ChainGuard: Securing Open Source: The Chainguard Journey to Safer Software Supply Chains.

Company profile
Company business details
Motivation to build the product
The founders were motivated by the increasing vulnerabilities associated with open source software and the need for enterprises to safely utilize these resources. They recognized that as open source software became more prevalent, it also became a target for security threats, prompting the need for a solution that could enhance security and integrity.Problem that their product solves
ChainGuard solves the problem of security vulnerabilities in the software supply chain, particularly those associated with open source software. The end users are organizations that rely on open source components for their software development. Solving this problem is crucial for these organizations to protect themselves from potential security threats and maintain compliance.Their unfair advantage
ChainGuard's unfair advantage lies in its focus on providing hardened and secured versions of open source packages, which enhances visibility and control over software components, thereby fostering trust in the software development process.Strategies
Pre-Launch (Product Development & MVP)
Leveraging AI for Automation
The company began experimenting with AI to automate various internal processes, such as generating functional tests and debugging suggestions. By using AI to handle 80-90% of routine tasks, the team could focus on more complex issues. This strategy involved integrating AI models to streamline workflows, reduce human error, and enhance productivity, ultimately leading to a more efficient development process.
Consulting Services First
Before building a product, Chain Guard's founders decided to start by offering consulting services to potential customers. This approach allowed them to establish relationships and understand the specific needs of their target market. They provided free advice and worked closely with clients to identify their pain points, which helped validate their business idea and build trust in the community. This strategy was particularly effective during the panic caused by the executive order on software supply chain security, as many companies were eager for guidance.
Launch Stage
Open Source Education and Awareness
The founder emphasized the importance of educating enterprises about the risks and responsibilities associated with using open source software. They highlighted the misconception that open source is inherently insecure and pointed out that many enterprises still include clauses in contracts that require warranties against the use of open source, despite purchasing open source solutions. This strategy involved engaging in conversations at industry events like RSA to raise awareness about the need for better inventory management and security practices when using open source software.
Dual Product Strategy
Upon launching, Chain Guard adopted a unique strategy by developing two distinct products simultaneously: Chain Guard Enforce and Chain Guard Images. This approach allowed them to test the market and see which product resonated more with customers. Enforce was aimed at security officers, while Images targeted developers. This dual strategy provided valuable insights into customer preferences and helped them pivot towards the more successful product, Images, which ultimately became their main focus.
Open-Source Software Foundation
Chain Guard established itself as a secure foundation for software development by providing guarded open-source software that is built from source and continuously updated. This approach helps organizations eliminate threats in their software supply chains. By focusing on transparency and security, Chain Guard resonates with customers who prioritize secure software development, allowing them to concentrate on their core competencies without the burden of security issues.
Learn more about ChainGuard

Dan Lorenc Talks Containers, Open Source, Startup Life, and More | CISO Breakfast Summit RSA 2024

Securing Open Source Software with Dan Lorenc, Co-founder & CEO of Chainguard

Container Security and AI: A Talk with Chainguard's Founder
