Platform Use Cases
DeployHub collects release data from GitHub, GitLab, GitOps, and Kubernetes logs for every workflow release, creating a configuration digital twin of what is running, where it is deployed, and who owns it.
The Risk
When vulnerability tracking stops at deployment, organizations lose visibility into the software that is actually running, and into the new CVEs disclosed against it later. Without continuously connecting CI/CD evidence, SBOMs, releases, and deployment data to live environments, teams can miss vulnerable components in production, underestimate blast radius, and waste time searching for affected systems after a critical disclosure. The result is longer exposure windows, slower remediation, and greater risk of business disruption from software that appeared safe when it was released.t.
Platform Benefits
DeployHub collects release data from GitHub, GitLab, GitOps, and Kubernetes logs for every workflow release, creating a configuration digital twin of what is running, where it is deployed, and who owns it. If an SBOM is not generated in the pipeline, DeployHub can generate one automatically. It then synchronizes release data with OSV.dev every ten minutes to provide continuous visibility into newly disclosed CVEs impacting operational endpoints.
DeployHub collects SBOMs, build metadata, Git/GitOps activity, and deployment evidence to create a continuously updated view of what software is running, where it is deployed, and who owns it.
Continuously correlate released software with newly disclosed CVEs, so vulnerabilities discovered after deployment are detected and mapped back to affected applications and endpoints.
Connect vulnerabilities to live services, ownership, and blast radius so teams can prioritize real production exposure instead of chasing vulnerability noise.
If you are not already generating an SBOM as part of your DevSecOps Pipeline integration, DeployHubโs integration with Syft can transform your DevOps pipeline to a DevSecOps platform.
DeployHub’s Continuous Vulnerability Management can consume CycloneDX formatted SBOMs. If you are already generating SBOMs, you will pass the name of the SBOM results to DeployHub Pro.
DeployHubโs Continuous Vulnerability Management can consume any SPDX formatted SBOM. If you are already generating SBOMs, you will pass the name of the SBOM results to DeployHub Pro.
DeployHub uses OSV.Dev to continuously monitor the vulnerabilities of your Components and Applications within your software supply chain. DeployHub Pro scans for new vulnerabilities every 10 minutes turning your DevOps pipeline into a DevSecOps platform that generates continuous vulnerability detection.
DeployHub watches the GitOps repo for new releases, and gathers endpoint deployment metadata to map a release to an endpoint.
You can configure DeployHub to call out to a Git Repo to pull deployable artifacts (binaries, scripts, etc.) as part of your deployment. The process will check out your deployable artifacts based on commit, branch or tag specified.
DeployHub consolidates OpenSSF Scorecard results into a single dashboard, mapping project security scores to applications, services, environments, and owners so teams can quickly identify risk, prioritize fixes, and prove continuous open-source governance.
Use the free DeployHub SaaS platform to detect and locate vulnerabilities across production environments, without waiting for budget approval or a lengthy procurement cycle.
Our free SaaS platform is based on Ortelius, an open-source project incubating at the Linux Foundation. No budget authority. No agents. No reason to wait.
Hereโs how DeployHub compares to Traditional SCA, Scanners, and SAST.
| Capability | DeployHub | Traditional SCA | Container Scanners | SAST |
|---|---|---|---|---|
| Maps CVEs to deployed applications | Yes | Limited | Container-only | No |
| Shows where vulnerable packages are running | Yes | No | Limited | No |
| Tracks ownership and blast radius | Yes | Limited | Limited | No |
| Uses SBOMs after deployment | Yes | Limited | Limited | No |
| Supports agentless operational visibility | Yes | Usually no | Usually no | No |
Know when a new CVE affects software you’ve already released by using your SBOM insights.
See the exact package, version, artifact, and endpoint affected by a newly reported CVE.
Continuously monitor your deployed software without agents or production rescanning.
DeployHub aggregates OpenSSF Scorecard data to help teams evaluate the security practices of the open-source projects they depend on, not just whether those projects currently have known CVEs
Turn static SBOM files into a live inventory of the open-source packages and versions running across your software estate.
Built on Ortelius, DeployHub gives teams an open, extensible foundation for software inventory, SBOM intelligence, deployment tracking, and vulnerability defense.
meet ortelius
DeployHub is built on Ortelius, the open-source foundation for post-deployment vulnerability intelligence. Ortelius connects SBOMs, deployment data, applications, environments, and endpoints so teams of all sizes and budget constraints can determine whether newly disclosed vulnerabilities are actually affecting live systems.
Ortelius is an open-source project incubating at the Continuous Delivery Foundation.