For Enterprise IT

One org-wide policy for every team

Deploy once on managed SaaS, in your VPC or air-gapped. Rules are scoped by repository; for several business units, we scope the rollout with you.

Rollout for shared services

Org-wide governance in three steps

  1. 01

    Stand up one instance

    Managed SaaS, your cloud or air-gapped. Same binary, same API.

  2. 02

    Publish the policy centrally

    One org-wide policy for vulnerabilities, licenses, provenance and supply-chain signals.

  3. 03

    Scope rules by repository

    Target a rule at specific repositories. Exceptions carry an expiry and optional two-person approval.

Availability

HA without a platform team

Two replicas behind a health check, and fail-over is automatic.

PartBehaviour
ProxyStateless. Any Kubernetes, ECS or Nomad scheduler; no sticky sessions.
Control planeYour managed database: RDS, Cloud SQL or self-managed.
CacheLocal disk for dev, S3-compatible blob store for prod.
Degraded dataFails open with an audit row by default. CHAINSAW_COVERAGE_MODE=closed refuses anything not fully checked against your mandatory sources.
Upstream outageServed from cache.
Metrics50+ Prometheus counters. OpenTelemetry tracing is opt-in.
Identity SAML 2.0, OIDC and SCIM 2.0 on Team and Enterprise. Admin, manager and viewer roles with fine-grained API scopes. Supported IdPs

Hardening levels

Four levels, one rollout path

Each level is additive: same proxy, same policy, more tooling around it. Each level in detail →

LevelAddsEffect
L1Monitor onlyAudit every install. Block nothing.
L2Admission webhookCluster-side enforcement on Kubernetes.
L3Egress allowlistBlock direct registry access at the network edge.
L4MDM payloadsLock the registry config on managed laptops.

Air-gapped

Disconnected from the public internet

Runs fully air-gapped on Enterprise.

  1. 01 · Signed intel bundle

    chainsaw-intel-bundle-YYYY-MM-DD.tar.gz
    • Trivy DB
    • KEV
    • OSV malware
    • GHSA
  2. 02 · Verify

    chainsaw bundle verify

    on your transfer schedule

  3. 03 · Apply

    chainsaw bundle apply

    loaded from CHAINSAW_INTEL_BUNDLE_PATH instead of phoning home

Migration

Front your existing registry

Chainsaw slots in front of what you run today.

You runHow Chainsaw fits
Artifactory / NexusKeep them. Chainsaw fronts the public registries they proxy. Zero dual-publish.
Cloudsmith / JFrog SaaSPoint Chainsaw's upstream at it; your URLs stay.
Verdaccio / npm mirrorThe mirror stays; Chainsaw replaces the public hop. No .npmrc change.
Snyk / SCA scannersRun both. Chainsaw decides what enters; SCA reports what is there.

Need on-prem or air-gapped?

Let's scope the deployment together

On-prem comes with the Enterprise plan. Book a 30-minute call to scope yours.