Get started
If youre new to Chainloop, you can get started using the guides below.Quickstart
Get started with Chainloop in minutes.
Getting Started Guide
A step-by-step guide to will walk you through many of the Chainloop features.
Concepts
Learn about the key concepts of Chainloop
Deep dive Guides
Guides to help you get the most out of Chainloop.
Cyber Resilience Act (CRA)
Supply-chain Levels for Software Artifacts (SLSA)
FedRamp (soon)
Whats Chainloop?
Chainloop provides a centralized platform for artifact management, real-time visibility, and automated compliance. It bridges gaps between Developers, security, and compliance teams. Some of Chainloops pillars include. Central Evidence Store for SDLC: A single platform to centralize, connect, and validate any evidence or metadata from SBOMs and IaC validation reports to SAST, DAST results, and cloud security checks. The collection of data
[info]
Change Management: We offer a clear separation of concerns and communication channels between Dev, SecOps, and compliance teams, fostering seamless collaboration, communication, and productivity.
[info]
Visibility & Alerting: Real-time insights into SDLC security posture with proactive alerts.
[info]
Automated Compliance: Offer automated validation through customizable policies, frameworks, and requirements, reducing manual effort and improving accuracy for security and compliance.
[info]
How does it work?
With Chainloop, Security, compliance, and Risk management teams on the right, get a single pane of glass where they can define security and compliance policies, what evidence and artifacts they want to receive, and where to store them. On the left, developers are shielded from all this complexity by being given simple instructions on what to provide when instrumenting their CI/CD pipelines.
[info]
Metadata Generation
Developers produce key datasuch as build artifacts, SBOMs, vulnerability reports, and other compliance evidenceduring the software build process.
Easy Integration
DevOps integrate Chainloop into existing CI/CD pipelines using our CLI or integrations, automatically capturing all the necessary evidence with context (e.g., Git commit details and pipeline configuration).
Digital Signing
Every piece of metadata is digitally signed (using SLSA, in-toto, sigstore, or your own PKI such as AWS KMS or Keyfactor) to ensure it is tamper-proof and verifiable.
Centralized Storage and Validation
Signed data is pushed to our secure evidence store, where it is validated and organized into a comprehensive record.
- Graph-Based Provenance: Every item is connected in a traceable graph, ensuring complete visibility over the software lifecycle.
- Immutable Storage: Artifacts are signed and stored immutably, providing a robust audit trail.