Listing Thumbnail

    Depi

     Info
    Sold by: Depi 
    Depi is an Upstream Security platform that continuously maps the exploitable paths through your upstream attack surface (dependencies, maintainers, registries, and CI pipelines) so you see the attack weeks before it becomes an incident.

    Overview

    Play video

    Most teams find out about an upstream attack when it is already running inside their build. Depi moves you to the other side of that timeline: knowing which paths an attacker could exploit, weeks before they become incidents.

    Traditional SBOM and SCA tools list what you depend on, after the fact. Depi maps the entire chain that produced it: every manifest, package, transitive dependency, maintainer account, registry, email domain, and CI pipeline. The result is a living graph of every trust relationship upstream of your code, continuously re-evaluated as the upstream changes. Against that graph, Depi detects 30+ exploit classes attackers actually use: dependency confusion, maintainer account takeover, GitHub Actions exploitation, and more.

    Because every analysis runs from your specific dependency graph, the answers are yours, not the ecosystem's. When an incident hits, the Incident Module answers the only question that matters: "which of my projects are affected, and how deep does it go?" You get a client-specific blast-radius map instead of a generic advisory. Each finding ships with a remediation strategy and an auto-generated GitHub/GitLab pull request, not just a report.

    The detection engine is built on the team's published research: the npm cache-poisoning vulnerability affecting 2.1M packages, the expired-email-domain takeover technique covering maintainers with 54.8M monthly downloads, and dependency-confusion RCEs reported at Netflix and a Fortune 500 company. That research is why Ledger Donjon caught the Rollup backdoor with Depi 7 days before the maintainer shipped a patch, and pinned it out of their build before public disclosure.

    Connect GitHub or GitLab and get your first exploit paths in minutes. Supports npm, PyPI, Bundler, Cargo, and GitHub Actions.

    Highlights

    • Depi maps the exploitable paths through your upstream attack surface before an attacker can. The first tool to flag anomalies before the community finds them, not after.
    • A living graph of every upstream trust relationship: packages, maintainers, registries, and CI pipelines. 35+ exploit classes detected, not a static SBOM list.
    • Client-specific blast radius on any incident, plus auto-generated fix PRs straight into GitHub or GitLab.

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (3)

     Info
    Dimension
    Description
    Cost/12 months
    Droplet
    Includes Access to Proactive Research, Full Dependency Tree Scanning and Upstream Maintainer Security. Covers up to 100 repositories with a weekly scan cadence.
    $42,000.00
    Bucket
    Everything in Droplet Pack, sized for growing teams: 250 repositories and an accelerated 72-hour scan cadence.
    $72,000.00
    Flood
    All capabilities with custom repository limits and custom scan frequency. Bespoke onboarding, SLAs and reporting. Contact contact@landh.tech for a tailored quote.
    $130,000.00

    AI Insights

     Info

    Dimensions summary

    Depi sells three contract packs sized by repository count and scan frequency. The Droplet pack covers up to 100 repositories with weekly scans. The Bucket pack fits growing teams, covering 250 repositories with a 72-hour scan cadence. All three packs include proactive research, full dependency tree scanning, and upstream maintainer security. The Flood pack keeps these capabilities but sets custom repository limits and custom scan frequency, adding bespoke onboarding, SLAs, and reporting through a tailored quote. You scale up by moving from set repository counts to a custom arrangement based on your needs.

    Top-of-mind questions for buyers

    Each package repository you connect to Depi counts toward your pack limit. The Droplet pack covers up to 100 repositories. The Bucket pack covers 250 repositories. Depi scans each connected repository, including its full dependency tree from direct dependencies to deep transitive layers.
    The Droplet pack scans your repositories once per week. The Bucket pack runs scans every 72 hours, checking for threats more often. The Flood pack sets scan frequency to whatever schedule you arrange, defined during onboarding through a tailored quote.
    Each pack has a fixed repository ceiling: Droplet up to 100, Bucket up to 250. To cover more, you move to the Flood pack, which sets custom repository limits and scan frequency. Flood is arranged through a tailored quote at contact@landh.tech.
    www.landh.tech
    Helpful?

    Vendor refund policy

    Refunds and credits are handled on a casebycase basis according to the terms negotiated in your contract. For refund or billing enquiries, please write to contact@landh.tech 

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Vendor resources

    Support

    Vendor support

    Support levels, response times and SLAs are defined individually in each customer contract. For any questions, or to obtain your specific support terms, email contact@landh.tech 

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 reviews
    No customer reviews yet
    Be the first to review this product . We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.