Chainguard — secure software supply chain: hardened images as a subscription
September 14 at 04:40 · $0.145 total
Investment Memo: Chainguard
Thesis The software supply chain is fundamentally broken. Post-SolarWinds and Log4j, securing the software development lifecycle (SDLC) has escalated from a developer headache to a boardroom mandate and federal requirement. Historically, the industry has relied on reactive scanning—finding vulnerabilities (CVEs) in open-source software and forcing developers into endless cycles of patching.
Chainguard flips this paradigm. Instead of scanning for vulnerabilities after the fact, Chainguard provides secure-by-default, hardened base images. By eliminating the noise of false-positive CVEs, they align the incentives of security teams (who want zero risk) and developers (who want zero friction). If Chainguard becomes the default trusted source for enterprise container images, they will own the foundational layer of the modern cloud-native stack. This is a classic "picks and shovels" play with the potential to be a $10B+ fund-returner, effectively becoming the Red Hat of the cloud-native era.
Product & Wedge Chainguard’s wedge is brilliant in its simplicity: developer toil. Developers spend up to 20% of their time chasing down and patching CVEs in standard base images (like Alpine, Debian, or Ubuntu).
Chainguard solves this with Chainguard Images: a subscription registry of minimal, "distroless" container images that contain only the exact dependencies an application needs to run. Because there is no package manager or shell included, the attack surface is drastically reduced, resulting in zero (or near-zero) known CVEs.
Once embedded via this wedge, Chainguard expands its footprint with policy enforcement and software bill of materials (SBOM) management, creating a sticky, enterprise-wide secure supply chain platform.
Market & Competition The DevSecOps and container security market is massive, but highly fragmented. Chainguard operates at the intersection of infrastructure and security, putting them up against several classes of competitors:
- Legacy OS & Registry Providers: Canonical (Ubuntu Pro), Red Hat, and Docker. These are the incumbents. Canonical is actively pushing its own hardened, minimal images to defend its turf.
- Security Scanners (CNAPPs): Snyk, Aqua Security, Wiz, and Palo Alto Networks (Prisma Cloud). While currently complementary (scanners scan Chainguard images and find nothing), these giants compete for the same DevSecOps budget and could attempt to move "further left" to offer remediation via their own secure base images.
- Cloud Providers (CSPs): AWS, Google Cloud, and Azure all offer native registries and could easily bundle hardened base images into their managed Kubernetes services.
Traction & Business Signal Note: As a private company, exact revenue figures are unknown.
- Team: Elite founder-market fit. Founded by Dan Lorenc, Kim Lewandowski, and Ville Aikas—the ex-Google engineers who created Sigstore, Tekton, and the original Distroless project.
- Capital: Hyper-funded. Raised a $50M Series A, $114M Series B, and recently a $140M Series C at a $1.12B valuation.
- Growth: Public statements indicate ARR tripled in 2023 (exact baseline unknown).
- Logos: Strong enterprise adoption, with publicly named customers including Snowflake, Canva, and Hewlett Packard Enterprise.
Risks To underwrite this deal, we must be comfortable with three existential risks:
- Commoditization by Incumbents ("The Docker/Canonical Threat"): The concept of distroless, hardened images is open-source. If Docker or Canonical decides to offer zero-CVE base images for free (or bundled with existing enterprise tiers) to protect their ecosystems, Chainguard’s core wedge could be commoditized. They are racing to build a moat of enterprise features before the underlying images become a commodity.
- The "Feature vs. Platform" Ceiling: Is paying for secure base images a standalone platform, or just a feature? Enterprise budgets are consolidating around massive CNAPP platforms (like Wiz or Palo Alto). If CISOs decide they want one vendor for cloud security, Chainguard may struggle to expand its ACV beyond a niche developer tool, capping its TAM.
- Migration Friction & Legacy Tech Debt: Adopting Chainguard for new microservices is easy. Migrating existing legacy applications to distroless images is notoriously difficult because developers often rely on the shell and package managers present in standard images for debugging. If enterprise migration proves too painful, net dollar retention (NDR) will stall as deployments get stuck in pilot purgatory.
Verdict Invest.
At a Series A stage, you are betting on founder-market fit, a hair-on-fire problem, and a wedge that users love. Chainguard has all three. The founders literally wrote the playbook on supply chain security at Google. The market timing—driven by government SBOM mandates and developer fatigue with CVE scanners—is perfect.
The One Question to Answer First: What is the exact friction and timeline for an enterprise to migrate a legacy application to a Chainguard Image, and what is the Net Dollar Retention (NDR) once they do? If they can prove that land-and-expand works seamlessly across legacy tech debt, this is a generational company.
Investment Memo: Chainguard (hypothetical Series A) Secure software supply chain — hardened container images as a subscription
Thesis Software supply-chain attacks (SolarWinds, Log4j, xz, countless CVE floods in base images) turned “what’s in my containers?” from a compliance checkbox into a board-level risk. Every enterprise running Kubernetes or CI/CD now faces a binary: keep patching Debian/Alpine/Ubuntu images that accumulate hundreds of CVEs, or adopt a purpose-built, continuously rebuilt, signed, SBOM-equipped alternative. Chainguard’s bet is that the latter can be sold as a high-margin subscription (Chainguard Images / Wolfi-based distroless images) that becomes the default runtime layer. If they own the image catalog and the rebuild pipeline, they own the trust root for the rest of the supply chain (signing, policy, provenance). That is a potential fund-returner: a wedge that expands into a platform (Enforce, custom builds, FIPS, air-gapped) with the same economics as a security or infrastructure subscription, sold into every cloud-native budget. Timing is favorable—post-EO 14028, SSDF, and EU CRA—while most incumbents still treat images as a free or low-value artifact.
Product & wedge Core offering: a catalog of hardened, frequently rebuilt container images (Wolfi + apko/melange toolchain) that are distroless or near-distroless, signed with Sigstore, accompanied by SBOMs, and claimed to have dramatically fewer (often zero) known CVEs versus equivalent official images. Customers pull via a private registry or Chainguard’s feed; updates are automatic. The wedge is replacement of the “FROM debian:xxx” or Bitnami/official Docker Hub image that every team already uses. Once the image is in the Dockerfile, switching cost rises and Chainguard can upsell custom packages, FIPS/STIG variants, policy enforcement, and broader supply-chain controls. Open-source Wolfi and the build tools create a community moat and talent funnel while the paid catalog + SLAs + enterprise features capture value. This is classic “secure by default” infrastructure: the product is the absence of work (patching, CVE chasing, audit evidence).
Market & competition TAM is the intersection of container runtime spend, software composition analysis, and emerging supply-chain security budgets—large and growing with Kubernetes penetration and regulation. Real competitors: (1) official/maintained images from Docker Hub, Bitnami (Broadcom), Red Hat UBI, AWS, Google Distroless, and Microsoft; (2) security vendors that scan or wrap existing images (Snyk, Aqua, Palo Alto Prisma, Anchore, Wiz); (3) DIY (Alpine + own rebuilds) or emerging “hardened image” players. Cloud providers can (and do) offer “secure” base images as a loss-leader. Differentiation today is rebuild cadence, CVE count, signing/SBOM completeness, and Wolfi’s minimalism. Long-term risk is that “good enough” hardened images become table stakes from hyperscalers or open-source distros.
Traction & business signal Publicly known: founded 2021 (Dan Lorenc et al., Sigstore/Google pedigree); $50M Series A (Nov 2022, Amplify/Sequoia et al.). Product launched and publicly marketed as Chainguard Images / Wolfi. Customer logos and case studies exist in marketing materials; usage in production by enterprises is claimed. Specific ARR, growth rate, NRR, logo count, or win rates versus Bitnami/official images: unknown. Broader funding history and later rounds exist but are outside a pure Series A snapshot. Signal is therefore founder/team quality + category timing + visible product adoption, not yet proven unit economics.
Risks (the three that actually kill the deal)
- Hyperscaler commoditization. AWS, Google, Microsoft, and Docker can ship “zero-CVE” or continuously rebuilt images at zero or near-zero incremental price, bundling them with the registry/K8s control plane. If customers accept “good enough + already in my cloud bill,” Chainguard’s paid catalog becomes a nice-to-have.
- Willingness-to-pay for images is structurally low. Many teams treat base images as free infrastructure. If the product remains “just images” rather than expanding into policy, custom builds, and compliance evidence that security/CISO budgets will fund, expansion stalls and churn appears when a cheaper or bundled alternative appears.
- Execution and talent concentration. The technical moat (rebuild pipeline, Wolfi, signing) is real but replicable; the company must convert open-source mindshare into enterprise sales motion, support, and SLAs at scale. Founder-led technical credibility is high; whether that translates into a repeatable, high-velocity GTM against entrenched Bitnami/official-image inertia is unproven at Series A.
Verdict Invest at a hypothetical Series A. The category is real, the wedge is clean, and the team has unique supply-chain credibility. The one question that must be answered first: what is early-customer net revenue retention (or at minimum logo retention + expansion) for paying Chainguard Images users after 6–12 months—i.e., do they stay and buy more once the initial “fewer CVEs” win is achieved, or do they treat it as a one-time swap? If NRR is already healthy, the platform expansion thesis is intact; if not, the deal is a pass until GTM proof appears.