Recommended Free Tools
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Chainguard announced a $356 million Series D financing on April 23, 2025, valuing the software-supply-chain security company at $3.5 billion. Kleiner Perkins and IVP led the round, joined by Salesforce Ventures and Datadog Ventures, along with existing investors. The funding supports Chainguard’s expansion from hardened container images into a broader source of secure open-source software artifacts.
The valuation reflects strong reported growth, but it is a private financing valuation—not a public-market price or independently verified measure of current company value.
What happened in Chainguard’s Series D?
Chainguard said it raised $356 million in Series D funding announced on April 23, 2025. The round valued the company at $3.5 billion.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsChainguard’s announcement named Kleiner Perkins and IVP as lead investors. Salesforce Ventures and Datadog Ventures joined as new investors. Existing participating investors included Sequoia, Spark, Amplify, Redpoint, Lightspeed, Mantis, and Kerrest & Co.
#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
Chainguard said it planned to use the proceeds to scale its go-to-market organization and support its growing customer base. SecurityWeek reported approximately $612 million in cumulative funding after the round, although that figure is a reported historical total rather than a complete, independently audited financing record.
Why investors are backing Chainguard
Modern software is assembled from thousands of open-source packages, container images, language libraries, operating-system components, and build tools. A vulnerability or compromised dependency can therefore affect many applications at once.
The conventional response is largely reactive: developers select an upstream package or image, security tools scan it, and engineering teams investigate, patch, replace, or accept the findings. That process becomes expensive when organizations operate large fleets and must repeatedly respond to newly disclosed vulnerabilities.
Chainguard’s investment thesis is that security should begin with the artifact itself. Rather than only scanning software after teams have adopted it, the company builds and distributes minimal, hardened artifacts designed to reduce unnecessary components and attack surface. Those artifacts are continuously rebuilt and accompanied by security and provenance information.
In its financing announcement, Chainguard cited supply-chain incidents including the xz-utils compromise and the tj-actions GitHub Action compromise as examples of the broader risk. These incidents illustrate the problem Chainguard is targeting; they do not demonstrate that Chainguard alone can prevent every supply-chain attack.
What Chainguard sells
Chainguard Containers
Containers remain Chainguard’s original and most established product category. Its images are built from source in Chainguard’s build infrastructure, designed to be minimal, continuously rebuilt, and patched.
The company distributes images with signed artifacts, software bills of materials (SBOMs), and provenance information. Its catalog includes base images, application images, AI and machine-learning images, and images intended for regulated environments. The container product page also describes images marketed as having no known CVEs at publish time.
That wording matters. “Zero-CVE” does not mean permanently vulnerability-free. New vulnerabilities can be discovered after publication, and customers still need to pull updated digests, test them, and redeploy them.
Chainguard Libraries
Chainguard Libraries extends the model to language ecosystems, including Python, Java, and JavaScript. The proposition is not simply to scan a customer’s existing dependencies. It is to provide continuously built, signed, and patched library artifacts.
Pricing is based on the relevant developer population and language ecosystem, according to the company’s pricing materials.
Chainguard VMs
Chainguard VMs applies the hardened-image approach to virtual-machine images, including base images, application images, and container-host VMs.
This is relevant for organizations that cannot run every workload in containers or that need hardened operating-system images for cloud, on-premises, or regulated deployments.
Rank #3
- equipped with atom n2600 d2700 processor, compatible with many freebsd based router systems, linux distros, or win.os supported, easy configuration and management
- Please note, this is a barebone only. A system memory, a storage drive and an operating system are needed to complete this system
- 13-19 inches 1u, 50w power, with power cord, make sure to use a big brand memory and ssd/hdd with quality assurance
- Designed with console, 2 x usb, 4 x lan, vga, power switch, size at 290 x 180 x 44mm
- There are 2 inside reserved fans on chassis, which could be removed freely or be turned on in a high temperature environment to ensure the best function of the product
Chainguard Factory
Chainguard describes its build system as a software factory that builds, patches, tests, and hardens open-source components. At the time of the Series D announcement, the company said the factory handled more than 13,000 packages and Git repositories and produced approximately 1,400 container images.
Those are historical April 2025 figures. Current product pages describe a larger catalog, so the two sets of numbers should not be treated as measurements from the same date.
How the model differs from ordinary vulnerability scanning
| Traditional workflow | Chainguard’s stated approach |
|---|---|
| Teams select an upstream package or image. | Chainguard builds a curated artifact from source. |
| Security tools identify vulnerabilities after adoption. | The artifact is minimized and hardened before distribution. |
| Engineers triage and patch findings themselves. | Chainguard continuously rebuilds and patches supported artifacts. |
| Provenance and SBOMs may require separate tooling. | Signed artifacts, SBOMs, and provenance are provided with the artifact. |
Paid offerings may also include contractual remediation commitments. Chainguard’s pricing page lists a seven-day SLA for critical vulnerabilities and 14 days for high, medium, and low vulnerabilities for applicable offerings. Buyers should confirm the exact scope and contract language rather than assuming the terms apply to every product or plan.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →This approach can reduce patching and triage work, but it does not eliminate the need for vulnerability management. Customers must still verify provenance, promote updated image digests through CI/CD, test compatibility, and address application flaws, secrets, identity risks, runtime threats, and misconfiguration.
Operating traction behind the valuation
Chainguard reported several growth indicators alongside the financing:
- Revenue increased from $5 million to $40 million over the preceding year.
- The company added more than 100 customers; SecurityWeek described them as paying enterprise customers.
- The container-image catalog grew from 400 to 1,400 images in one year.
- Chainguard said it planned to exceed $100 million in revenue during 2025.
- The company said customers had collectively saved more than 288,000 engineering hours.
These figures are company-reported or based on executive statements, not audited public-company financial disclosures. The $100 million figure should be treated as a forecast. SecurityWeek described a forecast of more than $100 million in annual recurring revenue, while Chainguard’s announcement used the term revenue. Revenue and ARR are not interchangeable, so the figures should not be merged into a single valuation calculation.
Reported customer names included ANZ Bank, Canva, GitLab, Hewlett Packard Enterprise, Oceaneering International, Snap, Univar Solutions, VPBank, and Wiz. Customer references indicate commercial adoption, but they do not establish how much each organization spends or which Chainguard products it uses.
Is the $3.5 billion valuation justified?
A rapidly growing cybersecurity infrastructure company can command a substantial private valuation when investors believe its product may become a standard layer in enterprise software development. Chainguard is targeting several durable pressures: expanding open-source use, increasing regulatory scrutiny, software-supply-chain attacks, and the rising cost of patching large application fleets.
Its reported increase from $5 million to $40 million in revenue, expanding image catalog, and enterprise customer growth help explain the investor interest. The company is also attempting to expand its addressable market beyond containers into libraries, virtual machines, and other open-source artifacts.
However, the financing does not establish that Chainguard is worth $3.5 billion under every valuation method. More specifically, the Series D valuation does not publicly answer:
- Whether the $3.5 billion figure is pre-money or post-money.
- What liquidation preferences or other preferred-share terms investors received.
- How much capital was primary financing versus secondary liquidity.
- Chainguard’s gross margins, net retention, customer concentration, cash burn, or profitability.
- Whether the company has a defined path to an initial public offering.
Accordingly, the accurate wording is that the Series D valued Chainguard at $3.5 billion. It should not be presented as a verified current valuation, especially because the financing announcement is historical and the available information does not establish whether it was the company’s latest financing after April 2025.
Free tools Windows power users keep installed
One-click scans. No signup required.
Where Chainguard may fit—and where it may not
Potentially strong fit
- Organizations operating large container fleets and carrying substantial vulnerability-remediation workloads.
- Regulated businesses requiring signed artifacts, SBOMs, provenance, or compliance evidence.
- Platform teams that want a curated image catalog instead of maintaining many internal base images.
- Companies where emergency patching and vulnerability triage cost more than a commercial subscription.
Potentially weak fit
- Small teams needing only one or two standard images.
- Organizations that already build minimal, signed, continuously rebuilt artifacts internally.
- Applications dependent on unusual packages, unsupported versions, or legacy operating-system behavior.
- Teams that cannot accommodate changes to Dockerfiles, package names, users, shells, certificates, or filesystem assumptions.
- Businesses whose main security problem is runtime detection, identity, cloud posture, or application logic rather than artifact integrity.
Minimal images can omit shells, package managers, debugging utilities, libraries, locale data, or expected filesystem paths. Replacing a base image can also change UID/GID behavior, default users, and certificate stores. These migration costs are important parts of the commercial decision.
Best Value
- HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
- UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
- OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
- RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
- EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
Competitive and strategic risks
Chainguard competes not only with security vendors, but also with internal platform teams and existing software-delivery infrastructure. Organizations may choose to build and maintain their own hardened images, use cloud-provider catalogs, or combine open-source tools with an artifact registry.
Alternatives occupy different parts of the market. Snyk focuses on application, dependency, and container security; JFrog provides artifact management and software-supply-chain infrastructure; GitLab integrates CI/CD with application security; Docker serves teams centered on its container ecosystem; and Trivy is an open-source scanning option for organizations willing to operate more of the workflow themselves.
The key strategic question is whether customers want a vendor-built stream of hardened artifacts or prefer to scan and manage their existing software themselves. Chainguard’s model can reduce operational work, but it introduces subscription costs, migration effort, reliance on a vendor’s catalog, and potential lock-in.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →What the funding is intended to support
Chainguard said the capital would support go-to-market expansion and its growing customer base. The broader strategy is to cover more classes of open-source software while making secure artifacts easier for enterprises to adopt and maintain.
For investors, the critical execution challenge is turning strong early growth into durable recurring revenue, high retention, attractive margins, and efficient customer acquisition. For customers, the question is whether the reduction in engineering labor and security exposure justifies the subscription and migration costs.
Pricing context
Chainguard’s pricing page, seen in August 2026, listed five free container images and a catalog plan starting at $19,000 for a team of 10. Broader container, library, VM, compliance, and enterprise arrangements may require a quote, and pricing can change.
That starting price is not a complete cost estimate. Enterprise buyers should request a quote covering image count, library and VM coverage, FIPS or STIG requirements, support, private packages, migration assistance, and any applicable discounts.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteBottom line
Chainguard’s $356 million Series D was a real financing announced on April 23, 2025, and it valued the company at $3.5 billion. The round was led by Kleiner Perkins and IVP, with Salesforce Ventures, Datadog Ventures, and existing investors participating.
The investment case is based on a shift from reactive vulnerability scanning toward secure-by-default software artifacts that are minimized, rebuilt, signed, and accompanied by provenance and SBOM data. Reported growth supports the case for investor enthusiasm, but public disclosures do not establish profitability, retention, margins, financing terms, or a current valuation. The round is best understood as a large venture bet that trusted software artifacts will become core enterprise infrastructure—not as proof that Chainguard has eliminated software-supply-chain risk.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

