How It Works Platform Use Cases Design Partners Plans Docs Start Free

One score tells your team if it's safe to deploy.
Before production finds out.

ChangeGuard combines security scanning, RBAC risk analysis, GitOps health, and runtime signals into a single deployment safety score β€” posted directly on your PRs, updated every 10 seconds.

The average Kubernetes incident costs $300K+ in downtime and engineering hours. One prevented incident pays for years of ChangeGuard.
$ curl -sL https://install.changeguard.ai | bash -s -- --api-key YOUR_KEY --cluster production
CSC SCORE
87
βœ“ SAFE TO DEPLOY

Every Deploy Is a Bet You Can't Measure

Your team ships to production multiple times a day. But the decision to deploy or hold is based on gut feel, not data.

πŸ”€
Signals Are Scattered

Monitoring, RBAC, CVEs, GitOps status, and runtime health live in different tools. Nobody has the full picture when it matters β€” right before deploy.

🀷
Decisions Are Subjective

Without a unified metric, deploy/no-deploy calls depend on who's on-call and how they feel. Two engineers look at the same cluster and reach different conclusions.

πŸ”₯
Incidents Are Preventable

Most production incidents trace back to a change that could have been flagged β€” overprivileged RBAC, a vulnerable image, a failing health check. The signal was there. Nobody saw it in time.

Change Safety Confidence (CSC)

A single, deterministic metric for deployment readiness β€” fully auditable and explainable.

🎯
One Score, One Decision

CSC aggregates policy compliance, runtime signals, cluster health, and historical patterns into a single 0–100 score β€” eliminating the need to correlate signals across multiple monitoring tools.

πŸ”
Fully Explainable

Every point in the score maps to a specific check. See exactly why a deployment scored 87 or 42 β€” no black box, full audit trail.

⚑
Automated Gating

Set thresholds to auto-approve or flag deployments for review. CSC β‰₯70 deploys automatically. CSC <50 triggers a warning with full risk context. Your team defines the rules.

How the Score Is Calculated

Deterministic model β€” every point is accounted for, every deduction is explainable

40
Policy & Compliance
CIS benchmarks, CVEs, RBAC risk, deprecated APIs, custom policies
28
Runtime Signals
Pod health, Falco alerts, error rates, restarts, OOM events
17
Historical
Score trends, incident frequency, recovery time
15
Cluster Health
Node capacity, resource pressure, GitOps drift

Fits Into Your Existing Workflow

One Helm install deploys 9 components. CLI validates manifests before deploy. PR checks post scores on every pull request. No pipeline migration.

01
CLI Validates
02
PR Check Posted
03
Agent Deployed
04
Cluster Scanned
05
Live Monitoring

Shift-Left CLI

Validate YAML, Helm charts, and Kustomize overlays against live cluster state before you deploy. Catches CVEs, RBAC risks, and missing policies in CI or locally.

YAML Helm Kustomize CI/CD gate

CI/CD & PR Checks

CSC scores posted as commit status checks and PR comments on every pull request. Works with GitHub branch protection rules.

GitHub Actions GitLab CI Jenkins Any CI

Alerts & Webhooks

Daily fleet digest via Slack/Teams at 9am. Real-time webhook events on score drops, critical CVEs, and Falco alerts β€” wire to PagerDuty, Jira, or any endpoint. HMAC-signed payloads.

Slack Teams Webhooks PagerDuty

Security & Compliance

Five scanning tools managed by the operator. Findings auto-mapped to compliance frameworks. Export branded PDF reports for SOC 2 audits.

SOC 2 PCI DSS HIPAA FedRAMP EO 14028

Security From Code to Cluster

Pre-deploy validation, runtime threat detection, identity risk analysis, attack path mapping, and automated compliance evidence β€” one platform, one score.

πŸ•ΈοΈ
ATTACK PATHS
Wiz-Style Risk Graph

Maps every path from internet to crown jewels: Ingress β†’ Service β†’ Pod β†’ ServiceAccount β†’ Secrets. Shows exactly how a compromised container reaches cluster-admin or steals credentials. The visual that makes CISOs act.

πŸ“‹
COMPLIANCE
Auto-Generated Audit Evidence

Every security finding mapped to SOC 2, PCI DSS 4.0, HIPAA, FedRAMP, and EO 14028 controls β€” with evidence, data source, and pass/fail status. Export a branded PDF report and hand it to your auditor. One click.

πŸ›‘οΈ
IDENTITY RISK
RBAC Risk Scoring

Graph-based analysis maps every ServiceAccount, User, and Group to their effective permissions and blast radius. Detects cluster-admin abuse, wildcard permissions, privilege escalation paths, and secrets exposure. Per-identity risk scores 0–100.

⬅️
SHIFT-LEFT
Catch It Before kubectl apply

changeguard validate -f deployment.yaml β€” checks manifests against live cluster state before you deploy. Catches CVEs, overprivileged SAs, missing network policies, and resource limit gaps. Runs locally or in any CI pipeline.

πŸ”’
SECURITY SCANNING
5-Tool Security Stack

KubeBench CIS benchmarks, Grype CVE scanning, Falco runtime threat detection, Pluto deprecated API detection, and Syft SBOM generation β€” all managed by the Kubernetes Operator, all feeding into one CSC score.

πŸ””
CI/CD
GitHub & GitLab PR Checks

CSC scores posted as commit status checks and PR comments on every pull request. Developers see deployment safety without leaving their workflow. GitHub Action, GitLab CI, and universal script included.

πŸš€
GITOPS
ArgoCD + Flux CD Integration

CRD-native watching β€” no API tokens or polling. Full visibility into ArgoCD Applications, Flux Kustomizations, HelmReleases, and Sources. Drift detection, sync failures, and stale source alerts feed directly into the CSC score.

🧠
AI ANALYSIS
Claude + NVIDIA NIM

Ask questions about your cluster's deployment safety in natural language. "Why did the score drop?" "Is it safe to deploy right now?" Grounded in live CSC scores, security scans, RBAC data, and Falco alerts. Toggle between Claude and NVIDIA NIM.

⚑
RUNTIME
Falco eBPF Threat Detection

DaemonSet on every node monitors syscalls in real-time via eBPF. Detects cryptominers, container escapes, privilege escalation, suspicious process execution, and file access violations β€” within seconds, not hours.

Design Partner Program

We're selecting 5 platform teams to shape the future of ChangeGuard.
Full platform access. Direct founder access. No cost for 60 days.

What You Get

Full Platform Access β€” 60 Days
Everything in Professional: security scanning, Falco runtime detection, identity risk analysis, GitOps monitoring, PR checks, up to 10 clusters. No credit card.
Direct Slack Channel With the Founder
Not a support ticket queue. A shared Slack channel with the founder β€” bugs get fixed in hours, not weeks.
Priority Feature Development
Your use cases drive the roadmap. Need a specific policy rule, integration, or alert? It gets built.
Guided Onboarding & Weekly Check-ins
The founder will help install the agent, configure policies, and walk through your first CSC scores live. Weekly 15-min syncs to make sure you're getting value.
Lock In Design Partner Pricing β€” Permanently
Convert at a permanently discounted rate after the evaluation. That rate stays with you forever β€” even as pricing increases.

What We Ask in Return

Run It in a Real Environment
Install the agent on at least one production or staging cluster. We need real-world signal, not sandbox testing.
30 Minutes of Feedback Per Week
A short sync β€” what's working, what's not, what you wish it did. This is how the product gets better for everyone.
A Case Study Quote (If You're Happy)
2-3 sentences about your experience. Only if you'd genuinely recommend it. No pressure, no ghost-written marketing copy.
Tell Us When Something Breaks
Early software has rough edges. We'd rather hear about them from you than discover them in production with a paying customer.
Ideal Design Partner
Platform or DevOps team running 10+ Kubernetes clusters with ArgoCD. Deploys multiple times per day. Has experienced at least one "we didn't see that coming" incident in the last 6 months.
5
design partner slots remaining
Apply for the Program β†’

Start Free. Scale With Your Fleet.

14-day free trial, no credit card. Pricing scales with your cluster count and the capabilities you need.

STARTER
Free Trial
then usage-based pricing
  • CSC Scoring (0–100)
  • KubeBench CIS Benchmarks
  • Grype CVE Scanning
  • Pluto API Deprecation
  • Syft SBOM Generation
  • ArgoCD + Flux Monitoring
  • GitHub / GitLab PR Checks
  • Slack & Teams Alerts
  • Score History & Export
Start Free Trial
ENTERPRISE
Custom
for large-scale fleets
  • Everything in Professional, plus:
  • Unlimited Clusters
  • NVIDIA NIM AI Analysis
  • SSO / SAML
  • Audit Export & SLA
  • On-prem Option (Air-gapped)
Contact Sales
All plans include a 14-day free trial. Design partners receive permanently discounted rates.

Request a Demo

Schedule a guided demonstration β€” our team will follow up within one business day.

Stop guessing. Start scoring.

The next incident your team prevents with ChangeGuard will pay for itself many times over. Install the agent in 60 seconds and see your first CSC score immediately.