I nostri prodotti
Quattro pack one-time self-hosted. Ogni pack include policy template, GitHub Action PR Gate, e report HTML firmati. Nessun SaaS, nessuna dipendenza esterna.
LeakLock
Previeni l'esposizione di segreti e sourcemap nei bundle frontend
- Scanner deterministico per segreti nei bundle
- Sourcemap guard per Vercel/Netlify/Cloudflare
- NEXT_PUBLIC lint con allowlist
- GitHub Action PR Gate
Webhook Fortress
Verifica firme HMAC e previeni replay attack su webhook
- Middleware per Cloudflare/Vercel/Netlify
- Preset per Stripe/Slack/GitHub/Shopify
- Replay guard con nonce
- CLI signer per test
SupplyShield
SBOM, licenze e SRI per la supply chain JavaScript
- Genera SBOM CycloneDX da lockfile
- NOTICE/Third-Party con SPDX
- SRI generator e verifica
- GitHub Action guard su licenze
StageShield
Proteggi staging e preview da indicizzazione e accesso non autorizzato
- robots.txt + X-Robots-Tag noindex
- Preview Gate con token
- Canonical Guard
- Config generator per piattaforme
Scegli per problema
🔑 Segreti esposti nei bundle
API keys, token, credenziali nei file JavaScript pubblici o sourcemap.
LeakLock🔓 Webhook non verificati
Webhook accettati senza verifica HMAC, vulnerabili a replay attack.
Webhook Fortress🌐 Staging indicizzato
Preview e staging accessibili pubblicamente e indicizzati da Google.
StageShieldConfronto rapido
| Funzionalità | LeakLock | Webhook Fortress | SupplyShield | StageShield |
|---|---|---|---|---|
| GitHub Action PR Gate | ✓ | ✓ | ✓ | ✓ |
| Report HTML firmato | ✓ | ✓ | ✓ | ✓ |
| Edge middleware | ✓ | ✓ | — | ✓ |
| CLI tools | — | ✓ | ✓ | — |
| SBOM generation | — | — | ✓ | — |
Tutti i pack includono policy template, documentazione completa e supporto email.
Documentazione
Ogni prodotto include documentazione completa con esempi pratici.
Leggi la documentazione