Trivy and Grype find thousands of CVEs, then the JSON scrolls off the terminal. Ephor is the open-source layer that comes next: it knows which findings are actually running in your cluster, ranks them by what's exploitable and fixable, and tracks them through triage to fix. Self-hosted — your scan data never leaves your cluster.
The Ephor dashboard — priority worklist, namespace heatmap, and pre-scan alerts.
CLI tools find vulnerabilities. Enterprise platforms manage them — at $50,000 to $500,000 per year. Between them: nothing. Until now.
Trivy, Grype, Syft
Self-hosted, unlimited
Prisma Cloud, Wiz, Aqua
Ephor keeps an index of every package in every image SBOM it has seen. When a critical CVE shows up in one image, Ephor checks the exact same package and version against the rest of your fleet and flags the images carrying it that nobody has scanned yet. You learn a vulnerable dependency is spreading on its way in, not a scan cycle later.
Ephor indexes every package in every image SBOM, so you can search your whole fleet for one dependency in a keystroke. Pick any two versions of an image and Ephor diffs them — what was added, removed, or bumped — so a quiet dependency change never slips in unnoticed.
P0–P3 tiers built from what's deployed, exploitable (CISA KEV / FIRST EPSS), and fixable. The worklist starts with the findings that matter — not 10,000 rows by CVSS.
The priority worklist, severity breakdowns, and trend charts across every cluster, namespace, and workload. One screen, full picture.
Filter by image, namespace, or severity — or by KEV, EPSS, and whether a fix exists. Get from 10,000 CVEs to the few that matter.
Assign, track, and manage vulnerability status with comments and full audit trails.
Flag critical findings and route them to the team that owns the workload.
Track fixes against SLAs. Measure remediation progress, not just vulnerability counts.
The Ephor Scanner discovers Kubernetes workloads and scans container images automatically using Trivy.
No venture capital. No investor pressure to enshittify the product. No exit strategy. Just the tooling.
Self-hosted by default. Your vulnerability data never leaves your infrastructure. No SaaS dependency, no third-party access, no data residency concerns.
No telemetry, no analytics, no usage tracking. Ephor doesn't call out to anyone. The only traffic is the scanner shipping results to your own API, inside your own cluster.
Licensed under AGPL v3 — an OSI-approved open-source license. Not BSL. Not SSPL. No bait-and-switch. Inspect every line. Fork if you want. This is real open source.
Ephor is free and self-hosted. Deploy with Helm, point the scanner at your cluster, done.