Stacklok focuses on improving software supply chain security by helping developers and open-source communities ensure their software and dependencies are secure. Its main product, Trusty, features an "Activity Scoring" system called the Trusty Score, which benchmarks software repository activity using public GitHub data. Trusty also verifies the authenticity of software packages through Sigstore and uses generative AI to recommend safer package alternatives. By offering Trusty as a free service via a web app and Visual Studio Code extension, Stacklok aims to build trust within the developer community.