Case 05 · Flagship

BlastGuard

Supply Chain Blast-Radius Control Plane: don't count CVEs — predict where they can reach, decide ALLOW/WARN/QUARANTINE/BLOCK, and prove remediation.

01

How it works

From CVE to a blast-radius decision.

BlastGuard by Andrey Lesnikov — predict supply-chain blast radius, enforce explainable decisions, and prove remediation before the exploit window matters.

BlastGuard architecture: discover inputs, digital twin graph, decide, enforce, verify remediation
Blast-radius plane: build-time truth + runtime truth → decision → proof.
BlastGuard lifecycle: Discover, Trace, Decide, Enforce, Verify with critical path and decision card
Lifecycle — Discover → Trace → Decide → Enforce → Verify
  1. 01

    Discover

    Attach SBOM, vulnerability advisories, VEX, and Sigstore provenance — build-time truth enters the twin.

  2. 02

    Trace

    Walk CVE → package → image → workload → service → ingress. Prune VEX, not-running, and unreachable branches.

  3. 03

    Decide & Enforce

    Policy returns ALLOW / WARN / QUARANTINE / BLOCK with an explicit reason — then admission / GitOps gate enforces it. No fake risk percentage.

  4. 04

    Verify

    After patch, recompute radius. Zero affected running paths means REMEDIATION PROVED. Rehearse images and CVEs before production changes.

02

Evidence

Problem, constraints, architecture, result.

Problem

Scanners invent finding counts. Without graph + runtime + exposure, teams drown in tickets while the one internet-facing path stays open.

Architecture

Discover SBOM/CVE/Sigstore truth, Trace through package→image→workload→ingress, Decide with explainable policy, Enforce at admission, Verify remediation until blast radius is zero.

Trade-offs

BlastGuard does not replace Syft/Grype/GUAC/Sigstore — it sits above them. The cost is twin hygiene; the payoff is decisions operators can defend.

Result

147 findings become one critical path, BLOCK with reason, a fix image, and REMEDIATION PROVED after patch — plus what-if rehearsal before promote.

03

Snapshot

Field notes.

Problem
CVE scanners produce finding counts. Without blast radius, runtime reachability, and exposure context, teams patch noise instead of real attack paths.
Constraints
SBOM truth, VEX, Sigstore provenance, Kubernetes runtime, ingress exposure, explainable admission decisions, and remediation proof.
Architecture
Discover → Trace → Decide → Enforce → Verify: correlate SBOM/CVE graphs with running workloads into ALLOW/WARN/QUARANTINE/BLOCK — then prove the radius is gone.
Result
Supply-chain security becomes predictive blast-radius control, not another vulnerability dashboard.
04

Related

Nearby systems.

Case 06

SBOM Integration

Software supply-chain data is often generated late, stored separately, and disconnected from deployment decisions.

Result: Supply-chain visibility becomes part of the delivery system, not a quarterly compliance export.

Case 15

Policy as Code Guardrails

Security and platform rules are often discovered only after deployment or during reviews.

Result: Teams get fast feedback while platform standards are enforced consistently across environments.

Case 24 · Flagship

Architecture Rehearsal

Teams discover architectural blast radius only after a change lands in production.

Result: Operators know what breaks before they deploy — and can prove whether the prediction was right after the change lands.

Available for meaningful infrastructure conversations

Build systems that stay calm under pressure.

Available for conversations

Talk infrastructure

Book a working session

Meet

Evidence first

For deep dives

Explore the systems

All cases