Skip to content
Watchdog
Sign inSurvey a repo — free

Works with

They see what ran. We see what is there.

Azul Intelligence Cloud, Contrast, Datadog, Dynatrace, Snyk's runtime sensor and the eBPF generation all read the same thing: the running system. Watchdog reads the commit. Neither substitutes for the other, and a team that runs both can act on a sentence neither tool can write alone.

A different evidence source · not a lower altitude.

The right-hand column is this page. Same altitudes as everything else — and an empty top row.

What the pair gives you

Fix the weak thing that is live.

They tell you which of your code production actually touched. We tell you which of it is unsound. Touched and sound needs nothing from anybody. Untouched and unsound can wait. The overlap is the work — and it is the only instruction either of us really wants your team to act on.

What they contribute

Which libraries, classes and methods actually ran in production — evidence no source reading can manufacture. Its sharpest use is dropping a CVE whose vulnerable code never executed, and on a large Java estate that is a real reduction in work.

What we contribute

One reproducible Codebase Assurance Index over the whole product, with architecture, testing, security posture, change safety and knowledge risk on the record — and a worst-first list ranked by impact ÷ effort, whether or not production has touched the code yet.

Both, pointed at your AI

You will hear a similar promise from both of us at the moment, because both are pointing your coding agent at a smaller target. We narrow differently, and the two compose: they scope by what production touched, we rank by what is worth fixing. Narrowing and ranking do not compete.

Where the line falls

Three things a runtime tool cannot reach — and every team running one has all three.

Out of its reach

  • Code that is not deployed yet
    The branch, the service still in build, the module written this sprint.
  • Code you do not operate
    A supplier's delivery, an inherited estate, anything running on someone else's hardware.
  • A repository someone is asking you to buy
    You cannot instrument a codebase you do not own yet.

Two more, worth saying plainly

  • Unexercised is not unreachable
    A quiet quarter is traffic, not proof. Code nothing called in June is still code that can be called in July.
  • A JVM tool sees the JVM
    Azul Intelligence Cloud is JVM-exclusive by design. The product around it is also TypeScript, Go and C# — and we model seventeen languages, each with its coverage on the record.

Point them at production. Point us at the commit.

The traffic is one-way, on purpose

Nothing of theirs enters the CAI — that is what keeps the number reproducible. Ours goes the other way freely: every finding is served read-only over MCP, so whatever you triage in can consume it.

Who reads what

Point each one at the thing it can actually see.

  • If you need…
  • Reach for…
  • Watchdog's role
  • To know whether a vulnerable class ever executed
  • Azul Intelligence Cloud · Contrast
  • None — point them at production; a CVE whose code never ran is theirs to close
  • Service topology and live traces
  • Datadog · Dynatrace · eBPF sensors
  • None — that is operations, and we do not instrument anything
  • Reachability without instrumenting production
  • Endor Labs · Backslash
  • Our side of the divider: computed from source, like every lens we run
  • To judge code not deployed, not operated, or being bought
  • Watchdog
  • That is the job — and no runtime tool reaches it

Four rows, one line each: none of them is a competitor.

Runtimes and app servers are not ours at all

Azul Core and Prime, Oracle Java SE, Corretto, Temurin, Red Hat, IBM Semeru — and Azul Payara or a WebLogic migration. If your question is a licence bill or JVM throughput, we have nothing to sell you.

Keep watching production. Measure the commit too.