What is the average CVE remediation time for critical vulnerabilities using Chainguard?
The average remediation time for critical CVEs is 20 hours, with a contractual SLA of 7 days for critical vulnerabilities and 14 days for high/medium/low severity issues.
How does Chainguard help with FedRAMP certification?
Chainguard offers FIPS-validated, STIG-hardened, and zero-CVE images off the shelf, which significantly shrinks the FedRAMP timeline. It addresses critical FedRAMP controls by default, provides an SLA for CVE management, simplifies POA&M reporting, and generates full build-time SBOMs and code signatures.
Are there free options available for Chainguard products?
Yes, Chainguard Containers offers a 'Free Images' tier with a select set of approximately 50 images for testing and deployment, including latest tags only.
What types of language libraries does Chainguard secure?
Chainguard Libraries provide malware-resistant, CVE-patched language libraries for Python, Java, and JavaScript ecosystems.
Does Chainguard offer discounts for multiple products or specific organization types?
Yes, Chainguard offers volume discounts for multi-year agreements or higher usage, bundled pricing for adopting multiple products (containers, libraries, VMs), and specific pricing options for qualified startups, SMBs, and public sector organizations.
What is the 'EOL Grace Period' for Chainguard Images?
Chainguard provides updated end-of-life images for up to 6 months with an EOL Grace Period, ensuring continued security even for components past their official end-of-life.