Inventory the trust boundary
Inspect extension metadata, install and upgrade SQL paths, native-code indicators, and other security-relevant patterns.
Alpha.16 · open source · customer-controlled
PgExtAssure turns an exact PostgreSQL extension source snapshot into portable, independently verifiable evidence before the extension is allowlisted, built, or installed.
No account, hosted service, telemetry, or introductory meeting required.
Public validation snapshot
Release 0.1.0-alpha.16 · Apache-2.0
Independently reproduced
Three external engineers ran the same unmodified, digest-bound alpha.16 protocol in forks they controlled. The records demonstrate bounded reproducibility—not certification, customer adoption, or employer endorsement.
The admission gap
PostgreSQL extension packages can combine privileged installation and upgrade SQL, control metadata, and code that runs inside the database server process. The decision to admit one is consequential—and often assembled manually.
PgExtAssure adds a repeatable static gate before that decision, so reviewers can work from pinned inputs, explicit policy, and independently verifiable artifacts.
A bounded workflow
Inspect extension metadata, install and upgrade SQL paths, native-code indicators, and other security-relevant patterns.
Apply an organization-owned policy, retain findings for review, and fail CI at the threshold your team selects.
Create evidence bundles, optional corporate-key signatures, trust-policy evaluations, and admission receipts.
Evidence you can reproduce
The default evaluation model runs in your CI, self-hosted runner, or isolated environment. PgExtAssure does not intentionally send source, findings, or telemetry to a PgExtAssure service.
Read the evidence modelClear boundaries
Current stage: PgExtAssure is alpha software with multiple independent external reproductions. No customer adoption, security certification, compliance certification, or production-safety claim is made.
Founding Partner Evaluation
A fixed ten-business-day evaluation covers one bounded extension scope, one organization policy, one customer-controlled integration path, verified evidence, an independent rerun, and a written limitations report.
Boris Shestakov
Independent Developer
boris@shbb.pro