Who We Are

Creators of Minefield, a lightning-fast SBOM graphing tool that has become the go-to solution for vulnerability impact analysis in enterprise security stacks.

We’re leading contributors to critical open source security projects that protect the modern software supply chain, including OpenSSF Scorecard,Criticality Score, GUAC, gittuf, and Sigstore. Our expertise is recognized across the industry through presentations at Linux Foundation conferences, RSA, and DEF CON, along with 3× Google Peer Bonus awards for our impact on the security ecosystem.

Our Story

A critical red team exercise of ours revealed what others missed, attackers could silently swap model weights post-deployment without detection. While traditional security stops at code review, we discovered that the real threats emerge during runtime.

Bomfather was born from this revelation. Our solution leverages eBPF within the Linux kernel to create a Merkle tree security architecture that monitors, protects, and comprehensively logs every file access, GPU call, and system interaction in real time. This cryptographic chain not only detects unauthorized changes to models, data, or libraries but also actively protects against them while maintaining immutable records of all system activities.

User's avatar

Subscribe to Bomfather

Insights into kernel level security.

People

Co-Founder of Bomfather | OpenSSF project maintainer | Leetcode Knight | NYU research assistant | Youngest speaker at Cloud Native Security Con
Nathan Naveen, is a co-founder of Bomfather, is passionate about algorithms and is a Leetcoder. He is actively involved in coding competitions, contributes to open-source projects, and is a jiu-jitsu practitioner.