Technology, software & SaaS

Your product is your attack surface, and your customers know it

For a software company, a breach is not an operational problem — it is a product problem, a renewal problem and a fundraising problem. Guardian Sentinel secures the path from a developer's laptop to a production tenant: source code, build pipeline, artefact registry, runtime and the isolation boundary your customers are trusting.

  • SOC 2 Type II
  • ISO 27001 & 27017
  • SLSA Level 3
  • SSDF / NIST SP 800-218
  • CSA STAR
3.2× Growth in attacks targeting build systems rather than production since 2022 Guardian Labs software supply-chain tracking
61% Of enterprise deals now include a security questionnaire before technical evaluation Median 214 questions, 19 days of engineering time
11 min Median time from a leaked cloud key being pushed to first adversarial use Automated scrapers watch public repositories continuously
4.1% Of production identities in a typical SaaS estate are non-human and unowned Service accounts, CI tokens and abandoned integrations

Source code & CI/CD

The pipeline is the shortest path to every customer you have

An attacker who compromises production reaches one environment. An attacker who compromises your build reaches every environment you ship to, signed, with your release notes attached. Guardian instruments each stage of the software factory and treats a change in build behaviour with the same seriousness as a change in production behaviour.

ATTACKER TECHNIQUE Stolen session cookie, malicious IDE extension Force-push to a protected branch, rogue collaborator Workflow injection, dependency confusion Unsigned artefact substitution, tag mutation Stolen deploy credential, drift from declared state Tenant boundary escape Workstation Source repo CI build Registry Deploy Runtime laptops, IDEs Git, reviews runners, secrets images, packages IaC, clusters tenants GUARDIAN CONTROL EDR + device posture gate on every push and token issuance Branch protection telemetry, secret scanning, commit signature checks Runner runtime detection, egress allow-list, build provenance capture Signature and attestation verification, SBOM diff per release IaC policy checks, drift detection, deploy identity verification Tenant isolation monitoring, runtime EDR Unbroken provenance Every artefact in production resolves back to the commit, the reviewer, the runner and the build that produced it — in one query, in under two seconds.
The trust chain from workstation to tenant. Guardian's job is to make every arrow in this diagram verifiable after the fact.

Developer machines, without the mutiny

Engineers will route around a security agent that costs them build time. Guardian's macOS and Linux sensors exclude toolchain directories from synchronous inspection by default, add a measured 1.8% to a cold Rust build, and never quarantine a file mid compile. Where a real detection fires, the developer gets an in-context explanation rather than a silent block and a support ticket.

Endpoint security

Build runners are production

A CI runner holds cloud credentials, registry write access and your signing identity. Guardian treats it as a tier-one asset: runtime detection inside the job, an egress allow-list so a compromised dependency cannot phone home, and an alert the moment a build step executes something that was not in the workflow definition.

Cloud & workload security

Secrets, found before the scrapers find them

Guardian scans commits pre-receive, scans the history you already have, and — more usefully — validates whether a discovered credential is live. A revoked key in a 2019 commit is noise. A live production token in a public fork is an incident, and Guardian opens it with the revocation action already staged.

Data protection

Multi-tenant isolation

The boundary you sell is the boundary you must monitor

Every SaaS security review eventually arrives at the same question: how do you know tenant A cannot read tenant B's data? “Because the query includes a tenant ID” is an answer that has failed publicly many times. Guardian gives you evidence instead of an assertion.

Cross-tenant access detection

Guardian learns the normal shape of data access per service and flags the query path, API route or background job that touches more tenant partitions than its function requires — the signature of both a broken authorisation check and an active enumeration attempt.

Namespace and workload boundaries

For per-tenant Kubernetes namespaces or per-tenant clusters, Guardian enforces and verifies the network policy that separates them, and alerts on any pod that acquires a service account, mount or route belonging to a different tenant.

Key separation, verified continuously

Where you offer per-tenant encryption keys or customer-managed keys, Guardian confirms the key actually in use on each write path matches the tenant's declared key — because key configuration drift is invisible until a customer audits it.

Support access, recorded

Your support engineers can impersonate a customer, and your customers know it. Guardian records every impersonation session with the ticket reference, the data viewed and the duration, and can expose that log to the affected tenant directly.

TENANT PARTITIONS tenant-04a1 tenant-1c72 tenant-2f09 tenant-3b55 EU-west · CMK US-east · CMK EU-west · shared AP-south · CMK 142 principals 1,104 principals 89 principals 377 principals Shared services API gateway · auth service · job runner · object store Every call carries a tenant assertion; Guardian verifies the assertion matches the data touched CROSS-TENANT ACCESS · SEV 1 Job runner batch-export touched tenant-1c72 and tenant-2f09 in one execution. Tenant assertion present for 1c72 only. Root cause: unbounded query in the export path. Contained in 41 s — job paused, export artefacts held, owning team paged with the query.
An isolation violation caught by behaviour, not by a customer.

Customer trust & attestations

Turn the security questionnaire from a tax into an asset

Enterprise buyers gate on security review long before they gate on features. The companies that win those cycles are not the ones with the most controls — they are the ones who can evidence the controls in a week rather than a quarter.

Attestations and frameworks a growing SaaS company typically faces, when they usually become blocking, and what Guardian supplies toward each.
Framework Typically blocking at The hard part What Guardian supplies
SOC 2 Type II First six-figure enterprise deal Proving controls operated continuously across the observation window, not on audit day Continuous control evidence with timestamps, exported per trust services criterion
ISO 27001 & 27017 First serious European or APAC enterprise deal Annex A coverage, risk treatment records and management review inputs Control mapping, asset inventory and incident register in the structure the auditor expects
SLSA Level 3 When your buyers ship regulated software themselves Non-falsifiable build provenance and isolated, ephemeral build environments Provenance capture at the runner, artefact attestation verification and drift alerting
NIST SSDF (SP 800-218) US federal and federal-adjacent sales Evidence for the secure software attestation form, signed by an executive Practice-level evidence for PO, PS, PW and RV groups, generated from live pipeline telemetry
FedRAMP Direct US government sale Boundary definition, continuous monitoring and 325 controls with an authorising official FedRAMP High deployment option and ConMon telemetry that maps to the monthly deliverable
CSA STAR & CAIQ Any deal where procurement uses a standard questionnaire Keeping 261 answers accurate as the product changes weekly Answer library backed by live control state, so a drifted answer is flagged rather than shipped

Scroll the table sideways to see every column.

A trust page that is actually true

Guardian can publish a live subset of your control state — patch currency, MFA coverage, incident count, uptime — into your own trust centre, so prospects self-serve the answers instead of queuing behind your solutions engineer.

Sub-processor and vendor posture

Your customers hold you responsible for your vendors. Guardian monitors the SaaS applications and OAuth grants inside your own estate and flags the ones that acquired production data access without a review.

Integrations

Breach notification you can meet

Most enterprise contracts commit you to notification inside 24 or 48 hours with specifics. Guardian's incident narrative gives you the affected-tenant list and the timeline in hours, so the clause is survivable.

Incident response

Scaling without re-platforming

Security that survives your next three growth stages

The tooling that suits a forty-person startup is usually abandoned at three hundred and torn out at a thousand. Guardian is one platform across all three, and the things that change are configuration, not architecture.

Seed to Series A — 10 to 60 people, one product, one cloud account

There is no security team. There is one engineer who cares, and a founder who has just been sent a 214-question spreadsheet by a prospect. The priorities are laptop coverage, MFA everywhere, secret scanning and a defensible answer about production access.

Guardian deploys in an afternoon: agents by MDM, cloud connected read-only, source control connected by app install. Managed detection carries the on-call, because a four-person engineering team cannot also be a SOC. This is the same configuration described on the small business page, and it costs accordingly.

Series B to C — 60 to 400 people, multiple environments, first security hire

Now there are staging environments nobody owns, three cloud accounts created during a hackathon, a data team with production read access, and a compliance deadline. The first security hire spends month one building an inventory by hand unless something already has it.

Guardian's estate model — assets, identities, repositories, pipelines, cloud resources and the relationships between them — is that inventory, and it is already populated on day one because the sensors have been running since the seed stage. Policy graduates from “alert someone” to environment-specific enforcement.

Series D and beyond — 400 to 3,000 people, regulated customers, multiple products

Product lines diverge, an acquisition arrives with its own stack, a regional deployment is required for a European customer, and the security team is now eleven people organised into functions. Delegated administration matters, and so does the ability to give the acquired company its own console view without merging identity systems on day one.

Guardian's multi-tenant governance handles both: business units get scoped consoles, shared detection content, and roll-up reporting for the CISO. See enterprise for how that model works at the largest scale.

Acquisition and integration — inheriting an estate you did not build

Diligence tells you what the acquired company documented. Guardian tells you what it actually runs. Deploying sensors during the integration window typically surfaces two to three material findings — an unrotated shared credential, an internet-exposed admin interface, a data store nobody named — inside the first fortnight.

Because the acquired estate can run as its own scope under your contract, you get visibility before you get integration, which is the correct order.

1 afternoonTypical initial deployment at Series A scale
400+Connectors and a documented open API
< 2 sArtefact-to-commit provenance lookup
1.8%Measured build-time overhead on developer machines

How it fits your engineering workflow

Security that arrives where engineers already are

A finding that lands in a security console is a finding that waits. A finding that lands in the pull request, the terminal or the incident channel gets fixed in the same session.

In the pull request

Guardian comments on the specific line, explains the exploitability in your codebase rather than in the abstract, and suppresses the finding automatically if the code path is unreachable from any entry point.

In the pipeline

Policy gates are declared as code, evaluated in the build, and return a machine readable verdict. Break-glass overrides exist, are logged with the person and reason, and appear in the weekly report.

In the incident channel

Guardian posts the narrative into the channel your on-call already lives in, with the evidence attached and the containment action offered as a button rather than a runbook step.

In the API

Everything the console does is available over a documented REST and GraphQL API with webhooks, so the parts of the workflow you have already automated stay automated.

Native integrations, not a screenshot of one GitHub, GitLab, Bitbucket, Jenkins, CircleCI, Buildkite, Argo CD, Terraform Cloud, Kubernetes, AWS, Azure, GCP, Snowflake, Okta, Entra ID, Slack, PagerDuty, Jira and Linear — installed by OAuth app or Terraform module, with least-privilege scopes documented per connector.

We closed our largest deal in company history on a security review that took eleven days instead of the usual quarter. Their assessor asked for evidence that our build environment was isolated and our artefacts were attested. We exported it from Guardian while she was still on the call. That is worth more to me than any dashboard.

Julian Tran
Head of Security Engineering, Series D infrastructure SaaS
11 days Median enterprise security review with evidence on demand Against a 63-day baseline before Guardian
41 s Median containment time for a cross-tenant access violation Job paused, artefacts held, owning team paged
1,780 Software companies running Guardian across their pipeline and runtime From seed stage to public company

Trace one artefact back to one commit, live

Connect a repository and a cloud account in a thirty-minute session, and we will pick a running container in your environment and resolve it to the commit, the reviewer and the build that produced it — in front of you. If we cannot, that is worth knowing too.