Held to a higher bar.

A security tool is a target. Here is what is enforced today, how each control is proved, and what is not done yet.

No customer codeScans run in your CI, on your laptops or in a Runner in your network. Only results reach Cordon.proved: by design
One database schema per organisationAnother organisation's records read as not found.proved: isolation tests, live cross-organisation probes
Sender-bound sessionsA stolen token is useless without the browser's own key (DPoP).proved: refused live without a proof
A second factor on every sensitive actionAn app code, or an emailed code. Organisations can require an app.proved: tested end to end
Breached passwords refused12 to 128 characters; checked against known breaches without sending the password.proved: tests
A tamper-evident audit trailHash-chained, signed with a key outside the database, append-only.proved: checked at start-up
Signed policy and evidenceEd25519. The CLI pins your organisation's key at sign-in.proved: verifiable offline
Credentials encryptedCode-host and alert credentials are field-encrypted and never returned.proved: tests
Outbound calls locked downCustomer-supplied URLs reach public HTTPS hosts only: no redirects, no internal addresses.proved: SSRF tests
PasskeysSign in with the device's own unlock. A fake sign-in page cannot use one, and a replay is refused.proved: tests with real signatures
Signed CI uploads verifiedA signed scan counts only from a CI identity your trust rules accept, or the very job that uploaded it, for the repository and commit it names.proved: a real Sigstore bundle
An assistant that cannot be talked roundIt answers only from your own organisation's records, treats every finding and file it reads as data, never takes an action, and never puts your data in a link.proved: injection and envelope-forgery tests
A hardened edgeTLS 1.2+, strict headers, per-address limits, slow requests cut off.proved: attacked live
Attacked on purpose

Tried, and refused.

Each line is a result we measured: the edge attacked live, isolation probed across organisations, and the rest proved by tests.

attack TLS 1.1 handshake refused
attack handshake for an unknown host name refused
attack 400 requests at once from one address 269 refused, 429
attack one header line every 10 seconds cut off at 60 s
attack forged X-Forwarded-For and X-Real-IP replaced
attack 60 password guesses on monitoring 27 refused, 429
attack create a container via the socket proxy 403
attack read another organisation's data 0 of 4 pairs leaked
attack forged signature on a CI upload refused as forgery
attack replay a passkey sign-in refused
attack a token written into a log line redacted
The scanner, on your machines

Safe to run beside your keys.

What a default scan sendsNothing that names a package or a file. It fetches the signed intel feed, which is the same for everyone.
What --online sends, and only when askedA package's name and version to its own registry, an image's digest to its registry, and a tool-list request to an MCP server your config names. Each archive fetched is checked against the digest its registry publishes, and nothing is installed or run.
What an upload sendsFindings, coverage and the inventory, after evidence is masked. Never source, never a secret's value.
Its own supply chainZero third-party runtime dependencies. The core imports only the Python standard library.
How you know it is oursWheel, image and Action signed with Sigstore, with SLSA provenance and byte-reproducible output.
What it does not defend against

A tool that overclaims is worse.

  • An attacker who studies the rules and writes code to slip past them. Behaviour rules raise the bar from one campaign to the common shapes; they do not make evasion impossible.
  • Code that behaves exactly like a benign package until a trigger fires long after install. The opt-in sandbox installs a second time with the clock moved 400 days ahead, which catches a date check; a trigger that waits on anything else stays out of reach.
  • A machine that is already compromised. The scan trusts the environment it runs in.
  • Someone who can both commit and approve their own review.

Cordon is the supply-chain layer of a defence in depth, beside branch protection, secret scanning and a cooldown on brand-new releases, not a replacement for them.

Not done yet

Nothing claimed early.

These move to the list above only when they are finished.

External penetration testPlanned
SOC 2 Type I, then Type IIPlanned
ISO 27001Planned
Verify what we publishScanner releases and images are signed. Key fingerprints are published with the first release.
Report a vulnerabilityPrivately, through a GitHub security advisory. Acknowledged within 2 working days, with safe harbour for good-faith research.

See it running.