Security products that
replace trust with proof.
We secure the software supply chain with hardware-rooted verification instead of loose trust assumptions.
Software supply chain security
Your software is mostly
other people's code.
Almost every update pulls in new, unaudited code.
Your code
What you control
Open-source dependencies
most of the code you ship, written and updated by thousands of open-source developers
Build & CI
Artifact → your users
We provide auditability
and source provenance
before your dependency upgrades.
Provenance tells you where code came from, not whether it's safe. A backdoor committed upstream still passes those checks, so we also audit the code itself.
Backdoored releases & unread dependency diffs
xz-style, committed upstream: passes every provenance check
✓ Attested AI audit · Dependency Canary
Unverifiable builds & pre-compiled binaries
no proof the binary matches its source
✓ Attested build · Attestable Builds
No due-diligence evidence
CRA · NIS2 obligations, landing late 2027
✓ Signed, portable evidence
Every audit runs in hardware-attested compute and yields an attestation anyone can verify.
Dependency Canary
Attested AI audits of dependency updates, published within 24 hours of a release: a baseline check against malicious changes until a human can review. cargo-vet compatible and queryable by humans and AI agents. Rust first.
Learn More →Attestable Builds
Hardware-signed proof that the binary you ship was really built from its source. Useful on its own, stronger with Canary.
Learn more →Confidential SBOMs
Customers ask whether a specific package is in your product and get an attested answer, without you handing over your SBOM.
Learn more →Built for your team
Light Squares' provenance and audit graphs help your entire team.
AppSec / DevSecOps
- Attested audit verdicts instead of rubber-stamping.
- Complementary to your SCA stack, not another scanner.
Developer
- Check the audit verdict for any update before you merge.
- Your coding agents query the audit graph via API.
CISO / Compliance
- Portable, signed proof, not black-box scores.
- Attested audit trails as evidence for NIS2 duties that already apply, and for the CRA ahead of late 2027.
- European, sovereignty-aligned by design.
Why Light Squares
- Verify it yourself
- Portable, signed, attestation-backed audit artifacts anyone can verify and import, not a risk score you have to take on faith.
- Open about limits
- We are upfront about what AI audits can and cannot catch: they are a baseline, not a guarantee. Trust claims should be checkable (including ours).
- Complementary, not a rip-and-replace
- Works with tools like Snyk and Dependabot. Keep your scanners; add the audit layer they don't provide.
- European & compliance-ready
- Sovereignty-aligned and built for CRA and NIS2 due-diligence evidence.
Our public roadmap
What we work on
Attestable Builds
Runs on our platform today: verify artifacts from attested pipelines against the transparency log and there's a public demo artifact to try. Running your own builds is invite-only for now.
Learn more →Dependency Canary
Our first release is a free, public set of attested audits for widely used Rust crates, published in cargo-vet format so existing tooling can import them directly.
See the plan →Design-partner pilots
We're looking for security-conscious teams to shape Dependency Canary with us, with early access and a direct line to the founders.
Get started →Backed by research
Founded by two security PhDs who met doing research together at the University of Cambridge and supported by:



Ready to raise the bar for your third-party dependencies?
Join the early access program or book a call with one of our co-founders.




