Patches That Keep the Same Version Number
A sealed package is built from the same origin version with only the security fix backported in, preserving the public release’s API, behavior, and dependencies. No new features, no breaking changes, no migration burden — and no code changes required from developers.
A 72-Hour Remediation SLA
Seal commits to remediating critical and high-severity CVEs within 72 hours of public disclosure. Each sealed package is reviewed by Seal’s vulnerability research team and automatically tested before release, so speed does not come at the cost of validation.
Cryptographically Signed With Fix Attestation
Sealed packages ship cryptographically signed with a fix attestation and SBOM. Delivered through Artifactory and attested via JFrog AppTrust, each patch joins the same signed evidence chain as every other ecosystem partner’s fix, so auditors see one consistent trail.
A Drop-In Remediation Source Through Artifactory
Seal’s artifact server configures as an Artifactory remote repository per package type, so sealed packages reach developers through established Artifactory workflows with no change to your artifact management architecture or private registry layout.
Build-Time Only, No Source Access Required
Seal operates entirely at build time and needs no permissions to production or to source repositories. The Seal CLI can run inside a pipeline, see dependencies there, and report back — which matters where source access is restricted for privacy or compliance reasons.