Layer 01
Read the estate
Establish what has leaked, what is enforced, and what the tooling misses.
Full-history secret scanning
A pinned scanner (gitleaks or TruffleHog) and a single ruleset, run across every repository.
- Findings split into still present and history only
- Sorted by credential format, never by testing a credential
- Noise rate measured at factory settings first
Recurring readiness audit
A dozen scored dimensions, with the evidence behind each check.
- Application security, supply chain, AI security, prevention coverage
- Surprising verdicts re-verified by hand
- A locked baseline the re-audit is measured against
Organization-wide posture scoring
OpenSSF Scorecard across the estate: required checks, dependency updates, branch protection.
- Read per check, never on the aggregate score
- Required status checks separated from present ones
- Dependency update coverage per repository
Agent-surface inventory
Hooks, plugin servers, instruction files and permission patterns, read from the settings files.
- Hooks defined as inline command strings included
- Plugin servers and the version each one is pinned to
- Permission patterns read for credential material