Starter
$299/ month
For small teams starting a security program
- Up to 5 users
- Up to 20 repositories
- Secrets and IaC scanning
- Container scanning
- Unified findings dashboard
GuardRail runs ten security scanning modules in your CI pipeline, from secrets and dependencies to infrastructure as code and container images, and brings every finding into one report before code reaches production.
Early access. Demos take 20 minutes and run on a repository you choose.
$ guardrail --modules secrets,iac,container --fail-on HIGH
[guardrail] Modules: secrets iac container
[guardrail] Module completed: secrets
[guardrail] Module completed: iac
[guardrail] Module completed: container
[guardrail] CRITICAL: 2
[guardrail] HIGH: 1
[guardrail] TOTAL: 3
[guardrail] Scan FAILED — findings at or above HIGH severity detected
3 findings at or above HIGH
Built on
Enterprise platforms are priced for large companies. Assembling open-source scanners yourself takes weeks of setup, and their overlapping output buries the findings that matter.
API keys and tokens get committed by accident, and they stay in git history after the file is fixed.
A public storage bucket or an over-permissioned IAM role is easy to miss in a Terraform review.
Packages and base images go stale. Known CVEs ship unless every build is checked.
Overlapping tools report the same issue several times, until teams stop reading the output.
GuardRail ships as a single container image. It reads your code from a read-only mount, and there are no agents to install.
Use the reusable GitHub Actions workflow or the GitLab CI template. A CLI is available for local runs.
The modules you choose run in parallel on each pipeline run.
Findings from every tool are normalized into one format and sent to the GuardRail dashboard and, on GitHub, to code scanning.
Builds fail on findings at or above your threshold. If a scanner itself fails, the build fails too, so a broken scan never passes as clean.
Each module wraps a proven open-source engine, plus GuardRail's own mobile scanner. Tools are scoped so the same issue isn't reported twice.
Keys, tokens, and credentials in source code and git history, with more than 700 detectors.
TruffleHog
Known vulnerabilities in your lockfiles, checked against the OSV database, plus a CycloneDX SBOM.
OSV-Scanner, Syft
Insecure patterns in application code, using rules bundled into the scanner image.
Opengrep
Terraform, CloudFormation, Kubernetes, and Helm misconfigurations before they deploy.
Checkov
CVEs and secrets in image layers, and image signature verification.
Trivy, Cosign
Dynamic tests against a URL you provide, and posture benchmarks for AWS, Azure, and GCP accounts.
Nuclei, Steampipe
Android APK, iOS IPA, and mobile source analysis.
GuardRail Mobile
Container, signature, dynamic, and cloud checks run when you point them at an image, URL, or cloud account.
Every plan starts with a 20-minute demo on a repository you choose. Prices are per month.
$299/ month
For small teams starting a security program
$699/ month
For growing teams running in the cloud
$1,499/ month
For teams preparing for a security audit
Custom
For consultancies, agencies, and larger organizations
In a 20-minute demo, we run GuardRail against a repository you choose and walk through the findings with you.