covers over 13,000 packages and git repositories [0][2][3][5][6].
Go-to-market
Direct enterprise sales ("Talk to an expert") combined with a free self-serve entry point, a public image directory, developer education via Chainguard Academy and a community Slack, conference presence (e.g., RSA Conference 2025) and its own Assemble user event, plus channel and technology partnerships (ILS for federal registries, AWS Security Hub Extended, Upwind, Endor Labs, Datadog integration) [0][2][3][5][6][7]. The company has said it is scaling go-to-market operations and expanding in EMEA and APAC and in its federal business [5][7].
Enterprise engineering, platform and security teams, including Fortune 500 companies, cybersecurity vendors, financial institutions, and regulated/public sector and defense customers subject to FedRAMP, DoD and similar compliance regimes [3][5][7].
Geography
Headquartered in Kirkland, Washington, United States, with stated expansion of go-to-market operations into EMEA and APAC and a growing U.S. federal government business [5][7].
History
Chainguard began with its Containers product at the end of the software supply chain, growing its catalog from 400 to 1,400 images between 2024 and 2025. It raised a $140 million Series C in July 2024 at a $1.12 billion valuation, then a $356 million Series D in April 2025 at a $3.5 billion valuation, bringing total funding to $612 million. In 2025 it introduced Chainguard VMs and Chainguard Libraries at its Assemble event, and subsequently expanded to OS Packages, Actions and Agent Skills. Later company news items describe RHEL 9/10 RPM support in Chainguard OS and joining FINOS, partnerships with Upwind and Endor Labs, Gartner Magic Quadrant Leader recognition, and a Booz Allen Hamilton enterprise license agreement [0][5][6][7].
Risks & controversies
No controversies or risk disclosures are described in the available sources. Growth and revenue figures cited are company-reported, and forward-looking ARR targets (>$100 million by end of fiscal year 2026) were unverified projections at the time of publication [6][7].
Compiled by commissioned research from 8 cited public sources — announcements, filings, and press listed under research sources below.
Key figures
latest reportedCompany-reported or press-reported figures, each dated to when it was claimed — not independently audited.
Timeline · 12
launches, deals, and filingsChainguard reported being named a Leader in the inaugural Gartner Magic Quadrant for Software Supply Chain Security.
Athena is described as an industry coalition for orchestrated defense of open source software; Chainguard later announced the addition of new coalition members.
Round co-led by new investor Kleiner Perkins and existing investor IVP, with new investors Salesforce Ventures and Datadog Ventures and all existing investors participating; total raised reached $612 million.
$356M source ↗
Announced at the company's Assemble event: Chainguard VMs, minimal zero-CVE virtual machine images built from source, and Chainguard Libraries, a catalog of guarded Java language libraries built from source.
Series C led by Redpoint Ventures, Lightspeed Venture Partners and IVP, with participation from Sequoia Capital, Spark Capital and Mantis VC; total funding raised reached $256 million.
$140M source ↗
Kendra Mitchell, formerly Chief People Officer at Chief, became Chainguard's first VP of People; Caitlin Quinlan joined as SVP of Go-to-Market Strategy after roles at Gainsight, Mixpanel and MongoDB.
Suite of CPU and GPU-enabled hardened container images including PyTorch, Conda and Kafka, aimed at AI workloads.
Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.
In the news
▸Research sources · 8
primary sources listed
- Chainguardchainguard.dev · web
8 public sources were cited for this profile; the first-party ones are listed here.
Frequently asked questions
- What does Chainguard do?
- Chainguard builds hardened, minimal open source artifacts—containers, libraries, VMs, packages, actions—rebuilt from source.
- Who founded Chainguard?
- Chainguard was founded by Matt Moore, Dan Lorenc, Ville Aikas in 2021.
- Who are Chainguard's investors?
- Chainguard's investors include 137 Ventures, Alpha Partners, Amplify Partners, IVP (Institutional Venture Partners), Kleiner Perkins, Lightspeed Venture Partners, Mantis Capital, Redpoint Ventures and 7 more.
- How much funding has Chainguard raised?
- Chainguard has disclosed $356M raised across 1 of its 6 known rounds.








.png)