System administrators lack tools to verify that installed binaries match intended source code.
Create a service that cross-checks package hashes against multiple independent build environments, alerting on discrepancies.
Security-conscious enterprises would pay for continuous verification of their critical systems.
Start with major distribution packages before expanding coverage.
Risk is the service itself becoming an attack target.