REAL-TIME PROTECTION

Check before download.

Every package request passes through the PexLens proxy, is analysed against its security signals, and is blocked the moment it fails your checks — not at the next scheduled scan.
Inline at request time
Policy-driven verdicts
Every decision recorded

THE PROBLEM

A scan tells you what already happened.

By the time a scheduled scan reports a malicious package, it has been downloaded, installed and possibly executed. The window between request and detection is where the damage happens.

INSTALLED FIRST

Lifecycle scripts run instantly

Credentials read, payloads dropped, and persistence achieved before any scheduled security reports are ever compiled.

SPREAD ALREADY

Rapid lateral propagation

A single un-intercepted developer request quickly turns into a complex fleet-wide remediation and cleanup exercise.

REMOVAL IS MANUAL

Shifting burden to teams

Reactive detection without active prevention drags your engineering team away from writing software into manual cleanup.

THE REQUEST PATH

Every request goes through the gate

STEP 01

Request made

A developer, CI job or build server asks for a package version.

STEP 02

Proxy intercepts

The request is routed through the PexLens proxy before it reaches the registry.

STEP 03

Analysed inline

Threat signals, dependencies, publisher history and risk are evaluated instantly.

PASS

Download proceeds

Delivered from the registry, unchanged.

FAIL

Download refused

Blocked at the gate, finding recorded.

Nothing reaches the machine unchecked. The verdict is made on the version being requested, at the moment it is requested.

OUTCOME · ALLOWED

Clean packages move at full speed

When a version passes, it is served straight from the registry. No queue, no ticket, no waiting for manual security reviews.
  • Verdict cached for the same version
  • No change to developer tools or workspace commands

OUTCOME · BLOCKED

Unsafe packages never land

When a version fails your policy, the download is refused at the gate & the finding is recorded against the device, project & requester.
  • Reason returned to the developer inline
  • Recorded for centralized security audit and review

POLICY YOU CONTROL

You set the line. The gate enforces it.

Team-level policies
Apply rules to a team and manage all members & devices together seamlessly.
Consistent enforcement
Every single request is evaluated programmatically against the rules you define.
Adjustable by default
Sensible pre-configured defaults that you can easily tune to your organization's risk profile.
Built for velocity
Ensure fast dev progress without compromising security thresholds.

Stop threats the moment they knock.

Every package request evaluated in real time — allowed or blocked, instantly.