Marcello Delcaro
I have worked in software supply chain security since 2020. Vigilance is the tool I wanted the whole time.
Boots on the ground
I started at aDolus Technologies in 2020, right as SolarWinds broke. I was boots on the ground for it. Then 3CX. Then Log4j.
I built binary analysis there, on an engine called FACT that takes a program apart and lists every piece inside it. Exiger acquired the company in 2024. Today I am co-founder and CTO of Cabreza.
Everyone guards one slice
Every company in this space watches one part of the supply chain. They wrap the finding in a CVE number or a CWE class and call the job done. It never was.
SBOMs became a paperweight
The industry's answer was the SBOM, a parts list for software. It got over-engineered, and it mostly sits there as a paperweight. Nobody wanted to do the real work it takes to secure the supply chain.
Code quality is not a backdoor
A clean, well-written codebase can still ship a backdoor. Those are two different problems, and most tools only look at the first one. A planted file does not care how tidy the code around it is.
So I built this
I built Vigilance for the whole chain. For the vendor who ships, the person who installs, and everyone in between. One file, no network. It names the one thing that changed, and nothing else.
See it for yourself.
One line and you are watching.