Developer docs
API playgroundTry for free, no card

Search company profiles

Safeguard

Full company profile

uuid022bk8c

Namestring
Safeguard
Legal namestring
Safeguard.sh Inc
Websiteurl
safeguard.sh
Company typeenum
Private
Founded yearint
2024
Descriptiontext

Safeguard.sh Inc, founded in 2024 and headquartered in Dublin, California, is an AI-native software supply chain security platform that combines proprietary purpose-built models with autonomous remediation. The company's core technology is a model family — Griffin (five variants from 8B to 671B-MoE), Eagle (13B), and Lion (1B distilled) — trained exclusively on an 11M+ document cybersecurity corpus using a security-augmented tokenizer and an adversarial disproof decoder head, served on the Aegis architecture. The platform delivers 100-layer call-graph reachability analysis (40 layers deeper than legacy SCA), 11 fused scanners across code, containers, and IaC, and Auto-Fix that authors, tests, and merges remediation pull requests under policy gates. Its product surface includes ESSCM, SBOM Studio, TPRM, Open Source Manager, IaC Security, DAST, Safeguard Guard (runtime LLM protection), Cowork, and a Gold Registry of 500K+ zero-CVE hardened components, with 373 compliance framework mappings including FedRAMP HIGH, IL7, SOC 2, ISO 27001, NIST SSDF, EO 14028, DORA, NIS2, and EU AI Act.

The business model is usage-based pricing positioned at roughly a tenth of per-seat Snyk-class ($1,200/dev/yr) and below Vanta-class GRC pricing, with consumption tiers spanning shared cloud, dedicated clusters, VPC-isolated, and sovereign/air-gapped deployments (multi-year contracts) running Griffin Zero on configured 11x H100 to 22x H100 multi-AZ footprints. Revenue also flows from enterprise support and services, plus a Marketplace with 40 community-authored policies and partner-built scanner SDK. GTM is multi-modal: a free 7-day sandbox with self-serve conversion, direct enterprise field sales targeting regulated industries (financial services, banking, defense, healthcare, government), and an MCP-native distribution channel where AI agents (Claude, Cursor, Cline) can evaluate, subscribe, and pay end-to-end over Model Context Protocol. Geographic reach spans nine US regions including GovCloud IL5, ten European cities, sovereign India via GIFT City (IFSCA), thirteen APAC cities, and five Middle East cities.

Customers include a top-5 US bank, a Fortune 100 SaaS platform, a global investment bank under FedRAMP HIGH/IL7, a defense systems integrator, a large healthcare network, a multinational retailer, a managed security provider, and a Series C fintech with 1,400 microservices under management. Reported Q2 2026 transparency metrics include 1,240 active tenants, 3.42M findings shipped, 61% of findings closed by automatic patch, a 0.948 mean adversarial resistance score across the Griffin family, 147 coordinated disclosures, and 100K+ autonomous AI remediations applied. One Fortune 100 customer achieved 10,000+ autonomous fixes with mean time to remediate dropping from 11 days to 3 hours.

Short descriptiontext

Safeguard is an AI-native software supply chain security platform that uses proprietary Griffin, Eagle, and Lion models to autonomously find and fix vulnerabilities across dependencies, containers, and infrastructure. It serves regulated enterprises in financial services, banking, defense, healthcare, and government with FedRAMP HIGH/IL7 sovereign deployments and 373 compliance framework mappings.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
51–100
akta.pro rankint
HeadquartersCalifornia City, United States
HQ citystring
California City
HQ countrystring
United States
HQ regionstring
North America
Markets served

Serves global market

Offices4 records

Each record includes

City, Country, Type, Description, Source

Keyword5 values
software supply chain security, AI vulnerability remediation, SBOM management, compliance automation, third party risk management
Industry3 codes
1Supply Chain & Firmware Security for Industrial Devices
CodeHDADAJALPrimaryYes
2Security Awareness, Training & Compliance Attestation
CodeHDADAIAJPrimaryNo
3Configuration & Exposure Hardening (CIS/Benchmarking)
CodeHDADAHAHPrimaryNo
NAICS code2 codes
  • Computer Systems Design and Related Services54151
  • Computer Systems Design Services541512
SIC code2 codes
  • Services-Prepackaged Software7372
  • Services-Computer Programming, Data Processing, Etc.7370
Product category
Application Security Software
GTM motion4 records

Each record includes

Type, Description, Source

Revenue model4 records
1Platform Subscription (Usage-Based)
TypeUsage Based
Description

Usage-based subscription for the core ESSCM platform. The platform is a functional superset of point scanners (Snyk-class) and GRC tools (Vanta-class), priced at roughly a tenth of per-seat pricing. Agents can also complete the entire procurement lifecycle autonomously over MCP — evaluate, sign up, subscribe, pay — without human handoff.

safeguard.sh
2Sovereign / Air-Gapped Deployments
TypeSubscription Recurring
Description

Sovereign-tier and air-gapped deployments (Griffin Zero, Aegis appliance) for defense, government, and regulated enterprises. Griffin Zero runs on documented multi-GPU sizing from 11x H100 (Growth) to 22x H100 multi-AZ (Mature). Separate compute, infrastructure, and support tiers.

safeguard.sh
3Enterprise Support & Services
TypeProfessional Services
Description

Enterprise customers receive dedicated support, architecture reviews, pen-test summaries, SOC 2 reports, and full control documentation under NDA. Quarterly business reviews and private roadmap reviews are available for enterprise tiers.

safeguard.sh
4Marketplace
TypeMarketplace Commission
Description

Community-contributed policies, guardrails, and remediation recipes published, versioned, and consumed through the Marketplace. First wave includes 40 community-authored policies covering supply chain, AI safety, and licensing. Partner-built scanner SDK enables third-party contributions.

safeguard.sh
Marketing channels11 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels8 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components5 values
Technology or R&D, Personnel, Infrastructure, Operations, Marketing or Sales
Pricing details6 tiers
1Free evaluation sandbox — no credit card, 7-day expiry
ModelFreemiumBilling cadencePay-as-you-go
Notes

7-day sandbox tenant pre-loaded with deliberately vulnerable demo monorepo, full Safeguard stack, Lion on local CLI/VS Code, Eagle and Griffin in cloud, all 11 scanners and 7 enrichment feeds enabled. Self-destructs after 7 days unless converted. No production-grade SLAs.

safeguard.sh
2Usage-based cloud tier — shared multi-tenant inference
ModelUsage-basedBilling cadencePay-as-you-go
Notes

Shared cloud deployment with 99.5% application-layer availability SLA. Pay per scan, per finding, per auto-fix. Griffin Lite, S, M, L auto-routing. Eagle batched INT8. No minimum commitment implied.

safeguard.sh
3Dedicated cluster — single-tenant GPU
ModelUsage-basedBilling cadenceAnnual
Notes

Dedicated cluster with single-tenant GPU pool. 99.9% application-layer availability SLA. Griffin L as default tier. For high-throughput enterprise customers.

safeguard.sh
4VPC-isolated — private cloud deployment
ModelUsage-basedBilling cadenceAnnual
Notes

VPC-isolated deployment. 99.9% application-layer availability SLA. Customer-controlled key material for envelope encryption and signing. Griffin M/L/Zero tiers.

safeguard.sh
5Sovereign / Air-gapped — IL7 / FedRAMP HIGH
ModelSubscriptionBilling cadenceMulti-year contract
Notes

Air-gapped or VPC-isolated deployment for defense, government, and regulated enterprises. 99.95% application-layer availability SLA. Griffin Zero (671B-MoE) on documented multi-GPU sizing from 11x H100. IL7 and FedRAMP HIGH architecture. ITAR/export-control review per release. Customer-controlled keys.

safeguard.sh
6Special tiers for startups, OSS, nonprofits, students, educators
ModelSubscriptionBilling cadenceAnnual
Notes

Dedicated pricing pages for Startups & Bootstrapped, Open Source & Nonprofits, Students, and Educators. Safeguard Academy provides free courses with verifiable certificates.

safeguard.sh
GTM typeB2B
B2B
Offering typeSoftware
Software
Brand1 of 23 records shown
1Griffin AI
Description

Autonomous security agent with 100-layer reachability analysis

+22 more records
Core offering1 text field

Safeguard provides an AI-native software supply chain security platform (ESSCM) that autonomously discovers and fixes Zero-Day and reachability-filtered vulnerabilities across code, containers, dependencies, and infrastructure-as-code. The platform is built on a proprietary model family (Griffin for deep remediation, Eagle for adversarial triage, Lion for on-device inline analysis) and is delivered as a unified control plane that maps findings to 373 compliance frameworks and produces policy-gated pull requests.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 8 values shown
  • ~80% reduction in false positives via reachability analysis vs traditional SCA scanners
+7 more records
Product overview1 text field

Safeguard is an AI-native software supply chain security platform built around autonomous remediation. The core offering is Griffin AI — a family of five purpose-built models (Griffin Lite 8B, S 14B, M 32B, L 70B, Zero 671B-MoE) — supported by Eagle (13B) for ranking and triage, and Lion (1B) for on-device inline analysis. These models are served on the Aegis architecture with sliding-window attention, a security-augmented tokeniser, and adversarial disproof heads. The platform is delivered as a unified ESSCM (Enterprise Software Supply Chain Manager) with integrated modules: Scanner Suite (11 scanners + 7 enrichment feeds), Auto-Fix for autonomous remediation, SBOM Studio for SBOM lifecycle management, TPRM for third-party risk, Open Source Manager for OSS registry intelligence, IaC Security for infrastructure scanning, and DAST for dynamic testing. Access surfaces include a web Portal, Trust Center, MCP Server (25+ tools for Claude/Cursor/Cline agents), Safeguard Code IDE agent, Safeguard Guard runtime protection, Safeguard Cowork collaboration surface, a CLI tool, and a Gold Registry marketplace of 500K+ zero-CVE hardened components. The platform covers 373 compliance frameworks with policy-gated workflows and automated evidence generation.

Product and service20 records
1Griffin AI
Categorycore product
Description

Purpose-built AI reasoning engine for software supply chain security. Five variants (Lite 8B, S 14B, M 32B, L 70B, Zero 671B-MoE) perform autonomous vulnerability discovery, reachability analysis, adversarial disproof, patch authoring, and policy-gated automated remediation across the software lifecycle.

2Eagle
Categorycore product
Description

13B ranking and clustering model for wide-angle triage and adversarial Zero Day discovery across repositories. Eagle Gen 5 (190B) handles multi-jurisdiction policy synthesis across NIS2, DORA, EU AI Act, FedRAMP High, and ISO 27001:2022.

3Lion
Categorycore product
Description

1B distilled on-device model for inline gut-check in the IDE and CLI. Sub-100ms p95 on developer laptop with no network egress. Sink detection, sanitiser quality scoring, and inline triage at commit time. Works offline.

4ESSCM (Enterprise Software Supply Chain Manager)
Categorycore product
Description

Enterprise-grade supply chain security platform providing continuous compliance monitoring across 373 frameworks. Ingests all repos, containers, and manifests into a live SBOM graph with deep transitive and cross-package taint edges, with policy-gated merge workflow from scan to fix to attestation.

5Aegis Architecture
Categorycore product
Description

Reasoning architecture underlying every Griffin variant. Features sliding-window plus landmark attention, security-augmented tokeniser (~28k extra tokens), mixture-of-experts routing (Zero tier), and structured trace output as a first-class contract.

6Auto-Fix
Categorycore product
Description

Autonomous remediation engine that analyses vulnerable dependencies, generates compatible upgrades, opens policy-gated pull requests, runs CI, validates regression suites, and merges fixes. Campaign mode coordinates fan-out across services affected by the same CVE.

7SBOM Studio
Categoryadd-on/module
Description

Software Bill of Materials management for ingesting, slicing, and distributing SBOMs in CycloneDX and SPDX formats with automated generation on every build, version control for SBOM history, and EO 14028 self-attestation integration.

8TPRM (Third Party Risk Manager)
Categoryadd-on/module
Description

Third Party Risk Manager providing vendor SBOM verification and continuous vendor tracking, with sub-processor tracking and compliance mapping across multiple regulatory frameworks.

9MCP Server
Categoryadd-on/module
Description

Model Context Protocol server providing 25+ tenant-scoped tools enabling Claude, Cursor, Cline, and custom agents to scan repos, query vulnerabilities, generate remediation plans, apply fixes, merge PRs, and check compliance gates. Supports agentic end-to-end procurement.

10Gold Registry
Categoryadd-on/module
Description

Marketplace of 500K+ curated zero-CVE hardened container images and packages across npm, PyPI, Maven, NuGet, Go, Rust, RubyGems, PHP, containers, and Helm, signed with SLSA L3 provenance and rebuilt continuously.

11Scanner Suite
Categoryadd-on/module
Description

Eleven integrated scanners running in parallel against ingested artifacts, fused into a single ranked candidate set with cross-scanner evidence. Seven enrichment feeds: NVD, OSV, EPSS, KEV, GHSA, VirusTotal, VulnCheck.

12Open Source Manager (OSM)
Categoryadd-on/module
Description

Registry intelligence for open source software dependencies. Monitors and analyses OSS packages across ecosystems, tracking maintainer risk, typosquat campaigns, and dependency confusion attacks.

13Safeguard Code
Categoryadd-on/module
Description

Local coding agent for IDE and CLI that writes and refactors securely by default, respecting repo conventions and security policy, with 42 secure completions per hour.

14Safeguard Guard
Categoryadd-on/module
Description

Runtime protection layer providing guardrails for LLM apps and agents, including prompt-injection, jailbreak, and exfiltration defense at the I/O boundary.

15Portal
Categoryadd-on/module
Description

Security team's command center providing live posture monitoring, policy management, evidence trails, and compliance dashboards across 373 frameworks.

16Trust Center
Categoryadd-on/module
Description

Public-facing live security posture page on the customer's own domain displaying real-time compliance status (SOC 2, ISO 27001, GDPR, HIPAA), controls passing rates, SBOM freshness, and verified sub-processors.

17IaC Security
Categoryadd-on/module
Description

Infrastructure-as-Code security scanning for Terraform, Pulumi, and Crossplane, with policy gates enforced in CI and admission controller.

18DAST (Dynamic Application Security Testing)
Categoryadd-on/module
Description

Dynamic application security testing capabilities with reviewed, ready-to-apply fix plans alongside dynamic findings.

19Safeguard Cowork
Categoryadd-on/module
Description

Collaboration surface for security teams enabling security and engineering teams to collaborate on findings, remediation workflows, and policy management across the organisation.

20CLI Tool
Categoryadd-on/module
Description

Command-line interface for local scanning, SBOM generation, policy enforcement, and CI/CD pipeline integration, with Lion running locally via CLI for on-device inference.

Scale indicator17 records

Each record includes

Type, Value, Description, Source

Partnership3 partners
Strategic tierFlagshipTypeTechnology or IntegrationAnnounced on2026-06-12
Description

Safeguard is available as a connector in Claude, bringing software supply chain security tools into Claude alongside continuous compliance monitoring. The MCP server integration enables Claude to query vulnerabilities, scan repos, generate remediation plans, apply fixes, merge PRs, and check compliance gates directly.

2All Major Frontier Model Families
Strategic tierCoreTypeTechnology or IntegrationAnnounced on2026-06-10
Description

Safeguard's Multi-Agent TAOR Deep Think AI Engine (now branded Griffin Gen 5) supports every major frontier model family, plus private model hosting. Universal AI model support enables continuous zero-day discovery and automated remediation wired for any model deployment.

3Marketplace Policy Contributors
Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-03-12
Description

Policies, guardrails, and remediation recipes can be published, versioned, and consumed through the Safeguard Marketplace. First wave includes 40 community-authored policies covering supply chain, AI safety, and licensing. Partner-built scanner SDK enables third-party detection logic.

safeguard.sh
Recent move6 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight8 records

Each record includes

Type, Description

Peers10 records
TypeEmerging player
Description

Closest emerging competitor on the "zero-CVE base images and dependencies" thesis. Chainguard's curated hardened container images overlap with Safeguard's Gold Registry but lack the broader SCA + GRC + autonomous remediation platform; valuable comparable for the supply-chain-clean-start story.

TypeDirect peer
Description

Long-standing direct peer in software supply chain and open-source dependency intelligence (Nexus Lifecycle, Nexus Repository). Comparable focus on OSS risk and SBOM, but relies on traditional heuristics rather than a purpose-built LLM family for reachability reasoning.

TypeEmerging player
Description

Emerging SCA competitor with reachability-based prioritization as its core thesis — directly comparable to Safeguard's 100-layer reachability pitch. Targets similar enterprise and FinServ buyers but lacks Safeguard's full compliance framework coverage and air-gapped sovereign tier.

TypeBroad incumbent
Description

Broad DevOps + security platform combining artifact repository (Artifactory), Xray SCA, and lifecycle management. Overlaps with Safeguard on container/IaC scanning and CI/CD gates but ships as part of a wider DevOps portfolio rather than a security-first autonomous platform.

TypeDirect peer
Description

Direct SCA/SAST competitor named explicitly by Safeguard as the incumbent it displaces. Both target developer-led adoption with per-seat pricing for code and dependency vulnerability scanning; Snyk has the larger installed base and significantly more funding, but lacks Safeguard's purpose-built AI model family and autonomous auto-fix loop.

TypeEmerging player
Description

Emerging supply-chain security startup focused on malicious-package detection, dependency behavior analysis, and OSS risk in npm/PyPI. Comparable in targeting developer-led adoption with AI-driven signals; narrower in scope than Safeguard's full ESCM platform.

TypeDirect peer
Description

Established application-security platform covering SAST, DAST, and SCA with strong regulated-enterprise penetration. Overlaps directly with Safeguard's DAST, IaC, and SCA modules and competes for the same Top-5 bank and federal-defense buyers; has a deeper historical installed base but slower model-driven roadmap.

TypeDirect peer
Description

Direct SCA competitor with overlap in dependency scanning, license compliance, and container security. Targets similar regulated-enterprise and FinServ buyers with a usage-based SaaS model; differentiated from Safeguard primarily by lack of an autonomous patch-authoring agent.

TypeEmerging player
Description

Leading automated compliance/GRC platform named explicitly by Safeguard as a displaced alternative. Overlaps on the 373-framework compliance automation and SOC 2/ISO 27001 evidence pipeline but does not provide SCA, reachability analysis, or autonomous fix authoring.

TypeBroad incumbent
Description

Microsoft-owned bundled SCA/SAST/secret-scanning offering included with GitHub Enterprise. Competes head-to-head in the same developer workflow (PR-time scanning) but ships as part of a much broader platform; lacks a comparable sovereign/air-gapped tier and autonomous-remediation agent.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat6 records

Each record includes

Type, Details

Key risks5 records

Each record includes

Headline, Details, Source

Key highlights7 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers10 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment6 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile6 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
Yes

Docs URL, Description

Integration27 records

Each record includes

Title, Type, Description, Source

AI capability11 records

Each record includes

Type, Description, Source

AI maturity
App detail

Has app

Feature11 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
No data
Compliance16 records

Each record includes

Name, Class, Description

Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Safeguard

Application Security Softwaresafeguard.sh

Safeguard is an AI-native software supply chain security platform that uses proprietary Griffin, Eagle, and Lion models to autonomously find and fix vulnerabilities across dependencies, containers, and infrastructure. It serves regulated enterprises in financial services, banking, defense, healthcare, and government with FedRAMP HIGH/IL7 sovereign deployments and 373 compliance framework mappings.

What Safeguard does

Safeguard.sh Inc, founded in 2024 and headquartered in Dublin, California, is an AI-native software supply chain security platform that combines proprietary purpose-built models with autonomous remediation. The company's core technology is a model family — Griffin (five variants from 8B to 671B-MoE), Eagle (13B), and Lion (1B distilled) — trained exclusively on an 11M+ document cybersecurity corpus using a security-augmented tokenizer and an adversarial disproof decoder head, served on the Aegis architecture. The platform delivers 100-layer call-graph reachability analysis (40 layers deeper than legacy SCA), 11 fused scanners across code, containers, and IaC, and Auto-Fix that authors, tests, and merges remediation pull requests under policy gates. Its product surface includes ESSCM, SBOM Studio, TPRM, Open Source Manager, IaC Security, DAST, Safeguard Guard (runtime LLM protection), Cowork, and a Gold Registry of 500K+ zero-CVE hardened components, with 373 compliance framework mappings including FedRAMP HIGH, IL7, SOC 2, ISO 27001, NIST SSDF, EO 14028, DORA, NIS2, and EU AI Act.

The business model is usage-based pricing positioned at roughly a tenth of per-seat Snyk-class ($1,200/dev/yr) and below Vanta-class GRC pricing, with consumption tiers spanning shared cloud, dedicated clusters, VPC-isolated, and sovereign/air-gapped deployments (multi-year contracts) running Griffin Zero on configured 11x H100 to 22x H100 multi-AZ footprints. Revenue also flows from enterprise support and services, plus a Marketplace with 40 community-authored policies and partner-built scanner SDK. GTM is multi-modal: a free 7-day sandbox with self-serve conversion, direct enterprise field sales targeting regulated industries (financial services, banking, defense, healthcare, government), and an MCP-native distribution channel where AI agents (Claude, Cursor, Cline) can evaluate, subscribe, and pay end-to-end over Model Context Protocol. Geographic reach spans nine US regions including GovCloud IL5, ten European cities, sovereign India via GIFT City (IFSCA), thirteen APAC cities, and five Middle East cities.

Customers include a top-5 US bank, a Fortune 100 SaaS platform, a global investment bank under FedRAMP HIGH/IL7, a defense systems integrator, a large healthcare network, a multinational retailer, a managed security provider, and a Series C fintech with 1,400 microservices under management. Reported Q2 2026 transparency metrics include 1,240 active tenants, 3.42M findings shipped, 61% of findings closed by automatic patch, a 0.948 mean adversarial resistance score across the Griffin family, 147 coordinated disclosures, and 100K+ autonomous AI remediations applied. One Fortune 100 customer achieved 10,000+ autonomous fixes with mean time to remediate dropping from 11 days to 3 hours.

Safeguard firmographics

Firmographics
Name
Safeguard
Legal name
Safeguard.sh Inc
Website
https://safeguard.sh
Company type
Private
Founded year
2024
Operating status
Operating
Headcount range
51–100 employees
Short description
Safeguard is an AI-native software supply chain security platform that uses proprietary Griffin, Eagle, and Lion models to autonomously find and fix vulnerabilities across dependencies, containers, and infrastructure. It serves regulated enterprises in financial services, banking, defense, healthcare, and government with FedRAMP HIGH/IL7 sovereign deployments and 373 compliance framework mappings.
Ownership category
akta.pro rank

Safeguard industry classification

Industry
Product category
Application Security Software
NAICS
Computer Systems Design and Related Services (54151), Computer Systems Design Services (541512)
SIC
Services-Prepackaged Software (7372), Services-Computer Programming, Data Processing, Etc. (7370)
akta.pro primary industry
Supply Chain & Firmware Security for Industrial Devices (HDADAJAL)
akta.pro secondary industries
Security Awareness, Training & Compliance Attestation (HDADAIAJ), Configuration & Exposure Hardening (CIS/Benchmarking) (HDADAHAH)

Keywords

  • Software supply chain security
  • AI vulnerability remediation
  • SBOM management
  • Compliance automation
  • Third party risk management

Where Safeguard is headquartered

Location

Headquarters

HQ city
California City
HQ country
United States
HQ region
North America

Offices4 records

Markets served

Safeguard business model

Business model
GTM type
B2B
Offering type
Software
Cost components
Technology or R&D, Personnel, Infrastructure, Operations, Marketing or Sales

Revenue model

  1. Platform Subscription (Usage-Based): Usage-based subscription for the core ESSCM platform. The platform is a functional superset of point scanners (Snyk-class) and GRC tools (Vanta-class), priced at roughly a tenth of per-seat pricing. Agents can also complete the entire procurement lifecycle autonomously over MCP — evaluate, sign up, subscribe, pay — without human handoff.
  2. Sovereign / Air-Gapped Deployments: Sovereign-tier and air-gapped deployments (Griffin Zero, Aegis appliance) for defense, government, and regulated enterprises. Griffin Zero runs on documented multi-GPU sizing from 11x H100 (Growth) to 22x H100 multi-AZ (Mature). Separate compute, infrastructure, and support tiers.
  3. Enterprise Support & Services: Enterprise customers receive dedicated support, architecture reviews, pen-test summaries, SOC 2 reports, and full control documentation under NDA. Quarterly business reviews and private roadmap reviews are available for enterprise tiers.
  4. Marketplace: Community-contributed policies, guardrails, and remediation recipes published, versioned, and consumed through the Marketplace. First wave includes 40 community-authored policies covering supply chain, AI safety, and licensing. Partner-built scanner SDK enables third-party contributions.

Pricing tiers

ModelBillingPrice
FreemiumPay-as-you-goFree evaluation sandbox — no credit card, 7-day expiry
Usage-basedPay-as-you-goUsage-based cloud tier — shared multi-tenant inference
Usage-basedAnnualDedicated cluster — single-tenant GPU
Usage-basedAnnualVPC-isolated — private cloud deployment
SubscriptionMulti-year contractSovereign / Air-gapped — IL7 / FedRAMP HIGH
SubscriptionAnnualSpecial tiers for startups, OSS, nonprofits, students, educators

Go-to-market motion4 records

Distribution channels8 records

Marketing channels11 records

Safeguard product offering

Product offering

Core offering

Safeguard provides an AI-native software supply chain security platform (ESSCM) that autonomously discovers and fixes Zero-Day and reachability-filtered vulnerabilities across code, containers, dependencies, and infrastructure-as-code. The platform is built on a proprietary model family (Griffin for deep remediation, Eagle for adversarial triage, Lion for on-device inline analysis) and is delivered as a unified control plane that maps findings to 373 compliance frameworks and produces policy-gated pull requests.

Product overview

Safeguard is an AI-native software supply chain security platform built around autonomous remediation. The core offering is Griffin AI — a family of five purpose-built models (Griffin Lite 8B, S 14B, M 32B, L 70B, Zero 671B-MoE) — supported by Eagle (13B) for ranking and triage, and Lion (1B) for on-device inline analysis. These models are served on the Aegis architecture with sliding-window attention, a security-augmented tokeniser, and adversarial disproof heads. The platform is delivered as a unified ESSCM (Enterprise Software Supply Chain Manager) with integrated modules: Scanner Suite (11 scanners + 7 enrichment feeds), Auto-Fix for autonomous remediation, SBOM Studio for SBOM lifecycle management, TPRM for third-party risk, Open Source Manager for OSS registry intelligence, IaC Security for infrastructure scanning, and DAST for dynamic testing. Access surfaces include a web Portal, Trust Center, MCP Server (25+ tools for Claude/Cursor/Cline agents), Safeguard Code IDE agent, Safeguard Guard runtime protection, Safeguard Cowork collaboration surface, a CLI tool, and a Gold Registry marketplace of 500K+ zero-CVE hardened components. The platform covers 373 compliance frameworks with policy-gated workflows and automated evidence generation.

Differentiator

Problem solved

Functional benefit

Brands

  • Griffin AI: Autonomous security agent with 100-layer reachability analysis
  • Aegis Architecture
  • ESSCM
  • SBOM Studio
  • Scanner Suite
  • TPRM
  • Open Source Manager
  • Auto-Fix
  • MCP Server
  • IaC Security
  • DAST
  • Safeguard Code
  • Safeguard Guard
  • Safeguard Cowork
  • Marketplace
  • Gold Registry
  • Griffin Lite
  • Griffin S
  • Griffin M
  • Griffin L
  • Griffin Zero
  • Eagle
  • Lion

Products and services

  • Griffin AI Purpose-built AI reasoning engine for software supply chain security. Five variants (Lite 8B, S 14B, M 32B, L 70B, Zero 671B-MoE) perform autonomous vulnerability discovery, reachability analysis, adversarial disproof, patch authoring, and policy-gated automated remediation across the software lifecycle.
  • Eagle 13B ranking and clustering model for wide-angle triage and adversarial Zero Day discovery across repositories. Eagle Gen 5 (190B) handles multi-jurisdiction policy synthesis across NIS2, DORA, EU AI Act, FedRAMP High, and ISO 27001:2022.
  • Lion 1B distilled on-device model for inline gut-check in the IDE and CLI. Sub-100ms p95 on developer laptop with no network egress. Sink detection, sanitiser quality scoring, and inline triage at commit time. Works offline.
  • ESSCM (Enterprise Software Supply Chain Manager) Enterprise-grade supply chain security platform providing continuous compliance monitoring across 373 frameworks. Ingests all repos, containers, and manifests into a live SBOM graph with deep transitive and cross-package taint edges, with policy-gated merge workflow from scan to fix to attestation.
  • Aegis Architecture Reasoning architecture underlying every Griffin variant. Features sliding-window plus landmark attention, security-augmented tokeniser (~28k extra tokens), mixture-of-experts routing (Zero tier), and structured trace output as a first-class contract.
  • Auto-Fix Autonomous remediation engine that analyses vulnerable dependencies, generates compatible upgrades, opens policy-gated pull requests, runs CI, validates regression suites, and merges fixes. Campaign mode coordinates fan-out across services affected by the same CVE.
  • SBOM Studio Software Bill of Materials management for ingesting, slicing, and distributing SBOMs in CycloneDX and SPDX formats with automated generation on every build, version control for SBOM history, and EO 14028 self-attestation integration.
  • TPRM (Third Party Risk Manager) Third Party Risk Manager providing vendor SBOM verification and continuous vendor tracking, with sub-processor tracking and compliance mapping across multiple regulatory frameworks.
  • MCP Server Model Context Protocol server providing 25+ tenant-scoped tools enabling Claude, Cursor, Cline, and custom agents to scan repos, query vulnerabilities, generate remediation plans, apply fixes, merge PRs, and check compliance gates. Supports agentic end-to-end procurement.
  • Gold Registry Marketplace of 500K+ curated zero-CVE hardened container images and packages across npm, PyPI, Maven, NuGet, Go, Rust, RubyGems, PHP, containers, and Helm, signed with SLSA L3 provenance and rebuilt continuously.
  • Scanner Suite Eleven integrated scanners running in parallel against ingested artifacts, fused into a single ranked candidate set with cross-scanner evidence. Seven enrichment feeds: NVD, OSV, EPSS, KEV, GHSA, VirusTotal, VulnCheck.
  • Open Source Manager (OSM) Registry intelligence for open source software dependencies. Monitors and analyses OSS packages across ecosystems, tracking maintainer risk, typosquat campaigns, and dependency confusion attacks.
  • Safeguard Code Local coding agent for IDE and CLI that writes and refactors securely by default, respecting repo conventions and security policy, with 42 secure completions per hour.
  • Safeguard Guard Runtime protection layer providing guardrails for LLM apps and agents, including prompt-injection, jailbreak, and exfiltration defense at the I/O boundary.
  • Portal Security team's command center providing live posture monitoring, policy management, evidence trails, and compliance dashboards across 373 frameworks.
  • Trust Center Public-facing live security posture page on the customer's own domain displaying real-time compliance status (SOC 2, ISO 27001, GDPR, HIPAA), controls passing rates, SBOM freshness, and verified sub-processors.
  • IaC Security Infrastructure-as-Code security scanning for Terraform, Pulumi, and Crossplane, with policy gates enforced in CI and admission controller.
  • DAST (Dynamic Application Security Testing) Dynamic application security testing capabilities with reviewed, ready-to-apply fix plans alongside dynamic findings.
  • Safeguard Cowork Collaboration surface for security teams enabling security and engineering teams to collaborate on findings, remediation workflows, and policy management across the organisation.
  • CLI Tool Command-line interface for local scanning, SBOM generation, policy enforcement, and CI/CD pipeline integration, with Lion running locally via CLI for on-device inference.

Quantifiable outcome

  • ~80% reduction in false positives via reachability analysis vs traditional SCA scanners
  • +7 more outcomes

Companies that use Safeguard

Customer profile

Named customers10 records

Segments6 records

Ideal customer profiles6 records

Safeguard technology and API

Technology

Technology focussed Yes

API detail

Has API
Yes
API docs
API detail

Core technology

AI maturity

App detail

Integration27 records

AI capability11 records

Feature11 records

Safeguard partnerships and signals

Strategic signal

Partnerships

Three partnerships are on record, tiered flagship and core.

  • Anthropic (Claude)flagshipTechnology or Integration · 12 June 2026Safeguard is available as a connector in Claude, bringing software supply chain security tools into Claude alongside continuous compliance monitoring. The MCP server integration enables Claude to query vulnerabilities, scan repos, generate remediation plans, apply fixes, merge PRs, and check compliance gates directly.
  • All Major Frontier Model FamiliescoreTechnology or Integration · 10 June 2026Safeguard's Multi-Agent TAOR Deep Think AI Engine (now branded Griffin Gen 5) supports every major frontier model family, plus private model hosting. Universal AI model support enables continuous zero-day discovery and automated remediation wired for any model deployment.
  • Marketplace Policy ContributorscoreStrategic or Co-development Partner · 12 March 2026Policies, guardrails, and remediation recipes can be published, versioned, and consumed through the Safeguard Marketplace. First wave includes 40 community-authored policies covering supply chain, AI safety, and licensing. Partner-built scanner SDK enables third-party detection logic.

Scale indicators17 records

Recent moves6 records

Expansion highlights8 records

Safeguard competitors and assessment

Company assessment

Emerging players

  • Chainguard: Closest emerging competitor on the "zero-CVE base images and dependencies" thesis. Chainguard's curated hardened container images overlap with Safeguard's Gold Registry but lack the broader SCA + GRC + autonomous remediation platform; valuable comparable for the supply-chain-clean-start story.
  • Endor Labs: Emerging SCA competitor with reachability-based prioritization as its core thesis — directly comparable to Safeguard's 100-layer reachability pitch. Targets similar enterprise and FinServ buyers but lacks Safeguard's full compliance framework coverage and air-gapped sovereign tier.
  • Socket: Emerging supply-chain security startup focused on malicious-package detection, dependency behavior analysis, and OSS risk in npm/PyPI. Comparable in targeting developer-led adoption with AI-driven signals; narrower in scope than Safeguard's full ESCM platform.
  • Vanta: Leading automated compliance/GRC platform named explicitly by Safeguard as a displaced alternative. Overlaps on the 373-framework compliance automation and SOC 2/ISO 27001 evidence pipeline but does not provide SCA, reachability analysis, or autonomous fix authoring.

Direct peers

  • Sonatype: Long-standing direct peer in software supply chain and open-source dependency intelligence (Nexus Lifecycle, Nexus Repository). Comparable focus on OSS risk and SBOM, but relies on traditional heuristics rather than a purpose-built LLM family for reachability reasoning.
  • Snyk: Direct SCA/SAST competitor named explicitly by Safeguard as the incumbent it displaces. Both target developer-led adoption with per-seat pricing for code and dependency vulnerability scanning; Snyk has the larger installed base and significantly more funding, but lacks Safeguard's purpose-built AI model family and autonomous auto-fix loop.
  • Veracode: Established application-security platform covering SAST, DAST, and SCA with strong regulated-enterprise penetration. Overlaps directly with Safeguard's DAST, IaC, and SCA modules and competes for the same Top-5 bank and federal-defense buyers; has a deeper historical installed base but slower model-driven roadmap.
  • Mend (formerly WhiteSource): Direct SCA competitor with overlap in dependency scanning, license compliance, and container security. Targets similar regulated-enterprise and FinServ buyers with a usage-based SaaS model; differentiated from Safeguard primarily by lack of an autonomous patch-authoring agent.

Broad incumbents

  • JFrog: Broad DevOps + security platform combining artifact repository (Artifactory), Xray SCA, and lifecycle management. Overlaps with Safeguard on container/IaC scanning and CI/CD gates but ships as part of a wider DevOps portfolio rather than a security-first autonomous platform.
  • GitHub Advanced Security: Microsoft-owned bundled SCA/SAST/secret-scanning offering included with GitHub Enterprise. Competes head-to-head in the same developer workflow (PR-time scanning) but ships as part of a much broader platform; lacks a comparable sovereign/air-gapped tier and autonomous-remediation agent.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat6 records

Key risks5 records

Key highlights7 records

Customer concentration

Safeguard social profiles

Digital presence

Safeguard compliance and trust

Trust signal

Compliance16 records

Safeguard financial estimates

Financial estimate

Revenue estimate

Valuation estimate

Safeguard leadership team

Management profile

Number of profiles

Safeguard funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

Safeguard M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about Safeguard

What does Safeguard do?

Safeguard provides an AI-native software supply chain security platform (ESSCM) that autonomously discovers and fixes Zero-Day and reachability-filtered vulnerabilities across code, containers, dependencies, and infrastructure-as-code. The platform is built on a proprietary model family (Griffin for deep remediation, Eagle for adversarial triage, Lion for on-device inline analysis) and is delivered as a unified control plane that maps findings to 373 compliance frameworks and produces policy-gated pull requests.

Is Safeguard a public or private company?

Safeguard is a private company. It is classified as unknown and is currently operating.

When was Safeguard founded?

Safeguard was founded in 2024. It employs 51 to 100 people.

Where is Safeguard based?

Safeguard is headquartered in California City, United States, in the North America region.

How does Safeguard make money?

Four revenue lines are on record. Platform Subscription (Usage-Based) is the primary driver. The others are sovereign / Air-Gapped Deployments, enterprise Support & Services and marketplace.

Who are Safeguard's main competitors?

Emerging players on record are Chainguard, Endor Labs, Socket and Vanta. Direct peers are Sonatype, Snyk, Veracode and Mend (formerly WhiteSource). Broad incumbents are JFrog and GitHub Advanced Security.

Does Safeguard have an API?

Yes. Safeguard exposes a REST API surface documented at /resources/api-reference. The platform also ships a first-class MCP (Model Context Protocol) server with 25+ tenant-scoped tools: safeguard_scan_repository, safeguard_list_vulnerabilities, safeguard_get_remediation_plan, safeguard_fix_vulnerability, safeguard_merge_pull_request, safeguard_list_findings, and 19 more. Claude Desktop, Claude Code, Cursor, Cline, and custom agents connect over MCP to query vulnerabilities, scan repos, generate remediation plans, apply fixes, merge PRs, and check compliance gates. Every tool call carries tenant and org context, hits the same policy engine as the UI, and lands in the same audit trail. Agentic procurement is also supported — agents can evaluate, sign up, subscribe and pay end-to-end over MCP. Developer documentation is at docs.safeguard.sh.

What industry is Safeguard in?

Safeguard's product category is Application Security Software. Its primary akta.pro industry code is HDADAJAL, Supply Chain & Firmware Security for Industrial Devices, with a secondary code of HDADAIAJ, Security Awareness, Training & Compliance Attestation. Its NAICS code is 54151 and its SIC code is 7372.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
SafeguardSafeguard Crosses $1M ARR — First Annual Recurring Revenue MilestoneSafeguard.sh Inc. announced it crossed $1 million in annual recurring revenue, its first ARR milestone, reached in 2026 two years after founding. The revenue is aggregate across direct sales, partners, and self-serve sign-ups, with partner-led revenue growing. The company also opened its channel and white-label partner program worldwide.SafeguardSafeguard × OffShield Security: AI-Native Supply Chain Security Launches in NigeriaSafeguard.sh Inc. partnered with OffShield Security to deliver its AI-native supply chain security platform to Nigerian enterprises, marking Safeguard's first Nigeria and West Africa channel. The partnership covers SAST, DAST, SCA, and zero-day discovery, with 93% of organizations suffering supply-chain attacks in 2026.Ani NewsTechD Cybersecurity Launches TECHD ONE: AI-Native Unified Cybersecurity PlatformTechD Cybersecurity Limited launched TECHD ONE, an AI-native unified cybersecurity platform featuring four production-ready modules (Dark Vector AI, Provenance AI, Human Trust AI, and OT Shield AI) designed to consolidate fragmented enterprise cyber defence tools. The platform, developed through strategic collaboration with Safeguard.sh, targets Indian enterprises seeking sovereign cybersecurity solutions, with Phase 2 modules including SecOps AI, PrivacyOps AI, and Identity Guard currently under development for 2027. The company, which serves over 500 enterprise clients including Adani Group and JM Financial, reported that its September 2025 IPO was oversubscribed 718 times, reflecting strong market demand for cybersecurity listings.SafeguardSafeguard × TechD: Provenance AI Launches Exclusively for India and the Middle EastTechD Cybersecurity and Safeguard.sh announced an exclusive collaboration to deliver Provenance AI, an AI-native supply chain security platform, across India and the Middle East. The platform, powered by Safeguard's engine, coordinates 50+ zero-days and 100K+ autonomous remediations. TechD is the exclusive partner for deployment and managed services in these regions.SafeguardSafeguard Launches Griffin, Eagle, and Lino: A Security-Only AI Model LineupSafeguard launched Griffin, Eagle, and Lino, a security-only AI lineup for software supply chain security. The models are trained on a cybersecurity-only corpus, with Griffin offering five sizes and Eagle ranking findings by exploitability. The lineup is available to existing Safeguard customers.