Skip to main content
S

StepSecurity

The startup offers a software security platform that enhances computer and network security by implementing minimum token permissions and dependency pinning. This approach strengthens software supply chain security, reducing vulnerabilities and ensuring safer workflows for clients.

Dover, United KingdomFounded 20211610K+ followers
Updated 18 months ago

Funding

$3M raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.

RV
Funding rounds are not available yet.

Founders

Product

Problem

CI/CD pipelines are vulnerable to supply chain attacks due to the use of third-party components and the potential for compromised credentials, leading to unauthorized code changes, secret exposures, and malicious software releases. Existing security solutions often lack visibility into the unique runtime behavior of CI/CD environments, making it difficult to detect and respond to these threats effectively.

Solution

StepSecurity provides a comprehensive CI/CD security platform that protects against supply chain attacks by combining real-time threat detection, automated remediation, and a secure internal marketplace for vetted CI/CD components. The platform monitors network, file, and process activity on CI/CD runners, blocking suspicious behavior and providing detailed insights into the origin of each event. StepSecurity also helps organizations manage their CI/CD security posture by identifying misconfigurations, enforcing least privilege, and automating security best practices through pull requests.

Target Audience

StepSecurity targets security and DevOps teams responsible for securing CI/CD pipelines in organizations using GitHub Actions, GitLab CI, Jenkins, Bitbucket, or Azure DevOps.

Features

  • Real-time threat detection and response for CI/CD pipelines, including detection of compromised packages, dependencies, and build tools
  • Harden-Runner monitors network, file, and process activity on CI/CD runners, blocking suspicious behavior instantly
  • Internal GitHub Actions Marketplace allows organizations to vet, approve, and manage Actions internally, ensuring developers use secure, compliant components
  • Automated remediation pull requests to fix security gaps in pipelines, pin third-party actions to immutable references, and enforce least privilege
  • CI/CD security posture management to identify misconfigurations, script injection vulnerabilities, and risky third-party Actions
  • Workflow Run Policy to block runs with unapproved Actions, disallowed runners, or suspicious secret access
  • GitHub Checks integration provides real-time security feedback within the development workflow
  • Support for GitHub Actions, GitLab CI, Jenkins, Bitbucket, and Azure DevOps
This profile is AI-generated and may contain inaccuracies.