Log in
Enquire now
Stacklok

Stacklok

Stacklok is a Seattle-based software developing offering tools to help developers and open-source software communities keep their software secure and choose safe dependencies.

OverviewStructured DataIssuesContributors

Contents

stacklok.com
Is a
Organization
Organization
Company
Company

Company attributes

Industry
Software
Software
0
Open-source software
Open-source software
0
Software security
Software security
0
Location
Seattle
Seattle
0
CEO
Craig McLuckie
Craig McLuckie
0
Founder
Craig McLuckie
Craig McLuckie
0
Luke Hinds
Luke Hinds
0
Pitchbook URL
pitchbook.com/profiles...527723-83
Number of Employees (Ranges)
11 – 500
Email Address
press@stacklok.com0
hello@stacklok.com0
partnerships@stacklok.com0
Investors
Madrona
Madrona
Accel
Accel
Founded Date
2023
0
Total Funding Amount (USD)
17,500,000
Competitors
Adolus Inc.
Adolus Inc.
0
JFrog
JFrog
0
StackHawk
StackHawk
0
Enso Security
Enso Security
0
Revenera
Revenera
0
Chainguard
Chainguard
0
Phylum
Phylum
0
Kiuwan
Kiuwan
0
Business Model
Subscription (with freemium option)0
CTO
Luke Hinds
Luke Hinds
0
Latest Funding Type
Series A
Series A
Overview

Stacklok is a developer of an open-source platform intended to help developers understand and mitigate risks in daily tasks, software tool choices, and code dependencies. The company offers a free-to-use service that assists developers in making safer dependency choices. The open-source platform helps software developers and maintainers secure their software.

The company was founded in 2023 by Craig McLuckie and Luke Hinds and is headquartered in Seattle, Washington. Prior to founding the company, McLuckie was one of the creators of Kubernetes at Google, and Hinds founded the open-source project Sigstore. Stacklok was founded in part in the light of Executive Order 14028, "Improving the Nation's Cybersecurity: NIST's Responsibilities Under the May 2021 Executive Order," which will require developers and open-source communities to be held to stricter standards in regard to their source code and the security of the software supply chain.

Platform
Trusty

Stacklok's Trusty solution is made for developers to help them understand whether an open-source package is authentic, non-malicious, and actively maintained. The Trusty tool is free to use and accessible as a web app and as a Visual Studio Code extension. Features of Trusty include activity scoring, which works to establish a benchmark for average levels of package activity; package provenance, which displays a verifiable chain of trust back to the source code; package recommendations, to help developers evaluate other packages to help find safer options; and IDE support, to give developers alerts about packages with low scores to help them choose safer packages at the outset and avoid rework and security risks.

Minder

Stacklok's Minder solution is an open-source platform developed to help development teams and open-source communities build secure software and to prove to others that the software has been built securely. Features of the Minder tool include repo configuration and security, which works to help simplify configuration and management of security policies and settings across project repos; proactive security enforcement, which continuously enforces security best practices, like secret scanning, branch protections, and artifact signing; artifact attestation, to help users ensure artifacts are tamper-proof through policy setting and verification; and dependency and license management, to help users manage their dependency security posture and supported licenses. Minder and Trusty can integrate with each other to enable policy-driven management on dependency risk levels.

Timeline

No Timeline data yet.

Funding Rounds

Products

Acquisitions

SBIR/STTR Awards

Patents

Further Resources

Title
Author
Link
Type
Date

From Creating Kubernetes to Founding Stacklok: Open-Source and Security with Craig McLuckie

Coral Garnick

https://www.madrona.com/founded-funded-stacklok-craig-mcluckie/

Web

January 24, 2024

Kubernetes and sigstore founders raise $17.5M to launch software supply chain startup Stacklok | TechCrunch

Frederic Lardinois

https://techcrunch.com/2023/05/17/kubernetes-and-sigstore-founders-raise-17-5m-to-launch-software-supply-chain-startup-stacklok/

Web

May 17, 2023

Stacklok Builds on Sigstore to Identify Safe Open Source Libraries

Joab Jackson

https://thenewstack.io/stacklok-builds-on-sigstore-to-identify-safe-open-source-libraries/

Web

November 7, 2023

References

Find more companies like Stacklok

Use the Golden Query Tool to find similar companies in the same industry, location, or by any other field in the Knowledge Graph.
Open Query Tool
Access by API
Golden Query Tool
Golden logo

Company

  • Home
  • Press & Media
  • Blog
  • Careers
  • WE'RE HIRING

Products

  • Knowledge Graph
  • Query Tool
  • Data Requests
  • Knowledge Storage
  • API
  • Pricing
  • Enterprise
  • ChatGPT Plugin

Legal

  • Terms of Service
  • Enterprise Terms of Service
  • Privacy Policy

Help

  • Help center
  • API Documentation
  • Contact Us
By using this site, you agree to our Terms of Service.