Open Source Security Foundation
Open Source Security Foundation (OpenSSF), a Linux Foundation project, is a non-profit that secures the open source software supply chain through a portfolio of free tools (SLSA, Sigstore, GUAC, OSPS Baseline, Scorecard, OSV.dev) and standards, serving maintainers, enterprises, and policymakers with active CRA regulatory engagement.
- Company typePrivate
- Founded2020
- HeadquartersSan Francisco, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Open Source Security Foundation does
Open Source Security Foundation (OpenSSF) is a community-driven, non-profit foundation operating as a project under The Linux Foundation, founded in 2020 and headquartered in San Francisco. Its mission is to secure the open source software supply chain that underpins modern digital infrastructure, serving open source maintainers, enterprise software consumers, security engineers, and policy makers across the US, EU, and globally. OpenSSF delivers an interoperable portfolio of graduated and incubating technical projects — including GUAC (a supply chain analytics graph), SLSA (a graduated supply chain integrity framework), Sigstore (artifact signing standard), OSPS Baseline (security baseline framework for CRA alignment), OpenSSF Scorecard, OSV.dev, in-toto/Witness, OpenVEX, and the Malicious Packages repository — alongside working groups in AI/ML Security, Supply Chain Integrity, Vulnerability Disclosures, and Global Cyber Policy. Newer additions include OSS-CRS and FuzzingBrain (AI-driven Cyber Reasoning Systems from the DARPA AIxCC challenge), Protobom/Bomctl/SBOMit (SBOM interoperability tooling), Gemara/AMPEL (compliance governance), and Gittuf (Git trust framework), with cross-cutting training (LFEL1001), publications, and the "What's in the SOSS?" podcast.
The foundation is funded primarily through multi-year corporate grants (notably $5M from Microsoft and Google in 2023 and $15M from an Anthropic/AWS/GitHub/Google/Microsoft/OpenAI coalition in 2026) and tiered membership dues (Premier and General). In March 2026, OpenSSF was approved as a CEN/CENELEC Liaison Organization, positioning it as a recognized authority shaping the EU Cyber Resilience Act and SBOM/vulnerability standards. Its go-to-market is community-led and event-driven (OpenSSF Community Days, Open Source SecurityCon co-located with KubeCon, working groups, the Ambassador Program), with policy engagement and partner-provided tooling (Kusari, Sigstore ecosystem) extending reach into enterprise CI/CD pipelines. All projects, training, and resources are free of charge.
Open Source Security Foundation firmographics
Firmographics- Name
- Open Source Security Foundation
- Legal name
- Open Source Security Foundation (OpenSSF) – operated under The Linux Foundation
- Website
- https://openssf.org
- Company type
- Private
- Founded year
- 2020
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Open Source Security Foundation (OpenSSF), a Linux Foundation project, is a non-profit that secures the open source software supply chain through a portfolio of free tools (SLSA, Sigstore, GUAC, OSPS Baseline, Scorecard, OSV.dev) and standards, serving maintainers, enterprises, and policymakers with active CRA regulatory engagement.
- Ownership category
- akta.pro rank
Open Source Security Foundation industry classification
Industry- Product category
- Open Source Security Software
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Prepackaged Software (7372), Services-Educational Services (8200)
- akta.pro primary industry
- Network Security Managed Services (Firewall/IDS/IPS/SASE) (BPAEADAG)
- akta.pro secondary industry
- Secure Software & DevOps Awareness (Secure Coding Basics) (EDABAGAN)
Keywords
Where Open Source Security Foundation is headquartered
LocationHeadquarters
- HQ city
- San Francisco
- HQ country
- United States
- HQ region
- North America
Offices5 records
Markets served
Open Source Security Foundation business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure, Others
Revenue model
- Membership dues: Recurring membership fees from General Members (e.g., Helvethink, Spectro Cloud, Quantrexion, Target Corporation, Thread AI) and Premier Members (e.g., Red Hat), the foundation's core funding mechanism as a Linux Foundation project.
- Grants and corporate donations: Multi-year grants from major tech companies fund projects such as Alpha-Omega: $5M from Microsoft and Google (2023), $12.5M from Anthropic, AWS, GitHub, Google, Google DeepMind, Microsoft, and OpenAI (March 2026), with AWS committing an additional $2.5M (total $15M). Anthropic separately committed USD 4M to open-source security foundations.
- Event sponsorship: Event-based sponsorship revenue from corporate underwriters (e.g., Honda as Gold sponsor of OpenSSF Community Day North America 2026).
- In-kind contributions and partner-provided tooling: Partners such as Kusari provide commercial-grade tools (Kusari Inspector) at no cost to OpenSSF projects, representing an in-kind contribution that supports adoption without direct revenue.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Pay-as-you-go | Free access to projects, tools, training, and guides |
| Other | Annual | Membership tiers (Premier, General) for organizations |
Go-to-market motion4 records
Distribution channels5 records
Marketing channels9 records
Open Source Security Foundation product offering
Product offeringCore offering
OpenSSF is a non-profit foundation that develops and curates a portfolio of open source security tools, frameworks, and standards—including GUAC, Sigstore, SLSA, OSPS Baseline, Scorecard, and the Malicious Packages repository—to secure the software supply chain. It also delivers free training programs, working groups, and policy engagement to coordinate industry, government, and maintainer communities around open source security.
Product overview
Open Source Security Foundation (OpenSSF) is a Linux Foundation-hosted foundation delivering a portfolio of interoperable technical projects, working groups, and standards under a platform-plus-modules architecture for securing open source software. Its flagship products include GUAC (supply chain analytics graph), OSPS Baseline (security baseline framework), Sigstore (signing standard with Cosign), and SLSA (graduated supply chain integrity framework). These are complemented by an extensive module ecosystem: OpenSSF Scorecard, Best Practices Badge, OpenSSF Security Insights, the SBOM Everywhere toolkit (Protobom, Bomctl, SBOMit), the Malicious Packages repository, the Alpha-Omega funding project, OSS-CRS and FuzzingBrain (AI-driven Cyber Reasoning Systems), in-toto/Witness and OpenVEX (provenance and exploitability), Gemara and AMPEL (compliance governance), Gittuf (Git trust), and the pyscg secure coding guide. Cross-cutting programs include the Free Training and Certification program (LFEL1001), the 'What's in the SOSS?' Podcast, public policy working groups (EU CRA, Global Cyber Policy), and an Ambassador Program. Working Groups coordinate efforts in AI/ML Security, Supply Chain Integrity, Vulnerability Disclosures, and Global Cyber Policy, allowing the foundation to act as a 'Skyway' connecting standards bodies (ISO/IEC, CEN/CENELEC, ETSI, BSI), regulators, foundations, and maintainers.
Differentiator
Problem solved
Functional benefit
Brands
- Alpha-Omega: Open source security project managed jointly by OpenSSF and the Linux Foundation; receives industry grant funding to secure open source software.
- SLSA (Supply-chain Levels for Software Artifacts)
- Sigstore
- GUAC
- OSPS Baseline (Open Source Project Security Baseline)
- Scorecard
- Best Practices Badge
Products and services
- GUAC (Graph for Understanding Artifact Composition) GUAC ingests SBOMs, provenance attestations, vulnerability reports, and OpenSSF Scorecard results into a continuously queryable graph model that delivers directed, actionable insights into the security of a software supply chain and supports dependency-aware risk analysis at scale.
- OSPS Baseline (Open Source Project Security Baseline) OSPS Baseline defines structured, tiered security requirements for open source projects that are aligned with international frameworks, standards, and regulations (including the EU CRA), serving as a starting point for security attestation by stewards and manufacturers.
- Sigstore Sigstore is a standard for signing, verifying, and protecting software, including Cosign for keyless artifact signing and verification using ephemeral certificates and BYOPKI, enabling tamper-evident software supply chains.
- SLSA (Supply-chain Levels for Software Artifacts) SLSA is a graduated project that safeguards artifact integrity across any software supply chain through a tiered framework of build provenance and integrity levels; it is recognized as a reference framework under the EU CRA and was applied to automotive In-Vehicle Infotainment development.
- OpenSSF Scorecard OpenSSF Scorecard provides automated checks on repository hygiene and secure development practices, producing a machine-readable score that assessors and tools (including GUAC) consume to evaluate project security posture.
- OpenSSF Malicious Packages Repository The Malicious Packages repository is the first open source system for collecting and publishing cross-ecosystem reports of malicious packages (dependency confusion, typosquatting, offensive security tooling, protestware), using the OSV format with MAL- prefixed identifiers integrated with OSV.dev, osv-scanner, and deps.dev.
- OSS-CRS (OpenSSF Cyber Reasoning Systems) OSS-CRS is an OpenSSF Sandbox Project showcasing AI agents that autonomously find and patch security vulnerabilities in open source repositories, built specifically for the LLM era.
- Alpha-Omega Project Alpha-Omega is a project managed by the Linux Foundation and the OpenSSF that invests directly in the security of open source software, including $5M continued funding from Microsoft and Google and a $12.5M grant coalition from Anthropic, AWS, GitHub, Google, Google DeepMind, Microsoft, and OpenAI to help maintainers manage AI-generated vulnerability reports.
- Secure Coding Guide for Python (pyscg) pyscg is a framework-independent Secure Coding Guide for Python providing new developers with a single baseline resource for establishing secure coding practices in Python.
- Best Practices Badge Best Practices Badge offers structured indicators of project maturity and security adoption, helping downstream consumers evaluate open source project quality and security posture.
Quantifiable outcome
- 10,000+ high/critical-severity vulnerabilities discovered across 1,000+ open-source projects via Project Glasswing (partner initiative) with 90% true-positive validation rate
- +4 more outcomes
Companies that use Open Source Security Foundation
Customer profileNamed customers7 records
Ideal customer profiles3 records
Open Source Security Foundation technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration23 records
AI capability12 records
Feature10 records
Open Source Security Foundation partnerships and signals
Strategic signalPartnerships
Six partnerships are on record, tiered flagship, core and minor.
- AnthropicflagshipAnthropic partnered with OpenSSF's Alpha-Omega project for Project Glasswing. Claude Mythos identified 10,000+ vulnerabilities across 1,000+ open-source projects. Anthropic committed USD 4 million to open-source security foundations to support maintainer remediation and outlined plans to work with governments to expand the initiative.
- KusaricorePartnered with OpenSSF in March 2026 to offer Kusari Inspector at no cost to OpenSSF projects. Adopted by GEMARA, GitTUF, GUAC, in-toto/Witness, OpenVEX, Protobom, and SLSA; also launched Darnit for AI security orchestration at OpenSSF Community Day.
- Honda Motor Co.minorGold sponsor of OpenSSF Community Day North America 2026 in Minneapolis. Honda engineers presented on applying SLSA guidelines to automotive In-Vehicle Infotainment (IVI) development.
- Red HatflagshipPremier Member of OpenSSF; transitioned to leadership role shaping EU CRA standards via direct engagement with the European Commission. Championed OSPS Baseline, Global Cyber Policy Working Group, and SLSA as reference frameworks; featured in joint OpenSSF case study on defending the open source supply chain.
- CEN-CENELECflagshipOpenSSF was approved as a CEN/CENELEC Liaison Organization, enabling formal contribution to European cybersecurity standards supporting the EU CRA implementation.
- European Commission and ENISA
Scale indicators15 records
Recent moves6 records
Expansion highlights6 records
Open Source Security Foundation competitors and assessment
Company assessmentDirect peers
- OWASP Foundation: OWASP is the most direct peer: a non-profit foundation producing open security standards, tools, and training (e.g., OWASP Top 10, Dependency-Track, CycloneDX) used by the same developers and security practitioners OpenSSF targets. Both convene industry around free, foundation-backed security guidance.
- Cloud Native Computing Foundation (CNCF): CNCF is a sibling Linux Foundation project hosting cloud-native open source projects (Kubernetes, Argo, SPIFFE/SPIRE for workload identity). It directly intersects with OpenSSF through supply-chain security SIGs and overlapping TAG Security work, and shares LF governance and sponsorship models.
- Eclipse Foundation: Eclipse Foundation is a comparable non-profit host for open source projects (Jakarta EE, Theia, Adoptium) and runs the Eclipse Public License. It operates a similar member-funded governance model with overlapping enterprise ISVs and developer communities.
- Apache Software Foundation: ASF is a comparable non-profit foundation stewarding widely used OSS projects (Kubernetes, Kafka, Tomcat). Its vendor-neutral governance and reliance on volunteer maintainers mirror OpenSSF's structural model and member dynamics.
- OpenJS Foundation: OpenJS Foundation is a sibling Linux Foundation project hosting JavaScript runtimes and frameworks (Node.js, jQuery, Electron). It shares LF governance, member-funded operations, and overlapping supply-chain security needs that intersect with OpenSSF's SBOM and Sigstore work.
- Internet Security Research Group (ISRG / Let's Encrypt): ISRG operates Let's Encrypt, the free automated certificate authority underpinning Sigstore-style keyless signing. It is a comparable non-profit delivering internet-scale security infrastructure, sharing the LF ecosystem and free public-good funding model.
Emerging players
- Chainguard: Chainguard provides hardened, minimal container images and a software factory built around SLSA-style provenance. It is a commercial counterpart that consumes and competes with the Sigstore/SLSA stack OpenSSF ships, representing how OpenSSF's open tooling can be productized.
- Anchore: Anchore commercializes Syft and Grype, the SBOM-generation and vulnerability-scanning tools that interoperate with OpenSSF's OSV.dev, Protobom, and SBOMit. It is a leading commercial SBOM platform targeting the same compliance and supply-chain use cases OpenSSF addresses for free.
Broad incumbents
- Snyk: Snyk is an incumbent developer security platform spanning SCA, SAST, container, and IaC scanning that competes with OpenSSF Scorecard and OSV-Scanner at the enterprise tier. Its commercial reach and integration breadth make it the dominant paid alternative to OpenSSF's free supply chain tooling.
- Sonatype: Sonatype operates Nexus and the Lifecycle platform for open source governance, SBOM, and policy enforcement. It is a broad incumbent addressing the same OSS supply chain risk management and CRA-readiness use cases that OpenSSF's GUAC, OSPS Baseline, and SBOMit target.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks7 records
Key highlights7 records
Customer concentration
Open Source Security Foundation social profiles
Digital presenceOpen Source Security Foundation compliance and trust
Trust signalCompliance5 records
Open Source Security Foundation financial estimates
Financial estimateRevenue estimate
Valuation estimate
Open Source Security Foundation leadership team
Management profileNumber of profiles
Profiles5 records
Open Source Security Foundation funding detail
Funding detailFunding overview
Funding rounds2 records
Investors7 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Open Source Security Foundation M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Open Source Security Foundation
What does Open Source Security Foundation do?
OpenSSF is a non-profit foundation that develops and curates a portfolio of open source security tools, frameworks, and standards—including GUAC, Sigstore, SLSA, OSPS Baseline, Scorecard, and the Malicious Packages repository—to secure the software supply chain. It also delivers free training programs, working groups, and policy engagement to coordinate industry, government, and maintainer communities around open source security.
Is Open Source Security Foundation a public or private company?
Open Source Security Foundation is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was Open Source Security Foundation founded?
Open Source Security Foundation was founded in 2020. It employs 11 to 50 people.
Where is Open Source Security Foundation based?
Open Source Security Foundation is headquartered in San Francisco, United States, in the North America region.
How does Open Source Security Foundation make money?
Four revenue lines are on record. Membership dues are the primary driver. The others are grants and corporate donations, event sponsorship and in-kind contributions and partner-provided tooling.
Who are Open Source Security Foundation's main competitors?
Direct peers on record are OWASP Foundation, Cloud Native Computing Foundation (CNCF), Eclipse Foundation, Apache Software Foundation, OpenJS Foundation and Internet Security Research Group (ISRG / Let's Encrypt). Emerging players are Chainguard and Anchore. Broad incumbents are Snyk and Sonatype.
Does Open Source Security Foundation have an API?
Yes. OpenSSF's Malicious Packages repository publishes records via the OSV (Open Source Vulnerability) format. The OSV.dev API endpoints used include /v1/vulns (e.g., https://api.osv.dev/v1/vulns/MAL-2025-6812), /v1/query (for looking up malicious packages by name and ecosystem), and /v1/querybatch (for querying multiple packages, versions, and ecosystems in a single call). These APIs allow developers to programmatically detect known malicious packages such as typosquatted or compromised dependencies. OpenSSF also integrates the OSV-Scanner GitHub Action to scan pull requests for malicious packages. Developer documentation is at osv.dev.
What industry is Open Source Security Foundation in?
Open Source Security Foundation's product category is Open Source Security Software. Its primary akta.pro industry code is BPAEADAG, Network Security Managed Services (Firewall/IDS/IPS/SASE), with a secondary code of EDABAGAN, Secure Software & DevOps Awareness (Secure Coding Basics). Its NAICS code is 54151 and its SIC code is 7372.