Product tour
See StepSecurity working, without booking a call
Every capability below is a real product walkthrough you drive yourself. This is the same Prevent, Detect and Respond map as the documentation, so what you read and what you can watch line up exactly.
Start here
Play the demo
Harden Runner Detailed Demo
The full walkthrough of runtime monitoring for a CI/CD pipeline: what Harden-Runner sees, how a baseline is learned, and what happens when a workflow does something it has never done before.
Platform at a glance
Pick a capability, watch it work
The same matrix as the platform overview and the documentation. Every cell opens the demo behind it.
🖥️ Developer Machines
📁 Code Repositories
♾️ CI/CD Pipelines
Prevent
Stop the bad change before it lands.
01Block malicious OSS packages at install time on dev machines and CI with Secure RegistryHow to Configure and Monitor Secure Registry Policies
02Allow only approved IDE extensionsDevice Policies
03Enforce safe package manager configurationsPackage Manager Configuration Audit Across Developer Machines
01Block PRs that pull in compromised package versionsFind PRs upgrading to compromised versions
02Enforce a cooldown period before new package releases are adoptedConfigure GitHub Checks with npm Package Cooldown Periods
03Roll out secure Dependabot configs across all reposDependabot configuration
01Restrict network egress from CI runners with Harden-RunnerAdding Harden-Runner to a workflow file
02Enforce security policies on every workflow runHow to Setup Allowed Actions Policy
03Replace risky third-party Actions with StepSecurity Maintained ActionsStepSecurity Maintained Actions
Detect
See what actually happened at runtime.
01Discover AI coding agents and MCP servers on every machineDocumentation, no demo recorded yet
02Inventory installed IDE extensions
03Find a compromised package on dev machines in secondsSearch for npm Packages Across Branches, PRs, and Developer Machines
01Screen every PR for risky dependency changesFind PRs upgrading to compromised versions
02Search for any package across repos, PRs, and machines at onceSearch for npm Packages Across Branches, PRs, and Developer Machines
03Stream detections to your SIEM in real timeDocumentation, no demo recorded yet
01Detect runtime compromise in CI with eBPF monitoringHarden Runner Memory Read Detection
02Flag anomalous outbound calls against learned network baselinesCreate security policy from Baseline
03Get alerted the moment a run behaves abnormallySetting up Slack notifications
Respond
Find the blast radius and shut it down.
01Pinpoint compromised packages and extensions on machines
02Detect attacker-planted files, like tampered IDE extension filesView and Investigate Suspicious Files Across Enrolled Devices
03Sweep all dev machines during an incidentSearch for npm Packages Across Branches, PRs, and Developer Machines
01Track active supply chain attacks in Threat CenterDocumentation, no demo recorded yet
02Map the blast radius: which repos, PRs, and machines are affectedSearch for npm Packages Across Branches, PRs, and Developer Machines
03Verify every affected repo is actually remediatedDocumentation, no demo recorded yet
Want to see this on your own code?
Start free to run StepSecurity against your own pipelines, repositories, and developer machines, or talk to us about the enterprise tier.
