Skip to content

Chainloop

Open-source evidence store and policy platform for software supply chain attestations, SBOMs, and CI/CD compliance.

Visit Website ↗ + Add to Compare Claim This Company
52/100Incremental Innovator

Overview

Chainloop is an open-source platform that collects and stores supply chain evidence such as attestations, SBOMs, VEX documents, SARIF and QA reports from CI/CD pipelines, and evaluates it against policies.

The core is Apache 2.0 licensed. It was founded in 2023 by former VMware Tanzu/Bitnami engineers, and Thoughtworks lists it in its Technology Radar.

Innovation Matrix Assessment

Innovation Velocity 6/10

Rapid open-source development; a small team shipping steadily.

Operational Value 6/10

Centralizing pipeline evidence and policy gates supports audit and compliance workflows.

Market Momentum 3/10

Very small team and no funding found; Thoughtworks Radar mention is the main external signal.

Category Disruption 5/10

Evidence-store model separates compliance from scanner choice, a modest shift.

Real-World Efficacy 4/10

Used in documentation by Keyfactor; no independent test data found.

Enduring Relevance 7/10

SBOM/attestation requirements are expanding through regulation.

Why CISOs Should Care

Gives security and compliance teams one auditable record of what was built, scanned and approved.

What Makes It Different

Treats attestations as first-class stored evidence with policy enforcement, independent of scanners.

The Matrix Verdict

52/100 — INCREMENTAL INNOVATOR

Chainloop is an Incremental Innovator. A relevant open-source approach with strong timing, but early stage and limited adoption evidence.

Editorial Note: Claims vs. Verified Findings

Founding year and HQ are self-reported via LinkedIn; no funding data found. Thoughtworks Radar mention is independent.

Sources