# About Chainsaw

> About Chainsaw, founded in 2026 to help teams control package consumption earlier in the modern software supply chain.

Source: https://chain305.com/about/

---

About Chainsaw

# The refusal point: a firewall that decides on every install

Scanners flag dependencies already in production. The install path is the one place left where a policy decision can still refuse a package before it lands.

Socket, Sonatype and JFrog all refuse before download. None of them lets you read the code that made the call, or run the whole control plane inside your own boundary. The engine is Apache-2.0: read the function that returns the 403 first.

[Documentation](https://docs.chain305.com/) [Contact sales](mailto:sales@chain305.com)

Company facts

Founded

2026

Focus

Install-time package control

Built for

Platform, security and compliance teams

Deployment

Cloud and on-prem

---

## Long form

The full text behind this page, including detail the page itself leaves out.

Why we built this

### We built the refusal point: a firewall that decides on every install

We got tired of finding risky packages after they shipped. Scanners flagged dependencies already in production — xz-utils, event-stream, Shai-Hulud read as CVEs we couldn't undo. SBOMs got assembled the week before an audit. The install path is the one place left where a policy decision can still refuse a package before it lands. So that's where we built — and we close the loop in CI, on the endpoint, and at the network, with an enforcement audit trail a scanner can't produce.

Founded in 2026

Dependency policy only matters where it can still refuse a package — on the install path itself. Socket, Sonatype and JFrog all refuse before download too. What none of them do is let you read the code that made the call, or run the whole control plane inside your own boundary. The engine is Apache-2.0: an AppSec lead can read the function that returns the 403 before routing a single install through it. That's the line between a vendor you trust and one you can check.

[Documentation](https://docs.chain305.com/) [Contact sales](mailto:sales@chain305.com)

Company facts

Founded **2026**

Focus **Install-time package control**

Deployment **Cloud and on-prem**

Contact [sales@chain305.com](mailto:sales@chain305.com)

Context

#### Why the category matters now

A published package reaches a build in minutes, and an install decision propagates across every repo and CI job just as fast. When the window between a malicious publish and a landed dependency is that short, the control that matters is the one that refuses on the install path — before the bytes land, not after the scan runs.

01

##### Why it exists

Most supply-chain tools look like older auditing categories: scan, alert, ticket, upgrade. That loop runs after risk has already entered the system. The install path is the last place you can refuse a package cheaply. So that's where we built.

02

##### What it's built for

Platform, security, and compliance teams who need dependency policy enforced the same way every time — not as a PDF in a wiki, not as a scanner report reviewed on Mondays, but as a decision made on every install request in every environment.

03

##### How to reach us

For product questions, deployment discussions, or enterprise requirements, contact [sales@chain305.com](mailto:sales@chain305.com).
