Tooltrust
A managed extension mirror and trust registry that preserves upstream artifacts, verifies signatures and software bills of materials, records review evidence, enforces team install policy, and observes declared external-service behavior without promising that a vetted extension is safe.
The supplied research confirms a machine-scale open extension registry, a new managed registry service, active security work, free signing and software-bill-of-materials standards, and no identified enterprise product focused on extension governance. It does not verify the two proposed APIs or prove that the registry operator has committed never to build governance. Tooltrust's opportunity is a customer-controlled mirror, evidence history and enforceable install policy. Signature, scan and review results must remain bounded evidence rather than a safety certification.
The developer platform, application security, endpoint engineering, compliance, or software-supply-chain team governing extensions across a large organization.
Mirroring, evidence, policy and fleet inventory scale through software after difficult integrations.
Central control must reduce extension risk without freezing developer workflows or creating false trust.
New registry infrastructure helps but does not prove the barrier that prevented governance.
The registry scale, security primitives, enterprise buyer and extension-specific governance gap create a concrete product surface.
No connected-idea convergence exists, proposed APIs are unverified, the incumbent blind spot is asserted rather than proven, and deep endpoint integration is required.
Discussion
No comments yet — be the first to weigh in.
