Platform Use Case
Ortelius is the open-source project behind DeployHub’s post-deployment vulnerability management capabilities. DeployHub hosts a free SaaS version of Ortelius for small teams and also offers the commercial DeployHub platform for organizations that need enterprise scale, governance, and support.
Platform
The Risk
Software that was secure when it was deployed can become vulnerable overnight. Without post-deployment visibility, teams may not know which newly disclosed CVEs affect their live applications, where vulnerable components are running, or how far the exposure reaches.
Ortelius gives you a free, open-source way to close that visibility gap now. Start with the hosted SaaS version, connect your software data, and begin identifying real production risk in minutes—before the next vulnerability turns into an incident.
From discovering where open-source packages are being used, to federating OpenSSF Scorecard, Ortelius.io serves as a central hub for vulnerability detection so teams can trust the open-source they rely on from code to cloud. Free to use, incubating at the Continuous Delivery Foundation, with a SaaS offering hosted by Deployhub.
Start free and see which vulnerable packages are actually running across your applications and endpoints.
Chat with the Ortelius vulnerability detection community. Ask them anything.
Join the community, explore issues, attend meetings, test features, improve documentation, or help shape the roadmap.
The Ortelius vulnerability management open source tool is an open source project at the Continuous Delivery Foundation, part of the Linux Foundation ecosystem.
The project follows open governance and community-driven development. Contributors from any organization can participate, propose ideas, contribute code, and help shape the direction of the project.
That independence helps keep Ortelius open, interoperable, and driven by the needs of its users and contributors.
Ortelius brings together contributors from cybersecurity, DevOps, platform engineering, AI, software supply chain security, and open-source governance. The project is shaped by people who use the software, test new ideas, report problems, improve documentation, build integrations, and contribute code. You do not need to be a core developer to participate. Some of the most valuable contributions come from practitioners who can tell us where vulnerability management breaks down in the real world.
Contributing to Ortelius gives you the opportunity to work on real problems in software supply chain security and post-deployment vulnerability management.
Community members can:
There are many ways to contribute to Ortelius:
Our free SaaS offering gives teams a hosted version of Ortelius to identify which open-source vulnerabilities are affecting deployed software, locate where vulnerable components are running, and focus on the risks that matter most. No budget approval required, with actionable value in 10 minutes or less.
Use the DeployHub Free SaaS to:
Continuously identify newly disclosed vulnerabilities that affect software already running in production, even if those CVEs did not exist when the software was built.
See which applications, environments, and endpoints contain an affected open-source package so teams know exactly where remediation is needed.
Combine component data from multiple services, repositories, and artifacts into a unified application-level view of packages, versions, licenses, and vulnerabilities.
Quickly determine how broadly a new vulnerability affects deployed software, including the applications, environments, and endpoints that may be exposed.
Maintain visibility into what software is running and where it is deployed without installing or managing persistent endpoint agents.
Focus on vulnerabilities tied to software that is actually deployed instead of spending time investigating every CVE found in source code, repositories, or unused components.
Use the hosted Ortelius SaaS environment without procurement delays or budget approval and begin gaining post-deployment vulnerability visibility in 10 minutes or less.
Join the open-source community to test features, report issues, improve documentation, contribute code, and help shape the future of post-deployment vulnerability management.
DeployHub extends the Ortelius open-source foundation with enterprise access controls, broader component coverage, and commercial support.
Here’s how the Ortelius OS Vulnerability Management platform compares to Traditional SCA, Scanners, and SAST.
| Capability | Ortelius | Traditional SCA | Container Scanners | SAST |
|---|---|---|---|---|
| Maps CVEs to deployed applications | Yes | Limited | Container-only | No |
| Shows where vulnerable packages are running | Yes | No | Limited | No |
| Tracks ownership and blast radius | Yes | Limited | Limited | No |
| Uses SBOMs after deployment | Yes | Limited | Limited | No |
| Supports agentless operational visibility | Yes | Usually no | Usually no | No |