Cairn Index

For a limited time only, we're opening a limited number of spots in our pilot program to visionary teams ready to co-develop and secure their stack alongside us. Get in early: your direct feedback on onboarding ramp, integration with other platforms, and more will go straight into the final product.
Cairnlytics Stand: K70 - DSIT Pavilion
Modern software is overwhelmingly built on open source: 96% of audited codebases include open-source software (OSS), and it can make up around 90% of an application. That scale creates systemic fragility. A widely used library can become unmaintained, patch slowly, or quietly accumulate security debt until a breaking change or exploit, like Log4j, ripples through transitive dependencies and hits production. This is now a board-level risk. Regulators are raising expectations around operational resilience and third-party and OSS governance (UK Cyber Security and Resilience Bill, EU DORA, US SBOM). But classic procurement due diligence does not translate to OSS. There is often no vendor to complete questionnaires, no site to audit, no SOC 2 pack, and no meaningful financial checks, which creates a governance blind spot. Teams default to CVE scanning and ad-hoc reviews, which miss health signals like maintainer concentration (bus factor), community engagement, and patch responsiveness. Attackers exploit the same gap: the “hit the maintainer, own the downstream” playbook is increasingly routine. Sonatype logged 512,847 malicious packages in the past year (+156% YoY), and in 2025 authorities warned about widespread npm compromises used to inject and propagate malicious code. At this scale, even one compromised dependency can rapidly become an outage, an incident, and a compliance problem all at once.

Cairnlytics provides an automated, data-driven way to quantify the resilience of OSS dependencies. Users submit either a list of dependencies (repository URLs or package names and versions) or an SBOM, and Cairnlytics builds the full direct and transitive dependency graph for each component, the “cairns”. It then computes a time series of Cairn Index risk scores (out of 1000) for every component, using development-health and risk signals extracted from project history from the earliest available activity onward.

The Cairn Index is dynamic and continuously recomputed as project activity, maintainership, and governance signals evolve. Cairnlytics highlights the specific “stones” most likely to bring a system down, supports deep recursive risk assessment across dependency chains, and provides monitoring dashboards so teams can track risk as it changes. Teams can configure alerts for practical failure and compromise indicators, such as a dependency becoming effectively unmaintained or “frozen in time,” or a sudden maintainership shift where a new maintainer authors, reviews, and merges their own changes, a governance pattern that can indicate supply-chain hijacking. The same approach can also be applied to internal software development health. Integration remains non-intrusive because it only requires access to Git metadata and repository history, not source code contents or sensitive internal systems.

Finally, Cairnlytics pairs an easy-to-communicate aggregate score with the detailed evidence behind it, helping developers prioritise fixes, enabling CISOs to understand portfolio-level exposure, and giving compliance teams defensible due diligence artefacts for audits and regulatory reporting.

Categories

  • Application & Cloud Security
  • Email & Data Security
  • Governance, Risk & Compliance (GRC)
Loading