IP Protection
Software supply chain security helps us patch known vulnerabilities, but patches can be delayed or vulnerabilities can be missed. That leaves room for data exfiltration.
Bomfather already protects against ransomware style encryption and malicious script injection. Now we also protect against secret theft with IP Protection.
IP Protection enforces network access at the executable level:
- Limit which IPs/DNS names an executable can connect to
- Limit which executables can connect to a specific IP/DNS destination
Unlike a traditional firewall that applies host-level policy, this applies per executable.