1. Home
  2. Products
  3. Chainsaw

Enterprise Products · Open core

Chainsaw

Block malicious packages before they download.

supply-chain signals, free on every tier
25
ecosystems through the registry proxy
16
enforcement surfaces, one signed policy
5
deployment models: SaaS, your VPC, air-gapped
3

Overview

Chainsaw is a firewall for your package installs. Every npm install, pip install or docker pull is checked against one signed policy and 25 supply-chain signals, and malicious or typosquatted packages are refused before a single byte lands on disk. Scanners and SCA tools report after the fact; Chainsaw decides on the install path. The guard and policy engine are open source, and the Chain305 platform adds the org-wide registry proxy, central policy, SSO, dashboards and SIEM export on top.

How it works

From setup to enforcement

  1. Step 01

    Turn it on

    One command wires the local guard into npm, pip, cargo, gem and go. To cover a whole organisation, change one registry URL per ecosystem so every install flows through the Chainsaw proxy. No SDK, no laptop agent, no CI plugin.

  2. Step 02

    Every request is evaluated

    Each package is checked in parallel, in low single-digit milliseconds, against vulnerability gates (CVE, CVSS, EPSS, KEV), licences, versions, provenance and the supply-chain attack signals.

  3. Step 03

    Bad packages are refused

    The install fails before download with the exact rule that fired, right in the developer's terminal. Allowed packages stream through a content-addressed cache, so repeat installs get faster.

  4. Step 04

    Monitor, then enforce

    Every rule can log its decision without blocking first. See what would fail across every repo and pipeline, add scoped exceptions with an expiry, then flip each rule to enforce.

Features

Key features

01

Stops the attacks behind the headlines

Install-script exfiltration (event-stream, ua-parser-js, xz-utils, PhantomRaven), maintainer takeover, publish-velocity worm bursts (Shai-Hulud), hidden characters (GlassWorm) and dependency confusion.

02

25 signals beyond CVEs

Typosquats across 15 ecosystems, install scripts, maintainer changes, release-age floors, version anomalies, reserved namespaces, container-image malware and AI model pickle ops.

03

Works offline

Known-malicious and typosquat data ships inside the binary, so the local guard blocks with the network unplugged.

04

One policy, five surfaces

The same signed Rego policy runs on the pull request, the developer's laptop, the CI proxy, internal publishing and Kubernetes admission, including installs your coding agents fire on their own.

05

Org-wide registry proxy

Enforces policy even on machines that never installed the CLI, across 16 ecosystems, with nothing to migrate from the registries you already use.

06

Hub-and-spoke federation

Every business unit inherits the central baseline and layers its own rules on top, with live spoke health and overrides visible before they ship.

07

Signed audit trail and SBOM

One signed audit row per decision, exportable for SOC 2, ISO 27001 and HIPAA reviews, plus CycloneDX 1.6 and SPDX SBOMs generated at install time.

08

Billy, the policy copilot

Drafts and explains policy changes, and the Hardening Wizard produces a Kubernetes admission, egress allowlist, MDM and CI bundle in one step.

09

Fails safe, not loud

If intelligence is degraded, installs proceed with an audit row (or refuse, if you choose). If an upstream registry is down, the cache serves previously allowed versions.

Who it's for

Built for how teams actually work

Developers

Malicious updates and typosquats are refused before they touch your disk. Type expresss instead of express and the guard stops it before the install resolves.

AppSec teams

Cut the window between disclosure and defence: one policy edit stops an affected version installing everywhere, with no coordinated upgrade PRs.

DevSecOps and compliance owners

The same licence, version and provenance rules apply in CI, on laptops and in Dockerfiles, and the evidence lands in the dashboard ready for auditors.

Enterprise IT

One deployment gives every engineering org the baseline, in SaaS, your VPC or fully air-gapped, with the same binary, API and policy format.

Technical details

Works with your stack

Local guard
npm, pip, cargo, gem, go
Registry proxy
npm, PyPI (pip, poetry, uv), Maven and Gradle, Cargo, Go modules, Composer, NuGet, RubyGems, Swift and CocoaPods, pub, Docker and OCI, Hugging Face, APT, Yum, DNF
Rule families
Vulnerability gates (CVE, CVSS, EPSS, KEV), SPDX licences, versions and release-age floors, provenance, client context, dated exceptions
Enforcement surfaces
Pull request check, local install, CI proxy, internal publish, Kubernetes admission
SBOM
CycloneDX 1.6 and SPDX export on every tier
SIEM and alerts
Splunk HEC, Microsoft Sentinel, IBM QRadar (Enterprise); Prometheus and Grafana metrics, Slack, Teams and PagerDuty webhooks (all plans)
Identity
SAML 2.0, OIDC and SCIM 2.0: Okta, Microsoft Entra, Google Workspace, Auth0, Keycloak (Pro and up)
Deployment
Managed SaaS, your VPC with a customer-controlled data plane, or fully air-gapped
Open source
CLI and policy engine at github.com/chain305/chainsaw-core

Pricing

Plans

The local guard is free forever and open source. Pro and Enterprise add the hosted control plane, SSO, SCIM, SIEM export and on-prem or air-gapped deployment. 14-day money-back guarantee on paid plans.

Free

$0 forever

Guard one machine offline, or 3 people on the hosted tier.

  • All 25 detection signals
  • No account needed to start
  • Blocks malicious and typosquatted packages at install
  • Hosted tier: 3 seats, 500 MB storage, 1 GB bandwidth
  • SBOM and inventory export

Pro

Popular
$149 per month

One central policy for the whole team, with your SSO.

  • 10 users, 5 GB storage, 25 GB bandwidth
  • SSO (SAML and OIDC) and SCIM
  • Central policy with monitor-to-enforce rollout
  • Billy policy copilot and Hardening Wizard
  • Shared audit trails, dashboards and webhooks
  • Priority email support

Enterprise

$1,199 per month

Run it your way, on your infrastructure, wired to your stack.

  • Unlimited users, storage and bandwidth
  • On-prem and air-gapped deployment
  • SIEM export: Splunk, Elastic, Sentinel, QRadar
  • Jira ticketing integration
  • 99.9% uptime SLA and dedicated onboarding

FAQ

Questions teams ask

Do I need an account to start?

No. The local guard installs and runs with no account and no server. Sign in only when you want to share policy across a team.

Will it break my installs or CI?

Not if you start in monitor mode. Every rule can log its decision without blocking, so you see what would fail before you enforce. Repeat installs hit the cache, so CI usually gets faster.

How is it different from SCA tools and scanners?

They report after the package is on disk. Chainsaw refuses on the install path, before the bytes land, and catches attack classes SCA misses: install scripts, maintainer takeover, worm bursts and hidden Unicode.

How is it different from JFrog, Nexus or Cloudsmith?

Those host packages. Chainsaw decides which requests get through, in front of the registries you already use, with nothing to migrate. You can run both.

Can we run it on-prem or air-gapped?

Yes, on Enterprise. The CLI can bake in your server URL so air-gapped users never see a public origin, and CHAINSAW_OFFLINE=1 disables every outbound path.

Products

More from Cyphlon

See all products →

Book a call

Book a 30-minute call

Pick a time that suits you. We'll talk through what you're building and where your security stands, then suggest where to start.

Logo

Cyphlon

1:1 Consultation Call

30 min Google Meet

An introductory call with our engineers about any engagement: a pentest, continuous testing, managed AppSec, security engineering, agentic AI security or a fractional CISO. We'll ask about your stack, your deadlines and what your customers or auditors expect, and tell you plainly if we're not the right fit.

Logo Cyphlon

Research and tool releases by email

Unsubscribe any time. Privacy Policy

About Us

Cyphlon is a security engineering company. We implement DevSecOps, application security, Zero Trust and supply-chain security, build the products we deploy, and publish our research.

[email protected]

© 2026 Cyphlon LLC · Dubai, United Arab Emirates · Founded 2016

Privacy Policy Terms of Use