The Open Source Technology Improvement Fund is a corporate non-profit dedicated to securing open source apps that we all depend on. Securing software isn’t easy, and we know what it takes to succeed. By facilitating security audits and reviews, OSTIF makes it easy for projects to significantly improve security.

Better Security Through A Massive Community



Through the Open Source Technology Improvement Fund, projects have been able to find and fix critical security bugs.

partner projects

world class security experts

hours of security review

severe bugs patched


Support the OSTIF Mission

Open-source projects keep today’s Internet infrastructure afloat. They are critical for the operation of every webserver, every browser, and every banking platform. And they are cared for by a surprisingly small group of people with a limited amount of time. Without dedicated security experts, these projects often don’t get the attention they require.

We can do it with help from supporters like you.

Become a Sponsor

Our Review of Falco is Complete! Falco joins a growing number of CNCF Projects that completed a third-party security audit organized by OSTIF. A follow up to their 2019 audit, the Falco project requested a new… Read more »
The OSTIF Impact Report for the Cloud Native Computing Foundation Open Source Technology Improvement Fund (OSTIF) is proud to share the Cloud Native Computing Foundation (CNCF) Impact Report for 2022. This report is a follow-up to our August 2022 post… Read more »
Our Software Supply Chain Audit of Git for Windows is Complete Open Source Tech Improvement Fund (OSTIF) is proud to announce that our work with Chainguard on the supply chain review of git for Windows is complete. We'd like to thank… Read more »