Enterprise rollout

Monitor, audit, enforce. Ship in four weeks.

Enforcement goes on per rule, per team, at your pace, so no developer loses a build.

The schedule

Four weeks, ≈ 40 platform-engineering hours

Every rule can stay in monitor as long as you want before you flip it.

  1. Week 1

    Deploy, point one pilot team

    ≈ 8 platform-eng hours

  2. Week 2

    Monitor mode, org-wide

    ≈ 8 platform-eng hours

  3. Week 3

    Enforce the low-risk rules

    ≈ 12 platform-eng hours

  4. Week 4

    Enforce the high-risk rules

    ≈ 12 platform-eng hours

Every step, week by week

Week 1 · Deploy, point one pilot team

  • Stand up Chainsaw on your cloud or managed SaaS. Docker Compose for dev; Kubernetes or ECS for prod.
  • Provision the control-plane database and (optional) Redis for webhook delivery at scale.
  • Issue scoped client credentials to one pilot team's CI and laptops.
  • Confirm installs flow through the proxy. No policy active yet; everything passes with an audit record.

Week 2 · Monitor mode, org-wide

  • Roll out the baseline policy template (CVE floor, license allowlist, and every supply-chain attack signal your proxied ecosystems support) in monitor mode.
  • Point the remaining teams at the proxy. Nothing breaks because monitor mode logs without blocking.
  • Review the daily monitor report. Every legitimate install that trips a rule is a candidate for exception or rule tuning.
  • Assign owners for exceptions: one reviewer per team, tracked in the dashboard with expiry dates.

Week 3 · Enforce the low-risk rules

  • Flip known-malware, dependency-confusion, and hidden-Unicode rules to block. Each fires on coordinate-exact or byte-level evidence, so a refusal names the specific thing it found.
  • Flip typosquat to block, and budget for exceptions. It infers from name similarity, so it refuses some real packages: measured on 24,206 real packages held outside the popularity corpus, 1.02% are refused. Each clears in one command, per coordinate, offline: an exception, not an outage.
  • Flip the Docker malware feed and per-layer image enforcement to block for new image builds.
  • Coordinate one short announcement: developers know what now fails and who owns the exception path.
  • Shift monitor reports to weekly cadence once the signal is steady.

Week 4 · Enforce the high-risk rules

  • Flip CVE floor, license allowlist, install-script exfiltration, publisher-changed, and publish-velocity rules to block or quarantine.
  • Wire SIEM stream (Splunk HEC, Microsoft Sentinel, or IBM QRadar) if you're on Enterprise.
  • Document your rollout and exception process. That doc feeds your SOC 2 / ISO evidence pack.
  • Move to steady state: weekly review of new exceptions, quarterly policy review, rule additions as new attack patterns land.

Availability

What "HA" means in practice

Two proxy replicas behind a health check, and failover is automatic.

Proxy tierstateless; scales horizontally, no sticky sessions
Control planeyour RDS, Cloud SQL or self-managed database
Blob-store cachelocal disk for dev, S3-compatible for prod
Degraded data sourcefails open with an audit row; CHAINSAW_COVERAGE_MODE=closed refuses anything not fully evaluated against your mandatory sources
Upstream registry outageserved from cache
Observability50+ Prometheus counters, opt-in OpenTelemetry
RTO / RPOfollows your control-plane failover; Chainsaw recovers in seconds once the DB is reachable

Migration

Front your existing registry

No dual-publish, no cut-over day.

Artifactory / NexusKeep them. Public installs route through Chainsaw.
Cloudsmith / JFrog SaaSChainsaw's upstream points at Cloudsmith.
Verdaccio / internal npm mirrorChainsaw replaces the public-upstream hop. .npmrc unchanged.
Snyk / SCA scannersRun both. Chainsaw decides what enters; SCA reports on what's there.

Hardening levels

Four levels, one rollout path

Most teams start at Level 1 and stop at Level 2. Each level is additive.

LevelAddsNeeds
L1 · Monitor onlyAudit every install, block nothingproxy + dashboard
L2 · Admission webhookCluster-side enforcement on KubernetesK8s admission controller
L3 · Network egress allowlistBlock direct registry access at the network edgenetwork egress policy
L4 · MDM payloadsLock the developer machineMDM profile, checksum-verified CLI

On Team and Enterprise, the /onboarding/hardening wizard generates the manifests, firewall snippets and MDM payloads.

Ready to brief your rollout?

Book a 30-minute working session

We walk through your environment and hand back a rollout plan you can share with your team.