private preview · live rev0.0.5 build scmGitLab scannersTrivy · Grype · Semgrep · Checkov · Kingfisher · ChainArmor
Private preview GitLab native

Your next merge request ships a known-exploited CVE. We catch it first.

OpsArmor Gate is a GitLab merge-request security gate. Scanners run on MRs and default branches. Findings land in one inbox — scored, evidenced, and triaged before merge.

Google SSO for operators  ·  GitLab PAT age-encrypted  ·  Self-host

SCM GitLab Merge requests + default branch. Not a GitHub App. No cloud OIDC keys.
Coverage 6 Scanner engines — Trivy, Grype, Semgrep, Checkov, Kingfisher, ChainArmor
Ingest 30+ Import formats — SARIF, CycloneDX, GitLab, OpenVEX, Wazuh, Nuclei, Gitleaks, Snyk…

§03One GitLab install. One findings inbox.

No GitHub App. No “zero stored keys” claim. Operators sign in with Google SSO. Each install stores a GitLab PAT, envelope-encrypted with age. Scanners comment on the MR; the inbox is where work happens.

Live

Findings inbox

CVE, secrets, SAST, and misconfig in one feed. Assign, snooze, ignore, override severity, add notes. Grouped or single. Import a scan without waiting for the next MR.

Inbox · open · assigned to you
KEV   CVE-2021-23337  lodash@4.17.20     critical
SECRET AKIA••••WXYZ   .gitlab-ci.yml:42  critical
SAST  sql-injection   src/api/users.go   high
actions: snooze · ignore · assign · scan again
            
Live

Secrets that stay secrets

Kingfisher on the working tree by default. Git history only if you turn it on. Prefixes only in the UI. Autofix does not rewrite leaked credentials — rotate them.

Dependencies + KEV

Trivy and Grype, scored with EPSS and CISA KEV. ChainArmor asks OSV.dev for supply-chain advisories. VEX statements demote what you have already attested.

SAST that names a line

Semgrep / opengrep on the clone. Path and keyword ignore rules at the org. Rescan from the finding drawer.

Live

Evidence-bound AI triage

AI assessments cite scanner evidence. They do not invent blast-radius graphs or merge-block on a hunch. Operators keep the decision. Optional Autofix can stage a GitLab fix for eligible findings — off until you turn it on.

evidence-bound advisory, not autonomous EPSS · KEV · VEX autofix opt-in

Checkov policy, not a graph

Terraform, Kubernetes, Helm, Dockerfile, CloudFormation. Policy findings on the clone. Not a Pulumi / CDK blast-radius product.

Google SSO & GitLab PAT

Allowlisted Google emails. GitLab token stored age-encrypted. Self-host on your VPS. There is no GitHub App and no GitHub OIDC cloud-role federation.

§04From GitLab install to an inbox you can work.

Install once with a GitLab PAT. Scanners run on the next merge request and on the default branch. Findings are fingerprinted, scored, and opened in the inbox — with one MR comment, not ten duplicate alerts.

  1. GitLab connected.

    Google SSO for operators. A GitLab personal access token, envelope-encrypted with age. Webhooks on MRs. No GitHub App to install.

  2. Scanners run.

    Trivy, Grype, Semgrep, Checkov, Kingfisher, ChainArmor on the clone. Default-branch coverage plus the merge-request diff. Import SARIF / CycloneDX when CI already scanned it.

  3. Findings scored.

    Fingerprint, EPSS, KEV, VEX. Same finding across scanners is one row. AI assessment is advisory and must bind to that evidence.

  4. Inbox + MR comment.

    One comment on the merge request. The work happens in Gate: assign, snooze, ignore, notes. Autofix stays off unless you enable it for eligible findings.

§05Scanners you already trust.

Gate runs them on the GitLab clone and accepts the reports you already produce. Same fingerprint, same inbox row.

finding/evidence.json fingerprinted · inbox row
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11{
  "scanner": "grype",
  "package": "lodash@4.17.20",
  "cve":     "CVE-2021-23337",
  "kev":     true,
  "epss":    0.84,
  "fixed":   "4.17.21",
  "source":  "merge_request+default"
}
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11{
  "scanner":  "semgrep",
  "check_id": "go.lang.security.sql",
  "path":     "src/api/users.go",
  "line":     84,
  "severity": "high",
  "snippet":  "db.Query(fmt.Sprintf(...))"
}
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11{
  "scanner": "kingfisher",
  "kind":    "aws_access_key",
  "path":    ".gitlab-ci.yml",
  "line":    42,
  "prefix":  "AKIA••••WXYZ",
  "note":    "rotate; do not autofix"
}

Also live: Checkov (Terraform / Kubernetes / Dockerfile policy), ChainArmor (OSV.dev), OpenVEX, and import of SARIF, CycloneDX, GitLab, Wazuh, Nuclei, Gitleaks, Snyk, and more. Not a Pulumi / AWS CDK blast-radius product.

§06Changelog.

What actually landed on main. Preview while Gate is still being finished — planned items are issues, not slogans.

Shipped

Evidence-bound AI findings

AI assessments must cite scanner evidence. Scorecard, routing, and currentness so a stale verdict cannot pretend to be live. Operators keep the decision.

Shipped

Inbox import + feed operations

SARIF, CycloneDX, GitLab, OpenVEX, Wazuh, native scanner JSON, and 30+ tool formats. Assign, severity override, notes, package ignore. Autofix stays off.

In progress

Eligible Autofix + GitLab merge-blocking

Autofix can stage a GitLab fix for eligible findings — off until you enable it. Dedicated Terraform / IaC review and IaC Autofix are still open P1s. Merge-blocking needs GitLab Premium external status checks. None of these are on by default.

§07Pricing. Per operator. Waitlist while Gate finishes.

Preview rates for GitLab teams. Seats are humans who triage findings — bots are free. Self-host is the same product, on your VPS.

Private preview. Gate is a GitLab security gate — scanners, inbox, evidence-bound AI. New teams join the waitlist. Autofix and merge-blocking stay off until you enable them.

Free

$0preview

Waitlist · small teams

  • Google SSO · GitLab PAT
  • MR + default-branch scans
  • Findings inbox
  • Scan import
  • Org SLA · self-host
Join free waitlist
Most popular

Team

$2923/ seat / mo

Min 10 seats · $290/mo floorMin 10 seats · billed annually · saves 20%

  • Everything in Free
  • Evidence-bound AI triage
  • Assign · snooze · ignore rules
  • Members & invites
  • Eligible Autofix opt-in
Join team waitlist

Business

$5947/ seat / mo

Min 20 seats · $1,180/mo floorMin 20 seats · billed annually · saves 20%

  • Everything in Team
  • Org SLA tracking
  • Org triage + ignore rules
  • Audit log of operator decisions
  • Merge-blocking GitLab Premium
Join business waitlist

Enterprise

Talk to us

annual · self-host

  • Everything in Business
  • Self-host on your VPS
  • Your allowlist, your age key
  • MCP for agent workflows
  • Named onboarding
Join enterprise waitlist

Google SSO for operators. GitLab PAT stored age-encrypted. Scanners plus optional Autofix write — Autofix is off by default. Seats = humans who triage; service accounts are free. This is OpsArmor Gate, not a GitHub IaC blast-radius product.

Private preview · GitLab teams

Join the preview waitlist.

Tell us your GitLab (SaaS or self-hosted) and where findings pile up today — CVE inbox, secrets, or SAST. We reply in batches. No GitHub App to install.

Waitlist only. We use your email to follow up about preview access — nothing else.