Cairnlytics Logo

CAIRNLYTICS

Understand Open-Source Risk

Edinburgh Decentralisation Index Logo
What's Your Open-Source Risk?
Dependency

Your software stack is like a cairn - a tower of stones. It looks solid from the outside, but its stability relies on dependencies you didn't create and often don't see. The Cairn Index measures the structural integrity of these hidden stones, analysing development history to pinpoint weak spots before the whole stack collapses.

Who is Cairnlytics For?

Whether you are a developer, a compliance officer, or an overseer of open-source procurement, Cairnlytics empowers you to make informed, evidence-based decisions.

Follow us on LinkedIn

Software risk scores

Out of 1000

Firefox
124
Docker Bus Factor Risk
512
Kubernetes
201
OpenVPN
579
TensorFlow
53
Node.js
658
OpenSSL
973
!
PostgreSQL
159
Apache Kafka
301
Vim
177

Note: Data presented in this mock-up is for demonstration purposes only.

OpenSSL973/1000

Historical risk scores

0 200 400 600 800 1000 Jan-10 Mar-10 May-10 Jul-10 Sep-10 Nov-10 Jan-11 Mar-11 May-11 Jul-11 Sep-11 Nov-11
Author
Merge committer
Line changes
Last commit
Today
Developers
1
Reviewers
1
Contributors
(all time)
4!
Contributors
(last year)
2!
Time to patch after vulnerability disclosure: 3 weeks (avg)

Note: Data presented in this mock-up is for demonstration purposes only.

Achieve Regulatory Compliance

Cairnlytics helps IT companies achieve regulatory compliance by delivering data-driven evidence aligned with key standards like DORA, the UK's Cyber Security and Resilience Bill, FCA PS21/3, SBOM, PCI DSS 4.0, the NCSC Cyber Assessment Framework, and the UK's Software Security Code of Practice. It also tackles NCSC Cross-Cutting Problems by making assessments more data-driven (CC2) and establishing meaningful security metrics (CC3).

Frictionless & Objective Insight

Traditional Third-Party Risk Management (TPRM) tools rely on questionnaires and audits - methods that fail with open-source software because there is no vendor to interview. Cairnlytics bridges this gap. Simply enter a repository URL or import your SBOM. We instantly generate objective risk scores and real-time alerts, replacing blind trust with measurable data.

Academic Rigour & Transparency

We quantify software supply chain resilience through non-intrusive, data-driven concentration risk analysis. Cairnlytics is a pre-spinout from the Edinburgh Decentralisation Index™ (EDI), a pioneering project at the University of Edinburgh initiated in 2022. We build upon the EDI codebase, which is open source under an MIT licence.
EDI website: https://informatics.ed.ac.uk/blockchain/edi

Mojtaba Tefagh - Technology Transfer & Go-to-Market Strategy

Laura Antunes - Lead Researcher, Supply Chain Risk Analytics

Callum Ruddock - Commercial Lead, Business Development