Chainloop centralizes software delivery artifacts and evidence to help teams track security, compliance, and context across the delivery process. Its evidence store can hold metadata for SBOMs, QA reports, vulnerability scans, and legal reviews. The service links artifacts and metadata in a provenance graph, supporting control gates, quality checks, and compliance dashboards. Its CLI and integrations collect pipeline evidence, including Git commit details and pipeline configuration, and documentation describes digital signing with SLSA, in-toto, Sigstore, or customer PKI such as AWS KMS or Keyfactor. The paid platform adds curated policies and frameworks including SLSA, SSDF, CRA, DORA, and NIS2. Chainloop offers cloud and self-managed deployment, including on-premises and airgapped options. Community Edition is free and open source, self-hosted, and includes community support, but has no UI or curated policy library. The enterprise platform lists dedicated support; its price is available by contacting the company.
Who it is for
Community Edition is aimed at technically skilled starters, evaluators, and small teams. The enterprise platform is for organizations seeking SDLC security and compliance across cloud or self-managed deployments.
What is good
- Evidence store includes SBOMs, QA reports, scans, and legal reviews.
- CLI and integrations capture CI/CD pipeline context.
- Supports on-premises and airgapped deployments.
- Community Edition is free and open source.
What to know first
- Community Edition is self-hosted and has no UI.
- Community Edition lacks a curated policy library.
- Some integrations are limited to paid plans.
- Enterprise pricing is available by contacting the company.
Verdict
Chainloop combines artifact evidence, provenance context, and pipeline attestations for software delivery security and compliance work. Community Edition provides a free self-hosted starting point, while curated policies and dedicated support are part of the paid platform.
Chainloop plans and pricing
All plansCompared on software supply chain security software
- Free plan
- Yes
- Source & repo security
- Yes
- Dependency analysis
- Yes
- SBOM management
- Yes
- Build provenance
- Yes
- Artifact signing
- Yes
- Provenance attestations
- Yes
- Release policy gates
- Yes



