Uncain

WE CONTAIN TRUST DRIFT

Your supply chain is shifting.We're watching.

Uncain maps the trust graph behind the work that ships: workflows, packages, and agents. When that trust drifts, we help contain unsafe execution before it becomes release history.

TRUST DRIFT

Trust drift is the threat model most teams never drew.

A tag moves. A maintainer gets write access. A reusable workflow starts inheriting secrets. A package beneath the build changes shape. An agent runs with more authority than anyone intended.

None of that needs a CVE. It still changes what your delivery system trusts - and how wide your blast radius gets.

  • 412 workflows in the median GitHub org
  • 340 unverified transitive dependencies
  • 0 containment plans

HOW IT WORKS

Map. Detect. Contain.

One graph. Three moves. No alert theater.

Map the trust graph

Uncain resolves workflows, Actions, reusable workflows, package install context, runtime paths, and the agents working beside developers into one execution map.

workflows -> Actions -> packages -> agents

Detect trust drift

We watch for trust-bearing change: moved tags, permission drift, package drift, weakened evidence, and runtime behavior that changes what should be allowed to run.

tag drift + package drift + runtime authority

Contain before execution

When policy breaks on a supported path, Uncain cancels unsafe runs, quarantines trust objects, and opens remediation paths before the next run lands.

cancel runs + quarantine refs + remediation PRs

NOT ANOTHER SCANNER

Trust is a graph, not a checklist.

Other tools flatten trust into lists. Uncain keeps the relationships intact, so a change can be judged by where it can execute and what authority it can reach.

One platform, one graph

A deploy workflow can trust a third-party Action, the packages that Action installs, and the agent session that edits the repository. Uncain keeps that lineage together.

execution lineage

  • release workflow
  • third-party Action
  • package install context
  • agent workspace activity

Drift, not backlog

A trust-bearing change can matter before a vulnerability database catches up. Uncain watches the movement itself: a tag rewrite, a mutable package selector, a widened permission, an elevated agent mode.

what moved

  • deploy-action@v2 -> new SHA
  • latest selector introduced
  • id-token: write added
  • permission mode elevated

Decisions, not theater

The graph should lead to a decision an operator can trust: cancel the unsafe run, hold a drifted ref, block a risky runtime command, or show why the change can keep moving.

decision path

  • run cancelled
  • ref quarantined
  • command blocked
  • evidence retained

Blast radius, not generic severity

Uncain explains what the change can reach: the workflows, repositories, secrets, environments, packages, and agent activity connected to the drift.

blast radius

  • 3 repos affected
  • 5 workflows exposed
  • 2 deploy paths at risk

WHAT WE FIND

It's 2 AM. An upstream dependency just changed.

47 of your workflows will execute it on the next push. Two carry deploy authority. Nobody is awake for the first alert.

We built Uncain so you can sleep through that.

ACCESS UNCAIN

We contain trust drift.

Open the graph behind the work that ships. See what changed. Decide what should run.

Open Uncain