Cairn Index
For a limited time only, we're opening a limited number of spots in our pilot program to visionary teams ready to co-develop and secure their stack alongside us. Get in early: your direct feedback on onboarding ramp, integration with other platforms, and more will go straight into the final product.
Cairnlytics provides an automated, data-driven way to
quantify the resilience of OSS dependencies. Users submit either a list of
dependencies (repository URLs or package names and versions) or an SBOM, and
Cairnlytics builds the full direct and transitive dependency graph for each
component, the “cairns”. It then computes a time series of Cairn Index risk
scores (out of 1000) for every component, using development-health and risk
signals extracted from project history from the earliest available activity onward.
The Cairn Index is dynamic and continuously recomputed as
project activity, maintainership, and governance signals evolve. Cairnlytics
highlights the specific “stones” most likely to bring a system down, supports
deep recursive risk assessment across dependency chains, and provides
monitoring dashboards so teams can track risk as it changes. Teams can
configure alerts for practical failure and compromise indicators, such as a
dependency becoming effectively unmaintained or “frozen in time,” or a sudden maintainership
shift where a new maintainer authors, reviews, and merges their own changes, a
governance pattern that can indicate supply-chain hijacking. The same approach
can also be applied to internal software development health. Integration
remains non-intrusive because it only requires access to Git metadata and
repository history, not source code contents or sensitive internal systems.
Finally, Cairnlytics pairs an easy-to-communicate aggregate score with the detailed evidence behind it, helping developers prioritise fixes, enabling CISOs to understand portfolio-level exposure, and giving compliance teams defensible due diligence artefacts for audits and regulatory reporting.
Categories
- Application & Cloud Security
- Email & Data Security
- Governance, Risk & Compliance (GRC)