Adams Nel
Private preview

Dendra

Dependency risk, rated

Modern software uses a lot of third-party code. Dendra tells you how far each package can be trusted — dependency by dependency all the way down the stack, graded like a credit rating, with evidence supporting every grade.

Contact us to request accessDendra is currently in private preview.

In short

Dendra is a trust-rating service for the third-party packages your software depends on. Point it at a dependency and it returns a plain letter grade and a breakdown of why — built from public, observable evidence: security advisories and their severity, how quickly maintainers remediate, maintenance health, supply-chain integrity, and the state of the dependency tree underneath.

It doesn’t stop at the packages you chose. Dendra follows each dependency to its own dependencies, and theirs, all the way down — scoring every package in the tree, because that’s the code you’re actually running.

It’s the third-party-risk-rating model — continuous, non-invasive, evidence-weighted — pointed at the software supply chain instead of corporate infrastructure.

How it works

A grade, and the reasons for it

Every package gets a composite letter grade and a per-domain view beneath it, so a verdict is always one click from the facts that produced it — the advisory, the timestamp, the registry signal.

The whole tree, not just the top

Your direct dependencies are the small part. Dendra maps the transitive tree and shows where risk actually concentrates — which deep, quiet package a large part of your build inherits from.

What to fix first

Findings are ranked by how much grade they'd recover, weighted by how far the risk reaches — so you spend effort where it moves the needle, with safer, functionally-comparable alternatives suggested where they exist.

Unknown is not safe

A dependency Dendra can't verify is carried as unverified risk, never quietly assumed clean. The gaps are part of the picture.

Evidence you can hand to an auditor

Dendra speaks the supply-chain compliance languages: bring a CycloneDX or SPDX SBOM (or just a package.json) and get it back graded, with an OpenVEX record of what’s been assessed and dismissed. Grade thresholds can be expressed as policy, annotated against frameworks like S2C2F, NIST SSDF, and the EU CRA, and exported as an audit pack.

SBOMVEXS2C2FSSDFEU-CRA

What it covers

Packages across nine ecosystems — spanning TypeScript, JavaScript, Python, Java, Kotlin, Go, Swift, C#, C, and C++.

npmPyPIMaven / GradleGo modulesNuGetSwiftPMCocoaPodsCargoC/C++ (vcpkg / Conan)

Who it’s for

Engineering and security leads who need to answer “what are we built on, and what should we do about it?” — with evidence, not vibes.

Dendra is currently in private preview.