Per developer machine
Veln
$9.99
per device · one-time · USD
Full supply-chain protection across every package manager, on every developer machine. One lifetime license per machine — no subscription, no renewals.
More machines? Buy another device license anytime — each one is a one-time $9.99 purchase you activate on the next machine. Buy one or several at once.
Every device license includes
- npm, yarn, pnpm, bun — every install intercepted
- pip, pip3, uv, pipx — every install intercepted
- go, cargo, bundle, dotnet, mvn, gradle — install-time gate routing
- OS-level install-script isolation (Linux Landlock, macOS sandbox-exec, Windows Job Object — see capabilities for the Windows network-isolation caveat)
- OSV vulnerability lookups + npm publish-attestation checks
- Maintainer-drift, dormant-revival, license-change, and dependency-confusion signals
- Obfuscation, dynamic-eval, and packed-payload detection
- Capability / permission-creep + telemetry, secret-exfil, and geo-targeting signals
- SBOM export (CycloneDX & SPDX), policy-as-code rules, and VEX suppressions
- Local Console with full per-package finding history