Package firewall
Every install goes through one gateway with a policy in front: known-bad packages are stopped, brand-new versions wait, and what passes is recorded.
What it watches
- Every install, every ecosystem
Requests from machines and pipelines through one gateway for each package ecosystem you use.
- Known-bad packages
Shared intelligence on malicious packages, seeded from open vulnerability databases and kept current.
- Brand-new versions
A cooldown for versions published hours ago, the window most malicious releases use.
- Policy
Blocklists, allowlists and per-team rules, with the reason each package was stopped.
- Out-of-policy installs
Machines that went around the gateway, and what they installed.
- Exfiltration attempts
Install scripts that try to send tokens, keys or files out of the machine.
Three modes, one gateway
Teams start by watching, then block what is clearly bad, then lock the side doors. Each step is a setting, not a migration.
- MonitorWeek 1
- Every install is recorded
- Nothing is blocked
- A baseline of what your teams really use
- EnforceWhen the baseline is clean
- Known-bad packages are blocked
- New versions wait out the cooldown
- Blocks explain why and who can override
- StrictFor sensitive teams
- Installs only through the gateway
- Side doors to public registries closed
- Unknown sources need an approval
A local cache keeps verdicts fast, so developers wait milliseconds, not seconds.
How it connects
Every module reports to the tower. Some feed each other.
Reports to
Fed by
The services behind it
The module watches. These services set the station up, with your team, so there is something worth watching.
In development. Early-access teams get it first and shape what it watches.
Join early access →