Platform Use Cases
DeployHub is an attack surface visibility tool designed to show security teams what is actually exposed after deployment. Unlike traditional source-code and repository scanners, DeployHub connects newly disclosed CVEs to the open-source packages, applications, environments, and endpoints where vulnerable software is actually running.
ย
The Risk
Your production attack surface changes every time software, dependencies, services, or deployment locations change. Without continuous attack surface visibility, security teams can lose track of software that introduces new exposure and business risk.
Hidden backend components, open-source packages, and transitive dependencies can expand the attack surface without appearing in traditional vulnerability assessments. An effective attack surface visibility tool helps teams understand what is running, where it is deployed, and which vulnerabilities create real production riskโnot simply how many vulnerabilities exist.
.
Platform Benefits
DeployHub provides continuous attack surface visibility across production environments by connecting software inventory, deployment data, SBOMs, and newly disclosed vulnerabilities. Security teams can see which components are actually deployed, where vulnerable packages are running, and which applications and endpoints are affected.
Get immediate post-deployment attack surface visibility with the DeployHub SaaS platform. Detect newly disclosed vulnerabilities, locate where affected packages are running, and understand the blast radius across your production systems, without deploying endpoint agents or waiting through a lengthy procurement cycle.
Maintain an always-current view of the software, dependencies, applications, environments, and endpoints that make up your production attack surface.
Discover backend components and transitive dependencies that may expand your attack surface without appearing in source-code assessments.
See every artifact, application, environment, and endpoint affected by a vulnerable component..
Locate where specific open-source packages and versions are deployed across your software estate.
Connect CVEs to the exact package, version, artifact, application, environment, and endpoint affected.
Move beyond raw vulnerability counts and focus remediation on vulnerabilities tied to software that is actually deployed and exposed.
Hereโs how DeployHub compares to Traditional SCA, Scanners, and SAST.
| Capability | DeployHub | Traditional SCA | Container Scanners | SAST |
|---|---|---|---|---|
| Maps CVEs to deployed applications | Yes | Limited | Container-only | No |
| Shows where vulnerable packages are running | Yes | No | Limited | No |
| Tracks ownership and blast radius | Yes | Limited | Limited | No |
| Uses SBOMs after deployment | Yes | Limited | Limited | No |
| Supports agentless operational visibility | Yes | Usually no | Usually no | No |
Know when a new CVE affects software you’ve already released by using your SBOM insights.
See the exact package, version, artifact, and endpoint affected by a newly reported CVE.
Continuously monitor your deployed software without agents or production rescanning.
DeployHub aggregates OpenSSF Scorecard data to help teams evaluate the security practices of the open-source projects they depend on, not just whether those projects currently have known CVEs
Turn static SBOM files into a live inventory of the open-source packages and versions running across your software estate.
Built on Ortelius, DeployHub gives teams an open, extensible foundation for software inventory, SBOM intelligence, deployment tracking, and vulnerability defense.
meet ortelius
DeployHub is built on Ortelius, the open-source foundation for post-deployment vulnerability intelligence. Ortelius connects SBOMs, deployment data, applications, environments, and endpoints so teams of all sizes and budget constraints can determine whether newly disclosed vulnerabilities are actually affecting live systems.
Ortelius is an open-source project incubating at the Continuous Delivery Foundation.