Anchore
Anchore is a private software supply chain security company that sells an SBOM-powered container security platform (Anchore Enterprise) — combining SBOM management, vulnerability scanning, and policy-driven compliance automation — to Fortune 500 enterprises and U.S. federal/defense agencies including the DoD and Air Force.
- Company typePrivate
- Founded2016
- HeadquartersSanta Barbara, United States
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
What Anchore does
Anchore, Inc. is a private software company founded in 2016 and headquartered in Santa Barbara, California (with a UK regional office in London), that builds an SBOM-powered software supply chain security platform for enterprises and government agencies operating containerized workloads. The core product, Anchore Enterprise, is composed of three integrated modules: Anchore SBOM (ingestion, normalization, and lifecycle management of Software Bills of Materials in SPDX, CycloneDX, and Syft formats), Anchore Secure (continuous vulnerability, malware, and secret scanning with false-positive/negative mitigations), and Anchore Enforce (policy-as-code compliance automation with pre-built policy packs for FedRAMP, NIST 800-53/190/171/218, DISA STIG, CMMC Level 2, DORA, and CIS Docker benchmarks). The platform is anchored on the company's open source projects — Syft (SBOM generation), Grype (vulnerability scanning), and Grant (license checking) — and includes a 'Bring Your Own SBOM' capability launched in May 2025 plus runtime inventory across EKS, ECS, AKE, GKE, and OpenShift clusters.
Anchore is named as a required scanning tool in the DoD Container Hardening Guide and is IL-6 ready for air-gapped classified environments, with availability through the DoD ESI Master License Agreement. Named customers include Cisco, eBay, NVIDIA, GitHub, GitLab, Infoblox, DreamFactory, the U.S. Department of Defense, and the U.S. Air Force (Platform One). The company earns revenue primarily through quote-based annual Anchore Enterprise subscriptions (Anchore SBOM is included in all subscriptions), supplemented by professional services under Essential and Complete Success Plans.
Commercially, Anchore operates a hybrid go-to-market model: direct enterprise field sales with Request a Demo and Free Trial CTAs for Fortune 500 and federal customers, combined with product-led growth through its open source Syft and Grype CLIs that feed enterprise upgrade pipelines, plus channel partners, system integrators, and resellers for federal and government deployments. The company has raised approximately $41M across multiple rounds (most recent $20M Series 2 from SignalFire in January 2020 and a $10M Espresso Capital facility in October 2022) and was recognized in 2026 as one of the top 10 container security firms by Inventiva. Notable recent moves include a strategic partnership with Chainguard announced in September 2025 and ongoing platform enhancements aligned with FedRAMP, EU CRA, and DORA regulatory timelines.
Anchore firmographics
Firmographics- Name
- Anchore
- Legal name
- Anchore, Inc.
- Website
- https://anchore.com
- Company type
- Private
- Founded year
- 2016
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- Anchore is a private software supply chain security company that sells an SBOM-powered container security platform (Anchore Enterprise) — combining SBOM management, vulnerability scanning, and policy-driven compliance automation — to Fortune 500 enterprises and U.S. federal/defense agencies including the DoD and Air Force.
- Ownership category
- akta.pro rank
Anchore industry classification
Industry- Product category
- Software Supply Chain Security
- NAICS
- Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (518)
- SIC
- Services-Computer Programming Services (7371)
- akta.pro primary industry
- Intrusion Detection & Prevention Systems (IDS/IPS) (HDAFAFAD)
- akta.pro secondary industry
- Intrusion Prevention/Detection Systems (IPS/IDS) (HDADABAH)
Keywords
Where Anchore is headquartered
LocationHeadquarters
- HQ city
- Santa Barbara
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
Anchore business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Anchore Enterprise Subscription: Enterprise software subscription model for the full platform including SBOM management, vulnerability scanning, and compliance enforcement. Anchore SBOM is included in all Anchore Enterprise subscriptions.
- Professional Services: Technical Account Manager (TAM) and Technical Account Engineer services, Essential Success Plan and Complete Success Plan for onboarding and support.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise subscription with full platform access |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels7 records
Anchore product offering
Product offeringCore offering
Anchore sells Anchore Enterprise, an SBOM-powered software supply chain security platform that ingests and analyzes Software Bills of Materials and continuously scans container images for vulnerabilities, malware, and secrets. The platform enforces policies for regulatory frameworks (FedRAMP, NIST, DISA STIG, CIS, CMMC, DORA) from build to runtime, anchored by Syft and Grype open source tools.
Product overview
Anchore offers Anchore Enterprise, the first SBOM-powered software supply chain management platform. The platform consists of three integrated modules: Anchore SBOM (for SBOM generation, ingestion, and management), Anchore Secure (for vulnerability scanning, malware detection, and secret scanning), and Anchore Enforce (for compliance automation and policy enforcement). The platform also includes Anchore Federal for government deployments. Anchore maintains a portfolio of open source tools including Syft (SBOM generation), Grype (vulnerability scanning), and Grant (license checking), which form the foundation for the enterprise platform.
Differentiator
Problem solved
Functional benefit
Brands
- Syft: Open source CLI tool for generating Software Bill of Materials (SBOM) from container images and filesystems.
- Grype
- Grant
- Anchore Enterprise
- Anchore SBOM
- Anchore Secure
- Anchore Enforce
- Anchore Federal
Products and services
- Anchore Enterprise SBOM-powered software supply chain management platform for continuous security and compliance; centralizes internal and external SBOMs to track software supply chain issues, ensures security of software products, and embeds security and compliance checks across the development lifecycle. Sold to enterprise customers (Fortune 500 and government).
- Anchore SBOM Enterprise SBOM analysis and compliance module that ingests SBOMs in SPDX, CycloneDX, and Syft native formats, normalizes and deduplicates them, organizes them in Application and Version contexts, and applies searchable annotations with key/value pairs. Included with Anchore Enterprise subscriptions.
- Anchore Secure Container security scanning module that automates scanning of container images, source code, and filesystems for vulnerabilities, malware, and secrets; provides continuous vulnerability monitoring, ecosystem coverage, false positive/negative mitigations, and runtime context across Kubernetes clusters.
- Anchore Enforce Compliance automation module that enforces policies at every stage of the SDLC; provides FedRAMP, NIST, DISA, and DoD policy packs, flexible reporting, runtime context for production compliance verification, license management, and Dockerfile controls.
- Anchore Federal Public sector deployment of Anchore Enterprise designed for air-gapped environments meeting DoD IL-6 and FIPS requirements; supports NIST compliance tools and federal policy packs for DoD, Air Force Platform One, DISA, and other federal agencies.
- Syft Open source CLI tool for generating Software Bills of Materials from container images and filesystems; produces high-fidelity SBOMs with dependencies, file metadata, licenses, and content in JSON, SPDX, and CycloneDX output formats. Forms the SBOM engine inside Anchore Enterprise.
- Grype Open source CLI vulnerability scanner for container images, SBOMs, and filesystems; produces lists of known vulnerabilities with OS and language-specific package matching across multiple sources. Forms the vulnerability scanning engine inside Anchore Enterprise.
- Grant Open source CLI tool and Go library for checking software licenses in container images, SBOMs, and filesystems; supports license policy enforcement as part of Anchore's open source ecosystem.
Quantifiable outcome
- Vulnerability response time reduced from weeks to minutes with SBOM-based approach
- +2 more outcomes
Companies that use Anchore
Customer profileNamed customers12 records
Segments4 records
Ideal customer profiles3 records
Anchore technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration20 records
AI capability2 records
Feature9 records
Anchore partnerships and signals
Strategic signalPartnerships
Five partnerships are on record, tiered core and flagship.
- ChainguardcoreAnchore and Chainguard partnered to deliver next-generation supply chain security solutions, strengthening software delivery integrity and protection against threats. The partnership aims to enhance supply chain security through combined solutions.
- GitHubcoreGitHub Actions integration with Anchore Container Scan enables developers to build security directly into their workflows. Anchore is featured in GitHub Actions marketplace.
- GitLabcoreGitLab integration with Anchore scanning technology helps joint customers increase speed to mission delivery and reduce risks associated with software development.
- U.S. Department of DefenseflagshipAnchore is named as a required scanning tool in the DoD Container Hardening Guide and Container Image Creation and Deployment Guide. Key component for DoD Iron Bank container security. Available via DoD ESI Master License Agreement.
- U.S. Air Force (Platform One)flagshipCollaboration on container hardening process for Platform One DevSecOps initiative. Anchore's strong understanding of DoD goals translated into strong support for adoption of modern DevSecOps practices.
Scale indicators2 records
Recent moves6 records
Expansion highlights6 records
Anchore competitors and assessment
Company assessmentDirect peers
- Sonatype: SBOM and software supply chain security vendor (Nexus platform) — directly comparable to Anchore's SBOM-centric value proposition and enterprise compliance focus.
- Aqua Security: Direct competitor in container and cloud-native application security, offering vulnerability scanning, runtime protection, and compliance for Kubernetes environments — the closest functional competitor to Anchore Enterprise.
- Snyk: Developer security platform with strong container image scanning and SBOM capabilities alongside SCA, IaC, and code security; overlaps Anchore in container vuln scanning and enterprise DevSecOps workflows.
- Cycode: Software supply chain security platform covering SDLC, secrets, SCA, and container security with a focus on pipeline integrity — comparable in positioning to Anchore's supply-chain narrative.
- Chainguard: Supply chain security company focused on hardened, minimal container base images and recently partnered with Anchore — overlapping in software supply chain security messaging and buyer base.
- Mend (formerly WhiteSource): SCA and SBOM management vendor serving enterprise development teams — comparable to Anchore SBOM and Anchore Secure for open source dependency and container vulnerability management.
Broad incumbents
- JFrog: Binary repository and DevSecOps platform with security scanning (Xray) and SBOM capabilities — adjacent competitor for enterprise buyers consolidating software supply chain tooling.
- Wiz: Cloud security platform with growing container and workload protection capabilities; an enterprise incumbent that increasingly overlaps Anchore's runtime/Kubernetes visibility narrative.
- Prisma Cloud (Palo Alto Networks): Broad CNAPP from Palo Alto Networks (incorporating ex-Twistlock) covering container security alongside CSPM, CIEM, and CWPP — competes head-on with Anchore at enterprise tier but as part of a much larger platform.
- GitHub Advanced Security: GitHub's bundled code, dependency, and container scanning offering; competes with Anchore for developer-led adoption and is already integrated via Anchore's GitHub Actions presence.
Market position
Strengths5 records
Weaknesses4 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
Anchore social profiles
Digital presenceAnchore compliance and trust
Trust signalCompliance11 records
Anchore financial estimates
Financial estimateRevenue estimate
Valuation estimate
Anchore leadership team
Management profileNumber of profiles
Profiles8 records
Anchore funding detail
Funding detailFunding overview
Funding rounds6 records
Investors3 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Anchore M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Anchore
What does Anchore do?
Anchore sells Anchore Enterprise, an SBOM-powered software supply chain security platform that ingests and analyzes Software Bills of Materials and continuously scans container images for vulnerabilities, malware, and secrets. The platform enforces policies for regulatory frameworks (FedRAMP, NIST, DISA STIG, CIS, CMMC, DORA) from build to runtime, anchored by Syft and Grype open source tools.
Is Anchore a public or private company?
Anchore is a private company. It is classified as venture growth investor backed and is currently operating.
When was Anchore founded?
Anchore was founded in 2016. It employs 51 to 100 people.
Where is Anchore based?
Anchore is headquartered in Santa Barbara, United States, in the North America region.
How does Anchore make money?
Two revenue lines are on record. Anchore Enterprise Subscription is the primary driver. The others are professional Services.
Who are Anchore's main competitors?
Direct peers on record are Sonatype, Aqua Security, Snyk, Cycode, Chainguard and Mend (formerly WhiteSource). Broad incumbents are JFrog, Wiz, Prisma Cloud (Palo Alto Networks) and GitHub Advanced Security.
Does Anchore have an API?
Yes. Every feature and operation in Anchore can be instrumented using an API call. The API enables creation of a 100% automated and integrated 'headless' solution with flexibility to define preferred security workflows. Anchore Enterprise provides comprehensive API access for all platform operations. Developer documentation is at docs.anchore.com.
What industry is Anchore in?
Anchore's product category is Software Supply Chain Security. Its primary akta.pro industry code is HDAFAFAD, Intrusion Detection & Prevention Systems (IDS/IPS), with a secondary code of HDADABAH, Intrusion Prevention/Detection Systems (IPS/IDS). Its NAICS code is 518 and its SIC code is 7371.