Now in early access
OSPulse
Dependency health and supply-chain compromise intelligence.
Traditional scanners wait for a CVE to exist. By then the package has been abandoned for months, or the maintainer account was taken over last week. OSPulse watches the things that happen before a CVE — and tells you which of your applications are in the blast radius.
Compromise intelligence
Breach feeds across eight-plus sources — advisories, malware reports, threat intelligence, CISA KEV — cross-referenced against your dependency tree. Maintainer takeover, typosquatting, and dependency confusion included.
Drift detection
Commit-velocity collapse, maintainer activity across 90- and 365-day windows, bus-factor risk, release-cadence decay. Abandonment caught while you still have time to move.
Health scoring, with the evidence
A 0–100 score across ten weighted dimensions, each one carrying a full evidence trail and a confidence rating that flags where the evidence is thin. Weights are configurable per policy.
EU Cyber Resilience Act
The clock is 24 hours.
Reporting duties under Article 14 apply from 11 September 2026: 24 hours to early warning, 72 to notification, 14 days to the final report. OSPulse gives you the CycloneDX SBOM, the exploitation-intelligence watch, and submission-ready report packs for products already on the EU market. You remain the one who reports — this is evidence and speed, not absolution.
See the CRA modulePost-quantum readiness
Do you know where all your RSA is?
Google has committed to completing its own post-quantum migration by 2029; NIST deprecates RSA and ECC in 2030 and disallows them in 2035. The quantum proofing scanner finds every legacy certificate and outdated crypto library across your codebase and dependency tree.
See the scanner