GuardRails security

Security claims need
visible boundaries.

GuardRails analyzes privileged developer tooling. The product should make it easy to see what is isolated, what is retained, and where a result stops being a guarantee.

Security postureEvidence before assurance
Package executionDisabled
Artifact identityVersion + SHA-256
Incomplete analysisDenied as approval
Public report limitations remain visible
Product controls

What GuardRails protects today.

These statements describe the current web scanner and workspace—not the future native GuardRails IDE sandbox.

Analysis

Extension packages are not executed

Deep Scan extracts and statically inspects an exact published artifact. Extension entrypoints, lifecycle hooks, and bundled executables are not launched by the scanner.

Evidence

Every result keeps its identity

Reports preserve extension ID, version, artifact SHA-256, scanner build, ruleset, coverage, and limitations so a newer result cannot silently replace the reviewed evidence.

Credentials

Notification targets stay encrypted

Workspace delivery targets are encrypted at rest and are excluded from audit exports. Test delivery responses return health metadata rather than stored credentials.

Isolation

Deep Scan uses disposable runners

Published packages are prepared for analysis in an isolated runner. Results cross the boundary through a validated scan-result contract, not through extension-controlled output.

Delivery

Failures remain observable

Notification attempts record delivery state, bounded retries, and safe error details. A failed Slack or email delivery does not change the underlying extension decision.

Claims

Incomplete never means allowed

Missing required analysis, unverifiable artifact identity, and unsupported outcomes remain visibly incomplete instead of being converted into a reassuring score.

Responsible disclosure

Found a security issue?

Do not include secrets, personal data, or unnecessary exploit material. Share the affected route or component, reproducible steps, expected impact, and a safe way to validate the issue through the support channel associated with your GuardRails workspace.

Include01 · Affected component02 · Reproduction steps03 · Security impact04 · Suggested validation
Data handlingSee what GuardRails receives and retains.ValidationInspect exact frozen benchmark evidence.Detection catalogReview rules and evidence classes.