# Crash Override > Crash Override is Software Observability for the AI era — the data plane for software. We observe human and AI-agent activity on the developer's machine via Crash Override Endpoint, perform deep build inspection on every artifact, tag everything with cryptographic provenance, and track it as it beacons back from production. Prompt to production. ## Company Overview Nobody knows what code AI agents are writing on developers' desktops right now. It flows unchecked into builds, ships to production, and becomes everyone's problem. And even when humans write the code, the build system is a black box — what happens in the build, stays in the build. Vegas rules. Crash Override solves this. We give engineering teams end-to-end visibility from the developer's desktop through the build to every running container in production. Deterministic. Cryptographic. Irrefutable. No false positives. Build systems don't hallucinate. **Business model**: Enterprise platform; contact for demos. Chalk and Ocular are free and open source (GPL). **Target audience**: IC developers and IC security engineers adopt the tools. Engineering leaders and CISOs purchase the enterprise platform. **Founded by**: Mark Curphey (OWASP founder, SourceClear/Veracode, Microsoft) and John Viega (AES-GCM inventor, Capsule8/Sophos). **Funded by**: Syn Ventures, Google Ventures. ## Four Capabilities — Understand. Inspect. Tag. Track. ### Understand We observe human and agent activity on the developer's machine — before code even hits the build. Crash Override Endpoint, deployed zero-touch via your existing MDM, observes what developers and AI coding agents write in real time. Before anything enters the build pipeline, you already know what's coming. GA on macOS and Windows; Linux coming soon. ### Inspect Deep build inspection. We run inside the build system — the black box — inspecting every layer of every artifact. We know exactly what's in the build, who put it there, and how it got assembled. Deterministic. No inference. No hallucination. ### Tag Cryptographic tagging of every artifact. A deterministic flight record — a complete, tamper-proof record of everything that happened in the build — embedded into every artifact that ships. ### Track AirTag provenance. Artifacts beacon back from production, reporting where they are, what's in them, and what changed since they shipped. Continuous visibility, forever. ## Products ### Chalk (Open Source — GPL Licensed) Chalk is the open-source code provenance and tagging engine — the foundation the Crash Override platform builds on. The platform adds deep build inspection on top. **Key capabilities**: - Generates SBOMs from source code, build artifacts, and container images - Embeds provenance metadata (chalk marks) into build outputs - Tracks artifact lineage from source commit through production deployment - Integrates with GitHub Actions, GitLab CI, Jenkins, and other CI/CD systems - Supports Docker, OCI containers, and native binaries ### Ocular (Open Source — GPL Licensed) [ocularproject.io](https://ocularproject.io) — Open-source policy DSL and runtime scanner for evaluating security policies across infrastructure. **Key capabilities**: - Define security policies as code using a purpose-built DSL - Scan Kubernetes clusters for policy violations - Evaluate container images against organisational standards - Integrate with scanners like Semgrep, Trivy, and GitHub Advanced Security - CRD-based configuration for Kubernetes-native deployment ### Innovation Lab Where we experiment with the future of software visibility. Agent governance, advanced provenance, and build intelligence. ## Use Cases ### AI Code Traceability Know exactly what an agent wrote, when, and where it's running now. AI agents are writing code on developers' desktops — Crash Override monitors that activity and tracks the code all the way to production. ### Software Compliance True SBOM generation, full SLSA provenance, internal development standards. Compliance evidence is generated at build time, not reconstructed weeks later. Audit-ready on demand. ### Incident Response End-to-end provenance, change ledger, production replication, code ownership and attribution. When something breaks in production, you already have the answer — no more 2am archaeology. ## Deployment Zero friction. Instant results. - **Crash Override Endpoint**: Rolls out zero-touch to all developers via your existing MDM. No developer opt-in, no workflow change. - **Build inspection**: Five lines of YAML for CI. One build server covers the whole team. - **Time to value**: Five lines of YAML for CI, zero-touch coverage on developer machines, no platform migration. Tens of thousands of builds tracked within hours. ## Integrations - **Source control**: GitHub, GitLab, Bitbucket - **CI/CD**: GitHub Actions, GitLab CI, Jenkins, CircleCI - **Containers**: Docker, Kubernetes, OCI registries - **Cloud**: AWS, Azure, GCP - **Security scanners**: Semgrep, Trivy, GitHub Advanced Security ## Enterprise Features - Single Sign-On (SAML, OIDC) - Role-Based Access Control - Audit logging - Dedicated support and SLA ## Leadership - **John Viega** — Co-founder & CEO. Invented AES-GCM (the encryption your browser uses). Built Capsule8 (acquired by Sophos). - **Mark Curphey** — Co-founder, Innovation. Founded OWASP in 2002. Led engineering at Microsoft. Founded SourceClear (acquired by Veracode). - **Brandon Edwards** — CTO - **David Coffey** — Chief Product Officer - **Mike Flouton** — CMO **Board**: Erik Nordlander (Google Ventures), Jay Leek (Syn Ventures), Gerhard Eschelbeck (first CSO at Google). ## Links - [Homepage](https://crashoverride.com/) - [Product Overview](https://crashoverride.com/product) - [About](https://crashoverride.com/about) - [Use Cases](https://crashoverride.com/use-cases) - [Blog](https://crashoverride.com/blog) - [Documentation](https://crashoverride.com/docs) - [Open Source Hub](https://crashoverride.com/open-source) - [Chalk Project](https://crashoverride.com/docs/chalk) - [Ocular Project](https://crashoverride.com/docs/ocular/overview) - [Innovation Lab](https://crashoverride.com/innovation-lab) - [Knowledge Base](https://crashoverride.com/resources/knowledge-base) - [Contact](https://crashoverride.com/contact) - [Careers](https://crashoverride.com/careers) - [Events](https://crashoverride.com/events) ## Optional - [AI Code Traceability](https://crashoverride.com/use-cases/ai-code-traceability) - [Software Compliance](https://crashoverride.com/use-cases/software-compliance) - [Incident Response](https://crashoverride.com/use-cases/incident-response) - [Privacy Policy](https://crashoverride.com/privacy) - [Terms of Service](https://crashoverride.com/terms) - [Sitemap](https://crashoverride.com/sitemap-html)