Chainguard provides trusted open source artifacts for every layer of your modern software stack—containers, language libraries, and VM images.
Summary from the company’s website.
Publicly advertised compliance posture
As observed on September 8, 2026 on the organization’s public trust center.
-
SOC 2
Independent CPA audit of controls for security, availability, and confidentiality.
-
ISO 27001
International standard for an information security management system, certified by accredited bodies.
-
Cyber Essentials
Publicly advertised on the organization’s trust center.
-
GDPR
Public claim of alignment with the EU General Data Protection Regulation.
-
CCPA
Publicly advertised on the organization’s trust center.
Compliance timeline
-
September 8, 2026
Posture last observed by Trust Index
Security & compliance hiring
Open roles on the organization’s public job board, a signal of active investment in security and compliance.
- Security Engineer
- Security Engineer
- Senior Product Security Engineer
- Senior Product Security Engineer
- Senior Product Security Engineer
- Senior Security Analyst (Governance and Trust)
- Senior Security Engineer (Cloud)
Subprocessors
Third parties Chainguard discloses on its trust center. Linked entries have their own profile in the Trust Index.
83% chain trust: 5 of 6 disclosed subprocessors are themselves in the Trust Index.
- Google Cloud Platform Cloud service provider
- Cloudflare Content delivery services
- Vercel Data infrastructure and hosting services
- Zendesk Customer support platform
- Okta Identity management services
- Feature-specific Subprocessors
About this data
The Trust Index reports only what organizations publicly advertise. A missing framework here means no public claim was observed as of September 8, 2026; it never means an organization is non-compliant. HIPAA entries reflect a public claim of compliance; no HIPAA certification exists. Corrections are welcome and verified against public evidence. Read the full methodology.