The Open Source Technology Improvement Fund is a corporate non-profit dedicated to securing open source apps that we all depend on. Securing software isn’t easy, and we know what it takes to succeed. By facilitating security audits and reviews, OSTIF makes it easy for projects to significantly improve security.

Better Security Through A Massive Community

 

Through the Open Source Technology Improvement Fund, projects have been able to find and fix critical security bugs.

62+
partner projects

1000+
world class security experts

5000+
hours of security review

100+
severe bugs patched

billions
protected

Support the OSTIF Mission

Open-source projects keep today’s Internet infrastructure afloat. They are critical for the operation of every webserver, every browser, and every banking platform. And they are cared for by a surprisingly small group of people with a limited amount of time. Without dedicated security experts, these projects often don’t get the attention they require.

We can do it with help from supporters like you.

Become a Sponsor

2024 CNCF/OSTIF Independent Security Audit Impact Report OSTIF is proud to share the results of our 2024 security audit collaboration with the Cloud Native Computing Foundation (CNCF). Over the past three years, OSTIF and the CNCF have… Read more »
OSTIF Receives a Fourth Yearly Donation from DuckDuckGo For a fourth year in a row, DuckDuckGo has generously donated to the Open Source Technology Improvement Fund (OSTIF) as part of its annual charitable donations program.  Funding administrative overhead… Read more »
Node.js Fuzzing Audit Complete! OSTIF is proud to share the results of our security audit of Node.js. Node.js is an open source project that is designed to build scalable network applications through asynchronous event-driven… Read more »