For the procurement triad
The install-path firewall, across every business unit.
Every refusal carries a signed audit row. Map it to NIS2, DORA, CRA, GDPR or SOC 2 when the questionnaire arrives.
Trust packet: compliance statements with subprocessor list, security architecture, data-flow diagrams and a completed CAIQ. DPA on request.
Enforcement points
One policy, five enforcement points
The same Rego runs at all five. The pull-request check sees only the dependency diff. One org-wide policy set, with rules scoped by repository and exceptions that carry an expiry and optional two-person approval. For estates with several business units, we scope the rollout with you.
Policy
One signed Rego policy bundle
The same rule at every surface below.
-
01 · Pull request
GitHub Action / chainsaw pr-scan
Fails the check on the dependency diff. Coordinate only: CVSS and malware rules apply from install on.
-
02 · Install path
npm / PyPI / Maven / NuGet / Docker + 12 more
Refuses the fetch, with the reason and the exception path.
-
03 · Publish
Hosted repo upload
Refuses an upload from your own build that fails policy.
-
04 · K8s admission
Validating webhook
Refuses the pod when the image fails the same Rego.
-
05 · Laptop
Local guard install hook / MDM
Refuses on the developer's machine, even where the proxy was bypassed.
Evidence
One signed audit row
carries every refusal, wherever it happened.
Deeper reading: architecture · vs JFrog Xray · EntIT view · four-week rollout
The roll-up
Refusals roll up by owning team
Escalation goes straight to the BU that owns the dependency.
Compliance mapping
Regime, article, Chainsaw evidence
No certification is claimed that isn't held.
| Regime | Article / control | Chainsaw control evidence |
|---|---|---|
| NIS2 | Art. 21 — supply-chain risk management | Signed policy bundle; signed audit row per install decision, naming the refusal signal. |
| DORA | Art. 6 — ICT risk framework; Art. 28 — third-party ICT risk | Per-repository enforcement evidence; append-only hash-chained audit export to SIEM; subprocessors in DPA; source-available exit clause. |
| CRA | Annex I — secure-by-design; vuln handling | SBOM export per release; KEV-aware refusal; exceptions with expiry, in the same audit row. |
| GDPR | Art. 32 — security of processing | Package metadata and decision records only: no source code, no payload bodies. EU-region SaaS or in-VPC. DPA with SCCs. |
| SOC 2 | CC6 (access), CC7 (operations), CC8 (change) | RBAC + SCIM; audit row with actor_type + correlation_id; signed bundle change history. Designed against the SOC 2 Trust Services Criteria; no SOC 2 attestation today. Need one as a contract pre-condition? Flag it on your first call. |
| ISO 27001 | Annex A.8 — asset & access management | Group → Rego scope mapping; JIT break-glass; identity events in the install-decision audit stream. |
Identity depth
Okta or Entra ID is the source of truth
Policy reads identity directly at decision time.
| Identity input | What policy does with it |
|---|---|
| Okta / Entra group | Mapped to a Rego scope |
| JIT break-glass | Time-boxed approver role; Billy holds the request, the audit row carries it |
| Conditional access | High-risk install from an unmanaged device refused, with that reason on the row |
Operations + support
Targets below; negotiated figures in your MSA.
| Availability (SaaS) | Agreed in your order form |
|---|---|
| P1 response | 15 minutes, 24/7 — dedicated Slack Connect |
| P2 response | 1 business hour, follow-the-sun |
| P3 response | 1 business day |
| Named CSM | Single contact across AppSec / DevSecOps / EntIT |
| QBR cadence | Quarterly; metrics on refusals, exceptions, BU adoption |
| RPO / RTO | Hourly backups with a tested restore procedure; recovery objectives agreed in your order form |
Cost shape at 30,000 developers
Predictable annual. Not per-seat.
Priced annually on these five dimensions. Your headcount is not one of them.
| Business units | Number of business units in scope |
|---|---|
| Residency | SaaS / VPC regions, or air-gapped sideload cadence |
| Audit retention | 12 / 36 / 84 months |
| Audit destinations | SIEM, data lake, regulator export |
| Support tier | Standard, 24/7 follow-the-sun, on-site QBR |
Vendor risk + escape hatch
If the vendor disappears, the proxy keeps refusing
| Source-available bundle clause | Negotiable into Enterprise MSAs. The checksum-verified binary keeps enforcing offline after license expiry, regardless. |
|---|---|
| Data portability | Audit rows, policy bundles and exception ledger to S3 / GCS / Azure Blob on a documented schema. Retention negotiated in MSA. |
| Offline continuity | Keeps refusing with no phone-home. Threat-intel updates arrive as signed bundles you verify. |
| Subprocessors | Full list in the DPA. Notice on material change, with right to object. |
Architecture review, not a demo
Bring your AppSec, DevSecOps, and EntIT leads. One call, one decision.
Thirty minutes: your BU shape mapped to one org-wide policy and repository-scoped rules, your top compliance asks mapped to the audit row.