Product design for open-source supply-chain security, from command-line tools to a product

Product design, user research, information architecture, and a design system that turned two command-line tools into a usable security product. 2025.

Product direction and design · supply-chain security · 2025

Two command-line tools for dependency and origin risk, turned into a product a security engineer can open, run and understand without the person who built them.

Open-source supply-chain security · software security · 2025

The team had two command-line tools for dependency and origin risk. Using them, or demonstrating them to a new user, still required the engineer who built them.

The blast-radius flow · which packages a compromised dependency reaches, rebuilt as a working prototype for this page
Decision

I redesigned the tools as a navigable product rather than placing a thin interface over the existing command line.

The design system carried into the team’s later products. The company’s numbers: a $3M pre-seed in March 2025 and a $1.79M AFWERX SBIR.

What I did
User research with security engineers, CISOs, UX design, information architecture, design system, and prototyping.
Role
I ran working sessions and prototype reviews with security engineers, then designed the information architecture, blast-radius workflow, interaction prototypes, and design system.
Password

Full write-up

Wedge definition, risk model, and enterprise trust work: password protected.