
Backed by Y Combinator
Know what’s inyour software
Agents resolve your full dependency graph, catch malicious and vulnerable packages before they ship, and keep an audit-ready SBOM current, automatically.
Scan dependencies
See first findings in 24 hours
Built by the team that secured:
Built by the team that secured:
[ how it works ]
01
Resolve
Connect a repository and agents parse your lockfiles into the complete dependency graph, capturing every direct and transitive package across every ecosystem you ship.
02
Inspect
Each package is checked against malware intelligence, known advisories, and your license policy, then matched to whether your own code actually reaches it.
03
Fix
Every finding ships with the safe version and a pull request that bumps it, so you patch in one click and re-scan the graph instantly.
[ why parameter ]
The graph.Not the guesswork
Most tools dump every advisory in your tree and call it coverage. Parameter raises only what an attacker can reach, and ships the fix with it.
Reachability, not a CVE dump
Parameter traces whether your code can actually reach the vulnerable path. The queue stays short, and every entry is real.
Malware caught at install time
Install scripts, obfuscated payloads, and typosquats are inspected before they run in CI. The attacks signature databases miss until it’s too late.
An SBOM that never goes stale
A signed CycloneDX and SPDX inventory regenerates on every push, so what you attest always matches what you shipped.
[ coverage ]
Every ecosystem you ship.Covered down to the last dependency.
One tool for every package manager you use. We resolve the full dependency tree, direct and transitive, across all six ecosystems.
JavaScript & TypeScript
npm, Yarn, pnpm, and Bun lockfiles.
Python
pip, Poetry, and uv with full transitive resolution.
Go
Go modules and go.sum, including replace directives.
Java & Kotlin
Maven and Gradle dependency trees.
Containers
Base images and OS packages in your Dockerfiles.
Rust, Ruby & PHP
Cargo, Bundler, and Composer manifests.
1,284
packages mapped in a single repo, direct and transitive.
92%
of advisories filtered out as unreachable.
5 min
from connecting a repo to a signed SBOM.
[ scanners ]
One platform.Your whole dependency tree.
Vulnerabilities ranked by what you run
Agents resolve the full graph and check every package against known advisories, then trace reachability, so a CVE buried in an unused transitive dependency never pages your team.
Replaces
[ FAQ ]
Frequently asked questions
Start testing today.
A URL and credentials is all it takes.
First findings land within 24 hours.

















