sigstore
Sigstore is a Linux Foundation-hosted open source framework, founded in 2021 by Red Hat and Google, that provides composable tools (Cosign, Rekor, Fulcio, Policy Controller) for keyless signing and verification of software artifacts and ML models, serving developers, open source maintainers, and security teams through community-led, product-led adoption.
- Company typePrivate
- Founded2021
- HeadquartersLondon, United Kingdom
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What sigstore does
Sigstore is an open source software supply chain security framework founded in 2021 as a collaboration between Red Hat and Google's Open Source Security Team and now hosted by the Linux Foundation. The project provides a collection of composable tools — Cosign for artifact signing and verification, Rekor for an append-only transparency ledger, Fulcio as a certificate authority issuing short-lived certificates via OpenID Connect, and Policy Controller for Kubernetes cluster policy enforcement — alongside language-specific clients (Python, Java, Go), GitHub Actions, GitSign for git commit signing, Rekor Log Monitor, and Model Transparency for ML model signing. Its key technical contribution is a keyless signing workflow: developers authenticate through OIDC, receive an ephemeral signing certificate from Fulcio, sign artifacts with Cosign, and have the signature published to the Rekor transparency log, eliminating long-lived private key management while preserving an immutable audit trail.
Sigstore's business model is non-commercial: all tools are open source under the Linux Foundation, freely available via GitHub, and sustained by corporate sponsorships from Google, Red Hat, GitHub, Chainguard, Cisco, VMware, HPE, Purdue University, and Stacklok. There is no product pricing, no license fees, and no direct revenue capture by the project; commercial value accrues instead to ecosystem participants (e.g., Chainguard, Stacklok) that build paid offerings on top of the open source foundation. The project is governed by a Technical Steering Committee drawn from Google, Red Hat, Chainguard, Purdue, and GitHub, and reaches its users through a community-led, product-led growth model anchored in developer self-service, Slack working groups, documentation, and annual SigstoreCon events.
Notable adoption signals include JPMorgan's Global CISO publicly endorsing Sigstore, GitHub and npm shipping package provenance on the framework, Wind River integrating Cosign into VxWorks for embedded systems, and Stacklok building its Minder and Trusty products on the core — each of which broadens the project's distribution and validates demand across financial services, package registries, RTOS/embedded, and security tooling segments.
sigstore firmographics
Firmographics- Name
- sigstore
- Legal name
- Sigstore (a Linux Foundation Project)
- Website
- https://sigstore.dev
- Company type
- Private
- Founded year
- 2021
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Sigstore is a Linux Foundation-hosted open source framework, founded in 2021 by Red Hat and Google, that provides composable tools (Cosign, Rekor, Fulcio, Policy Controller) for keyless signing and verification of software artifacts and ML models, serving developers, open source maintainers, and security teams through community-led, product-led adoption.
- Ownership category
- akta.pro rank
sigstore industry classification
Industry- Product category
- Software Supply Chain Security
- NAICS
- Software Publishers (5132), Software Publishers (513210)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Software Supply Chain & Dependency Security (SBOM, Signing) (HDADACAD)
Keywords
Where sigstore is headquartered
LocationHeadquarters
- HQ city
- London
- HQ country
- United Kingdom
- HQ region
- Europe
Markets served
sigstore business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Infrastructure, Operations, Marketing or Sales
Revenue model
- Open Source Software (Free): All Sigstore tools are open source and freely available. The project is funded through corporate sponsorships and maintained under the Linux Foundation.
Go-to-market motion2 records
Distribution channels2 records
Marketing channels6 records
sigstore product offering
Product offeringCore offering
Sigstore provides a collection of open source tools for software supply chain security, including Cosign for signing and verifying software artifacts and containers, Rekor as an append-only transparency ledger for signed metadata, Fulcio as a code-signing certificate authority issuing short-lived certificates via OpenID Connect, and Policy Controller for enforcing supply-chain policies on clusters. The tools are freely available and designed to make code signing accessible to open source maintainers and enterprise developers without traditional PKI complexity.
Product overview
Sigstore is a collection of open source tools for software supply chain security that can be used individually or in concert. The framework includes Cosign for signing and verifying artifacts, Rekor as an immutable transparency ledger, Fulcio as a certificate authority for issuing short-lived certificates, and Policy Controller for cluster policy enforcement. Additional tools include Rekor Log Monitor for transparency log monitoring, GitSign for git commit signing, Model Transparency for ML model signing, and language-specific clients for Python, Java, Go and other languages. Sigstore GitHub Actions enable CI integration.
Differentiator
Problem solved
Functional benefit
Brands
- Cosign: Easy-to-use solution for signing and verifying artifacts and containers.
- Rekor
- Fulcio
- Policy Controller
- Gitsign
- Rekor Log Monitor
Products and services
- Cosign An easy-to-use open source tool for signing and verifying software artifacts and containers, supporting keyless signing with ephemeral keys and short-lived certificates.
- Rekor An append-only, auditable transparency log service that records signed metadata to a tamper-resistant ledger, enabling verification of signatures and detection of changes.
- Fulcio A code-signing certificate authority that issues short-lived certificates to authenticated identities via OpenID Connect and publishes them to a certificate transparency log.
- Policy Controller A Kubernetes-native tool that enforces policy on clusters using verifiable supply-chain metadata from Cosign.
- Rekor Log Monitor
Quantifiable outcome
- Sigstore makes code signing free and easy for software developers
- +2 more outcomes
Companies that use sigstore
Customer profileNamed customers4 records
Segments4 records
Ideal customer profiles3 records
sigstore technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration2 records
Feature8 records
sigstore partnerships and signals
Strategic signalPartnerships
Five partnerships are on record, tiered core and minor.
- npmcorenpm released Sigstore support in public beta, allowing npm packages to verifiably link to their source repository and build instructions using Sigstore's transparency and signing technology.
- Linux FoundationcoreSigstore is developed and hosted under the Linux Foundation. The Linux Foundation provides organizational infrastructure, events management (SigstoreCon), and operational support for the open source project.
- OpenSSF (Open Source Security Foundation)coreSigstore is an OpenSSF project. OpenSSF provides governance, security expertise, and industry coordination for open source security initiatives including Sigstore.
- StacklokminorStacklok is a sponsor and has built Minder and Trusty tools on Sigstore's open source foundation. These free-to-use tools help developers and open source communities build safer software.
- Purdue UniversitycorePurdue University is a sponsor of Sigstore. Santiago Torres-Arias, Assistant Professor at Purdue University whose research focuses on securing the software development life-cycle, serves on Sigstore's Technical Steering Committee.
Scale indicators3 records
Recent moves6 records
Expansion highlights6 records
sigstore competitors and assessment
Company assessmentDirect peers
- Chainguard: Commercial container and supply chain security company that builds directly on Sigstore's open source foundation (Cosign, Rekor). It is the closest commercial analogue: same underlying technology, same customer base, with monetization layered on top.
- Stacklok: Open source security startup that built Minder and Trusty atop Sigstore. Comparable because it offers developer-facing supply chain security tooling using Sigstore primitives, and is itself a Sigstore sponsor/maintainer.
- in-toto: Software supply chain integrity framework that, like Sigstore, provides end-to-end attestation and verification of the software build pipeline. It targets the same architectural slot (SLSA-aligned supply chain integrity) and represents the closest architectural alternative.
- Notary Project: CNCF-hosted project for signing and verifying container images and other artifacts. Directly competes with Cosign for container signing workloads and shares the same developer-tooling, key-management, and signing-vocabulary space.
Emerging players
- The Update Framework (TUF): Software update security specification on which Sigstore actually builds its Trust Root. Comparable because it addresses an overlapping problem (secure software distribution and key management) and is sometimes positioned as an alternative to Sigstore's transparency-log-based approach.
- Sigsum: Open source transparency log for cryptographic signing with a similar architectural philosophy to Rekor. It is a lightweight alternative for organizations that want signing transparency without adopting the full Sigstore stack.
- Socket: Open source dependency security company focused on detecting malicious or risky packages. Competes for the same developer mindshare around 'software supply chain security' from a different architectural angle (behavioral/metadata analysis vs. cryptographic provenance).
Broad incumbents
- Anchore: Container security and SBOM platform with overlapping supply chain visibility features (image scanning, attestation, policy enforcement). It competes for the same enterprise buyer and overlapping use cases, though it does not specialize in keyless signing.
- Snyk: Developer security platform that, while broader in scope, includes supply chain security features (Snyk Container, dependency integrity) that overlap with Sigstore's open source dependency verification use case.
- GitHub: Both a major Sigstore sponsor/integrator and a competing supply chain security platform (Dependabot, native attestation, npm provenance). Comparable because GitHub's distribution advantages let it either amplify or marginalize Sigstore depending on its own product roadmap.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
sigstore social profiles
Digital presencesigstore financial estimates
Financial estimateRevenue estimate
Valuation estimate
sigstore leadership team
Management profileNumber of profiles
Profiles5 records
sigstore funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
sigstore M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about sigstore
What does sigstore do?
Sigstore provides a collection of open source tools for software supply chain security, including Cosign for signing and verifying software artifacts and containers, Rekor as an append-only transparency ledger for signed metadata, Fulcio as a code-signing certificate authority issuing short-lived certificates via OpenID Connect, and Policy Controller for enforcing supply-chain policies on clusters. The tools are freely available and designed to make code signing accessible to open source maintainers and enterprise developers without traditional PKI complexity.
Is sigstore a public or private company?
sigstore is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was sigstore founded?
sigstore was founded in 2021. It employs 1 to 10 people.
Where is sigstore based?
sigstore is headquartered in London, United Kingdom, in the Europe region.
How does sigstore make money?
One revenue line is on record: open Source Software (Free).
Who are sigstore's main competitors?
Direct peers on record are Chainguard, Stacklok, in-toto and Notary Project. Emerging players are The Update Framework (TUF), Sigsum and Socket. Broad incumbents are Anchore, Snyk and GitHub.
Does sigstore have an API?
Yes. Sigstore provides language-specific clients that allow users to interact with Sigstore tools using Python, Java, Go and more. These clients enable programmatic access to signing and verification functionality.
What industry is sigstore in?
sigstore's product category is Software Supply Chain Security. Its primary akta.pro industry code is HDADACAD, Software Supply Chain & Dependency Security (SBOM, Signing). Its NAICS code is 5132 and its SIC code is 7372.