What the Platform Adds
Governance Workflows
Approval flows with three enforcement modes. Advisory reports without blocking. Standard blocks on high-severity findings. Strict blocks on any finding. Acknowledged findings don't re-block.
Audit Trail
Every scan, finding, and approval anchored to a content hash. Append-only log with compliance exports (CSV, JSON) for SOC 2 and regulatory audits.
Dashboard
Finding trends and severity breakdowns across repos. Scan history, skill catalog with search and filtering, and team activity feed.
Custom Rule Builder
Create org-wide or project-specific rules in a visual UI. Rules are pushed to the CLI automatically via config pull. No YAML editing required.
GitHub App
Native check runs, branch protection, and PR comments managed by the platform. Acknowledged findings update check status automatically.
Team Management
Role-based access with seat-based licensing. Set org-wide rule policies that apply to every repo without per-project config.
How It Works
CLI Scans Locally
Run bouncerfox scan in your repo or CI pipeline. Code never leaves your machine. 35 built-in rules check for secrets, dangerous commands, supply chain risks, and misconfigurations.
Findings Upload to Platform
Rule IDs, severities, and line numbers are sent to the platform. Never file contents, code snippets, or matched secret values.
Platform Enforces Policy
The platform returns a verdict (pass, warn, fail) and manages GitHub check runs, branch protection, and approval gates for your team.
CLI vs Platform
The CLI is free and open source. The platform adds governance for teams.
| Feature | CLI (free, open source) | Platform (coming soon) |
|---|---|---|
| Detection rules | 35 built-in rules | 35 built-in + org custom rules |
| Configuration | Local .bouncerfox.yml | Org-wide policies pushed to CLI |
| Custom rules | YAML in config file | Visual rule builder UI |
| Output formats | Table, JSON, SARIF | Dashboard with trends and history |
| GitHub integration | GitHub Action + GITHUB_TOKEN | GitHub App with managed check runs |
| Enforcement | Exit code (pass/fail) | Advisory, standard, and strict modes |
| Audit | Local scan results | Append-only audit trail + compliance exports |
| Approvals | — | Acknowledge findings, unblock PRs |
| Team management | — | Roles, seats, org-wide policies |
Detection rules
Configuration
Custom rules
Output formats
GitHub integration
Enforcement
Audit
Approvals
Team management
Be the First to Know
Get notified when the BouncerFox platform launches. No spam, just the launch announcement.