Powerful Features forComplete Visibility

Everything you need to monitor your software supply chain

GitHub Integration

Connect Your Repositories

Install the Guardian GitHub App or use a Personal Access Token to connect your repositories. We automatically detect and analyze all dependency manifest files.

  • GitHub App or PAT authentication
  • Automatic webhook updates on push
  • Organization-wide or per-repo access
  • Branch-specific tracking
repositories: 24
last_scan: 2 min ago
dependencies: 1,847
Dependency Discovery

Multi-Ecosystem Support

Parse dependency files from all major package ecosystems. We extract exact versions from lock files when available for precise vulnerability matching.

  • go.mod / go.sum - Go modules
  • package.json / yarn.lock / pnpm-lock.yaml - Node.js (npm, yarn, pnpm)
  • requirements.txt / Pipfile.lock - Python
  • Cargo.toml / Cargo.lock - Rust
  • pom.xml / build.gradle - Java
  • Dockerfile / docker-compose.yml - Container images & packages
  • Makefile / .mise.toml - Tool versions
Go
npm
PyPI
Cargo
Maven
Docker
Vulnerability Intelligence

Multi-Source Vulnerability Database

Aggregated vulnerability data from three trusted open-source databases. Package-level vulnerabilities from GitHub Advisory Database (GHSA) and Google OSV, enriched with detailed CVE information from NIST NVD.

  • GitHub Advisory Database (GHSA) - Curated security advisories for open-source packages
  • Google OSV - Distributed vulnerability database for open-source ecosystems
  • NVD - CVSS v3 scoring, CPE matching, and detailed vulnerability context
  • Automatic version range analysis and affected package detection
  • Daily synchronization across all sources
12 Critical
47 High
156 Medium
892 Low
Alerting

Instant Notifications

Get notified the moment a new vulnerability affects your tracked versions. Configure alert rules by severity, ecosystem, or project.

  • Email notifications
  • Slack webhooks
  • Configurable severity thresholds
  • Project-specific rules
New Vulnerability Alert
CVE-2024-1234 affects express@4.17.1
Severity: High
Compliance

SBOM Generation

Generate Software Bill of Materials in industry-standard formats. Perfect for compliance requirements and supply chain transparency.

  • CycloneDX 1.4+ JSON/XML
  • SPDX 2.3 JSON format
  • One-click export
  • API-accessible
CycloneDX
Components: 247
Export JSON
Code Security

SAST Scanning

Static Application Security Testing with 15+ integrated security scanners. Find vulnerabilities in your source code before they reach production. Automatic deduplication by CWE and location.

  • gosec, semgrep, bandit, bearer, grype, trivy
  • checkov, kubesec, kube-score, detect-secrets
  • npm audit, cve-bin-tool (12 tools total)
  • CWE and CVE correlation
  • Parallel scanning with smart deduplication
SAST Results
3 Critical
12 High
47 Medium
15 tools scanned
AI-Powered

Intelligent Security Analysis

Leverage AI to cut through the noise. Automatically review findings for real-world exploitability, generate executive security reports, and create project-specific security rules.

  • Finding Review - AI analyzes SAST findings to identify false positives vs true vulnerabilities
  • CVE Impact Assessment - Evaluate real-world exploitability based on attack vectors and context
  • Security Report Generation - Create comprehensive incident and scan reports with remediation guidance
  • Impact Summaries - Executive-level summaries explaining security posture in plain language
  • Custom Semgrep Rules - AI generates project-specific security rules based on codebase analysis
AI Analysis
24 findings reviewed
8 false positives identified
16 true positives confirmed
Generate Report
Attack Surface

Asset Monitoring

Monitor your external attack surface with passive DNS-based discovery. Automatically find subdomains, track live domains, and maintain visibility into all your internet-facing assets.

  • Passive DNS Discovery - Find subdomains without active scanning using historical DNS data
  • Live Domain Probing - Automatically check which discovered domains are active and responding
  • IP Resolution - Resolve and track IP addresses for live domains
  • Host Tracking - Maintain an inventory of all hosts associated with your projects
  • Continuous Monitoring - Scheduled discovery and probing keeps your asset inventory current
Asset Discovery
12 subdomains found
8 live domains
15 hosts tracked
*.example.com
Incident Response

Incident Management

Track and manage security incidents from detection to resolution. Link vulnerabilities to incidents, maintain timelines, and coordinate response efforts across your team.

  • Incident Lifecycle - Track incidents through open, investigating, mitigating, resolved, and closed states
  • Alert Linking - Connect vulnerability alerts to incidents for full context
  • Timeline Tracking - Maintain a detailed timeline of all incident actions and updates
  • Assignment & Ownership - Assign incidents to team members for clear accountability
  • AI-Enhanced Reports - Generate comprehensive incident reports with remediation guidance
Incident Tracker
2 Open
1 Investigating
5 Resolved
View Timeline
Enterprise

Teams & Organizations

Manage access and collaboration at scale with multi-tenant organizations, team-based permissions, and role-based access control.

  • Multi-Tenancy - Isolated organizations with separate projects, users, and settings
  • Team Management - Organize users into teams with leads and members
  • Role-Based Access - Admin, member, and viewer roles with granular permissions
  • Project Access Control - Control which teams can access specific projects
  • SSO Integration - Sign in with Google or GitHub for seamless authentication
Team Access
3 Teams
12 Members
8 Projects
Google SSOGitHub SSO
Reporting

PDF Report Export

Generate professional, styled PDF reports for stakeholders and compliance. Reports match the Guardian dark theme and include all relevant security details.

  • Incident Reports - Comprehensive incident documentation with timelines
  • Scan Reports - Project security posture with finding breakdowns
  • Styled Output - Professional dark-themed PDFs matching the webapp
  • Markdown Support - Rich formatting with code blocks and syntax highlighting
  • One-Click Export - Generate and download reports instantly
PDF Export
Incident & Scan Reports
Download PDF

Ready to Get Started?

Connect your first project in under 5 minutes.