The Open Source Technology Improvement Fund is a corporate non-profit dedicated to securing open source apps that we all depend on. Securing software isn’t easy, and we know what it takes to succeed. By facilitating security audits and reviews, OSTIF makes it easy for projects to significantly improve security.

Connecting Security Experts

We maintain a global community of researchers and auditors who specialize in open-source security, and can quickly organize major initiatives when the need arises.

Our team navigates the complexities of procuring security resources so you don’t have to.

Learn more about OSTIF »

Cost-effective and productive audits

Leading research suggests that focused, properly scoped security reviews result in significant and impactful improvements.

Our proven methodology and deep expertise allow us to deliver audits effectively and efficiently.

OSTIF supported projects »

Better Security Through Community

Through the Open Source Technology Improvement Fund, projects have been able to find and fix critical security bugs. Working together, we have protected millions of technology users around the globe.

10
partner projects

25+
sponsors

3500+
hours of security review

100+
bugs patched

billions
protected

Support the OSTIF Mission

Open-source projects keep today’s Internet infrastructure afloat. They are critical for the operation of every webserver, every browser, and every banking platform. And they are cared for by a surprisingly small group of people with a limited amount of time. Without dedicated security experts, these projects often don’t get the attention they require.

We can do it with help from supporters like you.

Become a SponsorDonate Today

OSTIF has Received Another Contribution from DuckDuckGo Duckduckgo, the privacy search engine, has contributed to OSTIF for a second time by donating $25,000 USD. Their site that tracks their charitable donations Spread Privacy has the official announcement.… Read more »
OSTIF is working with the Open Source Security Foundation on Symfony OSTIF has been working with the Open Source Security Foundation's Securing Critical Projects working group to help identify critical pieces of infrastructure that require focused security attention. Symfony, a widely… Read more »
Google is partnering with Open Source Technology Improvement Fund, Inc to sponsor security reviews of critical open source software Announcement:  Google is partnering with Open Source Technology Improvement Fund, Inc to sponsor security reviews of critical open source software.  OSTIF is elated to announce that we are planning to… Read more »