Everything that happens
after the scan.

Trivy and Grype find thousands of CVEs, then the JSON scrolls off the terminal. Ephor is the open-source layer that comes next: it knows which findings are actually running in your cluster, ranks them by what's exploitable and fixable, and tracks them through triage to fix. Self-hosted — your scan data never leaves your cluster.

The Ephor dashboard — priority worklist, namespace heatmap, and pre-scan alerts.

Between free scanners and
six-figure platforms

CLI tools find vulnerabilities. Enterprise platforms manage them — at $50,000 to $500,000 per year. Between them: nothing. Until now.

CLI Scanners Free

Trivy, Grype, Syft

  • Find vulnerabilities
  • No management UI
  • No triage workflow
  • No remediation tracking
Open Source
Ephor Free

Self-hosted, unlimited

  • Find vulnerabilities
  • Full dashboard & search
  • Triage workflows
  • Remediation tracking
Enterprise Platforms $50K–$500K/yr

Prisma Cloud, Wiz, Aqua

  • Find vulnerabilities
  • Full platform
  • Compliance tooling
  • Vendor lock-in

Catch a vulnerable package
before your next scan finds it

Ephor keeps an index of every package in every image SBOM it has seen. When a critical CVE shows up in one image, Ephor checks the exact same package and version against the rest of your fleet and flags the images carrying it that nobody has scanned yet. You learn a vulnerable dependency is spreading on its way in, not a scan cycle later.

Pre-scan alerts: known CVEs matched against packages on images not yet scanned

Search every package
and see what changed between builds

Ephor indexes every package in every image SBOM, so you can search your whole fleet for one dependency in a keystroke. Pick any two versions of an image and Ephor diffs them — what was added, removed, or bumped — so a quiet dependency change never slips in unnoticed.

Scan, prioritize, triage, fix.
In one place.

Runtime-Aware Prioritization

P0–P3 tiers built from what's deployed, exploitable (CISA KEV / FIRST EPSS), and fixable. The worklist starts with the findings that matter — not 10,000 rows by CVSS.

Unified Dashboard

The priority worklist, severity breakdowns, and trend charts across every cluster, namespace, and workload. One screen, full picture.

Vulnerability Search

Filter by image, namespace, or severity — or by KEV, EPSS, and whether a fix exists. Get from 10,000 CVEs to the few that matter.

Triage Workflows

Assign, track, and manage vulnerability status with comments and full audit trails.

Escalation Management

Flag critical findings and route them to the team that owns the workload.

Remediation Tracking

Track fixes against SLAs. Measure remediation progress, not just vulnerability counts.

Automated Discovery

The Ephor Scanner discovers Kubernetes workloads and scans container images automatically using Trivy.

No VC. No vendor cloud.
No strings.

No Strings Attached

No venture capital. No investor pressure to enshittify the product. No exit strategy. Just the tooling.

Your Infrastructure, Your Data

Self-hosted by default. Your vulnerability data never leaves your infrastructure. No SaaS dependency, no third-party access, no data residency concerns.

No Phone Home

No telemetry, no analytics, no usage tracking. Ephor doesn't call out to anyone. The only traffic is the scanner shipping results to your own API, inside your own cluster.

Genuine Open Source

Licensed under AGPL v3 — an OSI-approved open-source license. Not BSL. Not SSPL. No bait-and-switch. Inspect every line. Fork if you want. This is real open source.

Stop managing CVEs in spreadsheets.

Ephor is free and self-hosted. Deploy with Helm, point the scanner at your cluster, done.