Light Squares

Security products that
replace trust with proof.

We secure the software supply chain with hardware-rooted verification instead of loose trust assumptions.

Software supply chain security

Your software is mostly
other people's code.

Almost every update pulls in new, unaudited code.

Your code

What you control

Open-source dependencies

crates.io
npm
PyPI
Maven

most of the code you ship, written and updated by thousands of open-source developers

Build & CI

Artifact → your users

We provide auditability
and source provenance
before your dependency upgrades.

Provenance tells you where code came from, not whether it's safe. A backdoor committed upstream still passes those checks, so we also audit the code itself.

Backdoored releases & unread dependency diffs

xz-style, committed upstream: passes every provenance check

Attested AI audit · Dependency Canary

Unverifiable builds & pre-compiled binaries

no proof the binary matches its source

Attested build · Attestable Builds

No due-diligence evidence

CRA · NIS2 obligations, landing late 2027

Signed, portable evidence

Every audit runs in hardware-attested compute and yields an attestation anyone can verify.

How it works →The technology behind it →

In Development

Dependency Canary

Attested AI audits of dependency updates, published within 24 hours of a release: a baseline check against malicious changes until a human can review. cargo-vet compatible and queryable by humans and AI agents. Rust first.

Learn More →

Built for your team

Light Squares' provenance and audit graphs help your entire team.

AppSec / DevSecOps

  • Attested audit verdicts instead of rubber-stamping.
  • Complementary to your SCA stack, not another scanner.

Developer

  • Check the audit verdict for any update before you merge.
  • Your coding agents query the audit graph via API.

CISO / Compliance

  • Portable, signed proof, not black-box scores.
  • Attested audit trails as evidence for NIS2 duties that already apply, and for the CRA ahead of late 2027.
  • European, sovereignty-aligned by design.

Why Light Squares

Verify it yourself
Portable, signed, attestation-backed audit artifacts anyone can verify and import, not a risk score you have to take on faith.
Open about limits
We are upfront about what AI audits can and cannot catch: they are a baseline, not a guarantee. Trust claims should be checkable (including ours).
Complementary, not a rip-and-replace
Works with tools like Snyk and Dependabot. Keep your scanners; add the audit layer they don't provide.
European & compliance-ready
Sovereignty-aligned and built for CRA and NIS2 due-diligence evidence.

Our public roadmap

What we work on

Early Access

Attestable Builds

Runs on our platform today: verify artifacts from attested pipelines against the transparency log and there's a public demo artifact to try. Running your own builds is invite-only for now.

Learn more →
In development

Dependency Canary

Our first release is a free, public set of attested audits for widely used Rust crates, published in cargo-vet format so existing tooling can import them directly.

See the plan →
Open now

Design-partner pilots

We're looking for security-conscious teams to shape Dependency Canary with us, with early access and a direct line to the founders.

Get started →

Backed by research

Founded by two security PhDs who met doing research together at the University of Cambridge and supported by:

Judge Business School AccelerateIgnite LondonCDTM

Meet the team →

Ready to raise the bar for your third-party dependencies?

Join the early access program or book a call with one of our co-founders.