In conjunction with

Software Supply Chain Evidence Store and Governance for Regulated Engineering Teams

Chainloop operates a software supply chain evidence and governance platform aimed at security, compliance, and platform engineering teams inside regulated enterprises. Co-founders Miguel Martinez and Daniel Liszka previously led the team behind VMware Tanzu Application Catalog, Bitnami, and Kubeapps, and built the company around a stated mission to automate trust for the software supply chain. The product targets organizations that must prove how software was built, and increasingly how AI-assisted code reaches production.

The architecture separates two audiences. Security teams define workflow contracts and Rego-based policies in a control plane that declares what evidence each pipeline must produce; developers wire a CLI into existing CI/CD jobs, which captures SBOMs, SARIF scans, VEX documents, test reports, and build artifacts along with Git context. An attestation engine evaluates the submitted evidence against policy, signs it using Sigstore and in-toto conventions, and files it into content-addressable storage as a linked provenance graph.

Differentiation rests on neutrality and data control: the core is Apache 2.0 licensed, evidence can be stored in the customer's own S3, GCS, or Azure Blob buckets, and signing can use Sigstore or an organization's existing PKI through AWS KMS or Keyfactor. Rather than replacing scanners, the platform aggregates their output, supporting CycloneDX and SPDX SBOMs, OpenVEX, SARIF, and SLSA provenance, with integrations into Dependency-Track and GUAC. Recent positioning centers on governing AI-generated code.

Market Segments:

Application SecurityContinuous Compliance Automation (CCA)

Categories:

SSCSCompliance AutomationGovernance