# Safeguard Documentation > Developer & API documentation for Safeguard — the software supply chain and AI security platform. Covers the CLI, MCP server (agent-native access and procurement), SCA/SBOM, scanning, autonomous remediation, integrations, and compliance frameworks. ## Documentation pages - [Abbreviations and Descriptions](https://docs.safeguard.sh/docs/abbreviations): Glossary of terms used in Safeguard documentation - [Account Recovery & Keys](https://docs.safeguard.sh/docs/account-recovery): Reset or change your password, manage Guard SDK secret keys, and recover access when you're locked out of SSO. - [AI-BOM & Model Security](https://docs.safeguard.sh/docs/ai-bom-model-security): Track, govern, and secure AI models — model cards, weight provenance, fine-tune lineage, and training-data risk. - [AI-BOM Discovery](https://docs.safeguard.sh/docs/ai-bom): Inventory every AI asset in your environment — models, ML dependencies, notebooks, prompts, vector stores, agents, MCP servers, and inference endpoints — into one tenant-scoped AI bill of materials. - [AI Gateway (LLM Firewall)](https://docs.safeguard.sh/docs/ai-gateway): A runtime guardrail layer for LLM apps and agents — prompt-injection, jailbreak, and PII/secret-egress checks in monitor or enforce mode, with fail-open safety so the protected app never breaks. - [AI Models (Griffin, Eagle, Lino)](https://docs.safeguard.sh/docs/ai-models): The three Safeguard-built security models — their roles, versions, and availability. - [AI Security Posture Management (AI-SPM)](https://docs.safeguard.sh/docs/ai-spm): Detect malware and hidden code in AI model files — across Pickle, PyTorch, safetensors, GGUF, and ONNX formats — before untrusted weights ever load into your environment. - [Air-Gapped Deployment](https://docs.safeguard.sh/docs/air-gapped-deployment): Run Safeguard end-to-end inside isolated, classified, or regulated environments with no internet egress required. - [All Frameworks](https://docs.safeguard.sh/docs/all-frameworks): The complete list of all 373 compliance frameworks Safeguard supports. - [Analytics & Dashboards](https://docs.safeguard.sh/docs/analytics-dashboards): Executive dashboards, custom reports, and exports that show posture trends and program effectiveness. - [API Reference](https://docs.safeguard.sh/docs/api-reference): MCP server, CLI, and the status of the REST API - [Application Security Testing (SAST & DAST)](https://docs.safeguard.sh/docs/application-security-testing): Find vulnerabilities in your source code (SAST) and running applications (DAST) with Safeguard's first-party, tenant-isolated application security testing. - [Asset Discovery](https://docs.safeguard.sh/docs/asset-discovery): Automatically discover every repository, container, package, SBOM, AI model, and vendor dependency in your software estate. - [Attestation & Signing](https://docs.safeguard.sh/docs/attestation-signing): SLSA provenance, Sigstore signing, in-toto attestations, and SBOM attestation — how Safeguard produces and verifies signed evidence. - [Autonomous Agent](https://docs.safeguard.sh/docs/autonomous-agent): How Griffin AI Search's autonomous agent watches your screen and acts on your behalf, and why some actions are executed directly while others only appear as a suggestion. - [AutoTriage](https://docs.safeguard.sh/docs/autotriage): Cross-scanner deduplication and noise reduction that cuts finding volume with a measured reduction metric — and never suppresses malware or secrets findings. - [Browser Extension](https://docs.safeguard.sh/docs/browser-extension): Install the Safeguard browser extension — now on the Chrome Web Store — to open Safeguard AI search in a side panel or sidebar in Chrome, Edge, and Firefox. - [Slack, Teams & Discord](https://docs.safeguard.sh/docs/chatops-integrations): Route findings and events into your team's Slack workspace, Microsoft Teams tenant, or Discord server — set up credentials, pick a default channel, and understand what's two-way today. - [CI/CD Integration](https://docs.safeguard.sh/docs/cicd-integration): Integrate Safeguard into your CI/CD pipelines - [Claude Integration](https://docs.safeguard.sh/docs/claude-integration): Connect Safeguard's MCP server to Claude (Claude.ai and Claude Desktop) to query your software supply chain security in natural language. - [Compliance](https://docs.safeguard.sh/docs/compliance): Architecture designed for FedRAMP HIGH and IL5, EO 14028, and regulatory compliance - [Connectors](https://docs.safeguard.sh/docs/connectors): The complete list of all 647 integrations Safeguard supports. - [Continuous Scanning](https://docs.safeguard.sh/docs/continuous-scanning): Safeguard re-evaluates every asset against new vulnerabilities, new malware signatures, and new policy rules continuously — not just at build time. - [CTEM & EASM](https://docs.safeguard.sh/docs/ctem-easm): Roadmap — external attack-surface management plus a Gartner-style continuous threat exposure management program that unifies every engine's findings into one prioritized, exploitability-validated exposure list. - [Deep Dependency Scanning (100 Levels)](https://docs.safeguard.sh/docs/deep-dependency-scanning): Scan dependencies 100 levels deep — 40 more than most SCA tools — to find vulnerabilities hidden in transitive dependencies. - [Desktop Application](https://docs.safeguard.sh/docs/desktop-app): The Safeguard desktop app — an Electron app that pairs the hosted web app with a local panel for file access, CLI execution, MCP hosting, and agent-driven tasks. - [Digital Risk Protection & Threat Intel](https://docs.safeguard.sh/docs/drp-tip): Roadmap — a threat-intelligence pipeline (ingest, normalize, dedup, enrich, score, age, correlate, disseminate) plus outward-facing digital risk protection for leaked credentials, look-alike domains, and brand impersonation. - [Data Security Posture Management (DSPM)](https://docs.safeguard.sh/docs/dspm): Discover and classify sensitive data — PII, PHI, payment-card data, and secrets — with an enforced redaction mandate so raw sensitive data is never stored. - [Endpoint Security (EDR/EPP)](https://docs.safeguard.sh/docs/endpoint-security): Roadmap — a lightweight cross-OS endpoint agent for EDR telemetry, behavioral detection, gated response, and (later) NGAV prevention, feeding the SecOps SIEM/XDR. - [Gold Open Source](https://docs.safeguard.sh/docs/gold-open-source): Safeguard's free, public directory of security-verified open-source software — packages, container images, CVEs, CWEs, the full MITRE ATT&CK framework, AI models, MCP servers, agent skills, and chip manufacturers, available at gold.safeguard.sh and as a Chrome extension. - [Gold Registry (Marketplace)](https://docs.safeguard.sh/docs/gold-registry): Curated zero-CVE, malware-free open source packages and container images — drop-in replacements for common components. - [Griffin AI](https://docs.safeguard.sh/docs/griffin-ai): Purpose-built LLM for software supply chain security - [Audit Trail & Alerts](https://docs.safeguard.sh/docs/guard-audit-alerts): How Guard records every policy decision as an audit event, rolls those events up into aggregates for reporting, and the alert-rule schema behind webhook notifications when a condition is met. - [Guard Policies](https://docs.safeguard.sh/docs/guard-policies): Author and manage the policies that decide whether a given MCP tool call is allowed, denied, or monitored by Guard. - [Guard Proxy Deployment](https://docs.safeguard.sh/docs/guard-proxy): Run Guard as a standalone, self-hosted reverse-proxy gateway in front of your MCP servers instead of embedding the Guard SDK in every agent process. - [Guard SDK](https://docs.safeguard.sh/docs/guard-sdk): Embed live Safeguard policy enforcement directly into your MCP server or AI agent process with the Guard SDK for Python, TypeScript, and Go. - [Servers & Agents](https://docs.safeguard.sh/docs/guard-servers-agents): How Guard maintains an inventory of the MCP servers and AI agents in your environment, and how policy targets them. - [Guard Webhooks](https://docs.safeguard.sh/docs/guard-webhooks): Deliver Guard alert events — jailbreak scores, anomaly detection, blocked-request ratios, and unreachable servers — to your own endpoint over a signed HTTP webhook. - [Guardrails & Enforcement](https://docs.safeguard.sh/docs/guardrails-enforcement): Policy-as-code guardrails enforced across CI/CD, registries, runtime, and procurement. - [IDE Support](https://docs.safeguard.sh/docs/ide-support): Real-time vulnerability scanning, inline Package Firewall checks, and AI-assisted remediation for VS Code, Cursor, and JetBrains IDEs. - [About Safeguard](https://docs.safeguard.sh/docs): What's in Your Software? Safeguard your software supply chain with comprehensive SBOM intelligence, continuous security, and enterprise compliance. - [Integrations](https://docs.safeguard.sh/docs/integrations): Every external system Safeguard connects to — source control, registries, clouds, identity, ticketing, notifications, SIEMs, and more. - [Identity Threat Detection (ITDR) & DLP](https://docs.safeguard.sh/docs/itdr-dlp): Roadmap — identity-attack detection (MFA fatigue, impossible travel, token theft, privilege escalation) with approval-gated response, plus data-loss prevention that reuses the DSPM classifier at the AI gateway, API, and export paths. - [License Compliance](https://docs.safeguard.sh/docs/license-compliance): Detect, classify, and enforce open-source license policies across code, containers, and vendor SBOMs. - [Malware Detection](https://docs.safeguard.sh/docs/malware-detection): Detect malicious packages, images, and model weights using Eagle — Safeguard's purpose-built classification model. - [Model Capabilities](https://docs.safeguard.sh/docs/model-capabilities): What Griffin, Eagle, and Lino can actually do — concrete tasks, input shapes, output contracts, and example prompts. - [Package Firewall](https://docs.safeguard.sh/docs/package-firewall): Stop malicious and typosquatted dependencies at install time — inline allow / warn / block enforcement for typosquats, dependency confusion, and known-malicious packages. - [PR Guard](https://docs.safeguard.sh/docs/pr-guard): AI-driven code review that runs against a pull request's diff and surfaces severity-ranked findings, inline in Safeguard and optionally posted back to the pull request itself. - [Product Offering](https://docs.safeguard.sh/docs/product-offering): Four products. Complete visibility. Absolute control. Zero compromise. - [RBAC, Teams & Organizations](https://docs.safeguard.sh/docs/rbac-teams): Organizations, teams, roles, SSO, API keys, and audit logging — how Safeguard handles identity and access. - [Vulnerability Prioritization (Reachability Analysis)](https://docs.safeguard.sh/docs/reachability-analysis): How Safeguard uses call-graph reachability, EPSS, KEV, and runtime context to cut 60-80% of CVE noise so teams patch what actually matters. - [Red Team (Defensive Adversary Emulation)](https://docs.safeguard.sh/docs/red-team): Validate your detections and attack paths with Safeguard's defensive-only adversary emulation — breach-and-attack simulation, purple-teaming, and safe attack-path analysis. No weaponized payloads, ever. - [Release Notes](https://docs.safeguard.sh/docs/release-notes): Latest updates and changes to Safeguard products - [Local Runner](https://docs.safeguard.sh/docs/runner): The Safeguard runner — execute Safeguard workflows and Griffin-driven fixes locally, similar in spirit to Claude Code. - [Runtime Protection (CWPP & CNAPP)](https://docs.safeguard.sh/docs/runtime-protection): ATT&CK-mapped runtime threat detection and cloud-native risk correlation — surfacing findings that are running, reachable, exposed, and over-privileged all at once. - [Safeguard Loop](https://docs.safeguard.sh/docs/safeguard-loop): Roadmap — a unifying name and view for Safeguard's continuous detect, prioritize, fix, and verify cycle across scanning, Griffin AI, and remediation engines. - [Safeguard Tag](https://docs.safeguard.sh/docs/safeguard-tag): Roadmap — the idea of tagging or @-mentioning Safeguard directly inside a Slack, Teams, or Discord conversation to send it a question or command, without leaving the chat. - [Software Composition Analysis (SCA)](https://docs.safeguard.sh/docs/sca): Find and prioritize known vulnerabilities, license risks, and malicious packages across your full dependency graph — with reachability-aware triage and a single findings model. - [SDKs](https://docs.safeguard.sh/docs/sdks): Official SDKs for Python, TypeScript/JavaScript, Go, Java, and Rust — typed, versioned, and signature-verifying by default. - [Search Connectors](https://docs.safeguard.sh/docs/search-connectors): Attach external MCP servers as live tools Griffin can call during a search conversation. - [Skills](https://docs.safeguard.sh/docs/search-skills): Reusable system prompts and MCP tool whitelists you can trigger with "/" in Griffin AI Search. - [Workspaces](https://docs.safeguard.sh/docs/search-workspaces): Group Griffin AI Search conversations under a shared system prompt, default model, attached files, and member access — like a project. - [SecOps (SIEM)](https://docs.safeguard.sh/docs/secops): OCSF-normalized security event ingestion, continuous detection with Sigma rules and IOC matching, and deduplicated alerts — the SIEM substrate, with SOAR, XDR, and an agentic SOC analyst on the roadmap. - [Secrets Scanning](https://docs.safeguard.sh/docs/secrets-scanning): Find leaked credentials, API keys, and tokens in source code, container images, Git history, and vendor SBOMs. - [Self-Healing Containers](https://docs.safeguard.sh/docs/self-healing-containers): Automatically rebuild and redeploy container images to patch new CVEs — without waiting for the next feature release. - [SaaS Security Posture Management (SSPM)](https://docs.safeguard.sh/docs/sspm): Roadmap — read-only posture, MFA/SSO, external-exposure, and identity checks across business SaaS, with OAuth-app and shadow-SaaS enumeration as the headline capability. - [Trusted Artifacts](https://docs.safeguard.sh/docs/trusted-artifacts): Roadmap — a curated catalog of hardened, minimal, signed base images with SBOM and SLSA provenance, plus (later) build-from-source and FIPS/STIG variants. - [Unified Findings & Feature Flags](https://docs.safeguard.sh/docs/unified-findings): Every security engine reports into one unified findings model, browsed from a single consolidated Findings tab with a scanner filter, and independently admin-toggleable via server-enforced feature flags. - [Vulnerability & Exposure Management](https://docs.safeguard.sh/docs/vuln-exposure-management): Roadmap — a single-pane management layer over the unified findings store, adding a deduplicated risk-ranked backlog, SLA policies, ownership routing, bi-directional ticketing, expiring risk exceptions, campaigns, and metrics. - [Web Application](https://docs.safeguard.sh/docs/web-app): The Safeguard web application — the primary interface for ESSCM, Portal, TPRM, and OSM in any modern browser. - [Webhooks & Events](https://docs.safeguard.sh/docs/webhooks-events): Subscribe to Safeguard events — findings, scans, remediations, attestations, audit — and drive your own automations. - [What's New — July 2026](https://docs.safeguard.sh/docs/whats-new-july-2026): Live agentic search, the governed Trust Center, cross-surface access (browser/CLI/IDE/MCP), and browser extensions. - [Workflow Library](https://docs.safeguard.sh/docs/workflow-library): Pre-built workflow templates covering auto-fix, admission gates, self-healing, vendor risk, compliance, and operations. One-click install. - [Workflows](https://docs.safeguard.sh/docs/workflows): Safeguard's workflow engine — chain discovery, scanning, policy, remediation, and notification steps into repeatable automations. - [Zero-Day Discovery](https://docs.safeguard.sh/docs/zero-day-discovery): How Safeguard finds, validates, and publishes zero-day vulnerabilities in open source and vendor software. - [Calendar & Study Tasks](https://docs.safeguard.sh/docs/academy/calendar): The learner calendar aggregates live sessions, meetups, study tasks, exam cooldowns, and certificate expiries — with Google Calendar links, .ics downloads, and a personal iCal feed. - [Certificates: Verifying & Sharing](https://docs.safeguard.sh/docs/academy/certificates): Every Academy certificate is a public, verifiable page — share the link, add it to LinkedIn in one click, post it to X or Reddit, download the branded PDF, or verify by QR code. - [Community & Live Sessions](https://docs.safeguard.sh/docs/academy/community-and-live-sessions): Course communities (doubts and discussions answered by AI tutors, human tutors, and peers), live sessions over Google Meet, and Academy-wide meetups on YouTube Live with a recording archive. - [Exams & Certifications](https://docs.safeguard.sh/docs/academy/exams-and-certifications): How Academy certification exams work — question-set and AI-interview modes, the grading pipeline (auto, AI with human review), cooldowns, and certification requirements. - [FAQ](https://docs.safeguard.sh/docs/academy/faq): Frequently asked questions about Safeguard Academy — pricing, accounts, exams, grading, certificate verification, languages, and more. - [For Teams](https://docs.safeguard.sh/docs/academy/for-teams): Using Safeguard Academy for team enablement — onboarding engineers onto supply chain security and the Safeguard platform, with verifiable certificates as the completion signal. - [Getting Started](https://docs.safeguard.sh/docs/academy/getting-started): Sign up for Safeguard Academy, browse the catalog, and enroll in your first course. - [Safeguard Academy](https://docs.safeguard.sh/docs/academy): Free courses and publicly verifiable certifications for software supply chain security at academy.safeguard.sh — video/text/audio lessons, AI tutors, course communities, live sessions, and shareable certificates. - [Taking Courses](https://docs.safeguard.sh/docs/academy/taking-courses): How Academy courses are structured — modules, lessons, video/text/audio blocks, progress rules, and the per-course AI tutor. - [Agents & LLMs](https://docs.safeguard.sh/docs/agents): How AI agents and LLM-powered assistants use the Safeguard platform — connection, authentication, tool governance, everyday workflows, and self-serve procurement. - [Procurement for agents](https://docs.safeguard.sh/docs/agents/procurement): The step-by-step guide for AI agents buying Safeguard — regional plan discovery, tier and audience comparison, Stripe checkout, payment verification, and entitlement checks. - [Safeguard CLI](https://docs.safeguard.sh/docs/cli): Command-line interface for Safeguard software supply chain security - [CLI Installation](https://docs.safeguard.sh/docs/cli/installation): Install the Safeguard CLI on macOS, Linux, or Windows - [Interactive terminal](https://docs.safeguard.sh/docs/cli/interactive): The terminal you get when you run safeguard with no arguments - [Slash commands](https://docs.safeguard.sh/docs/cli/slash-commands): Every command available inside the Safeguard interactive terminal - [Support Matrix](https://docs.safeguard.sh/docs/cli/support-matrix): Supported languages, package managers, and platforms for the Safeguard CLI - [System Configuration](https://docs.safeguard.sh/docs/cli/system-configuration): Configure the Safeguard CLI for your environment - [Troubleshooting CLI Issues](https://docs.safeguard.sh/docs/cli/troubleshooting): Resolve common Safeguard CLI problems and errors - [CLI Usage](https://docs.safeguard.sh/docs/cli/usage): Learn how to use the Safeguard CLI for common tasks - [Attestation](https://docs.safeguard.sh/docs/esscm/attestation): Component attestation and SCAL levels in Safeguard - [AI Remediate](https://docs.safeguard.sh/docs/esscm/auto-fix): Automated vulnerability remediation powered by Griffin AI - [Code Quality](https://docs.safeguard.sh/docs/esscm/code-quality): Code quality metrics and technical debt assessment - [Dashboard](https://docs.safeguard.sh/docs/esscm/dashboard): Monitor your software supply chain security at a glance - [EO 14028 Compliance Checks](https://docs.safeguard.sh/docs/esscm/eo-14028-checks): Executive Order 14028 compliance verification and reporting - [Explore SBOM](https://docs.safeguard.sh/docs/esscm/explore-sbom): Analyze and understand your Software Bill of Materials - [Findings](https://docs.safeguard.sh/docs/esscm/findings): View and manage all security findings across policies and gates - [Generate SBOM](https://docs.safeguard.sh/docs/esscm/generate-sbom): Create Software Bills of Materials from source code, containers, and more - [Enterprise Software Supply Chain Manager (ESSCM)](https://docs.safeguard.sh/docs/esscm): Complete visibility for code, containers, AI models, and CI/CD pipelines with AI Remediate capabilities - [JIRA Integration](https://docs.safeguard.sh/docs/esscm/jira-integration): Connect Safeguard with JIRA for automated issue tracking - [Mitigations](https://docs.safeguard.sh/docs/esscm/mitigations): Track and manage vulnerability mitigations and risk acceptances - [Organization & User Management](https://docs.safeguard.sh/docs/esscm/organization-management): Manage organizations, teams, and user access in Safeguard - [Policies & Gates](https://docs.safeguard.sh/docs/esscm/policies-gates): Define and enforce security requirements across your software supply chain - [Risk Score (RS)](https://docs.safeguard.sh/docs/esscm/risk-score): Understanding component integrity risk scoring in Safeguard - [Search](https://docs.safeguard.sh/docs/esscm/search): Search across all SBOMs with Griffin AI natural language queries - [Security Posture](https://docs.safeguard.sh/docs/esscm/security-posture): Component and security-posture-check distribution breakdowns for your projects, products, and components - [Suppliers & Licenses](https://docs.safeguard.sh/docs/esscm/suppliers-licenses): Track component suppliers and manage license compliance - [Vulnerabilities](https://docs.safeguard.sh/docs/esscm/vulnerabilities): View, prioritize, and remediate security vulnerabilities - [Create an Account](https://docs.safeguard.sh/docs/getting-started/create-account): Sign up for Safeguard and create your organization - [Getting Started](https://docs.safeguard.sh/docs/getting-started): Get started with Safeguard - create an account and configure your environment - [Onboarding Workflow](https://docs.safeguard.sh/docs/getting-started/onboarding-workflow): Complete the Safeguard setup and generate your first SBOM - [Payments & procurement](https://docs.safeguard.sh/docs/mcp/agent-payments): How AI agents buy Safeguard plans through the MCP server — regional pricing discovery, tiers and audiences, Stripe checkout, invoices, and entitlements. - [Aleph Alpha](https://docs.safeguard.sh/docs/mcp/aleph-alpha): Connect Safeguard's MCP server to Aleph Alpha (Germany) using its MCP configuration. - [Anthropic](https://docs.safeguard.sh/docs/mcp/anthropic): Connect Safeguard's MCP server to Anthropic's Claude using the Safeguard Security custom connector. - [Claude](https://docs.safeguard.sh/docs/mcp/claude): Connect Safeguard's MCP server to Claude (Claude.ai and Claude Desktop) to query your software supply chain security in natural language. - [Cohere](https://docs.safeguard.sh/docs/mcp/cohere): Connect Safeguard's MCP server to Cohere (North America) using its MCP configuration. - [Connector Setup (Claude, ChatGPT, Others)](https://docs.safeguard.sh/docs/mcp/connectors): Step-by-step instructions to connect Claude (Desktop & web), ChatGPT, Cursor, and other clients to the Safeguard MCP server. - [Microsoft Copilot](https://docs.safeguard.sh/docs/mcp/copilot): Connect Safeguard's MCP server to Microsoft Copilot (Microsoft, USA) using its MCP configuration. - [Cursor](https://docs.safeguard.sh/docs/mcp/cursor): Connect Safeguard's MCP server to the Cursor editor via its MCP settings. - [Gemini (Google)](https://docs.safeguard.sh/docs/mcp/gemini): Connect Safeguard's MCP server to Google Gemini using its MCP configuration. - [Grok (xAI)](https://docs.safeguard.sh/docs/mcp/grok): Connect Safeguard's MCP server to Grok by xAI using its MCP configuration. - [MCP Integrations](https://docs.safeguard.sh/docs/mcp): Connect Safeguard's MCP server to your AI assistant. - [Meta AI (Llama)](https://docs.safeguard.sh/docs/mcp/meta): Connect Safeguard's MCP server to Meta AI (Llama) by Meta (USA) using its MCP configuration. - [Le Chat (Mistral)](https://docs.safeguard.sh/docs/mcp/mistral): Connect Safeguard's MCP server to Le Chat by Mistral AI (France) using its MCP configuration. - [ChatGPT (OpenAI)](https://docs.safeguard.sh/docs/mcp/openai): Connect Safeguard to ChatGPT with a Custom GPT Action, or via the OpenAI MCP endpoint. - [Perplexity](https://docs.safeguard.sh/docs/mcp/perplexity): Connect Safeguard's MCP server to Perplexity (USA) using its MCP configuration. - [Tool availability & gating](https://docs.safeguard.sh/docs/mcp/tool-gating): How Safeguard controls which MCP tools each tenant can see and call, with per-tool feature flags. - [Attestation](https://docs.safeguard.sh/docs/osm/attestation): Supply chain integrity verification through attestations - [Security Database](https://docs.safeguard.sh/docs/osm/gold-directory): Browse open source package security information and vulnerability data - [Open Source Manager](https://docs.safeguard.sh/docs/osm): Open source security intelligence with vulnerability tracking, attestation verification, and license compliance - [License Compliance](https://docs.safeguard.sh/docs/osm/license-compliance): Manage open source license obligations and compliance - [User Guide](https://docs.safeguard.sh/docs/osm/user-guide): Complete guide to using Open Source Manager (OSM) - [SSO Authentication](https://docs.safeguard.sh/docs/sso-authentication): Configure SAML, OIDC, and social sign-in (Google, Microsoft, GitHub) for your Safeguard tenant. - [OpenID Connect (OIDC)](https://docs.safeguard.sh/docs/sso-authentication/oidc): Connect any OIDC 1.0-compliant provider, such as a self-hosted Keycloak, Auth0, or PingFederate instance. - [Provisioning Policy](https://docs.safeguard.sh/docs/sso-authentication/provisioning-policy): Control what happens on first SSO login and whether password login stays available. - [Testing & Troubleshooting](https://docs.safeguard.sh/docs/sso-authentication/troubleshooting): Verify a provider before rollout and debug the most common SSO sign-in errors. - [URLs & Endpoints](https://docs.safeguard.sh/docs/sso-authentication/urls-and-endpoints): The callback, ACS, and metadata URLs Safeguard generates — and how they differ for SAML vs OIDC/social providers. - [Audit Trails](https://docs.safeguard.sh/docs/portal/audit-trails): Complete activity logging for compliance and security - [Compliance](https://docs.safeguard.sh/docs/portal/compliance): EO 14028 and regulatory compliance verification - [Find & Review SBOMs](https://docs.safeguard.sh/docs/portal/find-review-sboms): Search, discover, and review SBOMs in the Portal marketplace - [Portal](https://docs.safeguard.sh/docs/portal): Centralized SBOM management with secure third-party sharing and compliance verification - [Manage Your Repository](https://docs.safeguard.sh/docs/portal/manage-repository): Organize and manage your SBOM repository in Portal - [My Products](https://docs.safeguard.sh/docs/portal/my-products): Manage your product catalog and associated SBOMs in Portal - [SBOM Repository](https://docs.safeguard.sh/docs/portal/sbom-repository): Centralized storage and organization for all your SBOMs - [Portal Settings](https://docs.safeguard.sh/docs/portal/settings): Configure Portal preferences and organization settings - [Sharing](https://docs.safeguard.sh/docs/portal/sharing): Securely share SBOMs with customers, partners, and auditors - [User Roles](https://docs.safeguard.sh/docs/portal/user-roles): Understanding Portal user roles and permissions - [Third Party Risk Manager](https://docs.safeguard.sh/docs/tprm): Transform vendor risk from blind spot to strategic advantage - [Monitoring](https://docs.safeguard.sh/docs/tprm/monitoring): Continuous monitoring of vendor security posture - [Risk Assessment](https://docs.safeguard.sh/docs/tprm/risk-assessment): Analyze and score vendor risk based on SBOM analysis - [SBOM Requests](https://docs.safeguard.sh/docs/tprm/sbom-requests): Request and collect SBOMs from your software vendors - [Vendor Management](https://docs.safeguard.sh/docs/tprm/vendor-management): Organize and track your third-party software vendors - [Integrations](https://docs.safeguard.sh/docs/esscm/integrations): Connect your source code repositories, container registries, AI models, and more to generate SBOMs - [AD FS](https://docs.safeguard.sh/docs/sso-authentication/saml/ad-fs): Configure Active Directory Federation Services (AD FS) as a SAML 2.0 identity provider for Safeguard. - [Auth0](https://docs.safeguard.sh/docs/sso-authentication/saml/auth0): Configure Auth0 as a SAML 2.0 identity provider for Safeguard via its SAML2 Web App addon. - [Authentik](https://docs.safeguard.sh/docs/sso-authentication/saml/authentik): Configure Authentik as a SAML 2.0 identity provider for Safeguard. - [CyberArk Identity](https://docs.safeguard.sh/docs/sso-authentication/saml/cyberark): Configure CyberArk Identity as a SAML 2.0 identity provider for Safeguard. - [Duo Security](https://docs.safeguard.sh/docs/sso-authentication/saml/duo): Configure Duo Single Sign-On as a SAML 2.0 identity provider for Safeguard. - [Microsoft Entra ID](https://docs.safeguard.sh/docs/sso-authentication/saml/entra-id): Configure Microsoft Entra ID (formerly Azure AD) as a SAML 2.0 identity provider for Safeguard. - [Google Workspace](https://docs.safeguard.sh/docs/sso-authentication/saml/google-workspace): Configure Google Workspace as a SAML 2.0 identity provider for Safeguard. - [IBM Security Verify](https://docs.safeguard.sh/docs/sso-authentication/saml/ibm-security-verify): Configure IBM Security Verify as a SAML 2.0 identity provider for Safeguard. - [SAML 2.0](https://docs.safeguard.sh/docs/sso-authentication/saml): Generic SAML setup steps that apply to any IdP, plus links to fifteen provider-specific guides. - [JumpCloud](https://docs.safeguard.sh/docs/sso-authentication/saml/jumpcloud): Configure JumpCloud as a SAML 2.0 identity provider for Safeguard. - [Keycloak](https://docs.safeguard.sh/docs/sso-authentication/saml/keycloak): Connect a separately-hosted Keycloak instance as an external SAML identity provider for Safeguard. - [Okta](https://docs.safeguard.sh/docs/sso-authentication/saml/okta): Configure Okta as a SAML 2.0 identity provider for Safeguard. - [OneLogin](https://docs.safeguard.sh/docs/sso-authentication/saml/onelogin): Configure OneLogin as a SAML 2.0 identity provider for Safeguard. - [Ping Identity](https://docs.safeguard.sh/docs/sso-authentication/saml/ping-identity): Configure PingOne / Ping Identity as a SAML 2.0 identity provider for Safeguard. - [SailPoint IdentityNow](https://docs.safeguard.sh/docs/sso-authentication/saml/sailpoint): Configure SailPoint IdentityNow as a SAML 2.0 identity provider for Safeguard. - [Shibboleth](https://docs.safeguard.sh/docs/sso-authentication/saml/shibboleth): Configure a Shibboleth Identity Provider as a SAML 2.0 identity provider for Safeguard. - [GitHub](https://docs.safeguard.sh/docs/sso-authentication/social/github): Set up "Sign in with GitHub" OAuth login for your Safeguard tenant. - [Google](https://docs.safeguard.sh/docs/sso-authentication/social/google): Set up "Sign in with Google" OAuth login for your Safeguard tenant. - [Social Login](https://docs.safeguard.sh/docs/sso-authentication/social): Set up "Sign in with Google/Microsoft/GitHub" OAuth login for your Safeguard tenant. - [Microsoft](https://docs.safeguard.sh/docs/sso-authentication/social/microsoft): Set up "Sign in with Microsoft" OAuth login for your Safeguard tenant. - [Hugging Face](https://docs.safeguard.sh/docs/esscm/integrations/ai-models/hugging-face): Connect Hugging Face models to generate SBOMs - [AI Models](https://docs.safeguard.sh/docs/esscm/integrations/ai-models): Generate SBOMs from AI and machine learning models - [Binary Files](https://docs.safeguard.sh/docs/esscm/integrations/binary-files): Generate SBOMs from compiled binaries, executables, and mobile apps - [Existing SBOM](https://docs.safeguard.sh/docs/esscm/integrations/existing-sbom): Upload and analyze existing SBOMs from other tools - [Azure Repos](https://docs.safeguard.sh/docs/esscm/integrations/source-code/azure-repo): Connect Azure DevOps Repos to generate SBOMs from your source code - [Bitbucket](https://docs.safeguard.sh/docs/esscm/integrations/source-code/bitbucket): Connect Bitbucket repositories to generate SBOMs - [Frequently Asked Questions](https://docs.safeguard.sh/docs/esscm/integrations/source-code/faq): Common questions about source code integrations - [Git (Generic)](https://docs.safeguard.sh/docs/esscm/integrations/source-code/git): Connect any Git repository using a generic Git URL - [GitHub](https://docs.safeguard.sh/docs/esscm/integrations/source-code/github): Connect GitHub repositories to generate SBOMs - [GitLab](https://docs.safeguard.sh/docs/esscm/integrations/source-code/gitlab): Connect GitLab repositories to generate SBOMs - [Source Code Management (SCM)](https://docs.safeguard.sh/docs/esscm/integrations/source-code): Generate SBOMs from source code repositories - [Amazon ECR](https://docs.safeguard.sh/docs/esscm/integrations/container-images/amazon-ecr): Connect AWS Elastic Container Registry to generate SBOMs - [Azure Container Registry](https://docs.safeguard.sh/docs/esscm/integrations/container-images/azure-acr): Connect Azure Container Registry (ACR) to scan container images - [Docker Hub](https://docs.safeguard.sh/docs/esscm/integrations/container-images/docker-hub): Connect Docker Hub repositories to generate SBOMs - [Frequently Asked Questions](https://docs.safeguard.sh/docs/esscm/integrations/container-images/faq): Common questions about container image integrations - [GCP Cloud Source](https://docs.safeguard.sh/docs/esscm/integrations/container-images/gcp-cloud-source): Connect Google Cloud container sources to generate SBOMs - [Container Images](https://docs.safeguard.sh/docs/esscm/integrations/container-images): Generate SBOMs from container images and registries - [OCI Registry](https://docs.safeguard.sh/docs/esscm/integrations/container-images/oci-registry): Connect Open Container Initiative compatible registries to generate SBOMs - [APK Upload](https://docs.safeguard.sh/docs/esscm/integrations/file-uploads/apk): Upload Android APK files for scanning - [CSAF/VEX Upload](https://docs.safeguard.sh/docs/esscm/integrations/file-uploads/csaf-vex): Upload CSAF and VEX files for vulnerability analysis - [File Uploads](https://docs.safeguard.sh/docs/esscm/integrations/file-uploads): Upload files directly for SBOM generation - [Manifest File Upload](https://docs.safeguard.sh/docs/esscm/integrations/file-uploads/manifest): Upload package manifest files for SBOM generation ## Full machine-readable content - All docs in one file: https://docs.safeguard.sh/llms-full.txt ## Related - Platform: https://safeguard.sh - App: https://app.safeguard.sh - Gold (CVE & package intelligence): https://gold.safeguard.sh