Chainguard is a Cloud & Application Security company founded in 2021 and based in Kirkland, United States. It has raised $892M in total funding, most recently a Series D in 2025 at a $3.5B valuation.
| Date | Stage | Amount | Valuation | Lead investors |
|---|---|---|---|---|
| Apr 23, 2025 | Series D | $356M | $3.5B | Kleiner Perkins, IVP |
| Jul 9, 2024 | Series C | $140M | $1.1B |
| Redpoint Ventures, Lightspeed Venture Partners, IVP |

An analysis piece on how open source software must evolve past its freewheeling origins toward security-hardened supply chain practices as enterprise adoption grows.

Qualys joins Chainguard's Athena coalition to validate exploitability of AI-discovered open-source vulnerabilities for prioritized patching.

Chainguard expands Athena to coordinate AI-discovered vulnerabilities, partner protections, and upstream fixes at scale.

Chainguard launches a Bugcrowd bug bounty program offering up to $200K in rewards for security researchers.

Chainguard launches Lens to monitor AI agents with real-time traces, evals, and safeguards.

Chainguard adds malware scanning and policy controls to its Repository; JavaScript Libraries reaches GA.
Chainguard Images are minimal, hardened container images built from source on Wolfi, a Linux distribution Chainguard maintains specifically for low-to-zero known vulnerabilities. Each image strips out unnecessary packages to shrink attack surface, ships with a software bill of materials and cryptographic signatures for provenance, and is rebuilt and patched continuously so customers pull images that stay at or near zero CVEs. Enterprises adopt them as drop-in replacements for common base images to clear vulnerability backlogs and satisfy supply-chain compliance requirements.
Extending the Images model beyond containers, Chainguard Libraries provides hardened, built-from-source language dependencies (such as Python and Java packages) drawn from a trusted, malware-screened supply, while Chainguard VMs deliver the same minimal, continuously-patched approach for virtual machine images. Together they let organizations source not just base images but the broader set of open-source artifacts their applications depend on from a single secure, signed, and provenance-tracked origin, reducing exposure to dependency-confusion and supply-chain attacks.
We don't have a live feed for this company's ATS. Their careers page has every open role.
View all careers ↗