Safeguard
Open Source & Nonprofits

Free security for the people who keep the ecosystem running.

Open-source maintainers secure the code the whole industry depends on, and nonprofits do vital work on tight budgets. Safeguard is free for both — the full platform, including reachability analysis, SBOMs, and Griffin AI autonomous remediation, at no cost.

What's included

Full platform, free

SCA, SBOM/AIBOM, container & IaC scanning, reachability analysis, and autonomous Auto-Fix — no feature gates.

Public repo coverage

Continuously scan your public projects and their dependency trees, with fix PRs opened straight against your repos.

SBOMs for your users

Publish CycloneDX/SPDX SBOMs so downstream consumers and enterprises can trust and adopt your project.

Maintainer-friendly

Low-noise, reachability-prioritized findings — so you spend time maintaining, not triaging false positives.

Nonprofit-ready evidence

Compliance-aligned reports and SBOMs for grant, donor, and audit requirements.

Academy access

Free Safeguard Academy courses and certifications for your contributors and staff.

The program in detail

Maintainers of public, OSS-licensed repositories. Free scanning for public projects, generous limits, a security badge and published SBOM for your repo.

What is included

  • Scanning for your public repositories, with generous limits
  • Dependency analysis, and an SBOM in CycloneDX or SPDX
  • Reachability-based prioritization, so you fix what is actually exploitable
  • A security badge for your README and a published SBOM for the repo
  • Autonomous fix PRs are limited on this program

Who qualifies

  • Public, OSS-licensed repositories only. Private repositories need a paid plan
  • We re-check periodically that the repository is still public and maintained
  • Not for commercial closed-source work

How we verify

Links your public repository so we can confirm it is OSS-licensed.

Renewal and what comes next

Runs for as long as the repository stays public and maintained, re-checked periodically. Private repositories move to a paid plan, and you keep your history.

Every program starts with the eligibility form. Nothing is granted without it.

Who qualifies

  • Maintainers of public open-source projects under an OSI-approved license.
  • Registered nonprofits, NGOs, and charities (501(c)(3) or local equivalent).
  • Public-good and civic-tech projects run by volunteers.
  • Projects and organizations that are not primarily commercial.

How to get started

01

Apply

Share a link to your public repo(s) or nonprofit registration.

02

Verification

We confirm the project's license or the organization's nonprofit status.

03

Activate

Your free license is enabled; connect your repositories in minutes.

04

Publish trust

Ship SBOMs and a clean security posture your users can rely on.

Frequently asked questions

Which open-source licenses qualify?

Any OSI-approved license (MIT, Apache-2.0, GPL, BSD, MPL, and others). The project must be genuinely public and open source, not source-available or commercial with an OSS veneer.

Is it free forever?

The open-source and nonprofit licenses are free for as long as you remain eligible. If a project becomes a commercial product, we'll help you transition to a standard plan.

Do nonprofits need to be US-based?

No. Registered nonprofits, NGOs, and charities worldwide qualify — 501(c)(3) in the US or the equivalent registration in your country.

Can I scan private repos under this program?

The OSS program covers your public projects. Nonprofits can cover their internal/private repositories used to run the organization. For broader commercial private use, a standard plan applies.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.