# Why SafePack exists.

Most of the code a company ships is open source it didn’t write. Every package pulled from npm, PyPI, Maven or Go can bring in a known vulnerability, a malicious release or a license the business can’t accept.

## What it does

SafePack lists every open-source package across your GitHub repositories, ranks vulnerabilities by real exploit risk using FIRST EPSS and CISA KEV, and flags malware and license violations, so teams fix what matters first.

## How it’s built

SafePack runs on-prem, inside your own infrastructure. Your source code is never copied, and findings stay in your own database. Supply Chain Firewall and PR Review are coming next.

## Where we are

SafePack is built in Bengaluru, India. To try it, email hello@safepack.dev.
