New — Runtime Enforcement
Stop it before it runs —
not just after you scan it
Static scanning tells you what's risky before you install it. Runtime enforcement reuses the exact same policy verdict your CI gate already calls — enforced live, at the moment someone tries to run something.
3
runtime surfaces: hook, watch, SDK
0–100
same deterministic score, enforced live
Fail-open
never bricks a session on error
or set your org policy first