For the procurement triad

The install-path firewall, across every business unit.

Every refusal carries a signed audit row. Map it to NIS2, DORA, CRA, GDPR or SOC 2 when the questionnaire arrives.

Trust packet: compliance statements with subprocessor list, security architecture, data-flow diagrams and a completed CAIQ. DPA on request.

Enforcement points

One policy, five enforcement points

The same Rego runs at all five. The pull-request check sees only the dependency diff. One org-wide policy set, with rules scoped by repository and exceptions that carry an expiry and optional two-person approval. For estates with several business units, we scope the rollout with you.

Policy

One signed Rego policy bundle

The same rule at every surface below.

  1. 01 · Pull request

    GitHub Action / chainsaw pr-scan

    Fails the check on the dependency diff. Coordinate only: CVSS and malware rules apply from install on.

  2. 02 · Install path

    npm / PyPI / Maven / NuGet / Docker + 12 more

    Refuses the fetch, with the reason and the exception path.

  3. 03 · Publish

    Hosted repo upload

    Refuses an upload from your own build that fails policy.

  4. 04 · K8s admission

    Validating webhook

    Refuses the pod when the image fails the same Rego.

  5. 05 · Laptop

    Local guard install hook / MDM

    Refuses on the developer's machine, even where the proxy was bypassed.

Evidence

One signed audit row

carries every refusal, wherever it happened.

Deeper reading: architecture · vs JFrog Xray · EntIT view · four-week rollout

The roll-up

Refusals roll up by owning team

Escalation goes straight to the BU that owns the dependency.

Chainsaw report showing policy violations grouped by owning team.
Report Violations by owning team, drawn from the same signed audit rows that feed the SIEM. Demo org seeded with synthetic install traffic.

Compliance mapping

Regime, article, Chainsaw evidence

No certification is claimed that isn't held.

Regime Article / control Chainsaw control evidence
NIS2 Art. 21 — supply-chain risk management Signed policy bundle; signed audit row per install decision, naming the refusal signal.
DORA Art. 6 — ICT risk framework; Art. 28 — third-party ICT risk Per-repository enforcement evidence; append-only hash-chained audit export to SIEM; subprocessors in DPA; source-available exit clause.
CRA Annex I — secure-by-design; vuln handling SBOM export per release; KEV-aware refusal; exceptions with expiry, in the same audit row.
GDPR Art. 32 — security of processing Package metadata and decision records only: no source code, no payload bodies. EU-region SaaS or in-VPC. DPA with SCCs.
SOC 2 CC6 (access), CC7 (operations), CC8 (change) RBAC + SCIM; audit row with actor_type + correlation_id; signed bundle change history. Designed against the SOC 2 Trust Services Criteria; no SOC 2 attestation today. Need one as a contract pre-condition? Flag it on your first call.
ISO 27001 Annex A.8 — asset & access management Group → Rego scope mapping; JIT break-glass; identity events in the install-decision audit stream.

Identity depth

Okta or Entra ID is the source of truth

Policy reads identity directly at decision time.

Identity inputWhat policy does with it
Okta / Entra groupMapped to a Rego scope
JIT break-glassTime-boxed approver role; Billy holds the request, the audit row carries it
Conditional accessHigh-risk install from an unmanaged device refused, with that reason on the row

Operations + support

Targets below; negotiated figures in your MSA.

Availability (SaaS)Agreed in your order form
P1 response15 minutes, 24/7 — dedicated Slack Connect
P2 response1 business hour, follow-the-sun
P3 response1 business day
Named CSMSingle contact across AppSec / DevSecOps / EntIT
QBR cadenceQuarterly; metrics on refusals, exceptions, BU adoption
RPO / RTOHourly backups with a tested restore procedure; recovery objectives agreed in your order form

Cost shape at 30,000 developers

Predictable annual. Not per-seat.

Priced annually on these five dimensions. Your headcount is not one of them.

Business unitsNumber of business units in scope
ResidencySaaS / VPC regions, or air-gapped sideload cadence
Audit retention12 / 36 / 84 months
Audit destinationsSIEM, data lake, regulator export
Support tierStandard, 24/7 follow-the-sun, on-site QBR

Vendor risk + escape hatch

If the vendor disappears, the proxy keeps refusing

Source-available bundle clauseNegotiable into Enterprise MSAs. The checksum-verified binary keeps enforcing offline after license expiry, regardless.
Data portabilityAudit rows, policy bundles and exception ledger to S3 / GCS / Azure Blob on a documented schema. Retention negotiated in MSA.
Offline continuityKeeps refusing with no phone-home. Threat-intel updates arrive as signed bundles you verify.
SubprocessorsFull list in the DPA. Notice on material change, with right to object.

Architecture review, not a demo

Bring your AppSec, DevSecOps, and EntIT leads. One call, one decision.

Thirty minutes: your BU shape mapped to one org-wide policy and repository-scoped rules, your top compliance asks mapped to the audit row.