Chainguard, a company focused on secure open-source software, has joined the Fintech Open Source Foundation (FINOS) as a Gold Member. FINOS is the financial services vertical of the Linux Foundation. The collaboration aims to address software supply chain security challenges specific to the financial sector, particularly as AI accelerates both code production and vulnerability exploitation.
Overview
Open-source software is foundational to financial services, powering trading systems, digital banking platforms, and AI infrastructure. As AI reshapes software development, it increases the volume of code and vulnerabilities entering production environments. AI systems can now identify and exploit vulnerabilities faster than organizations can patch them, while threat actors use AI to compress attack timelines. For regulated financial institutions, securing the software supply chain has become essential to operational resilience.
What Chainguard brings
Chainguard contributes expertise in software supply chain security, governance, and secure open-source adoption. The company builds and maintains an open toolchain for secure software delivery, contributes upstream fixes, and leads projects across the cloud-native ecosystem. Chainguard team members actively maintain and contribute to more than 100 widely used open-source projects, including Kubernetes, Sigstore, SLSA, Tekton, and Knative.
Chainguard also operates EmeritOSS, a program launched last year that offers safe, predictable maintenance for mature open-source projects that have reached stability. More recently, the company introduced DriftlessAF, an open-source agentic framework focused on reducing operational drift and improving software delivery consistency in modern infrastructure environments.
Focus areas
The collaboration will focus on standardizing best practices for trusted open-source adoption, with particular attention to software bill of materials (SBOM) management and secure open-source dependencies. FINOS provides a neutral, well-governed home for open-source collaboration across the financial industry, with a global community of more than 100 member organizations including major financial institutions, fintechs, and technology firms.
Why this matters
Dan Lorenc, CEO and Co-founder of Chainguard, stated that as AI accelerates how code is written, financial institutions cannot afford to build on software they cannot trust. Gabriele Columbro, Executive Director of FINOS, noted that no single institution can solve the resulting security, governance, and resilience challenges alone, and that Chainguard's expertise will help translate industry-wide principles into practical, production-ready open-source projects and standards.
Bottom line
Chainguard's membership in FINOS represents a practical step toward standardizing secure open-source practices in financial services. For institutions operating under regulatory scrutiny, the collaboration offers a path to adopt AI-driven development while maintaining control over software supply chain risks.