Platform Use Cases
DeployHub uses a digital twin for vulnerability management to create a continuously updated model of the software running across your production environments. It connects SBOMs, open-source packages, applications, deployment locations, endpoints, and newly disclosed CVEs so teams can see which vulnerabilities are actually affecting live systems.
This software security digital twin provides continuous post-deployment visibility without requiring endpoint agents or repeated production rescanning.
The Risk
Once software leaves the pipeline, the relationship between an SBOM, the application it belongs to, and the environment where it is running can quickly become difficult to track.
Packages are updated, applications are redeployed, versions drift, and new vulnerabilities appear against components that were considered safe when they were released. Static inventories and point-in-time scans do not preserve that operational context.
A digital twin for vulnerability management maintains those relationships over time, giving teams a living view of deployed software, its dependencies, and the vulnerabilities affecting it.
Platform Benefits
DeployHub creates a living digital twin of deployed software by connecting SBOM intelligence with application, environment, endpoint, and vulnerability data.
Instead of treating each scan, SBOM, or deployment as an isolated record, the digital twin preserves the relationships between them. When a new CVE is disclosed, teams can immediately see whether the affected package is deployed, which applications contain it, where those applications are running, and the blast radius across production.
Maintain a continuously updated model of deployed components, versions, applications, and environments.
See what was deployed, when it changed, and which vulnerabilities were associated with each release.
Connect SBOM data to the applications and endpoints where those components are actually running.
Trace vulnerable packages back to the artifact, component, version, application, and responsible owner.
Locate affected packages across Kubernetes, cloud, edge, HPC, disconnected, and on-orbit environments.
Identify every deployed application, environment, and endpoint affected by a newly disclosed vulnerability.
Use the free DeployHub SaaS platform to detect and locate vulnerabilities across production environments, without waiting for budget approval or a lengthy procurement cycle.
Our free SaaS platform is based on Ortelius, an open-source project incubating at the Linux Foundation. No budget authority. No agents. No reason to wait.
Hereโs how DeployHub compares to Traditional SCA, Scanners, and SAST.
| Capability | DeployHub | Traditional SCA | Container Scanners | SAST |
|---|---|---|---|---|
| Maps CVEs to deployed applications | Yes | Limited | Container-only | No |
| Shows where vulnerable packages are running | Yes | No | Limited | No |
| Tracks ownership and blast radius | Yes | Limited | Limited | No |
| Uses SBOMs after deployment | Yes | Limited | Limited | No |
| Supports agentless operational visibility | Yes | Usually no | Usually no | No |
Know when a new CVE affects software you’ve already released by using your SBOM insights.
See the exact package, version, artifact, and endpoint affected by a newly reported CVE.
Continuously monitor your deployed software without agents or production rescanning.
DeployHub aggregates OpenSSF Scorecard data to help teams evaluate the security practices of the open-source projects they depend on, not just whether those projects currently have known CVEs
Turn static SBOM files into a live inventory of the open-source packages and versions running across your software estate.
Built on Ortelius, DeployHub gives teams an open, extensible foundation for software inventory, SBOM intelligence, deployment tracking, and vulnerability defense.
meet ortelius
DeployHub is built on Ortelius, the open-source foundation for post-deployment vulnerability intelligence. Ortelius connects SBOMs, deployment data, applications, environments, and endpoints so teams of all sizes and budget constraints can determine whether newly disclosed vulnerabilities are actually affecting live systems.
Ortelius is an open-source project incubating at the Continuous Delivery Foundation.