Sigstore

United States · www.sigstore.dev · 2 vendors

Resilience scores

Technology vendors

Services catalogue

3 services in catalogue across 1 category; runs on 2 sub-vendors.

Insights

Last updated 2026-08-12 · revision 1

2 direct vendors, 72 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Sigstore exhibits high migration readiness, primarily driven by its extremely modern, cloud-native, and containerized tech stack. The extensive use of Google Cloud Platform (GCP), Google Kubernetes Engine (GKE), Kubernetes, Docker, and Terraform provides a highly portable and infrastructure-agnostic foundation. The Go (Golang) programming language further enhances portability. This architecture allows for significant flexibility in deploying and operating across various cloud environments or even on-premises infrastructure, making it well-suited for potential migrations. The main challenge for migration readiness stems from the deep integration with specific Google Cloud services, particularly GKE and Trillian (Google's Merkle tree framework). While Kubernetes offers a degree of abstraction, migrating a complex production workload off a specific managed service like GKE to another cloud provider's equivalent or a self-managed Kubernetes cluster can still involve considerable effort and potential re-architecture to decouple from GCP-specific features. The provided data states 'Total Vendors: 0', but if GCP is considered a primary vendor for infrastructure, then there is a concentration on a single major vendor, which could increase the complexity of a full migration away from Google's ecosystem. The lack of data regarding financial stability and data residency requirements also prevents a comprehensive assessment of potential funding for migration efforts or specific compliance-driven migration constraints.

Compliance

5 in-scope frameworks identified; showing 3.

US Executive Order 14028 — Assessment Required

US Executive Order 14028 ('Improving the Nation's Cybersecurity', May 2021) directly references software supply chain security and led to NIST guidance (NIST SP 800-218, SSDF) and requirements for software bill of materials (SBOM). Sigstore is explicitly cited in US government guidance as a recommended tool for software signing and supply chain integrity. While Sigstore itself is not a regulated entity under EO 14028, its adoption is encouraged by US federal agencies, and organizations supplying software to the US government are expected to use tools like Sigstore. This creates an indirect but significant regulatory relevance.

Evidence: https://www.whitehouse.gov/briefing-room/presidential-actions/2021/05/12/executive-order-on-improving-the-nations-cybersecurity/, https://www.nist.gov/system/files/documents/2022/02/04/software-supply-chain-security-guidance-under-EO-14028-section-4e.pdf, https://www.cisa.gov/resources-tools/resources/software-bill-materials-sbom, https://openssf.org/community/sigstore/

SOC 2 (source) — Assessment Required

Sigstore operates public cloud infrastructure (Rekor transparency log, Fulcio CA, TUF root) that is relied upon by thousands of open-source projects and enterprises globally for software supply chain security. As a critical shared infrastructure provider, SOC2 Type II certification would be highly relevant to demonstrate security, availability, and integrity controls. However, as a Linux Foundation open-source project rather than a commercial SaaS vendor, SOC2 certification is not standard practice. The risk is Medium because enterprise adopters of Sigstore's public infrastructure may require SOC2 assurance as part of their own vendor risk management programs, and the absence of SOC2 certification could be a barrier to enterprise adoption or create risk for organizations relying on Sigstore's public good infrastructure.

Evidence: https://www.sigstore.dev, https://www.linuxfoundation.org, https://docs.sigstore.dev/logging/overview/

CCPA — Assessment Required

Sigstore, as a US-based project under the Linux Foundation (a California-registered nonprofit), may be subject to CCPA if it collects personal information from California residents. The Rekor transparency log and Fulcio CA may process email addresses and identity information of California residents. However, the Linux Foundation is a nonprofit, and CCPA's primary applicability thresholds (for-profit businesses with $25M+ revenue, or processing data of 100,000+ consumers for commercial purposes) may not apply. Risk is Low because the Linux Foundation's nonprofit status likely exempts it from CCPA's primary provisions, and the personal data processed is limited in scope.

Evidence: https://www.linuxfoundation.org/privacy, https://oag.ca.gov/privacy/ccpa

Financials

Three-year financials

Financial Resilience Score: 7/10

Sigstore is not a commercial entity but an open-source project hosted under the OpenSSF and the Linux Foundation. As such, it does not generate revenue, hold equity, or report EBIT. Its financial resilience must be assessed through the lens of sponsor support, strategic relevance, and infrastructure sustainability rather than traditional financial metrics. The project benefits from a broad and deep sponsor base including Google, Microsoft, IBM/Red Hat, GitHub, Cisco, Intel, JPMorgan Chase, Meta, and Oracle, which contribute funding and engineering time via OpenSSF membership tiers. Sigstore has become de-facto infrastructure for software supply-chain integrity following high-profile incidents such as SolarWinds, Log4Shell, and the xz-utils backdoor. Regulatory tailwinds including US Executive Order 14028 and the EU Cyber Resilience Act reinforce demand for its tooling. Its operating cost base is low, with core services being lightweight and largely running on donated infrastructure. Key risks include the absence of a direct revenue model, dependence on continued sponsor goodwill, concentration in donated infrastructure (historically Google Cloud hosts Rekor and Fulcio), and maintainer concentration among a small group of engineers primarily at Chainguard, Google, Red Hat, and GitHub. Commercialization by adjacent vendors like Chainguard (valued at ~$3.5B in 2024) blurs the line between project and vendor but also validates the ecosystem.

Key strengths: Backed by Linux Foundation and OpenSSF with major tech company sponsors (Google, Microsoft, IBM/Red Hat, GitHub, Cisco, Intel, JPMorgan Chase, Meta, Oracle), Strategic relevance as de-facto infrastructure for software supply-chain integrity, Regulatory tailwinds from US EO 14028 and EU Cyber Resilience Act, Low operating cost base with donated infrastructure, Broad adoption by Kubernetes, npm, PyPI, Homebrew, and GitHub

Risk factors: No direct revenue model; dependent on sponsor goodwill, Concentration in donated infrastructure (Google Cloud hosts Rekor and Fulcio), Maintainer concentration among small number of paid engineers, Commercialization competition from adjacent vendors like Chainguard, Key-person risk among core contributors

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report