Federation
Gastropod instances are nodes that can talk to each other over an open protocol. Each one broadcasts what you host and, privately and by your choice, shares the findings that matter — without surrendering your data, your identity, or your tenancy to anyone's hub.
Three ways to federate
Options range from wide-open broadcast to a closed, credentialed network. You set the blast radius per org and per finding.
Public actor
Each org gets its own ActivityPub actor: @{slug}@your-host. When you turn
federation on, Gastropod announces its public package sightings to
followers across the open fediverse. Mastodon, GoToSocial, and any ActivityPub peer
can follow.
The @registry firehose & conversation
One feed lists everything public that your instance has indexed. Researchers can reply from their own fediverse account, and their comments thread into your community view with their avatar. You can reply, edit, and retract, each action signed by your instance.
Sectors
A closed, credentialed network of instances that share findings, including private and embargoed ones. Sharing is a deliberate choice the org owner confirms, with each organization getting credit for the advisories they share.
Speaks the open standards
No proprietary protocol. Federation uses ActivityPub, so any fediverse server can follow, comment, and interoperate.
ActivityPub
the open protocol Gastropod uses
Mastodon
follow & reply from any account
How it works
One toggle per org. After that, federation uses the same artifact identity the rest of Gastropod is built on.
Enable
An org owner enables federation. The org receives a keypair and an actor document; nothing federates until that deliberate action.
Announce
Gastropod pushes new public versions the org hosts to its followers and the
@registryfirehose automatically, each announcement signed and carrying no bulk history.Discuss
A peer comments on a sighting from their fediverse account. The comment threads into your community view. You can reply, edit, or remove it, and every instance that saw the original receives the update.
Share
An owner can share a finding, including an embargoed one, into a sector with a vetted network. The finding arrives attributed to your org, with tenancy preserved on the receiving instance.
Scan once, share the signal
Sharing findings stops every org from re-scanning the same packages. Vet an artifact once, or let a trusted peer vet it; Gastropod applies that intelligence everywhere the artifact appears.
Don't re-scan the world
A finding attaches to an exact artifact. Wherever that package is present, across your org or a trusted sector, Gastropod already has the answer, which reduces duplicated scanning, delivers intelligence faster, and eliminates rework.
Bring your own scanner (BYOS)
The ingest pipeline consumes findings in whatever format your tools produce: Trivy, Grype, Snyk, Anchore, CycloneDX, OpenVEX, native JSON. Each finding attaches to the artifact and propagates through the same federation as everything else. Gastropod integrates with your existing scanners and distributes their results.
MCP artifact orchestration
A built-in MCP server orchestrates findings and artifacts directly, so scanners and AI assistants submit findings and query the catalog with vetted, scoped access. Your tooling, and the agents you trust, connect to the same intelligence layer.
Built to be trusted
Sharing intelligence between orgs involves real risk, so the security model assumes the worst case: one instance can never forge, leak, or revoke another's findings, and nothing private leaves by accident.
Your data stays yours
Findings are stored on your instance and stay attributed to your org wherever they propagate. Run the node yourself or let Gastropod host it; either way, the protocol is open, so you own your findings, choose your peers, and keep your exit: you can stop sharing or leave at any time.
Verified identity, no spoofed origins
Each member instance has a keypair; gastropod.io verifies its identity before the instance can join a sector, and every finding it sends carries that signature. An instance can only act on behalf of the orgs it actually hosts. Nobody can forge a finding in your name, quietly revoke one you published, or federate anonymously.
Nothing leaves by accident
Sharing a private or embargoed finding requires a deliberate, explicit confirmation: this action discloses the finding to every member of the sector and cannot be reversed. Gastropod never discloses a private finding without explicit authorization.
You govern what you share
Each org decides exactly which findings go into which sectors. Sharing is opt-in, per finding, controlled by the org that owns it, never a single, all-or-nothing setting.
Sectors vs. Athena: one coalition, or your own?
Athena is one coalition, and membership is by invitation. Sectors let you run your own. In June 2026, Chainguard launched Athena, an industry coalition (BNY, Cisco, Cloudflare, JPMorganChase, and around two dozen others) that finds open-source vulnerabilities, many with AI assistance, fixes them before public disclosure, and delivers hardened rebuilds to members. Athena operates at large scale. Sectors take the opposite structure: instead of petitioning to join a single central club, you convene your own private sharing networks with exactly the partners you trust (your supply chain, your customers, an ISAC, your industry peers), on infrastructure you run or Gastropod hosts for you.
| Dimension | Gastropod sectors | Chainguard Athena |
|---|---|---|
| Shape | Decentralized: you create your own sectors | Centralized: one coalition Chainguard operates |
| Who's in the network | You set the roster: suppliers, customers, an ISAC, peers | Chainguard admits vetted members |
| Joining | Form or join a sector when you want; no waiting to be let in | Vetted enterprise membership, by invitation |
| What's shared | Findings you choose, including private and embargoed, with attribution | AI-found OSS vulns, coordinated pre-disclosure |
| Where your data lives | Your instance (self-hosted or we host it); it stays yours | Contributed into the coalition; fixes delivered as hardened forks |
| Run it yourself | Yes | No; Chainguard-operated |
| Trust & control | gastropod.io verifies identities; you own the roster and the exit | Chainguard is the trust & distribution hub |
| Pre-disclosure patching at scale | Not our intention; sectors share intel and you remediate | Batch hardening and rebuilt forks |
| AI-based vulnerability scanning | Enables more effective use of your AI-based vulnerability scanning | Members find vulnerabilities with AI (Glasswing / Daybreak) |
| Cuts redundant scanning | Shared findings propagate with the artifact: vet once, reuse everywhere | Yes: consume pre-hardened, rebuilt packages |
| Plugs into your scanners & agents | BYOS ingest in any format, plus MCP artifact orchestration | Members' AI programs feed the coalition |
Sectors and Athena are not direct substitutes, and they are not mutually
exclusive: you can run your own sectors and still pull hardened images from any
provider. Athena is one central coalition that hardens upstream open source at scale. Sectors
are the sovereign alternative for sharing your intelligence with exactly the partners
you choose, keeping your data, identity, and roster under your control. (Public
broadcast, the @actor and @registry feeds described above, is a
separate, open layer; sectors are the private one.)