Your endpoint agent watches what runs. It does not watch a developer download a trojanised release ZIP from a repository an AI recommended forty seconds ago. RepoGates sits at that moment, in the browser, on every machine on the team.
Three to five developers, one invoice, and the same gate on every machine — coming. Today: Personal, one per developer.
When Team ships, every seat gets the trust board, the gate and the ticker with no per-person setup. Today a Team purchase covers one person, which is why it is not on sale: buy Personal for each developer instead.
Three to five seats billed together, annually or monthly. Not on sale yet: the seat model that makes one purchase cover five people is being built. Until it ships, buy Personal per developer — same protection, one card each, nothing to migrate later.
Read the files themselves — OpenGrep, Gitleaks, Trivy, ClamAV and ScanCode in an isolated sandbox — and get a report with the fix for each finding, exportable as SARIF for your CI. Bought as packs, per account today; pooling across a team arrives with the seat model. Your AI agents can spend them too — one scan per call, only with your yes to that call, five agent-started scans a day.
Said plainly here rather than discovered after you buy.
Team is one purchase, one person, until the seat model ships — there is no invite, no member list and no shared licence today, so the tier is off sale rather than sold short. Target: December. Buy Personal per developer in the meantime.
There is no Entra or Google SSO, no organisation console, no policy per organisational unit, and no central audit log. Each person signs in with their own Google or Microsoft account and holds their own settings. If you need directory-managed access and a central record, RepoGates is not that product today — and we would rather say so than sell you a roadmap. What is being built carries a date and a gate on the roadmap; what is not, the reason.
The browser sends owner/repo — never URLs, never page contents, never repository code. Deep-scan findings name a rule, a file and a line, never the matched secret and never the source line itself, and they are deleted after 90 days. Nothing here monitors productivity, browsing or individuals.
It does not stop git clone, curl, npm install, go get, or a Docker build. A browser extension cannot see other processes — that is structural, not a roadmap item, and any vendor who tells you otherwise is selling you something.
What it does cover is the delivery path that the FakeGit campaign actually used: release-asset ZIPs downloaded through the browser, roughly 14 million of them. Our coverage table shows which of the 22 checks each competing product covers, including the ones where they beat us.
Inside Claude Code there is a plugin whose hook refuses a clone or install that names a blocked repository on the command line, before it runs; it sees Bash tool calls in that one client and does not see anything else. A registry package named on that line (npm install express, pip install flask) is resolved through npm or PyPI to the source repository it declares; direct dependencies only. The same skill runs in Claude.ai and Cowork, where it asks before a clone and has no hook to refuse.
For AI agents there is an MCP server: the agent asks RepoGates before it fetches, and assert_allowed fails the step rather than returning text a model can argue with. An agent that never calls it is not stopped — we say so plainly, because you will find out anyway. See the plans →