New · Enforce your engineering standards on every build with more than a hundred ready-made rules. Introducing Guardrails
Every organisation has rules for how software gets built and shipped. Guardrails check them automatically on every change, so risky mistakes are caught before they merge, every team works to the same standard, and you can prove it whenever someone asks.
Works with the CI you already run. More than a hundred ready-made rules, live in a day.
125
Ready-made rules
13
Language ecosystems
1
Command to adopt
0
Scripts to maintain
Your organisation already has standards. The trouble is that nothing checks them. Under deadline pressure they slip, each team drifts its own way, and nobody finds out until an incident, a customer security review or an audit asks for proof. Guardrails turn those standards into automatic checks on every change, rolled out in three steps without stopping anyone's work.
01
Start from more than a hundred ready-made rules and add your own. Every team runs the same maintained rules, so nobody has to build or own checks of their own.
02
Run the rules in report-only mode first. Nothing is blocked, every result is recorded with its evidence, and you see how close each team is to the standard.
03
Switch enforcement on rule by rule as each team catches up. From then on, risky changes are stopped on the pull request, when they are cheapest to fix.
Leaked credentials, unpinned dependencies and over-privileged pipelines are stopped before they reach production.
Answer security reviews and audits with a report, not a scramble.
Every team and every new service is held to, and measured against, the same rules.
Standards rise without blocking delivery or frustrating developers.
One view shows how far each team, project and service is from the standard, and whether that is getting better. See where a single shared fix would do the most good, and which services are not being measured at all.
Checks run wherever the CLI runs. Recording results and the team view come with a paid plan.
This team's guardrails
1,180 runs
Adoption
88%
37 ran guardrails · 5 no data
Coverage
94%
412 verdicts · 26 skipped
Compliance
81%
334 passed · 78 failed
Failing in the most modules
Maintained, tested and open source, covering the areas where most organisations carry risk, across the languages and CI platforms your teams already use. A few examples:
Stop the mistakes attackers look for before they reach production.
Know what every artifact is made of, and refuse what you do not allow.
Containers and cloud configuration built the same safe way in every team.
Changes small enough to review and traceable back to the work that asked for them.
Every file has an owner and every repository explains itself.
Agents in your pipelines held to the same standard as your engineers.
| Guardrail | Verdict | Violations | Severity | |
|---|---|---|---|---|
| ✅ | Commits follow Conventional Commits | passed | 0 | error |
| ✅ | Workflows declare the token permissions they need | passed | 0 | error |
| ❌ | Dockerfile base images are pinned | failed | 2 | error |
| ⏭️ | Coverage is at or above the floor | skipped | 0 | warning |
Dockerfile:1 builds from eclipse-temurin:21-jre with no digest
tools/Dockerfile:3 builds from alpine:latest with no digest
Pin each base image to the digest it resolves to today, so a rebuild of this commit starts from the same bytes.Developers see the result on their pull request with the exact problem and how to fix it. Issues are resolved by the person who introduced them, in minutes, instead of turning into tickets, exceptions or findings months later.
Pick the rules that would have prevented your last incident. Results appear on the next pull request, and you turn enforcement on when the team is ready.