ChangeGuard turns live cluster state — CIS benchmarks, CVE scans, RBAC blast radius, GitOps drift, runtime threats, and your software inventory — into one deterministic 0–100 deployment safety score, posted on every PR. Updated every 10 seconds. Fully explainable, every point accounted for.
Most production K8s incidents trace back to a change that could have been flagged before deploy. ChangeGuard makes those signals impossible to miss — with concrete, explainable detections.
CSC is deterministic — every deduction maps to a specific check. Show your auditors. Show your incident reviewers. Show your CFO who's tired of paying for tools nobody trusts.
100 pts total. Policy carries the most weight because it's where the signal is most concrete — a CVE either exists or it doesn't. Runtime gets meaningful share because eBPF data is real-time, not retrospective. Historical and Cluster Health shape the score without dominating it. Every deduction maps to a specific check, viewable from any score in the dashboard.
ChangeGuard fits into your existing workflow. The operator deploys and manages all five security scanners, a data collector, and a runtime threat-detection layer — all from a single Custom Resource. CLI validation and PR checks available in Beta.
Helm is the single install artifact — the one-liner, OCI, and GitOps paths all resolve to the same signed chart (operator + collector + five scanners). Pick whichever fits your workflow.
Add the repo and install. Creates the namespace, deploys the operator, and brings up the collector and all five scanners.
A thin bootstrap that wraps the Helm install above. Needs helm and kubectl already on your machine; the agent connects outbound only.
Install straight from the OCI registry — or mirror the chart and images into your own registry and repoint everything with a single global.imageRegistry value for fully air-gapped clusters.
Manage ChangeGuard the way you manage everything else. Drop in the ready-made ArgoCD Application or Flux HelmRelease from the chart's examples/gitops/ and let your CD tool reconcile it.
Every artifact is cosign-signed. Verify before you install: cosign verify --key https://charts.changeguard.ai/cosign.pub <image-or-chart>
Your data is isolated at the database layer, not just by application logic. A future code path that mistakenly forgot a tenant filter would silently return zero rows — not leak across customers. Defense in depth is the default, not an enterprise upsell.
Detailed security architecture, audit trail format, and SOC 2 control mapping live at docs.changeguard.ai/security. Active questions: security@changeguard.ai.
ChangeGuard isn't an APM or a CSPM. It solves a specific problem: there's no unified, deterministic signal for "is this Kubernetes deploy safe right now." Here's where it fits alongside tools you may already use.
● built-in · ◐ partial / add-on · ○ not available · based on general product category capabilities
14-day free trial on Starter, no credit card. Start on your own cluster, and we'll scope the right plan with you — every conversation starts with the product already running and scoring.
Every release is documented, every breaking change is signaled, every regression is owned. The full changelog lives at docs.changeguard.ai/changelog.
The next incident your team prevents will pay for ChangeGuard many times over. Install in 60 seconds, see your first CSC score immediately.