Guardrail your organizational standards

Every organisation has rules for how software gets built and shipped. Guardrails check them automatically on every change, so risky mistakes are caught before they merge, every team works to the same standard, and you can prove it whenever someone asks.

Works with the CI you already run. More than a hundred ready-made rules, live in a day.

125

Ready-made rules

13

Language ecosystems

1

Command to adopt

0

Scripts to maintain

From written down to built in.

Your organisation already has standards. The trouble is that nothing checks them. Under deadline pressure they slip, each team drifts its own way, and nobody finds out until an incident, a customer security review or an audit asks for proof. Guardrails turn those standards into automatic checks on every change, rolled out in three steps without stopping anyone's work.

01

Choose your standards

Start from more than a hundred ready-made rules and add your own. Every team runs the same maintained rules, so nobody has to build or own checks of their own.

02

See where you stand

Run the rules in report-only mode first. Nothing is blocked, every result is recorded with its evidence, and you see how close each team is to the standard.

03

Enforce when ready

Switch enforcement on rule by rule as each team catches up. From then on, risky changes are stopped on the pull request, when they are cheapest to fix.

Fewer incidents

Leaked credentials, unpinned dependencies and over-privileged pipelines are stopped before they reach production.

Audit-ready evidence

Answer security reviews and audits with a report, not a scramble.

One standard everywhere

Every team and every new service is held to, and measured against, the same rules.

No slowdown

Standards rise without blocking delivery or frustrating developers.

Know where every team stands

One view shows how far each team, project and service is from the standard, and whether that is getting better. See where a single shared fix would do the most good, and which services are not being measured at all.

  • Adoption shows how much of the organisation is covered.
  • Compliance shows how much of it meets the standard.
  • Trends show whether it is improving month on month.

Checks run wherever the CLI runs. Recording results and the team view come with a paid plan.

More than a hundred ready to use rules

Maintained, tested and open source, covering the areas where most organisations carry risk, across the languages and CI platforms your teams already use. A few examples:

Security

Stop the mistakes attackers look for before they reach production.

  • No credential file in the checkout
  • Workflows declare the token permissions they need
Supply chain

Know what every artifact is made of, and refuse what you do not allow.

  • The build produced a software bill of materials
  • No component carries a licence the team refuses
Infrastructure

Containers and cloud configuration built the same safe way in every team.

  • Dockerfile base images are pinned
  • Terraform state is encrypted at rest
Delivery

Changes small enough to review and traceable back to the work that asked for them.

  • Commits reference a work item
  • The change is small enough to review
Ownership

Every file has an owner and every repository explains itself.

  • CODEOWNERS covers everything
  • Repository documents how to report a vulnerability
AI coding agents

Agents in your pipelines held to the same standard as your engineers.

  • Claude runs in CI without bypassing its permissions
  • Repository instructs the coding agents working in it

Fixed in review, not after release

Developers see the result on their pull request with the exact problem and how to fix it. Issues are resolved by the person who introduced them, in minutes, instead of turning into tickets, exceptions or findings months later.

Start with three rules this week.

Pick the rules that would have prevented your last incident. Results appear on the next pull request, and you turn enforcement on when the team is ready.