Platform

Vulnerability Detection -The Ortelius Open Source Project

Ortelius is a free SaaS vulnerability detection platform for small teams, hosted by DeployHub.

Platform

Get 5-Day Implementation Assistance of Ortelius — DeployHub's Free SaaS Platform

Vulnerability Detection Platform for Post-deployment Defense

From discovering where open-source packages are being used, to federating OpenSSF Scorecard, Ortelius.io serves as a central hub for vulnerability detection so teams can trust the open-source they rely on from code to cloud. Free to use, incubating at the Continuous Delivery Foundation, with a SaaS offering hosted by Deployhub.

Built by a Dedicated Global Contributer Community

The relationship between the Ortelius open source community and DeployHub is a true symbiosis. Ortelius provides the open innovation foundation where new ideas, integrations, and best practices are continuously tested for vulnerability detection and refined by a global community of DevOps and platform engineers. DeployHub, in turn, contributes engineering resources, infrastructure, and real-world use cases that help advance Ortelius’ capabilities and maturity.

Together, they accelerate the evolution of vulnerability detection, post-deployment, with Ortelius driving community adoption and transparency, and DeployHub transforming those innovations into enterprise-ready solutions. This shared ecosystem ensures that both the open source community and the commercial platform grow stronger, smarter, and more trusted with every release.

Step 1

Sign Up For Ortelius

When you sign up for Ortelius, you will need a Company and Project Name to sign up. The Company Name you enter will be created as your company’s private domain, referred to as your Global Domain. Your Project Name will be used under your company’s Domain. Review the Terms of Use.

Step 2

15 Minute Test Drive

Login to the Ortelius OS SaaS environment to see how Ortelius manages its own open source vulnerabilities and security profile. This tutorial is a fast and easy way to learn how to manage vulnerabilities. 

Step 3

Try It With Your Data - Proof of Concept

Complete a POC that automates Ortelius OS via your CI/CD Pipeline. Ortelius uses a Command Line Interface to automate vulnerability management. We have provided a suggested POC starting point, which includes the CLI integration. Start your Proof of Concept and begin securing your software supply chain.

Incubating at the Continuous Delivery Foundation

The Ortelius vulnerability detection platform is an open source project incubated under the Continuous Delivery Foundation (CDF), part of the Linux Foundation, which ensures it operates under open governance and community-driven development. This means Ortelius is guided by transparent processes, a neutral governing board, and a merit-based model where contributors from any organization can participate equally. Being part of the CDF provides oversight, vendor neutrality, and alignment with other key DevOps projects, ensuring that Ortelius remains an open, interoperable standard for software supply chain visibility and continuous delivery innovation.

Join the Community

Join the Ortelius vulnerability detection community. Get involved in building the ultimate open source vulnerability management tool.   

Ortelius GitHub

Join the Project, open issues, add your name to the Read.me, explore PRs. 

Compare Solutions

Is Ortelius Open Source right for you? Find the best solution for your needs.

Ortelius Features

Continuous Open Source Vulnerability Management

Continuously identify and neutralize open source threats across all infrastructure assets with real-time vulnerability management.

Enhance Security and Compliance with Application-Level SBOMs

Assemble real-time Application SBOMs from CI/CD pipelines to drive open source vulnerability management and full supply chain visibility.

Rapid Threat Mitigation with Real-Time Vulnerability Management

Monitor OSV.dev in real time and receive daily CVE alerts to support rapid, ongoing open source vulnerability management.

Ensure Compliance with Open-Source Package Scoring

Use OpenSSF scorecard insights for every SBOM package to support compliance and improve open source vulnerability management.

Map Open-Source Vulnerabilities to Active Endpoints

Strengthen open source vulnerability management by linking package risks to their live deployment environments.

Vulnerability Detection Package Search

Locate and assess open-source package risks across all operational assets through the central dashboard to improve  vulnerability management efficiency and streamline response workflows.

ortelius-stacked-color-small

5 Day Ortelius Assistance Request

Thank you.

Get ready to take control! Our team will connect with you within the next business day to help you start detecting post-deployment threats in real time with Ortelius, our powerful, free, open-source solution.