Safeguard
Press Fact Sheet · Safeguard

Safeguard — AI-native software supply chain security.

Safeguard.sh Inc. is the Dublin, California–headquartered AI-native enterprise software supply chain security platform. The “.sh” stands for Self-Healing. Powered by three sovereign AI models — Griffin, Eagle and Lion — Safeguard delivers zero-CVE component supply, sub-hour zero-day discovery, autonomous remediation, deep transitive reachability analysis, continuous SBOM, SLSA L3+ provenance, third-party risk management, and AI-agent governance through its MCP Server.

By the numbers.

10,000+
Zero-days coordinated-disclosed
100K+
Autonomous fixes applied
1M+
Scans completed across customers
<1h
CVE drop to drafted fix PR
Deep
Transitive dependency reachability
Fewer
False positives with reachability analysis

What the platform does.

AI-native and traditional — on one platform, one policy, one workflow.

AI-Native

Built for the agent era

Griffin AI
Discovery + auto-fix. Walks deep into the transitive dependency graph, performs reachability and taint analysis, drafts fix PRs.
Eagle (13B)
Threat reasoning. Trained on exploit databases, EPSS, KEV, and live telemetry. Fewer false positives with reachability analysis.
Lion (1B)
Governance & guardrails. Runs alongside every AI coding agent — capability scoping, egress allowlists, signed audit trails.
MCP Server
Inventory and scope every MCP server agents call. Block prompt-injection inline. Audit every tool call.
Auto-Fix
Autonomous remediation. Patches drafted, compatibility-tested, and risk-scored — through your normal review gates.
AI-BOM
Continuous bill-of-materials for models, prompts, datasets — CycloneDX 1.6, regulator-ready for EU AI Act / CRA.
Traditional / Foundational

Battle-tested AppSec coverage

SCA
Software Composition Analysis across 40+ ecosystems
SBOM Studio
Continuous CycloneDX + SPDX SBOM generation
IaC Security
Terraform / CloudFormation / Pulumi / Kubernetes
DAST
Auth-aware dynamic AppSec scanning
Secure Containers
Zero-CVE distroless images, SLSA L3+ provenance
Secret Detection
Pre-commit + CI + repo-history scanning
TPRM
Third-party risk + supplier SBOM ingest
Scanner Suite
Unified PR check across every scanner

What customers actually get.

Fewer false positives with reachability analysis

Reachability + EPSS + KEV + business-impact prioritization means engineers only see CVEs that are exploitable in your code.

Remediation in days, not weeks

Auto-Fix drafts the PR, tests it, opens it — through your normal merge gates, so remediation lands in days, not weeks.

Zero-day response in <1 hour

From CVE drop to drafted, tested fix PR before your oncall finishes reading the advisory.

One platform, not five

Replace SCA + IaC + DAST + container + TPRM contracts with one engine and one policy.

Continuous, audit-ready SBOMs

Per-release CycloneDX + SPDX, VEX statements, SLSA L3+ provenance — ready for EU CRA, FDA premarket, SOC 2, ISO, FedRAMP.

AI agent governance, built in

Inventory MCP servers, scope agent capabilities, block prompt-injection — without bolting on a separate AI-security tool.

Company facts.

Company
Safeguard.sh Inc.
Founded
2024
Headquarters
7779 Topaz Circle, Dublin, California 94568, USA
Founder & CEO
Hritik Kumar Sharma
What we do
AI-native enterprise software supply chain security
Why ".sh"
Self-Healing — autonomous remediation is a first-class capability
Model lineup
Griffin (discovery + auto-fix), Eagle (threat reasoning), Lion (governance + guardrails)
Deployment
SaaS, private cloud, sovereign / air-gapped
Compliance posture
FedRAMP HIGH-ready, IL7-ready, SOC 2 Type II (audit in progress)
Channel partner — India & ME
TechD Cybersecurity Limited (NSE SME: TECHD) — Provenance AI on TECHD ONE
Open standards
CycloneDX 1.6, SPDX 3.0, VEX / OpenVEX, SLSA, in-toto, Sigstore, OSV, EPSS, KEV, purl
Press contact
press@safeguard.sh
Website
https://safeguard.sh
For copy-paste

Boilerplate.

Safeguard.sh Inc., headquartered in Dublin, California, is the AI-native enterprise software supply chain security platform. The “.sh” stands for Self-Healing. Powered by three sovereign AI models — Griffin (discovery and auto-fix), Eagle (threat reasoning), and Lion (governance and guardrails) — Safeguard delivers zero-CVE component supply (500K+ pre-vetted images and packages), fast zero-day discovery, autonomous AI remediation (100K+ applied fixes), deep transitive dependency-depth reachability analysis, continuous SBOM generation in CycloneDX and SPDX formats, SLSA Build Level 3 provenance, third-party risk management, and AI agent governance via its MCP Server. Safeguard is FedRAMP HIGH-ready, IL7-ready, and SOC 2 Type II (audit in progress), and supports cloud, on-premise and air-gapped deployments. Press contact: press@safeguard.sh. Web: safeguard.sh.

Need a quote, a demo, or a deeper briefing?

Press & analyst inquiries get a same-day response. Customer briefings & demos route through sales.

press@safeguard.sh