# Crash Override

**Canonical:** https://apis.io/providers/crash-override/  
**Website:** https://crashoverride.com/  
**APIs profiled:** 0

Crash Override is a software supply chain security company building a control plane for software development in the agentic era. It monitors code from developers and AI coding agents, inspects builds across CI/CD systems (GitHub Actions, GitLab CI, CircleCI, Jenkins), cryptographically tags software artifacts, and tracks them from development through production. The company delivers its capabilities primarily through open-source tools — Chalk (code provenance tagging) and Ocular (Kubernetes-native software asset scanning orchestration) — plus a hosted control plane with enterprise SAML 2.0, OIDC, and SCIM support. Founded by Mark Curphey (founder of OWASP) and John Viega, and backed by GV, Syn Ventures, Bessemer Venture Partners, and Blackstone. Philosophy: "Tag. Track. Trust." No public REST API or OpenAPI specification is published at this time; this profile was enriched from the company's public web, GitHub org, and security surface.

## Kin Score — 16.8 / 100 (emerging)

Scored 2026-08-17 under rubric 0.11.0. Trend: flat (+0.0 from 16.8).

| Facet | Score |
|---|---|
| Discoverability | 57.4 |
| Contract Quality | 0.0 |
| Governance | 0.0 |
| Operational Transparency | 15.8 |
| Developer Ergonomics | 23.9 |
| Commercial Clarity | 21.1 |

## Agent readiness — 2.7 (human-only)

| Dimension | Value |
|---|---|
| Spec Presence | no |
| Agentic Access | no |
| MCP Server | no |
| Auth Clarity | no |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | yes |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Unknown — onboarding: unknown, pricing: unknown, trial: no (confidence: low).

## Security (2)

- **Crash Override Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC
- **Crash Override Vulnerability Disclosure** — security.txt · contact published

## Tags

Company, Cybersecurity, Software Supply Chain, Application Security, Provenance, DevSecOps, Open Source, Artifact Tracking

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/crash-override/). Scores are computed from the provider's own public artifacts under a published rubric.
