Features built for continuous compliance
Scan your code and data, map findings to frameworks, and prove your posture — all in one platform.
Continuous GitHub scanning
Connect organizations and repositories with a least-privilege token. KollGuard scans for security gaps, risky settings, and exposed secrets — then keeps watching.
Database security scanning
Read-only scans for Supabase and Postgres surface missing Row Level Security, over-permissive grants, publicly exposed tables, and configuration drift.
Automatic SOC 2 & HIPAA mapping
Every finding is mapped to the relevant SOC 2 Trust Services Criteria and HIPAA safeguards, so you always know which control a gap affects.
Projects with rolled-up posture
Group related repos and databases into projects and get a single rolled-up posture score — perfect for reporting per product, team, or environment.
Evidence & downloadable reports
Produce auditor-ready evidence and exportable reports directly from your latest scans — no manual screenshots or spreadsheets.
AI cost & usage dashboard
Monitor AI usage and spend across every project from one dashboard so you can keep costs predictable as you scale scanning.
Secure by design
Credentials are encrypted in Supabase Vault and never stored in the browser. Scanning is read-only and your source code is never retained.
