A self-managed application-security platform. SCA, SAST, IaC, secrets, container scanning, attack paths, dependency firewall, and runtime monitoring on a single cryptographic signing root. Runs on your infrastructure. Air-gapped operation supported.
Every package, every path, every CVE.
Walk the full transitive tree and see exactly which vulnerabilities are reachable in your code — with fixes, not just noise.
- Over 1,300 dependencies mapped, direct and transitive
- Per-package CVEs, CVSS and EPSS, ranked by reachability
- Fixed-in versions and one-click auto-fix PRs
Why a CVE count isn’t an answer
This is one slice of a real scan. next@15.1.4 carries 25 advisories, but only the red path is reachable — your code actually calls into it. Everything else is inventory, not exposure.
- Direct
- Packages your manifest names. You choose these.
- Transitive
- Pulled in by your dependencies. You inherit these — most of the tree.
- Reachable
- A call path exists from your code to the vulnerable function. This is what to fix first.
In this run that filter cut 164 findings down to the 30 that are genuinely reachable.
Reachability first. Noise last.
Of 164 findings in this run, 30 are actually reachable in code — and 142 have a fix available. That ranking comes from KEV, EPSS, ExploitDB, NVD and your own advisories, so your team starts with what genuinely matters.
- SCA, SAST, secrets, IaC, containers and pipeline in one pass
- 1,316 dependencies resolved in 94 seconds
- Every tab exportable as signed, offline-verifiable evidence
Three layers sit on one signing root.
Every dpndncY capability shares the same exploitability-signal stack and the same DSSE-signing trust root. What changes between layers is where the decision lives.
Find the risk that matters.
Multi-ecosystem SCA across 30+ ecosystems, native SAST across 24 languages, IaC, container, secrets, attack paths. Findings ranked by KEV + EPSS + ExploitDB + reachability — not raw CVE count.
Read moreStop risk at install and at runtime.
The Dependency Firewall refuses risky packages before they enter your tree. The eBPF Runtime Agent attaches to four kernel hooks on your CI runners; in enforce mode, cgroup-BPF denies non-allowlisted egress.
Read morePortable, offline-verifiable evidence.
Every decision ships as a DSSE envelope over a SLSA in-toto Statement, signed with your keypair. A standalone dpndncy-verify binary checks it offline — no portal, no vendor dependency.
Read moreStop bad builds before they run.
dpndncY inspects your CI/CD the way it inspects code — evaluating every GitHub Action and install step, then blocking or gating what fails policy.
- Poisoned-pipeline & install-time execution detection
- Per-action admission decisions: allow, review, block
- observe → soak → enforce rollout, approval-gated bypass
Threats come from everywhere. Your firewall lives here.
Every pink dot is a real, documented supply-chain incident — event-stream, ua-parser-js, ctx, colors / faker, XZ Utils, tj-actions/changed-files, dozens more. The cyan arcs are threat signals (KEV, EPSS, ExploitDB, OSV) flowing into your self-managed dpndncY install — where the decision actually gets made.
Every decision is a file you can verify offline.
A standalone dpndncy-verify binary ships with the platform. Hand the attestation to your auditor, your customer, your insurer — they verify the signature with your public key. No portal login. No vendor dependency. No remote infrastructure to outlive you.
- Type
- dpndncy.io/agent/runtime-trace/v1
- Subject
- github-actions/acme/widget #1234567
- Digest
- sha256:a1b2c3d4e5f6…
- Builder
- urn:dpndncy:agent 0.1.0
- Window
- 2026-05-26 10:00:00 → 10:14:32 UTC
- Mode
- observe
- registry.npmjs.org:443×37
- api.github.com:443×12
- objects.githubusercontent.com:443×6
Know what you ship. Block what you shouldn’t.
Self-hosted, fully air-gappable, no telemetry. Every decision the platform makes is signed and verifiable with a public key. Early-access design partners get the full platform, direct engineering support, and input into the commercial model.