Features

What the gate records.

Guardrail Ledger is the control plane. Engines run on your Azure Pipelines agents. We decorate the PR, apply gates, and keep who approved an exception.

  • Azure Pipelines task

    One task wraps the four engines. Findings come back as SARIF. The PR gets the annotation.

  • SAST

    Opengrep community rules. Honest limit: no Semgrep Pro cross-file taint analysis.

  • SCA and SBOM

    Trivy scans packages, licenses, and images, and can emit an SBOM.

  • IaC

    Trivy and Checkov on templates and config before they ship.

  • Secrets

    Gitleaks on the agent. We store the finding, not the secret value.

  • Exception ledger

    Owner, approver, expiry, and reason on every accepted finding.

  • Severity gates

    You set what fails the PR. The ledger records who waived it.

  • AI-agent inventory

    MCP servers, agent configs, and plugins in the repo, next to the other findings.

  • Source stays in your tenant

    Nothing clones the repo to us. Only SARIF, SBOM, and policy decisions come over.

How it works.

  1. Install the Azure DevOps extension

    A pipeline task wraps Trivy, Gitleaks, Checkov, and Opengrep. They run on your agents.

  2. SARIF lands here

    We decorate the pull request and apply your severity gates.

  3. Exceptions stay on file

    Someone owns it, someone approved it, and it expires.

Put a gate on the pull request.

Run the scanners on your agents. We keep SARIF, exceptions, and who signed off.