For Enterprise IT
One org-wide policy for every team
Deploy once on managed SaaS, in your VPC or air-gapped. Rules are scoped by repository; for several business units, we scope the rollout with you.
Rollout for shared services
Org-wide governance in three steps
-
01
Stand up one instance
Managed SaaS, your cloud or air-gapped. Same binary, same API.
-
02
Publish the policy centrally
One org-wide policy for vulnerabilities, licenses, provenance and supply-chain signals.
-
03
Scope rules by repository
Target a rule at specific repositories. Exceptions carry an expiry and optional two-person approval.
Availability
HA without a platform team
Two replicas behind a health check, and fail-over is automatic.
| Part | Behaviour |
|---|---|
| Proxy | Stateless. Any Kubernetes, ECS or Nomad scheduler; no sticky sessions. |
| Control plane | Your managed database: RDS, Cloud SQL or self-managed. |
| Cache | Local disk for dev, S3-compatible blob store for prod. |
| Degraded data | Fails open with an audit row by default. CHAINSAW_COVERAGE_MODE=closed refuses anything not fully checked against your mandatory sources. |
| Upstream outage | Served from cache. |
| Metrics | 50+ Prometheus counters. OpenTelemetry tracing is opt-in. |
| Identity | SAML 2.0, OIDC and SCIM 2.0 on Team and Enterprise. Admin, manager and viewer roles with fine-grained API scopes. Supported IdPs |
Hardening levels
Four levels, one rollout path
Each level is additive: same proxy, same policy, more tooling around it. Each level in detail →
| Level | Adds | Effect |
|---|---|---|
| L1 | Monitor only | Audit every install. Block nothing. |
| L2 | Admission webhook | Cluster-side enforcement on Kubernetes. |
| L3 | Egress allowlist | Block direct registry access at the network edge. |
| L4 | MDM payloads | Lock the registry config on managed laptops. |
Air-gapped
Disconnected from the public internet
Runs fully air-gapped on Enterprise.
-
01 · Signed intel bundle
chainsaw-intel-bundle-YYYY-MM-DD.tar.gz- Trivy DB
- KEV
- OSV malware
- GHSA
-
02 · Verify
chainsaw bundle verifyon your transfer schedule
-
03 · Apply
chainsaw bundle applyloaded from CHAINSAW_INTEL_BUNDLE_PATH instead of phoning home
Migration
Front your existing registry
Chainsaw slots in front of what you run today.
| You run | How Chainsaw fits |
|---|---|
| Artifactory / Nexus | Keep them. Chainsaw fronts the public registries they proxy. Zero dual-publish. |
| Cloudsmith / JFrog SaaS | Point Chainsaw's upstream at it; your URLs stay. |
| Verdaccio / npm mirror | The mirror stays; Chainsaw replaces the public hop. No .npmrc change. |
| Snyk / SCA scanners | Run both. Chainsaw decides what enters; SCA reports what is there. |
Need on-prem or air-gapped?
Let's scope the deployment together
On-prem comes with the Enterprise plan. Book a 30-minute call to scope yours.