Skip to content
Home

Hextrap

Package firewall and pluggable code security tools that inspect Python, NPM, and Go installs to block malware, typosquatting, and vulnerable dependencies

hextrap.comSecurity MonitoringJun 2026TD Internet Solutions, LLC

The product is a package firewall and pluggable code security tools that inspect Python, NPM, and Go installs in real time to block malware, typosquatting, and vulnerable dependencies before they reach developer machines and CI pipelines. It sells to developers, engineering leaders, and security teams in startups, growing teams, and enterprises, including teams governing AI coding agents. It is delivered as SaaS via a transparent proxy requiring a single package manager configuration change with per-team firewalls, cached policy evaluation, and no SDK or code changes.

Key features

  • Allow lists and deny lists
  • Malware detection
  • Typosquatting protection for Python NPM Go
  • Real-time package vulnerability scanning
  • Supply chain attack prevention
  • Lightweight static analysis
  • Real-time vulnerability feedback
  • Pluggable security rules
  • CI/CD pipeline integration
  • Immutable audit logs with user attribution
  • SBOM generation SPDX CycloneDX
  • RBAC with custom roles
  • SSO SAML integration
  • MFA enforcement
  • Policy enforcement with versioning
  • AES-256 encryption at rest
  • TLS 1.3 in transit
  • Soak time window enforcement
  • Unmaintained package detection
  • No social media activity within the last 30 days
GTM channels
  • Blog
  • API
  • Docs
ICP
  • Software developers
  • Security teams
  • Engineering teams