dpndncY
Self-managed · air-gapped support · no telemetry
Application Security from code to runtime.

A self-managed application-security platform. SCA, SAST, IaC, secrets, container scanning, attack paths, dependency firewall, and runtime monitoring on a single cryptographic signing root. Runs on your infrastructure. Air-gapped operation supported.

30+ ecosystems24 SAST languages1,500+ rulesSBOM · IaC · secrets · runtime
app.dpndncy.com/scans/dpndncy-bench · findingsExample scan
30+ ecosystems
npm·PyPI·Maven·Gradle·Go·NuGet·Cargo·RubyGems·Composer·Hex·Pub·Swift PM·CocoaPods·Carthage·Conan·CPAN·CRAN·Conda·OPAM·PEAR·Debian·Alpine·RPM·OCI images·
24 languages · SAST
JavaScript·TypeScript·Python·Java·Kotlin·Scala·Groovy·C#·VB.NET·Go·PHP·Ruby·Swift·Objective-C·Objective-C++·Dart·Apex·C·C++·CUDA·Fortran·JSP·Erlang·Elixir·
Dependency intelligence

Every package, every path, every CVE.

Walk the full transitive tree and see exactly which vulnerabilities are reachable in your code — with fixes, not just noise.

  • Over 1,300 dependencies mapped, direct and transitive
  • Per-package CVEs, CVSS and EPSS, ranked by reachability
  • Fixed-in versions and one-click auto-fix PRs
/scans/dpndncy-bench · dependencies
Reachability graph — dpndncy-bench
reachable & criticalvulnerableclean

Why a CVE count isn’t an answer

This is one slice of a real scan. next@15.1.4 carries 25 advisories, but only the red path is reachable — your code actually calls into it. Everything else is inventory, not exposure.

Direct
Packages your manifest names. You choose these.
Transitive
Pulled in by your dependencies. You inherit these — most of the tree.
Reachable
A call path exists from your code to the vulnerable function. This is what to fix first.

In this run that filter cut 164 findings down to the 30 that are genuinely reachable.

/scans/dpndncy-bench
One scan, whole picture

Reachability first. Noise last.

Of 164 findings in this run, 30 are actually reachable in code — and 142 have a fix available. That ranking comes from KEV, EPSS, ExploitDB, NVD and your own advisories, so your team starts with what genuinely matters.

  • SCA, SAST, secrets, IaC, containers and pipeline in one pass
  • 1,316 dependencies resolved in 94 seconds
  • Every tab exportable as signed, offline-verifiable evidence
26
Critical caught
30
Reachable exploits
142
Auto-fixable
94s
Second full scan
The platform

Three layers sit on one signing root.

Every dpndncY capability shares the same exploitability-signal stack and the same DSSE-signing trust root. What changes between layers is where the decision lives.

Scan

Find the risk that matters.

Multi-ecosystem SCA across 30+ ecosystems, native SAST across 24 languages, IaC, container, secrets, attack paths. Findings ranked by KEV + EPSS + ExploitDB + reachability — not raw CVE count.

Read more
Block

Stop risk at install and at runtime.

The Dependency Firewall refuses risky packages before they enter your tree. The eBPF Runtime Agent attaches to four kernel hooks on your CI runners; in enforce mode, cgroup-BPF denies non-allowlisted egress.

Read more
Sign

Portable, offline-verifiable evidence.

Every decision ships as a DSSE envelope over a SLSA in-toto Statement, signed with your keypair. A standalone dpndncy-verify binary checks it offline — no portal, no vendor dependency.

Read more
Pipeline & action firewall

Stop bad builds before they run.

dpndncY inspects your CI/CD the way it inspects code — evaluating every GitHub Action and install step, then blocking or gating what fails policy.

  • Poisoned-pipeline & install-time execution detection
  • Per-action admission decisions: allow, review, block
  • observe → soak → enforce rollout, approval-gated bypass
/scans/dpndncy-bench · pipeline
Supply-chain threat surface

Threats come from everywhere. Your firewall lives here.

Every pink dot is a real, documented supply-chain incident — event-stream, ua-parser-js, ctx, colors / faker, XZ Utils, tj-actions/changed-files, dozens more. The cyan arcs are threat signals (KEV, EPSS, ExploitDB, OSV) flowing into your self-managed dpndncY install — where the decision actually gets made.

14
real incidents pinned
5
intel sources fused
1
enforcement point — yours
drag to rotate · pink = incident · cyan = signal flowing to you
Show your work

Every decision is a file you can verify offline.

A standalone dpndncy-verify binary ships with the platform. Hand the attestation to your auditor, your customer, your insurer — they verify the signature with your public key. No portal login. No vendor dependency. No remote infrastructure to outlive you.

Signature verifiedDSSE
Ed25519 · offline · agent-pub.pem
Type
dpndncy.io/agent/runtime-trace/v1
Subject
github-actions/acme/widget #1234567
Digest
sha256:a1b2c3d4e5f6…
Builder
urn:dpndncy:agent 0.1.0
Window
2026-05-26 10:00:00 → 10:14:32 UTC
Mode
observe
412
connect
58
exec
4
file
23
dns
decisionsallow 489 · warn 8 · review 0 · block 0
top egress
  • registry.npmjs.org:443×37
  • api.github.com:443×12
  • objects.githubusercontent.com:443×6
secured · verifiable offline
Runs where you already build
GitHub ActionsGitLab CIJenkinsCircleCIAzure PipelinesBitbucket PipelinesBuildkiteTektonArgo WorkflowsKubernetesHelmactions-runner-controller

Know what you ship. Block what you shouldn’t.

Self-hosted, fully air-gappable, no telemetry. Every decision the platform makes is signed and verifiable with a public key. Early-access design partners get the full platform, direct engineering support, and input into the commercial model.