For DevSecOps & Compliance

Every install leaves evidence. Compliance stops being a spreadsheet project.

The same license, version and provenance rules run in CI, on laptops and in Dockerfiles, and every verdict lands in a structured log.

Evidence mapping

The same export answers each framework

No framework requires install-time blocking, and Chainsaw doesn't certify you compliant. It produces the proof.

FrameworkControlsEvidence
SOC 2 Type II CC 8.1 change management, CC 6.6 logical access Install-path audit log; exception expiry and RBAC-scoped API keys.
NIST 800-161r1 C-SCRM SR-3, SR-4, SR-11 supply-chain controls Attack signals, SBOM export and maintainer-change detection.
ISO 27001 / ISO 27002 A.8.9 config mgmt, A.8.22 segregation, A.5.19 supplier Central policy and tenant-scoped rules; provenance and attack-signal rules.
SLSA v1.0 Provenance L2–L3, Source L2+, Build L3 Ingests Sigstore attestations, npm provenance and Go sumdb to enforce provenance levels.
Chainsaw report showing policy violations grouped by owning team.
Report Refusals grouped by owning team, from the audit rows that feed the SIEM. Demo org seeded with synthetic install traffic.

Enforce, then prove it

From draft policy to evidence in four steps

  1. 01

    Model your policy once

    License, version and provenance rules. One policy for CI, laptops and Dockerfiles.

  2. 02

    Watch monitor-mode traffic

    Every install gets a verdict in the audit log. Nothing breaks.

  3. 03

    Enforce rule by rule

    Flip each rule when you trust it.

  4. 04

    Export evidence on demand

    CycloneDX SBOMs per repo. Audit logs stream to Splunk HEC, Microsoft Sentinel or IBM QRadar on Enterprise.

Before the next questionnaire

Turn on Chainsaw in monitor mode

See what a real compromise would have hit today, without breaking a build.