
Container security platform for automated CVE triage, image patching, and scanning.

Container security platform for automated CVE triage, image patching, and scanning.
The Entire Cybersecurity Market, One Prompt Away
Connect your AI assistant to ... tools and ... vendors. Ask anything about the cybersecurity market.
HarborGuard is a container security platform that provides automated CVE triage, container image patching, and vulnerability management for teams deploying containerized applications. The platform is available as an open-source self-hosted solution (AGPL-3.0 licensed) and as a managed enterprise offering. Core capabilities include: - Automated CVE Triage: Monitors scan results and new CVE advisories from NVD, OSV, GitHub Security Advisories, and CISA KEV. Automatically opens prioritized triage runs, tracks SLA compliance, and supports false-positive attestations with an immutable audit trail. - Container Image Patching: Patches container images in place without requiring a Dockerfile rewrite or CI pipeline changes. Patched images are pushed back to the source registry via isolated ephemeral cloud workers. - Deep Scanning: Integrates six open-source scanners — Trivy, Grype, Syft, Dockle, OSV-Scanner, and Dive — to detect vulnerabilities, generate SBOMs (SPDX and CycloneDX), grade CIS benchmark compliance, and perform layer-by-layer image inspection. Findings are deduplicated across scanners. - Registry Support: Connects to 11 registry providers including Docker Hub, AWS ECR, GCR, ACR, GHCR, GitLab, Harbor, JFrog Artifactory, Quay, Nexus, and custom OCI-compliant registries. - Compliance Engine: Generates control-mapped compliance reports for SOC 2 Type II, PCI-DSS v4.0, NIST SP 800-53, HIPAA, FedRAMP Moderate, ISO/IEC 27001, CMMC Level 2, and CIS Docker Benchmark. - Enterprise Features: RBAC with five role types, SSO via SAML/OIDC/LDAP, SCIM provisioning, REST API, CI/CD integration, Slack/PagerDuty/webhook notifications, and deployable cloud sensors for Kubernetes and Docker environments.