Back to the registry
Agent passport

Chainloop

pcloudhosting · Software Development

Virtual MachinesNo attestation published

Certification per Microsoft Marketplace.

Provenance reach3 of 12 layers traced

Evidence tier Source Confirmed · 9 captures on record

User rating5 ★1 review on the listing
Runs onVirtual MachinesVirtual machine
ProvenanceUnknown33% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on Microsoft Marketplace.

Chainloop CLI is a command-line–driven software supply chain security solution designed to generate, manage, and verify attestations for build artifacts, source code, and CI/CD workflows. It enables organizations to ensure the integrity, traceability, and trustworthiness of software components without relying on graphical interfaces.

The solution supports modern DevSecOps and supply chain security workflows, including artifact attestation, provenance verification, and policy enforcement. Chainloop integrates seamlessly with CI/CD pipelines to provide cryptographic proof of how software is built and delivered, helping organizations meet compliance and security requirements.

Show the rest of the publisher’s description (13 more lines)

Features of Chainloop CLI:

  • CLI-based software supply chain attestation and verification.
  • Generation and validation of provenance for build artifacts.
  • Seamless integration with CI/CD pipelines and automation tools.
  • Policy enforcement and compliance support for secure software delivery.
  • Support for modern supply chain security standards and formats.
  • Scalable and automation-friendly for scripting and enterprise workflows.

To check if the Chainloop CLI is installed and accessible, use the following steps:

Check CLI version:

$ chainloop version

View available commands:

$ chainloop --help

Disclaimer: Chainloop CLI is provided “as is” under applicable open-source licenses. Users are responsible for proper configuration, secure key management, and validation of attestations. This solution is best suited for securing software supply chains, CI/CD pipelines, and artifact provenance in automated and cloud-native environments.

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Compliance

Government
  • FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27

Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.

Vendor

External enrichment · as of 2026-08-29

CompanyPcloud HostingAutomated
HQUnited States of AmericaAutomated
IndustryTechnologyAutomated
Websitehttps://pcloudhostings.com/

Sources

Marketplace listingmarketplace.microsoft.comSource
Privacy PolicyPrivacy PolicySource

Publisher resources

1 link

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Unknown
Not stated
Delivery
Virtual machine
https://pcloudhostings.com/
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.