
Lupin & Holmes offers Depi, an offensive cybersecurity platform that proactively identifies and validates software supply chain vulnerabilities before attackers can exploit them. Depi combines continuous research with agentic AI-driven exploit development to uncover complex, real-world risks across CI/CD pipelines and package ecosystems. The platform provides security teams with actionable evidence of how their supply chain links can be broken, enabling them to prioritize and remediate critical threats.
Funding
Funding not disclosed
Founders
Product
Problem
Software supply chains are increasingly complex and vulnerable, with attackers exploiting trust boundaries in CI/CD pipelines, package managers, and reusable workflows. Traditional security tools often fail to detect these sophisticated attack vectors, leaving organizations exposed to backdoor compromises and data breaches.
Solution
Depi is a proactive cybersecurity tool that takes an offensive security perspective to identify and validate supply chain vulnerabilities. It uses agentic AI to autonomously develop and execute exploit chains, demonstrating exactly how attackers could compromise an organization's software supply chain. Depi provides security teams with concrete evidence of exploitable weaknesses, enabling them to prioritize and remediate risks before they are exploited. The platform is built on cutting-edge research from ethical hackers who have uncovered real-world vulnerabilities, ensuring it addresses the most relevant and impactful threats.
Target Audience
Primary customers are security teams and DevOps professionals in organizations that rely on complex software supply chains, including those using CI/CD pipelines, package managers, and third-party dependencies.
Features
- Agentic AI-driven exploit development that autonomously discovers and validates attack chains
- Continuous scanning and attack modules for GitHub Actions pipelines and other CI/CD systems
- Detection of dependency confusion, command injection, and workflow-state confusion vulnerabilities
- Evidence-based reporting that shows exactly how an attacker could break supply chain links
- Research-backed detection models informed by real-world vulnerabilities and bug bounty findings