
Chainguard Raised $50M from Sequoia With No Revenue — Then Killed Its First Product: Dan Lorenc's Story
August 24, 2026
TL;DR: Chainguard is a software supply chain security company that sells hardened, continuously patched container images of open source software with a zero-CVE guarantee. It was founded in October 2021 by Dan Lorenc (CEO) and a team of ex-Google colleagues, after Lorenc quit Google with no startup idea at all. He raised a $5M seed within months and then $50 million from Sequoia, pre-revenue, on a handshake at a dinner table, with no pitch deck. Chainguard then built two products at once, got the first one to about $1M ARR — and killed it, because the second one was outgrowing it 10 to 1. Today Chainguard has raised $356M in a Series D at a $3.5 billion valuation. Lorenc told the whole story on The Product Market Fit Show.
What does Chainguard do?
Chainguard's product is a catalog of container images: the same open source software everyone already uses, but built, hardened, patched and maintained by Chainguard.
The problem it fixes is mundane and enormous. Pull the most up-to-date Python image from a public registry and, as Lorenc points out, it can carry roughly 1,400 known vulnerabilities before you write a single line of your own code — because public images bundle extra components and don't get updated often.
"Instead of like a tool to tell you about your supply chain issues, we just fix a whole bunch of them for you." — Dan Lorenc, Chainguard
Key stat: Chainguard offers a zero-CVE SLA, fixing newly discovered vulnerabilities within seven to fourteen days.
The catalog was around 900 images at the time of the episode, growing by roughly 100 a month. Pricing is an annual subscription based on how many images you pull, with tiers by company size — SaaS-style billing, but customers run the images on their own infrastructure.
Who founded Chainguard?
Chainguard was founded in October 2021 by Dan Lorenc (CEO), Matt Moore (CTO), Kim Lewandowski (CPO), Ville Aikas and Scott Nichols — a team that had worked together securing Google's own software supply chain.
Lorenc spent nearly a decade at Google, joining as an engineer in the earliest days of Google Cloud, working across cloud infrastructure and security. He watched Google's internal security posture change after Project Aurora and the Snowden disclosures — from "hackers" to nation-state adversaries with more resources than the biggest tech companies — and then watched the industry forget all of it as public cloud and open source exploded.
Then SolarWinds happened at the end of 2020: attackers compromised a vendor's build servers and pushed malware into the product its customers bought. Software supply chain security went from niche to national news.
The founding decision itself was almost aggressively casual. Moore had taken a sabbatical during the pandemic to do barbecue, and one day texted Lorenc that he was ready to quit and start something:
"If I think about this too much, I'd probably change my mind. But this does seem like a good idea. Let's go do it." — Dan Lorenc, Chainguard
They had no idea what to build. They knew only the problem area.
How much has Chainguard raised?
Chainguard's funding history is one of the more extreme in modern enterprise software:
- Seed — $5 million (2021). No pitch deck.
- Series A — $50 million from Sequoia Capital (2022). Pre-revenue. Handshake at a dinner; term sheet in three days.
- Series B — end of 2023, raised on a couple million in ARR after the images product took off.
- Series C — $140 million, closed shortly before the episode.
- Series D — $356 million at a $3.5 billion valuation (April 2025), co-led by Kleiner Perkins and IVP, with Salesforce Ventures and Datadog Ventures joining. Reported ARR at that point: $40 million.
"I just like pulled up my inbox and I was just like, these investors have been emailing me to chat about if I'm ever going to quit. Let me just respond to some of those emails and see." — Dan Lorenc, Chainguard
"Yeah, we didn't do a pitch deck or anything like that." — Dan Lorenc, Chainguard
The Sequoia round was pure timing. Chainguard planned to raise at the end of 2021 and was turning down preemptive offers. Then a seed investor called and said the market was turning. Lorenc happened to have dinner booked with Sequoia the next day.
"We like shook hands on terms that night at the dinner table." — Dan Lorenc, Chainguard
"They originally offered us less money and I was like, how about we take more money because we're trying to survive this crazy market downturn and they were even happier as a result." — Dan Lorenc, Chainguard
A month later, at close:
"I still remember at the end of the month, they were like, we wouldn't do this round again today." — Dan Lorenc, Chainguard
Key stat: three days from dinner to term sheet, roughly a month to close, and zero revenue at signing.
For the founder's side of this, see product market fit with no revenue and how to close a funding round fast.
Building two products on purpose — and killing the one that worked first
This is the part of Chainguard's story that founders should study, because it inverts the standard advice.
With $50M and a large engineering team, Chainguard deliberately split in half and built two products simultaneously:
- Chainguard Enforce — a policy, visibility and control dashboard that watched how developers wrote, built and deployed code and enforced gates along the way.
- Chainguard Images — the hardened open source container images that became the company.
"We started with two things about as far apart as you could be, hoping one of them worked." — Dan Lorenc, Chainguard
"It would have been crazy if both ideas we had worked." — Dan Lorenc, Chainguard
The reasoning was about feedback latency, not conviction. Enterprise security deals run three-to-nine-month cycles; the 2022 market crash stretched them further. Running two bets in parallel was a way to get more shots on goal inside the same calendar.
Enforce sold first — and then died on the vine. It reached about $1 million in ARR, then pipeline stopped, and even signed customers stalled during rollout. Lorenc's diagnosis is brutal and clear:
"Nobody wanted to roll this thing out because it made developers jobs harder. And it was like, that's kind of the entire point is making jobs harder. Of course nobody wants to roll this thing out." — Dan Lorenc, Chainguard
He describes one customer meeting where the buyer said, in effect: this tells me none of my stuff is secure — I already knew that, so why would I pay you to tell me?
Meanwhile Images kept improving, and the same customers in the same demos started reacting differently. Within six or seven months, pipeline had flipped 10 to 1 toward Images. Chainguard moved the entire company onto it through 2022 and into 2023.
Never miss a founder's PMF story
Subscribe to The PMF ShowLorenc's framing for the difference is the cleanest version of an old idea:
"Even if everybody knows this is good, like it's still hard to get people to take their vitamins. Even if they know it's good and better in the long run versus like all my dashboards are on fire, I'm missing SLAs, my customers are yelling about these vulnerabilities." — Dan Lorenc, Chainguard
Key stat: Enforce stalled at ~$1M ARR; Images passed it in revenue and had 10x the pipeline within roughly six months.
If you're in the same position, pivot vs persevere and false product market fit cover exactly this failure mode: real revenue from a product nobody will roll out.
The anti-stealth playbook: becoming the most famous company in a market with no buyers
Chainguard's other unusual bet was spending 2022 — a year Lorenc assumed nobody would buy anything — building brand instead of pipeline.
"Let's just try to end the year as the most well-known company in the space." — Dan Lorenc, Chainguard
"I guess the one thing I never understood is the whole stealth thing of like, we're just not going to tell anybody what we're working on." — Dan Lorenc, Chainguard
The mechanics were cheap: blogs about what they were building, open source work, conference presence, and — most importantly — direct relationships with reporters. Every few weeks there was a new breach or a new government regulation, and Lorenc made sure he was the person quoted. He specifically flags LinkedIn as the channel he wishes he'd started earlier, and warns that it only works if the content isn't a pitch:
"You've got to actually be out there with genuine interesting opinions on stuff." — Dan Lorenc, Chainguard
There's a counterweight in the story worth noting: the same regulatory attention that made the space hot also delayed purchasing. Executive orders after SolarWinds and Log4j set multi-year timelines, so buyers knew they'd eventually have to act — and therefore waited.
Key lessons from Dan Lorenc's playbook
1. Painkillers beat vitamins, and "makes developers' jobs harder" is disqualifying. Enforce's entire value proposition required someone to accept friction. Images removed work. Same market, same buyers, opposite outcome.
2. Two deliberate bets can beat one, when feedback cycles are long. This isn't a license to lose focus. Chainguard was funded, staffed, and knew enterprise security deals take six months to teach you anything. Lorenc picked two ideas as far apart as possible on purpose.
3. Revenue is not proof. A million in ARR from customers who never finish the rollout is a signal to leave, not to double down. Watch implementation and pipeline, not just bookings.
4. Hire your first two sales reps earlier than the advice says. Lorenc's single biggest regret. Founder-led sales teaches you the value pitch, but it doesn't teach you how to navigate a six-month enterprise procurement cycle — and reps who know how "see signals you're not going to see."
5. Do the public work before you need it. A decade of open source contributions and blog posts is why the seed round took an inbox search instead of a pitch deck.
6. Raise from strength. Chainguard consistently raised while it still had runway. As Lorenc puts it: you don't want to raise when you're desperate.
FAQ: Chainguard
Q: What is Chainguard? A: Chainguard is a software supply chain security company. It builds, hardens, patches and maintains container images of open source software so that companies can use open source without inheriting its known vulnerabilities, backed by a zero-CVE SLA.
Q: Who is the CEO of Chainguard? A: Dan Lorenc, who co-founded the company in October 2021 after nearly a decade at Google working on cloud infrastructure, security and open source supply chain projects.
Q: Who founded Chainguard? A: Dan Lorenc (CEO), Matt Moore (CTO), Kim Lewandowski (CPO), Ville Aikas and Scott Nichols, all of whom had worked on securing Google's software supply chain.
Q: How much funding has Chainguard raised? A: Publicly reported rounds include a $5M seed, a $50M Series A from Sequoia, a Series B in late 2023, a $140M Series C, and a $356M Series D announced in April 2025.
Q: What is Chainguard's valuation? A: $3.5 billion as of its April 2025 Series D, up from $1.1 billion a year earlier.
Q: Who are Chainguard's investors? A: Sequoia Capital led the Series A; the Series D was co-led by Kleiner Perkins and IVP, with Salesforce Ventures and Datadog Ventures participating.
Q: What happened to Chainguard Enforce? A: Chainguard Enforce was the company's first product, a policy and visibility dashboard for the software development lifecycle. It reached roughly $1M ARR before stalling, and Chainguard shifted the entire company to Chainguard Images.
Sources: Listen to the Full Founder Story
- Dan Lorenc, Co-Founder & CEO of Chainguard — nearly a decade at Google on cloud infrastructure and open source security, then founder of the company that raised $50M from Sequoia pre-revenue and reached a $3.5B valuation.
- Full episode: He quit Google with no startup idea, raised $50M from Sequoia with no revenue — & grew to 8 figures in ARR on The Product Market Fit Show.
Last updated: August 2026
Want more founder stories like this?
Subscribe to The Product Market Fit Show for weekly episodes.
Subscribe Now