Security that ships with your code

GuardRail runs ten security scanning modules in your CI pipeline, from secrets and dependencies to infrastructure as code and container images, and brings every finding into one report before code reaches production.

Early access. Demos take 20 minutes and run on a repository you choose.

Example runguardrail v0.2.0

$ guardrail --modules secrets,iac,container --fail-on HIGH

[guardrail] Modules: secrets iac container

[guardrail] Module completed: secrets

[guardrail] Module completed: iac

[guardrail] Module completed: container

[guardrail] CRITICAL: 2

[guardrail] HIGH: 1

[guardrail] TOTAL: 3

[guardrail] Scan FAILED — findings at or above HIGH severity detected

3 findings at or above HIGH

  • CRITICALAWS secret access key.env.prod
  • CRITICALStripe API keysrc/config/payments.js
  • HIGHS3 bucket "user-uploads" is publicly readableinfra/storage.tf

Built on

  • TruffleHog
  • OSV-Scanner
  • Opengrep
  • Checkov
  • Trivy
  • Syft
  • Cosign
  • Nuclei
  • Steampipe
  • GuardRail Mobile

Most security tooling assumes you have a security team

Enterprise platforms are priced for large companies. Assembling open-source scanners yourself takes weeks of setup, and their overlapping output buries the findings that matter.

  • Secrets in code

    API keys and tokens get committed by accident, and they stay in git history after the file is fixed.

  • Misconfigured infrastructure

    A public storage bucket or an over-permissioned IAM role is easy to miss in a Terraform review.

  • Vulnerable dependencies and images

    Packages and base images go stale. Known CVEs ship unless every build is checked.

  • Duplicate alerts

    Overlapping tools report the same issue several times, until teams stop reading the output.

One job in the pipeline you already run

GuardRail ships as a single container image. It reads your code from a read-only mount, and there are no agents to install.

  1. Add it to CI

    Use the reusable GitHub Actions workflow or the GitLab CI template. A CLI is available for local runs.

  2. Scan every change

    The modules you choose run in parallel on each pipeline run.

  3. Review one set of results

    Findings from every tool are normalized into one format and sent to the GuardRail dashboard and, on GitHub, to code scanning.

  4. Gate on severity

    Builds fail on findings at or above your threshold. If a scanner itself fails, the build fails too, so a broken scan never passes as clean.

Ten modules, one report

Each module wraps a proven open-source engine, plus GuardRail's own mobile scanner. Tools are scoped so the same issue isn't reported twice.

  • Secrets

    Keys, tokens, and credentials in source code and git history, with more than 700 detectors.

    TruffleHog

  • Dependencies

    Known vulnerabilities in your lockfiles, checked against the OSV database, plus a CycloneDX SBOM.

    OSV-Scanner, Syft

  • Source code

    Insecure patterns in application code, using rules bundled into the scanner image.

    Opengrep

  • Infrastructure as code

    Terraform, CloudFormation, Kubernetes, and Helm misconfigurations before they deploy.

    Checkov

  • Containers

    CVEs and secrets in image layers, and image signature verification.

    Trivy, Cosign

  • Running apps and cloud

    Dynamic tests against a URL you provide, and posture benchmarks for AWS, Azure, and GCP accounts.

    Nuclei, Steampipe

  • Mobile apps

    Android APK, iOS IPA, and mobile source analysis.

    GuardRail Mobile

Container, signature, dynamic, and cloud checks run when you point them at an image, URL, or cloud account.

Pricing

Every plan starts with a 20-minute demo on a repository you choose. Prices are per month.

Starter

$299/ month

For small teams starting a security program

  • Up to 5 users
  • Up to 20 repositories
  • Secrets and IaC scanning
  • Container scanning
  • Unified findings dashboard
Book a demo

Growth

$699/ month

For growing teams running in the cloud

  • Up to 20 users
  • Unlimited repositories
  • Everything in Starter
  • Cloud posture benchmarks
  • CI/CD pipeline gating
Book a demo

Compliance

$1,499/ month

For teams preparing for a security audit

  • Up to 50 users
  • Everything in Growth
  • SBOM generation
  • DAST scanning
Book a demo

MSP / Enterprise

Custom

For consultancies, agencies, and larger organizations

  • Everything in Compliance
  • Dedicated account manager
Book a demo

See what GuardRail finds in your code

In a 20-minute demo, we run GuardRail against a repository you choose and walk through the findings with you.

Submitting opens a pre-filled email to info@bmosan.com in your mail app.