Skip to content

Product

Protect

Your dependencies and your AI endpoints, watched continuously.

The problem

The package you installed last year was taken over last week. The MCP server somebody stood up for a demo is still listening, with no authentication in front of it.

How it works

  • Package policy: block what you have decided not to allow, at install time, with an exception path that records who allowed it and why.
  • Typosquat and maintainer-change detection on what you actually depend on, not on a feed of everything.
  • MCP endpoints: what each one exposes, which tools can reach outside, and whether a tool description is instructing the model that reads it.
  • Continuous monitoring, so a package that becomes dangerous after you installed it is still your problem and still ours.

What it does not do

It watches the dependencies and endpoints you have connected. A package installed on a machine we cannot see is not in scope.