Ten quarters ago, I reached out to my friend, Anand Revashetti, then a Fellow and Chief Architect at McAfee, with a simple question: Can you detect software supply chain tampers with any existing cyber-security tool? It was clear that runtime cybersecurity tools ignored how software was built. As always, he went down the path of detailed analysis.
Three days later, he had an answer. Every Shift-left tool, whether it’s a SCA tool, an App-Sec tool, a code-analysis tool, or a vulnerability tool, every one of them could easily be fooled. While these tools claimed that they could detect the components in your software, they had no idea what was inside these components. Their detection capability was nothing but only on the superficial layer of your software component hierarchy. In reality, on average, more than 70% of all applications were sourced from open source and third-party components, which contributed to more than 95% of the inherent risk in your software. One could conclude that the visibility and detections provided by all the Shift-Left tools in the market was indeed at a very minimal.
The implications were stunning:
The US Government, aware of these challenges, passed Executive Order 14028 mandating commercial software developers to pay attention and rectify these shortcomings by putting a deadline by when these challenges had to be addressed.
By the end of March 2022, we launched Lineaje Inc. – a company that would trace the complete lineage of all software, attest every component, and comprehensively and accurately assess risk starting with software in any form-factor: source code, containers, shipping binaries, and mobile apps, and, finally, optimize software risk remediation to provide relief to overwhelmed security professionals and software developers.
The technology challenge led us into a deeply technical, confused world where software development factories manage people, processes, and tools but not the ingredients that make up the final product. So, Lineaje delivered a sequence of industry firsts - groundbreaking innovations that are copied by fast-moving competitors and some slower whales.
We are proud to be the leading software supply chain innovator.
Every company today is a software company. Every software company has a software supply chain – as they source, build, sell, deploy, or buy software. And so, Lineaje offers software supply chain management solutions for software you source, build, sell, deploy or buy. Our products reduce risk in ALL software you use.
The AI revolution is upon us and the impact of AI risks is as large as its promise. AI software is more opaque, more tamperable and brings more risks. Our products reduce AI risk.
A Harvard Business Review Study published Jan 1, 2024. Harvard Business Review Study published Jan 1, 2024 estimated the value of open-source software usage for organizations to be $4.15 billion. They estimate the value generated by these open-source components to be $8.8 trillion. Open-source software is almost completely opaque, lightly maintained, and unmanaged. Our products reduce open-source risk and manage open-source software.
In 2024, according to Statista, Enterprises will spend more than a trillion dollars purchasing software. Our products can assess and reduce risks in software organizations’ buy.
We see the opportunity for Lineaje to be an essential ingredient in this digital transformation, needed by every organization that sources, builds, sells, or deploys software. We build products focused on these 4 spaces to help organizations:
Raising money is hard. At Lineaje, we have looked for “Greener than Green” investors -Investors whose money’s impact on Lineaje is multiplicative.
Beyond these, the round contains investment from SecureOctane, AlumniVentures, J-Ventures and additional contributions from senior cyber-security executives.
The new investment brings our total funding to $27 million ($7 Million Seed + $20 Million Series A).
Ultimately, we build the company and our products for our customers. Last two years we have worked with brilliant, cutting-edge customers. That is a great privilege. They help us build highly innovative products.
A mantra that is critical for us to deploy technology without creating waves, so your technology can create waves. With that goal, we will invest to build a world-class GTM organization accelerating customer acquisition, expanding partner distribution network, and given deep penetration in the U.S. public sector, delivering services for highly secure defense deployments.
In addition, Lineaje will fortify its AI-powered platform, expand its innovative BOMbots solution insights, and introduce new AI advancements to autonomously resolve software supply chain issues transparently.
We are amazingly pumped by this investment in our vision for the company. Our technology is groundbreaking, our market unrestricted, our investors are the greenest, and now it is time to put our heads down and execute!
Meet us at The Software Supply Chain Security Summit or at Booth SC212 at Black Hat