Hex Security is now ParameterWe're at Black Hat USA 2026

Parameter

Backed by Y Combinator

Know what’s inyour software

Agents resolve your full dependency graph, catch malicious and vulnerable packages before they ship, and keep an audit-ready SBOM current, automatically.

Scan dependencies

See first findings in 24 hours

Built by the team that secured:

Apple
Google
Microsoft
U.S. Department of Defense
T-Mobile
Henkel
Epic Games
AT&T
Yahoo

[ how it works ]

01

Resolve

Connect a repository and agents parse your lockfiles into the complete dependency graph, capturing every direct and transitive package across every ecosystem you ship.

02

Inspect

Each package is checked against malware intelligence, known advisories, and your license policy, then matched to whether your own code actually reaches it.

03

Fix

Every finding ships with the safe version and a pull request that bumps it, so you patch in one click and re-scan the graph instantly.

[ why parameter ]

The graph.Not the guesswork

Most tools dump every advisory in your tree and call it coverage. Parameter raises only what an attacker can reach, and ships the fix with it.

Reachability, not a CVE dump

Parameter traces whether your code can actually reach the vulnerable path. The queue stays short, and every entry is real.

Malware caught at install time

Install scripts, obfuscated payloads, and typosquats are inspected before they run in CI. The attacks signature databases miss until it’s too late.

An SBOM that never goes stale

A signed CycloneDX and SPDX inventory regenerates on every push, so what you attest always matches what you shipped.

[ coverage ]

Every ecosystem you ship.Covered down to the last dependency.

One tool for every package manager you use. We resolve the full dependency tree, direct and transitive, across all six ecosystems.

JavaScript & TypeScript

npm, Yarn, pnpm, and Bun lockfiles.

Python

pip, Poetry, and uv with full transitive resolution.

Go

Go modules and go.sum, including replace directives.

Java & Kotlin

Maven and Gradle dependency trees.

Containers

Base images and OS packages in your Dockerfiles.

Rust, Ruby & PHP

Cargo, Bundler, and Composer manifests.

1,284

packages mapped in a single repo, direct and transitive.

92%

of advisories filtered out as unreachable.

5 min

from connecting a repo to a signed SBOM.

[ scanners ]

One platform.Your whole dependency tree.

Vulnerabilities ranked by what you run

Agents resolve the full graph and check every package against known advisories, then trace reachability, so a CVE buried in an unused transitive dependency never pages your team.

Replaces

Snyk
Dependabot

[ FAQ ]

Frequently asked questions

Start testing today.

A URL and credentials is all it takes.

First findings land within 24 hours.