Offensive & defensive security
Security work, reported so your engineers can act.
BeeraSafe runs penetration tests and security engagements, and builds the two products that run them. Findings arrive as evidence and diffs, not as a score in a dashboard.
5
Finding categories scanned
2
Products, one login
0
Black-boxed verdicts
Our services
Security services for you
One platform for engagements and the engines that run them. Everything you can name below is running software, not a roadmap.
What runs
Five engines, and how a finding makes it to your repo
Rampart does not summarize a model's opinion about your repository. It runs five deterministic checks and records what each one read.
- Detect
Dependency, code, secret, IaC, and container engines report what they actually found.
- Understand
Each finding is graded for reachability and impact, with evidence a reviewer can check line by line.
- Respond
Remediation lands as a pull request, retests confirm it, and the evidence stays with you.
The unit of work
Every finding cites the record that produced it
Nothing is reported that cannot be reproduced from the artifact it cites. This is a finding, opened at evidence and remediation.
Engagement runbook
- 01Verify and authorize
Operator identity checked, scope and liability signed in writing.
- 02Scope the work
Targets, boundaries, and authorization agreed before any access.
- 03Run in isolation
Engagements execute in isolated workspaces, torn down afterward.
- 04Deliver evidence
Reproducible findings with a traceable trail. Nothing black-boxed.
- Authorized
- Testing runs under a signed scope, inside Uganda's Computer Misuse Act (2011) discipline.
- Recorded
- Every finding ties back to an artifact recorded during the engagement.
- Retestable
- The criteria to close a finding are named with the finding, not after.
- Yours
- Engagement files (findings, evidence references, timestamps) are yours to keep.
Two products
Bolt and Rampart on one account
Both sit on a single balance.
Bolt
Bring the case and the evidence. The engines run, the finding is graded, and the reasoning stays attached to it — in the workspace or your terminal.
- A scoped verdict with the evidence attached
- Reasoning your own reviewers can check
- Terminal CLI (npm i -g bolt-sec) on the same token balance
Rampart
Connect GitHub repositories, scan on every push and pull request, and ship fixes as pull requests.
- Fix pull requests you can review before merge
- Policies that gate risky merges
- Findings grouped by repository, not by scanner
How it works
Get your repositories gated in three steps
Connect the repository, let the engines run on every push, and review the fix before it merges.
- 01
Connect a repository
Authorise the org, pick repositories, and choose the branches worth protecting.
- 02
Scan on every push and PR
Dependencies, code, secrets, IaC, and containers run deterministically. Nothing is simulated.
- 03
Ship the fix
A finding becomes a pull request. Retests confirm it, and the evidence stays with you.
Why BeeraSafe
What you can hold us to.
Evidence stays with you
Findings ship with the trail that produced them, and it is yours to keep.
Scoped in writing
Targets, boundaries, and exclusions are signed before any access.
A human answers
You get a named reviewer, not a ticket queue. Ask how something was graded and you get the reasoning.
Security work you can verify, then act on.
No fabricated customers, no invented benchmarks. If we run it, it is real and it is inspectable. Backed by the BeeraSafe team in Kampala.

