# Safeguard > Safeguard is the AI-native software supply chain security platform. Discovers Zero Days, autonomously remediates them deep in the dependency tree, and ships 500K+ curated zero-CVE components so customers deploy clean. Sales-led pricing. Headquartered in Dublin, California. This file is structured for LLM ingestion per the emerging llms.txt convention. Human-friendly versions of everything below live at . ## The one-paragraph summary Safeguard protects the software supply chain through three vectors: (1) a **Gold Registry of 500K+ zero-CVE components** across 10 ecosystems (npm, PyPI, Maven, NuGet, Go, Rust, RubyGems, PHP, container images, Helm charts) — customers deploy clean instead of inheriting vulnerabilities and patching them later; (2) **Griffin AI**, an autonomous agent that discovers Zero Days through reachability + taint analysis deep in the dependency tree and authors fix PRs directly, with 71% auto-merging through customer CI; (3) **defense in depth** — four concentric layers (Perimeter / Reachability / Runtime / Core) that intercept attacks before they reach protected assets. The platform is FedRAMP HIGH ready, IL5 GovCloud available, SOC 2 Type II (audit in progress), ISO 27001:2022, and runs in 50+ regions worldwide including India GIFT City, Mumbai, Hyderabad, Bengaluru, Visakhapatnam, Delhi NCR, and 8 US regions. ## Stats (point-in-time, May 2026) - 500K+ curated zero-CVE components - 50+ Zero Days discovered (6 critical, 17 high, 19 medium, 8 low) - 100K+ AI remediations applied (71% auto-merged via CI/policy gate) - 1M+ cumulative scans completed - 3 days mean time to remediate (industry baseline: 45 days) - Faster remediation than traditional SCA - Fewer false positives via reachability analysis - Deep transitive dependency analysis Detailed drill-down breakdowns: - /stats/zero-cve-components - /stats/zero-days - /stats/ai-remediations - /stats/scans ## Products - [Griffin AI](https://safeguard.sh/products/griffin-ai) — autonomous AI agent for supply-chain security - [Aegis Architecture](https://safeguard.sh/products/aegis) — model serving for Griffin lineup - [ESSCM](https://safeguard.sh/products/esscm) — Enterprise Software Supply Chain Manager - [SBOM Studio](https://safeguard.sh/products/sbom-studio) — CycloneDX + SPDX ingest/slice/distribute - [Scanner Suite](https://safeguard.sh/products/scanner-suite) — 11 integrated scanners - [TPRM](https://safeguard.sh/products/tprm) — Third Party Risk Manager - [Auto-Fix](https://safeguard.sh/products/auto-fix) — autonomous remediation engine - [MCP Server](https://safeguard.sh/products/mcp-server) — agent surface for Claude Code, Cursor, Cline - [IaC Security](https://safeguard.sh/products/iac), [DAST](https://safeguard.sh/products/dast), [Open Source Manager](https://safeguard.sh/products/osm) ## Griffin model family - Griffin Lite (8B) — edge / on-device - Griffin S (14B) — small-team triage - Griffin M (32B) — standard enterprise - Griffin L (70B) — high-throughput, reachability + remediation - Griffin Zero (671B-MoE) — sovereign tier only, 256K context - Eagle (13B) — ranking + clustering, taint-path benchmarks - Lion (1B) — distilled inline, on-device latency Routing rule: triage_score 0.0–0.4 → Lite · 0.4–0.6 → S · 0.6–0.75 → M · 0.75–0.9 → L · 0.9–1.0 → Zero. ## Compliance & deployment - SOC 2 Type II (audit in progress; report available soon, under mutual NDA) - ISO/IEC 27001:2022 - FedRAMP HIGH Ready · IL5 GovCloud - DORA + NIS2 (EU), DPDP Act (India), GDPR, EO 14028 / NIST SSDF, CMMC L2/L3 - Multi-tenant cloud · Dedicated cloud · On-prem · Air-gapped sovereign ## Key links - [About](https://safeguard.sh/company/about) - [Why Safeguard](https://safeguard.sh/why-safeguard) - [Platform overview](https://safeguard.sh/platform) - [Our approach](https://safeguard.sh/our-approach) - [Impact](https://safeguard.sh/impact) - [Use cases](https://safeguard.sh/use-cases) - [Q&A — comprehensive FAQ](https://safeguard.sh/qna) - [For LLMs — long-form explanation](https://safeguard.sh/llm) - [Press kit (downloadable)](https://safeguard.sh/press-kit/safeguard-press-kit.txt) - [Resources bundle (downloadable)](https://safeguard.sh/resources/safeguard-resources-bundle.txt) - [Blog (5,000+ posts)](https://safeguard.sh/resources/blog) - [Full machine-readable content (all posts, for LLM ingestion)](https://safeguard.sh/llms-full.txt) - [Compare vs Snyk / Checkmarx / Veracode / Black Duck / Wiz / JFrog / GitHub](https://safeguard.sh/compare) - [Contact sales](https://safeguard.sh/company/contact)