Stacklok

Enhances software supply chain security tools

Seattle, Washington, United States

About Stacklok

Stacklok focuses on improving software supply chain security by helping developers and open-source communities ensure their software and dependencies are secure. Its main product, Trusty, features an "Activity Scoring" system called the Trusty Score, which benchmarks software repository activity using public GitHub data. Trusty also verifies the authenticity of software packages through Sigstore and uses generative AI to recommend safer package alternatives. By offering Trusty as a free service via a web app and Visual Studio Code extension, Stacklok aims to build trust within the developer community.

Seattle, WashingtonHeadquarters
2023Year Founded
$17MTotal Funding
SERIES_ACompany Stage
CybersecurityIndustries
11-50Employees

Benefits

Flexible Work Hours
Hybrid Work Options

Risks

Trusty's reliance on GitHub data may face challenges if access policies change.
Generative AI in Trusty could provide biased recommendations if not properly maintained.
Free model of Trusty may limit revenue without effective premium feature development.

Differentiation

Stacklok's Trusty uses Sigstore for package provenance, ensuring software authenticity.
Trusty Score benchmarks GitHub repository activity, aiding in assessing software trustworthiness.
Generative AI in Trusty suggests safer package alternatives, enhancing developer decision-making.

Upsides

Recent $17.5M Series A funding boosts Stacklok's product development and market expansion.
Shanis Windland's appointment as COO strengthens Stacklok's leadership and operational capabilities.
Growing adoption of Sigstore enhances Trusty's credibility and potential market reach.

Funding

Total raised$17.02 M
Latest valuation$87.50 M
StageSERIES_A
$18
$87.50 M