Loading…
Loading…
Local-first CLI and dashboard that scans source, dependencies, lockfiles, live URLs, SaaS toolchains, and Docker attack paths. Outputs SARIF, SBOM, OpenVEX, policy decisions, and triage-ready evidence for release gates.
CLI-first scanner with optional dashboard for project history, scoped API keys, policy packs, integrations, and audit logs. Depth modes from direct manifests to recursive dependency graphs.
CI release gates
AppSec triage workflows
SBOM and VEX evidence packs
Supply-chain risk scoring
Share constraints, integrations, and timeline. We will map architecture and delivery options.