Part of Spot Suite
PR gates for Azure DevOps,
with who signed off.
Scans run on your pipeline agents. Source stays in your tenant. We take SARIF and SBOM, decorate the PR, and keep the exception ledger.
GDPR · DORA · NIS2
Gates · PR checks and exceptions, tracked
Capabilities
What the gate records.
-
Pipeline gates
A pipeline task in Azure DevOps runs the scanners on your agents and fails the PR when policy says so.
-
Exception ledger
Every accepted finding gets an owner, approver, expiry, and reason. The gate stays closed until someone signs.
-
SAST without the scanner bill
Opengrep community rules on your agents. No Semgrep Pro taint analysis, and we do not pretend otherwise.
-
SCA, licences, containers, IaC
Trivy covers packages, licences, SBOM, images, and IaC. Checkov adds a second IaC pass.
-
Secrets on the agent
Gitleaks runs where the code already is. We store the finding, not the secret.
-
AI-agent inventory
MCP servers, agent configs, and plugins in the repo show up next to the other findings.
How it works.
-
Install the Azure DevOps extension
A pipeline task wraps Trivy, Gitleaks, Checkov, and Opengrep. They run on your agents. Source never leaves your tenant.
-
SARIF lands here
We take SARIF and SBOM, decorate the pull request, and apply your severity gates.
-
Exceptions stay on file
Someone owns the exception, someone approved it, and it expires. That record is what the auditor sees.
Pricing.
Team €299 / month for 50 contributors. Business €599 / month for 100. 30-day trial on the website.
Guardrail Ledger is a standalone Spot Suite product. Card checkout is on spot-suite.com. See pricing
Questions.
-
Where does the source code go?
It does not come here. Scanners run on your Azure Pipelines agents. We store SARIF, SBOM, gate decisions, and exception records under Spot Cloud B.V. An order without trial days (invoice, card or Marketplace) gets its own Postgres database in the region chosen at purchase: the EU by default, or the UK, US, Canada, Asia–Pacific or Latin America. A trial, or a card order that starts with trial days, gets its own schema in the shared EU project (Paris), and nothing moves it to its own database on first payment yet.
-
How does sign-in work?
Microsoft Entra SSO through Spot Suite OIDC. Your team uses a work account and lands in your own tenant store.
-
Is this a Snyk replacement?
No. It is a control plane over open-source engines, priced for 10–100 developer Azure DevOps shops. Community SAST has no cross-file taint analysis.
-
Can I buy it today?
Yes. Start a 30-day trial on the website. No Azure Marketplace subscription.
Spot Suite
The rest of the suite.
Same Spot Suite login and invoice if you already run this one. Trials are 30 days; some products are waitlist.
-
Secure file exchange Move files over SFTP, S3, Azure Blob and more, with a custody record per transfer. xevolve.io Open
-
TLS certificate lifecycle Find every certificate, renew it through ACME, and deploy it where it runs. automate-certificates.com Open
-
Web content filtering Block risky domains on managed devices and log every decision. clear-screen.ai Open
-
Cloud cost and forecasts Daily spend from AWS, Azure, GCP and StackIT, with anomalies flagged before the close. Join waitlist
-
IP address management Plan CIDR blocks across Azure tenants and catch conflicts before they ship. Join waitlist
-
Joiner, mover, leaver Onboard, move and offboard staff in Microsoft 365 or Google Workspace, with a log. Join waitlist
-
UBO and sanctions screening Screen owners and counterparties against UBO and sanctions lists. Join waitlist
Put a gate on the pull request.
Run the scanners on your Azure Pipelines agents. We keep SARIF, exceptions, and who signed off.