Rampart
Security findings your engineers can merge.
Rampart runs the checks on every push and pull request. A finding arrives as a fix pull request with the evidence in it.
01
From connected to gated
- 01
Connect
Authorise the org, pick repositories, choose protected branches.
- 02
Scan
Every check runs on each push and pull request. No schedule to remember.
- 03
Review
A finding opens a fix pull request your engineers read and decide on.
- 04
Gate
Policies make a class of finding a required check, not a reminder.
02
What runs, and what it does about it
| Check | What it does | Default |
|---|---|---|
| Dependencies | Advisories from OSV.dev, matched against the resolved lockfile. | Blocks when a fix exists |
| Code | Pattern and regex rules across the code that ships. | Reported per file and line |
| Secrets | Entropy and pattern detection, matched in place. | Blocks on high confidence |
| Infrastructure | Dockerfile, Terraform, Kubernetes, Actions. | Reported per definition |
| Containers | OCI manifest and configuration. Layers never pulled. | Reported per image |
03
Start free, pay when it earns it
New organizations start free: 3 repositories, 50 scans a month, the preset Production Security Gate. Monthly plans add repositories, scan volume, PR checks, and SSO — a plan per organization, priced in UGX for each 30-day period, activating the moment payment verifies.

