# Enterprise | Chainsaw

> Install-path firewall for large engineering orgs. One org-wide Rego policy, one signed audit row that satisfies AppSec, DevSecOps, and EntIT from the same decision.

Source: https://chain305.com/enterprise/

---

For the procurement triad

# The install-path firewall, across every business unit.

Every refusal carries a signed audit row. Map it to NIS2, DORA, CRA, GDPR or SOC 2 when the questionnaire arrives.

[Book 30-min architecture review](https://cal.com/chain305/30min) [Request trust packet](mailto:sales@chain305.com?subject=Trust%20packet)

[AppSec → Security](https://chain305.com/security) [DevSecOps → Architecture](https://chain305.com/architecture) [EntIT → Identity](#identity)

Trust packet: compliance statements with subprocessor list, security architecture, data-flow diagrams and a completed CAIQ. DPA on request.

Enforcement points

## One policy, five enforcement points

The same Rego runs at all five. The pull-request check sees only the dependency diff. One org-wide policy set, with rules scoped by repository and exceptions that carry an expiry and optional two-person approval. For estates with several business units, we scope the rollout with you.

Policy

One signed Rego policy bundle

The same rule at every surface below.

1.  01 · Pull request
    
    GitHub Action / chainsaw pr-scan
    
    Fails the check on the dependency diff. Coordinate only: CVSS and malware rules apply from install on.
    
2.  02 · Install path
    
    npm / PyPI / Maven / NuGet / Docker + 12 more
    
    Refuses the fetch, with the reason and the exception path.
    
3.  03 · Publish
    
    Hosted repo upload
    
    Refuses an upload from your own build that fails policy.
    
4.  04 · K8s admission
    
    Validating webhook
    
    Refuses the pod when the image fails the same Rego.
    
5.  05 · Laptop
    
    Local guard install hook / MDM
    
    Refuses on the developer's machine, even where the proxy was bypassed.
    

Evidence

One signed audit row

carries every refusal, wherever it happened.

Deeper reading: [architecture](https://chain305.com/architecture/) · [vs JFrog Xray](https://chain305.com/vs-jfrog-xray/) · [EntIT view](https://chain305.com/solutions/enterprise-it/) · [four-week rollout](https://chain305.com/product/enterprise-rollout/)

The roll-up

## Refusals roll up by owning team

Escalation goes straight to the BU that owns the dependency.

![Chainsaw report showing policy violations grouped by owning team.](/demo/threats-stopped.png?v=4)

Report Violations by owning team, drawn from the same signed audit rows that feed the SIEM. Demo org seeded with synthetic install traffic.

Compliance mapping

## Regime, article, Chainsaw evidence

No certification is claimed that isn't held.

Regime

Article / control

Chainsaw control evidence

NIS2

Art. 21 — supply-chain risk management

Signed policy bundle; signed audit row per install decision, naming the refusal signal.

DORA

Art. 6 — ICT risk framework; Art. 28 — third-party ICT risk

Per-repository enforcement evidence; append-only hash-chained audit export to SIEM; subprocessors in DPA; source-available exit clause.

CRA

Annex I — secure-by-design; vuln handling

SBOM export per release; KEV-aware refusal; exceptions with expiry, in the same audit row.

GDPR

Art. 32 — security of processing

Package metadata and decision records only: no source code, no payload bodies. EU-region SaaS or in-VPC. DPA with SCCs.

SOC 2

CC6 (access), CC7 (operations), CC8 (change)

RBAC + SCIM; audit row with actor\_type + correlation\_id; signed bundle change history. Designed against the SOC 2 Trust Services Criteria; no SOC 2 attestation today. Need one as a contract pre-condition? Flag it on your first call.

ISO 27001

Annex A.8 — asset & access management

Group → Rego scope mapping; JIT break-glass; identity events in the install-decision audit stream.

Identity depth

## Okta or Entra ID is the source of truth

Policy reads identity directly at decision time.

Identity input

What policy does with it

Okta / Entra group

Mapped to a Rego scope

JIT break-glass

Time-boxed approver role; Billy holds the request, the audit row carries it

Conditional access

High-risk install from an unmanaged device refused, with that reason on the row

Operations + support

## Targets below; negotiated figures in your MSA.

Availability (SaaS)

Agreed in your order form

P1 response

15 minutes, 24/7 — dedicated Slack Connect

P2 response

1 business hour, follow-the-sun

P3 response

1 business day

Named CSM

Single contact across AppSec / DevSecOps / EntIT

QBR cadence

Quarterly; metrics on refusals, exceptions, BU adoption

RPO / RTO

Hourly backups with a tested restore procedure; recovery objectives agreed in your order form

Cost shape at 30,000 developers

## Predictable annual. Not per-seat.

Priced annually on these five dimensions. Your headcount is not one of them.

Business units

Number of business units in scope

Residency

SaaS / VPC regions, or air-gapped sideload cadence

Audit retention

12 / 36 / 84 months

Audit destinations

SIEM, data lake, regulator export

Support tier

Standard, 24/7 follow-the-sun, on-site QBR

Vendor risk + escape hatch

## If the vendor disappears, the proxy keeps refusing

Source-available bundle clause

Negotiable into Enterprise MSAs. The checksum-verified binary keeps enforcing offline after license expiry, regardless.

Data portability

Audit rows, policy bundles and exception ledger to S3 / GCS / Azure Blob on a documented schema. Retention negotiated in MSA.

Offline continuity

Keeps refusing with no phone-home. Threat-intel updates arrive as signed bundles you verify.

Subprocessors

Full list in the DPA. Notice on material change, with right to object.

Architecture review, not a demo

## Bring your AppSec, DevSecOps, and EntIT leads. One call, one decision.

Thirty minutes: your BU shape mapped to one org-wide policy and repository-scoped rules, your top compliance asks mapped to the audit row.

[Book 30-min architecture review](https://cal.com/chain305/30min) [Request trust packet](mailto:sales@chain305.com?subject=Trust%20packet)

---

## Long form

The full text behind this page, including detail the page itself leaves out.

For the procurement triad

### The install-path firewall, across every business unit — and every refusal carries a signed audit row.

A public supply-chain attack lands — or your own near-miss does — and the security questionnaire arrives. Every refusal already carries a signed audit row, so the answer your auditor asks for is the row you already have. Map it to NIS2, DORA, CRA, GDPR, or SOC 2 after.

[Book 30-min architecture review](https://cal.com/chain305/30min) [Request trust packet](mailto:sales@chain305.com?subject=Trust%20packet)

[I’m AppSec → /security](https://chain305.com/security) [I’m DevSecOps → /architecture](https://chain305.com/architecture) [I’m EntIT → #identity](#identity)

Trust packet: compliance statements with subprocessor list, security architecture, data-flow diagrams and a completed CAIQ. DPA on request.

Three buyers, one decision

#### Each of your three teams walks in with a different question. Same audit row answers all three.

AppSec lead

“Snyk and Xray already scan. Why does this stop incidents they don't?”

Because scanners report after install. The proxy refuses on the install path — typosquats, maintainer takeovers, hidden Unicode, install-script exfiltration, KEV-listed CVEs — using 25 supply-chain signals beyond CVE. One Rego decision, one audit row, hand to the auditor.

[See the five enforcement points →](#four-points)

DevSecOps lead

“Fifty BUs, fifty Rego forks. How does this not become a policy zoo?”

One org-wide policy set, with rules scoped by repository and exceptions that carry an expiry and optional two-person approval. For estates with several business units, we scope the rollout with you.

[See the policy model →](https://chain305.com/product/policy/)

EntIT lead

“Identity is mine. Will this respect Okta/Entra groups and SCIM attrs?”

Group → Rego scope mapping. JIT break-glass with time-boxed elevation. Every identity event lands in the same signed audit row as the install decision.

[See the identity model →](#identity)

Policy architecture

#### One policy set, scoped by repository

One org-wide policy set, with rules scoped by repository and exceptions that carry an expiry and optional two-person approval. For estates with several business units, we scope the rollout with you.

One policy, five enforcement points

#### Same Rego fires at the pull request, install, publish, K8s admission, and runtime. Three vendors collapse to one seam.

Most stacks stitch together a PR scanner, a registry gate (JFrog Xray), a publish-time scanner, an admission controller (Wiz Code / OPA), and a runtime sensor. Five configs, five policy languages, five audit trails. The proxy ships one Rego policy that runs at all five. It is the same rule, not the same visibility: the pull-request check reads a dependency diff, so rules that need the package bytes take effect from the install path on. The same signed audit row carries every refusal, wherever it happened.

-   Pull request
    
    GitHub Action / chainsaw pr-scan
    
    Fails the check on a dependency diff. Reads the coordinate, not the bytes — CVSS and malware rules land from the install path on.
    
-   Install path
    
    npm / PyPI / Maven / NuGet / Docker + 12 more
    
    Refuses the fetch. Developer sees the reason and the exception path.
    
-   Publish
    
    Hosted repo upload
    
    Refuses the upload when one of your own builds pushes a package that fails policy.
    
-   K8s admission
    
    Validating webhook
    
    Refuses the pod when the image fails the same Rego the install path ran.
    
-   Runtime
    
    Package-manager install hook (local guard / MDM)
    
    Refuses the install on the developer's machine, even where the proxy was bypassed.
    

Deeper reading: [architecture overview](https://chain305.com/architecture/) · structural diff vs JFrog Xray in [/vs-jfrog-xray](https://chain305.com/vs-jfrog-xray/) · the EntIT shared-services view in [/solutions/enterprise-it](https://chain305.com/solutions/enterprise-it/) · the four-week [rollout schedule](https://chain305.com/product/enterprise-rollout/).

The roll-up

#### Refusals roll up by owning team — the report the QBR runs on.

One audit stream up means one report down: refusals grouped by the team that owns the dependency, so escalation goes to the right BU channel instead of a central triage bottleneck.

![Chainsaw report showing policy violations grouped by owning team.](/demo/threats-stopped.png?v=3)

Report A capture of the violations-by-owning-team report — refusals attributed to the team that owns the repository, drawn from the same signed audit rows that feed the SIEM. Demo org seeded with synthetic install traffic.

Compliance mapping

#### Regime → article → which audit row, which signed bundle, which export.

No certification is claimed that isn't held. Each control your reviewer asks about maps to a specific Chainsaw artifact.

Regime

Article / control

Chainsaw control evidence

NIS2

Art. 21 — supply-chain risk management

Signed policy bundle + signed audit row per install decision; refusal reasons map to specific signals (typosquat, maintainer takeover, install-script exfil).

DORA

Art. 6 — ICT risk framework; Art. 28 — third-party ICT risk

Per-repository enforcement evidence, append-only hash-chained audit export to SIEM, subprocessor list in DPA, source-available enforcement bundle clause for exit.

CRA

Annex I — secure-by-design; vuln handling

SBOM export per release, KEV-aware refusal, exception lifecycle with expiry — all carried in the same audit row.

GDPR

Art. 32 — security of processing

Narrow data model: package metadata + decision records, no source code, no payload bodies. EU-region SaaS or in-VPC. DPA with SCCs.

SOC 2

CC6 (access), CC7 (operations), CC8 (change)

RBAC + SCIM, signed audit row with actor\_type + correlation\_id, signed policy-bundle change history. Designed against the SOC 2 Trust Services Criteria; no SOC 2 attestation today. Need one as a contract pre-condition? Flag it on your first call.

ISO 27001

Annex A.8 — asset & access management

Group → Rego scope mapping, JIT break-glass, identity events in the same audit stream as install decisions.

Identity depth

#### Okta or Entra ID is the source of truth. Policy reads it directly.

Group → Rego scope mapping. JIT break-glass elevates a developer into an approver role for a time-boxed window — Billy holds the request, the audit row carries it. Conditional access from Okta / Entra propagates into refusal context, so a high-risk install attempted from an unmanaged device gets refused with that reason on the row.

Operations + support

#### Targets below; negotiated figures in your MSA.

-   Availability (SaaS)
    
    Agreed in your order form
    
-   P1 response
    
    15 minutes, 24/7 — dedicated Slack Connect
    
-   P2 response
    
    1 business hour, follow-the-sun
    
-   P3 response
    
    1 business day
    
-   Named CSM
    
    Single contact across AppSec / DevSecOps / EntIT
    
-   QBR cadence
    
    Quarterly; metrics on refusals, exceptions, BU adoption
    
-   RPO / RTO
    
    Hourly backups with a tested restore procedure; recovery objectives agreed in your order form
    

Cost shape at 30,000 developers

#### Predictable annual. Not per-seat.

Per-seat pricing in a 30k-engineer org turns every hire into a budget event and every BU acquisition into a re-paper. The proxy is priced annually on the dimensions that actually drive cost on our side — not on your headcount.

-   Number of business units in scope
-   Regions for SaaS / VPC residency or air-gapped sideload cadence
-   Audit retention window (12 / 36 / 84 months)
-   Audit-stream destinations (SIEM, data lake, regulator export)
-   Support tier (standard, 24/7 follow-the-sun, on-site QBR)

Vendor risk + escape hatch

#### If Chainsaw the company disappears, the proxy keeps refusing.

-   Source-available enforcement bundle clause
    
    Source-available enforcement bundle clause negotiable into Enterprise-tier MSAs. The checksum-verified binary continues to enforce policy offline after license expiry, regardless.
    
-   Data portability
    
    Audit rows, policy bundles, exception ledger — exportable to S3 / GCS / Azure Blob on a documented schema, on demand. Retention window negotiated in MSA (12 / 36 / 84 months).
    
-   Offline continuity
    
    The checksum-verified binary keeps refusing on the install path without phone-home. Threat-intel updates arrive as signed bundles you verify.
    
-   Subprocessors
    
    Full list in the DPA. Notification on material change with right to object.
    

Reference

#### Rollout pattern: a large multi-BU platform.

One org-wide policy set, with rules scoped by repository and exceptions that carry an expiry and optional two-person approval. For estates with several business units, we scope the rollout with you. Single audit stream to the central SIEM. One policy bundle replaces a stitched stack of registry gate, publish gate, and admission controller. We can walk through this rollout pattern during evaluation.

Architecture review, not a demo

#### Bring your AppSec, DevSecOps, and EntIT leads. One call, one decision.

Thirty minutes. Your BU shape mapped to one org-wide policy and repository-scoped rules, top three compliance asks (NIS2, DORA, your SOC 2 reviewer's list) mapped to the audit row, and the trust packet handed back.

[Get started](https://chain305.com/chainsaw/signup) [Request trust packet](mailto:sales@chain305.com?subject=Trust%20packet)
