Open Source Technology Improvement Fund
The Open Source Technology Improvement Fund is a corporate non-profit dedicated to securing open source apps that we all depend on. Securing software isn’t easy, and we know what it takes to succeed. By facilitating security audits and reviews, OSTIF makes it easy for projects to significantly improve security.
Better Security Through A Massive Community

Through the Open Source Technology Improvement Fund, projects have been able to find and fix critical security bugs.
100+
partner projects
1000+
world class security experts
13000+
hours of security review
130+
severe bugs patched
billions
protected
Support the OSTIF Mission
Open-source projects keep today’s Internet infrastructure afloat. They are critical for the operation of every webserver, every browser, and every banking platform. And they are cared for by a surprisingly small group of people with a limited amount of time. Without dedicated security experts, these projects often don’t get the attention they require.
We can do it with help from supporters like you.
CNCF Managed Audit Program Report 2025 For the past 4 years, OSTIF has run a Managed Audit Program for the CNCF. We’ve audited 33 projects in that time, working with maintainers all over the world to… Read more »
Sovereign Tech Agency and OSTIF Security Audit Report OSTIF is a proud participant in the Sovereign Tech Agency's Sovereign Tech Resilience Program. Outside of that work, we've also been funded to carried out ad hoc security engagements on… Read more »
zlib Audit Complete! The Open Source Technology Improvement Fund is proud to share the results of our security audit of zlib. Zlib is an open source lossless data-compression library for use on virtually… Read more »