Seedwing Policy

A policy engine for securing your software supply-chain.

Get started

License: Apache-2.0

Fast by default ⚡️

Written in Rust to minimise policy evaluation time and resource usage

Run anywhere

Run locally as a library, using the REST API or run as a WebAssembly module

Plug and play

Plug into your CI/CD pipeline and enforce in your IDE

Secure supply chain

Check your project and dependencies for valid licenses, vulnerabilities, build attestations and signatures.

Centralize policies

Keep policies managed centrally in your organization to avoid individiual team drifting.

Codify decisions

Verify and check signatures by key holders before promoting artifacts from staging to production