Alpha · static analysis · customer-controlled

Review the extension.
Before admission.

PgExtAssure gives PostgreSQL platform and product-security teams deterministic, reviewable evidence before an extension is allowlisted, built, or installed.

No private source is required for the first conversation.

pre-admission / policy gate offline-capable
01
Inspect approved sourceMetadata · SQL paths · native-code indicators
static
02
Apply organization policyVersioned controls · deterministic outcomes
review
03
Verify evidenceSource manifest · report · limited SPDX inventory
verify
Admission authority stays with your team.

Release 0.1.0-alpha.15 · ruleset 2026-07-29.6

16 / 16pinned public projects processed
2,114files analyzed in the snapshot
Open Extension Assurance Index

An allowlist says what may be installed. It rarely preserves why.

PostgreSQL extension packages can combine privileged installation and upgrade SQL, control metadata, and code that runs inside the database server process. The decision to admit one is consequential—and often assembled manually.

PgExtAssure adds a repeatable static gate before that decision, so reviewers can work from pinned inputs, explicit policy, and independently verifiable artifacts.

From source snapshot to reviewable decision evidence.

01

Inventory the trust boundary

Inspect extension metadata, install and upgrade SQL paths, native-code indicators, and other security-relevant patterns.

02

Enforce your policy

Apply an organization-owned policy, retain findings for review, and fail CI at the threshold your team selects.

03

Carry evidence forward

Create evidence bundles, optional corporate-key signatures, trust-policy evaluations, and admission receipts.

Designed for customer-controlled infrastructure.

The default evaluation model runs in your CI, self-hosted runner, or isolated environment. PgExtAssure does not intentionally send source, findings, or telemetry to a PgExtAssure service.

Read the evidence model

Review evidence, not a safety certificate.

PgExtAssure does

  • Statically inspect approved extension source trees
  • Produce deterministic, machine-readable review artifacts
  • Support CI gates and customer-owned policy
  • Make limitations and skipped coverage visible

PgExtAssure does not

  • Build, load, install, or execute the scanned extension
  • Prove an extension is safe or free of vulnerabilities
  • Replace expert review, runtime testing, or provenance checks
  • Make the final admission decision for your organization

Current stage: PgExtAssure is alpha software. No customer adoption, security certification, compliance certification, or production-safety claim is made.

Test one real admission workflow—inside your boundary.

A bounded evaluation can cover an agreed extension set, one organization policy, one controlled integration path, verified evidence, and a closeout report with limitations and next steps.

Request a 20-minute fit review

Boris Shestakov
Independent Developer
boris@shbb.pro