About
We built Repohelm because security backlogs are a governance problem, not a developer attention problem.
In 2022, while working at a Portland-area fintech company scaling from 30 to 150 repositories, Sarah spent roughly two months per year manually triaging Dependabot alerts. Most were false positives, but sorting the real CVEs from the noise required reading NVD entries, tracing import chains by hand, and writing Confluence docs that nobody trusted. That experience convinced her the bottleneck was not developer attention. It was the absence of any system that could evaluate exploitability in context and act on it automatically.
Repohelm was started in Portland in 2024 to solve that exact problem. Not to replace Dependabot or Renovate, but to add the governance layer those tools don't have: reachability-aware triage, policy as code, SBOM export, and license risk detection, all surfaced as pull requests your team can review or auto-merge.
The team
Two engineers. Combined background in platform security and infrastructure tooling at fintechs and logistics platforms.
Sarah Lindqvist
CEO & Co-Founder
Led platform security at a Portland-area fintech from 2021 to 2024, during a period when the company's repository count grew from 30 to over 150. Built internal tooling to triage CVE alerts across ecosystems. Started Repohelm after that tooling became the most valuable part of her workflow and nothing comparable existed as a product.
Tobias Reinholt
CTO & Co-Founder
Infrastructure engineer at a logistics platform from 2019 to 2023, where he built the internal dependency scanning pipeline used across 80 microservices. Joined Repohelm as co-founder and CTO in 2024. His view: most SCA tooling creates alert fatigue because it surfaces raw CVSS scores with no context about whether the vulnerable code path is even reachable in production.
How we work
Governance without gates
We don't block your CI or nag your developers. We open pull requests, the right medium for code changes.
Specific, not comprehensive
Repohelm does dependency governance. Not SAST. Not secrets. One thing, done precisely.
Context over alerts
A CVE number is not actionable. A PR with a diff, a severity rationale, and a one-click merge, that is.
We are a small team in Portland working on a focused problem. If dependency governance, SCA, or supply-chain security is the space you want to work in, write to us.
Get in touch