Trust & Compliance
A public supply-chain attack hit. Now the questionnaire asks how you stop the next install.
An install-path firewall in front of 16 package registries. SaaS, VPC, air-gapped: one binary. Below, the evidence your auditor asks for, by article.
Compliance statements with subprocessor list, security architecture, data-flow diagrams and a completed CAIQ. DPA on request.
Compliance mapping
Regime, article, Chainsaw artifact
No regime requires install-time prevention, and Chainsaw claims to satisfy none. Each row is evidence, and each is deep-linkable.
| Regime | Article / Control | Chainsaw evidence |
|---|---|---|
| NIS2 | Art. 21(2)(a) — risk analysis & information system security policies # | Signed, Sigstore-verified OPA bundle; digest on every decision. Same Rego at PR, install, publish, K8s admission and the local guard; PR sees only the package coordinate, so CVSS and malware rules apply from the install path on. held |
| NIS2 | Art. 21(2)(b) — incident handling # | Signed audit row per decision, tamper-evident chain. SIEM export via webhook or JSONL. held |
| NIS2 | Art. 21(2)(c) — business continuity, backup, crisis management # | Air-gapped tier runs offline; the binary keeps enforcing after license expiry; registry outages served from cache. Hourly database backups with a tested restore procedure. held |
| NIS2 | Art. 21(2)(d) — supply chain security # | The product: refuses malicious installs on the path across 16 registries. held |
| NIS2 | Art. 21(2)(e) — security in acquisition, development, maintenance # | Signed commits. SBOM-of-Chainsaw per release. Chainsaw's own dependencies enforced by its own policy bundle. held |
| NIS2 | Art. 21(2)(f) — policies on effectiveness of risk-management measures # | Audit row + bundle digest per decision reconstruct control state at any point in time. held |
| NIS2 | Art. 21(2)(g) — cyber hygiene & training # | Customer responsibility. Chainsaw provides enforcement; customer provides program. customer |
| NIS2 | Art. 21(2)(h) — cryptography # | TLS 1.2+ in transit, AES-256 at rest, cosign-signed bundles. CMEK/BYOK on Enterprise (target Q3). target |
| NIS2 | Art. 21(2)(i) — human resources, access control, asset management # | SAML/OIDC, SCIM 2.0, RBAC, auto-expiring JIT break-glass. Identity audit log separate from policy log. held |
| DORA | Art. 6 — ICT risk management framework # | Signed bundle → cosign verify → OPA eval → signed audit row. Reproducible from artifact. held |
| DORA | Art. 28 — third-party ICT risk (subcontracting chain) # | Subprocessors below; SCCs where applicable. Customer region for VPC, customer residency for air-gapped. held |
| CRA | Annex I §1 — security properties # | SHA-256 checksums per CLI binary (Sigstore-signed releases land with the release-signer-bot cutover). Strict JWT defaults. Tenant isolation at the query layer. in progress |
| CRA | Annex I §2 — vulnerability handling # | security@chain305.com + security.txt. CVE triage 1 business day, critical patch 7 days (target). Bug bounty: planned. target |
| GDPR | Art. 5(1)(c) — data minimisation # | No application source code; no developer secrets at rest. Captured: package, version, who installed, when, rationale. held |
| GDPR | Art. 28 — processor obligations # | DPA available. SCCs Module 2/3. 30-day subprocessor change notice. held |
| GDPR | Art. 30 — records of processing # | The signed audit row is the record of processing for policy events. JSONL + CSV export. held |
| GDPR | Art. 32 — security of processing # | Encryption in transit and at rest. Strict JWT, httpOnly cookie sessions. Pseudonymisation where applicable. held |
| SOC 2 | CC6 — logical & physical access # | SAML/OIDC, SCIM 2.0, Passkeys, TOTP, RBAC, JIT break-glass. Designed against the SOC 2 Trust Services Criteria; no SOC 2 attestation today. Need one as a contract pre-condition? Flag it on your first call. designed against |
| SOC 2 | CC7 — system operations / monitoring # | Signed audit row → SIEM export. Incident runbook (in progress). in progress |
| SOC 2 | CC8 — change management # | Signed policy bundles (cosign-verified at load), checksummed release binaries, audited change history. Bundle promotion gated by cosign verification. held |
| ISO 27001 | A.5 / A.8 / A.12 / A.14 — policies, asset mgmt, ops security, secure dev # | Designed against ISO 27001 Annex A; no certification today. designed against |
| ISO 27017 | Cloud-specific controls # | Hosted in the EU (Germany); self-host or in-VPC for your own region. held |
| ISO 27018 | PII in public cloud # | PII limited to signup + billing (name, work email, org slug); none from package contents. EU residency for SaaS. held |
Attestation chain
A tampered policy bundle refuses to load
-
01 · Signed
cosign signature
Recorded in the Sigstore transparency log
-
02 · Verified at load
- signature
- signing identity
- transparency-log entry
-
03 · Enforced
OPA evaluates the bundle
Its digest is exported with every decision
Tampered bundle refused. It never loads.
Operational resilience
What happens when Chainsaw is degraded
Hourly database backups with a tested restore procedure. Availability, RPO and RTO for Enterprise are agreed in your order form.
| Mode | When a data source is degraded |
|---|---|
Monitor | Records every decision; never refuses. |
Enforce | By default, a degraded database or threat-intel source fails open, with an audit row. |
Enforce + CHAINSAW_COVERAGE_MODE=closed | Refuses any package it could not fully evaluate against the sources you declare mandatory. |
Upstream-registry outages are served from cache.
Subprocessors
Subprocessor list
30-day notice of change. SCCs Module 2 or adequacy for every active subprocessor; none on the air-gapped tier.
| Subprocessor | Purpose | Region | Transfer mechanism |
|---|---|---|---|
| Contabo GmbH | SaaS hosting, object storage | EU (Germany) | Intra-EU; no third-country transfer |
| Cloudflare | Edge TLS termination, Turnstile bot defense | Global anycast; EU-resident logs | SCCs Module 2 + Cloudflare DPA |
| Paddle | Billing, merchant of record | Global (merchant of record) | SCCs Module 2 + Paddle DPA |
| Sigstore (public good) | Transparency log for signed bundles | Public log (verifiable, no PII) | Public infrastructure; no personal data submitted |
| Postmark | Transactional email | US | SCCs Module 2 + Postmark DPA |
| PostHog Inc. | Product analytics (consent-gated) | US | SCCs Module 2 + PostHog DPA |
| Google LLC (Google Analytics) | Marketing-site analytics (consent-gated) | US | EU-US Data Privacy Framework + SCCs |
Controls in detail
Open any control for the detail
Data flows & PII surface
No application source code is processed. No developer secrets at rest: install-script exfiltration is detected on ephemeral install traffic, and secrets it observes are not stored.
Captured per decision: package name, version, ecosystem, upstream URL, requesting identity, timestamp, policy bundle digest, decision (allow / refuse / quarantine) and the Rego rule that fired.
PII (GDPR Art. 5(1)(c)): signup and billing only (name, work email, org slug). Audit rows carry a stable internal ID; the mapping to a person lives in your identity provider.
EU data residency
SaaS runs on Contabo in Germany, with backups kept in the same region, so no GDPR Chapter V transfer is required.
VPC deploys into your region. Air-gapped runs entirely on your infrastructure with no Chainsaw-operated egress; the CLI's server URL can be baked into the binary.
Encryption
In transit: TLS 1.2+ on every ingress, AEAD suites only (AES-GCM, ChaCha20-Poly1305), HSTS on the SaaS edge.
At rest: SSO client secrets, TOTP seeds and SIEM credentials are encrypted in the application with AES-256-GCM before they reach the database. For keys you hold yourself, self-host or run in your VPC.
CLI release binaries ship with published SHA-256 checksums today; Sigstore-signed releases land once the release-signer bot is provisioned.
Open engine
The proxy, policy evaluation and the risk / typosquat / malware / provenance libraries are open source at github.com/chain305/chainsaw-core. Read how a refusal is reached before you route installs through it.
The multi-tenant control plane (dashboard, SSO/SCIM, premium intelligence, policy signing, SIEM delivery) is closed. The compiler enforces the boundary: enterprise code depends on the open core, never the reverse.
Identity & access
SAML 2.0 and OIDC against Okta and Entra ID. SCIM 2.0. WebAuthn + Passkeys and TOTP. CLI credentials in the OS keyring, never plaintext on disk.
RBAC at org / workspace / policy / registry granularity. JIT break-glass with auto-expiry (default 4 hours, configurable). Identity events write to a separate audit stream from policy decisions.
Short-lived JWT in an httpOnly cookie, revocable. Chainsaw refuses to boot without an explicit CHAINSAW_JWT_SECRET or persistent secret store.
Vulnerability handling & SDLC
Disclosure: security@chain305.com and /.well-known/security.txt. Acknowledgement within 1 business day. Safe harbor for good-faith research. Bug bounty: planned (target H2 2026).
Pen test: no third-party report to share yet. Scope one with us as part of your review.
CVE response SLA (target): triage 1 business day; critical patch 7 days, high 30, medium 90.
SDLC: signed commits on protected branches, SBOM-of-Chainsaw per release, and Chainsaw's own dependencies enforced by a Chainsaw policy bundle.
Termination & escape hatch
Data export: audit rows as JSONL + CSV, policy bundles as signed archives, configuration as YAML. Available during the contract and for 90 days after termination, then hard-deleted.
License expiry does not brick enforcement. The checksum-verified binary keeps enforcing the last-signed bundle offline; new bundles require renewal.
Source-available clause: if Chain305 ceases operations, the enforcement core is released under a source-available license per the Enterprise MSA escrow clause.
Trust packet
Send this to legal
Compliance statements with subprocessor list, security architecture, data-flow diagrams and a completed CAIQ. DPA on request.
Still have questions?
Talk to security engineering
Not sales. The engineer who wrote the signed-bundle verifier, the isolation tests or the JWT strict-default.