For DevSecOps & Compliance
Every install leaves evidence. Compliance stops being a spreadsheet project.
The same license, version and provenance rules run in CI, on laptops and in Dockerfiles, and every verdict lands in a structured log.
Evidence mapping
The same export answers each framework
No framework requires install-time blocking, and Chainsaw doesn't certify you compliant. It produces the proof.
| Framework | Controls | Evidence |
|---|---|---|
| SOC 2 Type II | CC 8.1 change management, CC 6.6 logical access | Install-path audit log; exception expiry and RBAC-scoped API keys. |
| NIST 800-161r1 C-SCRM | SR-3, SR-4, SR-11 supply-chain controls | Attack signals, SBOM export and maintainer-change detection. |
| ISO 27001 / ISO 27002 | A.8.9 config mgmt, A.8.22 segregation, A.5.19 supplier | Central policy and tenant-scoped rules; provenance and attack-signal rules. |
| SLSA v1.0 | Provenance L2–L3, Source L2+, Build L3 | Ingests Sigstore attestations, npm provenance and Go sumdb to enforce provenance levels. |
Enforce, then prove it
From draft policy to evidence in four steps
-
01
Model your policy once
License, version and provenance rules. One policy for CI, laptops and Dockerfiles.
-
02
Watch monitor-mode traffic
Every install gets a verdict in the audit log. Nothing breaks.
-
03
Enforce rule by rule
Flip each rule when you trust it.
-
04
Export evidence on demand
CycloneDX SBOMs per repo. Audit logs stream to Splunk HEC, Microsoft Sentinel or IBM QRadar on Enterprise.
Before the next questionnaire
Turn on Chainsaw in monitor mode
See what a real compromise would have hit today, without breaking a build.