Inventory the trust boundary
Inspect extension metadata, install and upgrade SQL paths, native-code indicators, and other security-relevant patterns.
Alpha · static analysis · customer-controlled
PgExtAssure gives PostgreSQL platform and product-security teams deterministic, reviewable evidence before an extension is allowlisted, built, or installed.
No private source is required for the first conversation.
Public, reproducible snapshot
Release 0.1.0-alpha.15 · ruleset 2026-07-29.6
The admission gap
PostgreSQL extension packages can combine privileged installation and upgrade SQL, control metadata, and code that runs inside the database server process. The decision to admit one is consequential—and often assembled manually.
PgExtAssure adds a repeatable static gate before that decision, so reviewers can work from pinned inputs, explicit policy, and independently verifiable artifacts.
A bounded workflow
Inspect extension metadata, install and upgrade SQL paths, native-code indicators, and other security-relevant patterns.
Apply an organization-owned policy, retain findings for review, and fail CI at the threshold your team selects.
Create evidence bundles, optional corporate-key signatures, trust-policy evaluations, and admission receipts.
Evidence you can reproduce
The default evaluation model runs in your CI, self-hosted runner, or isolated environment. PgExtAssure does not intentionally send source, findings, or telemetry to a PgExtAssure service.
Read the evidence modelClear boundaries
Current stage: PgExtAssure is alpha software. No customer adoption, security certification, compliance certification, or production-safety claim is made.
30-day technical evaluation
A bounded evaluation can cover an agreed extension set, one organization policy, one controlled integration path, verified evidence, and a closeout report with limitations and next steps.
Boris Shestakov
Independent Developer
boris@shbb.pro