Features
What the gate records.
Guardrail Ledger is the control plane. Engines run on your Azure Pipelines agents. We decorate the PR, apply gates, and keep who approved an exception.
-
Azure Pipelines task
One task wraps the four engines. Findings come back as SARIF. The PR gets the annotation.
-
SAST
Opengrep community rules. Honest limit: no Semgrep Pro cross-file taint analysis.
-
SCA and SBOM
Trivy scans packages, licenses, and images, and can emit an SBOM.
-
IaC
Trivy and Checkov on templates and config before they ship.
-
Secrets
Gitleaks on the agent. We store the finding, not the secret value.
-
Exception ledger
Owner, approver, expiry, and reason on every accepted finding.
-
Severity gates
You set what fails the PR. The ledger records who waived it.
-
AI-agent inventory
MCP servers, agent configs, and plugins in the repo, next to the other findings.
-
Source stays in your tenant
Nothing clones the repo to us. Only SARIF, SBOM, and policy decisions come over.
How it works.
-
Install the Azure DevOps extension
A pipeline task wraps Trivy, Gitleaks, Checkov, and Opengrep. They run on your agents.
-
SARIF lands here
We decorate the pull request and apply your severity gates.
-
Exceptions stay on file
Someone owns it, someone approved it, and it expires.
Put a gate on the pull request.
Run the scanners on your agents. We keep SARIF, exceptions, and who signed off.