Continuous software-supply-chain security

Your supply chain
has a blind spot.
We fix that.

A newly disclosed vulnerability or compromised package can affect developer machines and repositories before a security team has mapped the real exposure. Clarveil continuously correlates package-security intelligence against what is observed across your organisation, identifies where affected versions are present, and triggers the response workflow — from PR controls and remediation plans to Slack and Microsoft Teams notifications.

Talk to us about a pilot
Or email atul@clarveil.com directly
Continuous
Threat correlation
Organisation-wide
Reverse lookup
Human-controlled
Remediation
Patent pending
Security for AI-assisted development

Detect what is exposed today.
Help prevent risky dependency
decisions tomorrow.

Clarveil already helps enterprises detect known package threats, locate affected versions across their environment and coordinate remediation.

Our patent-pending direction moves the security decision earlier in the software-development lifecycle — helping developers and AI coding assistants assess dependencies before adoption.

Clarveil’s direction is therefore not only reactive detection. It is a progression from detect → map → respond toward assess → prevent → verify.

Even with tools,
the response loop is manual.

Fragmented intelligence

Threat intelligence keeps moving

Advisories, ecosystem reports, security research and newly reported compromised packages appear continuously. Security teams still have to determine whether a package actually exists anywhere in their organisation — including incidents that may not yet have a CVE.

Manual exposure checking

Finding the affected package is still too manual

Teams often rely on searches, scripts, messages and developer follow-up to work out whether a package and version is present. That can leave an incomplete picture of the organisation’s real exposure.

Repository-only visibility

A repository scan is not the whole developer fleet

Packages and extensions can also exist on developer endpoints outside the repository view. Clarveil adds endpoint-level inventory and reverse lookup across Windows, macOS and Linux, alongside repository context.

Manual follow-up

Detection is only the start

After exposure is identified, remediation is often coordinated through tickets, messages and ad-hoc records. It can be difficult to see what remains exposed, what action was recommended, what was approved and whether the issue has actually been resolved.

From new threat to verified response.

Intelligence

New intelligence appears

A vulnerability, malicious-package report or other package-security event is identified. The event may have a CVE, an advisory identifier or package-level evidence without a CVE.

Correlate

Clarveil correlates it

Clarveil checks the affected package and version against package inventory observed across the organisation.

Map

Exposure is mapped

Reverse lookup surfaces where the affected package is present, including relevant developer endpoints, install paths and repository context. Supported endpoint inventory also includes VS Code and IntelliJ extensions.

Prepare

Response is prepared

Clarveil produces machine-level and repository-level remediation guidance. The PR Bot can apply policy controls to dependency changes, while endpoint remediation remains human-controlled.

Notify

Teams are notified and response is tracked

Slack or Microsoft Teams notifications can surface the package, affected version, exposure context and recommended next action so security and engineering teams can respond from the same evidence.

Coverage
Windows macOS Linux Git repositories VS Code extensions IntelliJ extensions Jamf Intune Slack Microsoft Teams
Enterprise exposure + preventive security

Built for teams that need to answer:
“Are we exposed right now?”

When a new package threat appears, the first enterprise question is not simply “is this package bad?” It is “do we have it, where is it, and what should we do next?”

Clarveil connects package-security intelligence with organisation-specific inventory so security teams can move from a global package event to an actionable view of their own exposure.

SECURITY TEAMS

Prioritise by actual exposure

Reverse lookup newly disclosed package threats across the organisation and prioritise response using actual exposure.

PLATFORM & ENGINEERING

Give developers a concrete next step

Give developers clear repository-level and machine-level remediation guidance without relying on organisation-wide manual searches.

ENTERPRISE ENVIRONMENTS

Managed fleets, heavy open-source use

Designed for organisations with managed developer fleets and significant open-source dependency usage. Initial focus includes finance, retail and public-sector environments, with broader international applicability.

And Clarveil is designed to go further. Our patent-pending direction adds security before dependency adoption — helping developers and AI coding assistants make safer software-supply-chain decisions before dependencies enter the organisation.

Clarveil is engaging with selected enterprise design partners in New Zealand.

Security for AI-assisted development

AI is making dependency decisions faster.
Security needs to move with it.

AI coding assistants are increasingly helping developers select libraries, packages and dependencies. That creates a new security decision point before software enters the organisation.

A NEW DECISION POINT

Dependencies now arrive with a suggestion attached

Developers no longer choose every dependency unaided. Package selection increasingly begins with an assistant’s recommendation, and that recommendation is acted on quickly — often before any security review has taken place.

The decision of whether a dependency should enter the organisation at all is therefore being made earlier, and faster, than most review processes were designed for.

AI DEPENDENCY SAFETY

What happens when an AI suggests a dependency?

// Developer asks an AI coding
// assistant for a dependency
 
// AI suggests:
package-name-x
 
// Before adoption:
Is this package legitimate?
Does it require additional
  security review?
Should the organisation allow,
  review or hold the dependency?

Clarveil is developing patent-pending security controls designed to add an independent security decision before AI-suggested dependencies enter enterprise software.

CLARVEIL’S DIRECTION

Safer dependency decisions, before adoption

Clarveil is developing patent-pending safeguards designed to help developers and AI coding assistants make safer dependency decisions before adoption.

Available now
Detect known compromised and vulnerable packages, map where affected versions are present, and coordinate the response.
Patent-pending direction
Add an independent security decision between AI-generated recommendations and the software that enters the organisation.

From protecting organisations from compromised dependencies to helping AI avoid introducing risky dependencies in the first place.

5.2%–21.7%
Package hallucination rates
A large-scale USENIX Security study measured package hallucination rates of at least 5.2% for commercial code-generating models and 21.7% for open-source models.
USENIX Security 2025 ↗
1 every 6 minutes
New malicious open-source packages
Sonatype reported 21,764 malicious open-source packages in Q1 2026 — equivalent to approximately one newly identified malicious package every six minutes.
Sonatype Q1 2026 Malware Index ↗
205,474
Unique nonexistent package names
Researchers identified 205,474 unique nonexistent package names generated across 16 code-generating LLMs in a large-scale package-hallucination study.
USENIX Security 2025 ↗
Patent-pending direction

A security layer before
dependency adoption

AI-ASSISTED DEVELOPMENT

An independent decision before adoption

Add an independent security decision before AI-recommended dependencies are adopted.

ENTERPRISE CONTEXT

Your policy, applied to the decision

Apply organisation-aware security policy to dependency decisions.

PREVENTIVE REVIEW

Surface what needs a closer look

Surface dependencies that require additional verification before they become part of the software environment.

HUMAN-REVIEWABLE GUIDANCE

Explainable, and still yours to decide

Provide clear, explainable security guidance while keeping developers and security teams in control.

The direction is simple: move software-supply-chain security earlier — from reacting only after a threat is known toward making safer dependency decisions before adoption.

PATENT PENDING / R&D DIRECTION

Where Clarveil extends the
software-supply-chain response loop

Capability
Typical SCA / existing controls
Clarveil
Known vulnerability and malicious-package detection
Core capability
Repository dependency visibility
Core capability
Developer endpoint package inventory
Varies
Organisation-wide package/version reverse lookup
Varies
Windows, macOS and Linux endpoint coverage
Varies
VS Code and IntelliJ extension inventory
Varies
Repository remediation plan
Varies
Machine-level remediation plan
Varies
PR policy blocking
Varies
Slack / Teams threat notifications
Often integration-dependent
Jamf / Intune endpoint distribution
Integration-dependent
Security before AI-assisted dependency adoption
Emerging
PATENT-PENDING DIRECTION

Built to run inside
your network.

Clarveil is designed for enterprise-controlled deployment, with package inventory and developer telemetry kept within the customer-controlled environment wherever the deployment model allows.

On the roadmap
Expanded environment exposure mapping Preventive dependency review Expanded remediation orchestration Additional ecosystem coverage AI-assisted developmentPATENT PENDING

Detect.
Map.
Respond.
Then move security earlier.

Today, Clarveil helps security teams determine whether a known package threat affects their organisation, where the exposure exists and what should happen next. Current pilot capabilities combine continuous threat correlation, organisation-wide reverse lookup, PR controls, remediation guidance and enterprise notifications.

Our patent-pending direction moves the security decision earlier — helping developers and AI coding assistants make safer dependency decisions before adoption.

We are engaging with selected enterprise design partners. Talk to us about a pilot.

Email atul@clarveil.com
Privacy

Clarveil is designed for customer-controlled enterprise deployment. Package inventory, source-code context and developer telemetry are intended to remain within the customer-controlled environment. Public package-security intelligence can be pulled into the deployment on a configurable schedule. Deployment and outbound-connectivity requirements are agreed with each pilot organisation. This marketing site sets no analytics cookies, runs no third-party trackers, and makes no third-party network requests. Privacy questions: atul@clarveil.com.