OSTIF // Open Source Security Fund

Fund the audits that keep open source secure.

OSTIF runs independent security audits and rapid response work for the open source software the internet quietly depends on. Every dollar covers labor hours, specialist skill, and the research it takes to find and fix vulnerabilities before someone else finds them first.

100+
Projects audited

200+
Projects secured

900+
Vulnerabilities found

Why it matters

Open source runs on volunteer time. Security work can’t.

TRACK RECORD

Proof, not promises

We’ve audited over 100 projects, created measurable security impact in more than 200, and found 900 vulnerabilities — many in infrastructure you rely on every day.

SCALE

The problem keeps growing

Vulnerabilities surface at a frightening rate, and fixing them takes increasingly specialized, hard-to-find skill.

SPEED

Containment can’t wait

A live vulnerability needs a fast response. There’s no time to run a fundraiser for each individual case.

ACCESS

Not every project can ask

Some maintainers can’t fundraise for themselves — they’re too busy shipping code, or have no legal structure to accept funds at all.

Trusted by

Join the organizations already funding our work

How to help

Fund an audit, not a pitch deck

You or your company can fund OSTIF through a general, tax-deductible donation. There’s no minimum, and no obligation tied to a specific project — you’re backing the audit pipeline itself.

e.g. DuckDuckGo gives OSTIF $25,000 USD every year.