Twelve client repos, one dependency policy.

You ship into codebases you do not own, on deadlines you did not set, with juniors and contractors rotating between projects. A dependency you install today is a client’s problem for years, and it will have your name on it.

$ npm config set registry https://r.installsafe.io

Plain-text version for scripts and agents.

The liability outlives the engagement

A compromised package that reaches a client through work you delivered is a conversation nobody wants to have — and one where being technically not at fault helps less than it should. The engagement ended months ago; the dependency is still in their lockfile.

Per-project discipline does not survive contact with six projects. Whatever a scanner reports on your own repos, the work happening this week in a client repo with a fresh clone and a tight deadline is where the risk actually lives.

How it works across projects

  1. 01

    One policy, set once

    Severity threshold and a minimum package age, defined for the team rather than per repo. A new client project inherits it the moment someone installs through the proxy.

  2. 02

    A token per developer

    Seats rather than a shared login, so the install record shows who installed what. When a contractor rolls off, revoking their token takes effect within a minute.

  3. 03

    Something to show the client

    The activity log lists what was blocked and why. It is the evidence for a security questionnaire, and it is considerably more convincing than saying you use a scanner.

Our clients have their own security tooling

Most of it runs after the fact — a scanner on their CI, a dashboard someone reads on Mondays. That catches what you already installed, on their side of the fence, with your name on the commit.

This sits at your install step instead, which is the only point where the package can still be refused rather than reported. The two do not conflict; their scanner will simply have less to find.

What it costs

Free

Everything you need to stop installing known-bad versions.

$0

free forever · no card required

  • Secure installs through the proxy
  • Live vulnerability & malware filtering
  • Blocks Critical and High severity
  • Activity dashboard, 7-day log
  • One registry token

Pro

most popular

For working engineers who want the policy under their own control.

$19per month

7-day free trial · cancel anytime

  • Everything in Free
  • Configurable severity policy
  • Release quarantine & package-age rules
  • Package allow / block rules
  • Activity dashboard & 90-day audit log
  • Unlimited registry tokens

Team

One policy every engineer inherits, with no per-developer drift.

$25per seat / month

starts at 2 seats · add more any time

  • Everything in Pro
  • Org-wide policy: severity, quarantine, allow/block rules
  • Slack alerts whenever a version is kept out
  • Centralized member & token management
  • Team-wide audit log

Questions, answered.

Something else? support@installsafe.io

01Do our clients need accounts?

No. The proxy sits in front of your team’s installs. What the client gets is a codebase with fewer known-bad versions in it, and a log you can hand over if they ask.

02What if a client requires a specific package we block?

Allow rules are per account, so you can permit a specific package or version deliberately. That decision is recorded, which is better than it living in one developer’s memory.

03How does this work for contractors who come and go?

Each person gets their own token under your team. Add a seat when they start at $25 a month, revoke the token when they leave, and the audit trail keeps showing who installed what while they were here.

04Can we start small?

Yes — the free plan gives one developer 1 token and blocks Critical and High. Run one project through it before committing anyone else.

One policy. Every client project.

Start free on one project. Team seats are $25 each per month, from 2.