ABOUT DEPSHIELD

Security insight
that stays close to your code.

DepShield helps developers understand software supply chain risk through local dependency discovery, vulnerability intelligence, and clear security evidence.

01 / LOCAL FIRST

Keep the project local.

Analysis runs on your machine. Configured providers receive only necessary package or CVE metadata for vulnerability intelligence.

02 / DEPENDENCY TRANSPARENCY

Show the relationships.

Direct and locally evidenced transitive packages can be traced through the dependency graph, with coverage limits made clear.

03 / HONEST SIGNALS

Make uncertainty visible.

Unknown versions and provider errors remain distinct. A clean lookup is useful evidence, not a promise that the whole project is secure.

THE PRODUCT PRINCIPLE

Your code isn't our business.

DepShield keeps source analysis, scan history, reports, and SBOMs on the user's device. Vulnerability lookups use necessary metadata.

PUBLIC VULNERABILITY SOURCES
OSVNVDEPSSCISA KEV

Only the metadata needed for lookups leaves the device.

package metadata
and CVE identifiers
YOUR COMPUTERAnalysis and project files stay here
D
DepShieldDesktop application
LOCAL
FindingsDependency graphSBOMReportsScan history
i Project contents, paths, credentials, and Git history are not intentionally included in provider requests.

FIRST PUBLIC RELEASE

Local-first dependency security is coming to Windows.

Explore the documentation while the first public release completes validation.

Windows release — coming soon