The Open Source Technology Improvement Fund is a corporate non-profit dedicated to securing open source apps that we all depend on. Securing software isn’t easy, and we know what it takes to succeed. By facilitating security audits and reviews, OSTIF makes it easy for projects to significantly improve security.

Better Security Through A Massive Community

 

 

Through the Open Source Technology Improvement Fund, projects have been able to find and fix critical security bugs.

100+
partner projects

1000+
world class security experts

13000+
hours of security review

130+
severe bugs patched

billions
protected

Support the OSTIF Mission

Open-source projects keep today’s Internet infrastructure afloat. They are critical for the operation of every webserver, every browser, and every banking platform. And they are cared for by a surprisingly small group of people with a limited amount of time. Without dedicated security experts, these projects often don’t get the attention they require.

We can do it with help from supporters like you.

Become a Sponsor

2026- a (very early) OSTIF retrospective Welcome back from summer vacation! This year has been so busy for OSTIF and the industry at large that it’s been nice to hear from many folks that they’ve taken… Read more »
Security Engineer in Residence Program Breaking the Cycle of Security Funding OSTIF has been advocating for open source security funding over the past decade. During that time when there was an exploit or devastating hack,… Read more »
OSTIF AI Use in Security Research Policy Artificial Intelligence (AI) Use in Security Research Policy First version: April 2026  |  Second version: May 2026  |  Last updated: July 2026 Refer to the OSTIF Open Source Security Audit… Read more »