Know What's Vulnerable. Know Exactly Where It's Running.

SBOM tells you what OS packages you have. Ortelius tells you where they are running. .

Ortelius connects the software inventory in your SBOMs with Helm and deployment metadata to map open-source packages and versions to the endpoints and where they are running. Ortelius then continuously monitors that inventory for newly disclosed vulnerabilities. Already have an SBOM? We consume it. Don’t have one? We will generate it. Ortelius maps software inventory to newly disclosed vulnerabilities within 10 minutes of reporting —so when the next critical CVE appears, you can quickly determine whether you have it, which application contains it, and exactly where it is deployed.

Get Started Today

Finding a CVE Is Easy. Finding Where It's Running Is Hard.

Modern software relies on hundreds or thousands of open-source packages, containers, and microservices. Pre-deployment scans provide only a point-in-time view and often generate significant noise without showing what actually reached production. Post-deployment agent-based scanning can fill that gap, but deploying and maintaining agents across every environment is expensive, resource-intensive, and operationally heavy.

Don't Rediscover Your Software. Remember What You Deployed.

Your CI/CD pipeline already knows what was built and where it was deployed. Ortelius connects SBOM package and version data with Helm and deployment metadata to map software to artifacts, environments, and endpoints—so when a new CVE appears, you already know where the affected software is running.

When a New CVE Drops, Ortelius Answers These Questions

Do we use it? - Ortelius searches the SBOM inventory for the affected package and version.

Which artifact is impacted? - Ortelius maps packages and dependencies to artifact versions.

Where is that exact version running? - Ortelius uses Helm and deployment metadata to connect the OS package version to its deployed endpoints.

What actually needs to be fixed? - - Teams get the package, version, application, deployment, and ownership context needed to act.

From OS Package to Production Endpoint.

The harder question comes after a CVE is discovered.

Where is the affected software actually running?

Once your SBOM and deployment metadata is collected, Ortelius continuously correlates its packages against vulnerability intelligence. When a new CVE is disclosed tomorrow, next month, or next year, Ortelius can identify the software that contains the affected dependency and where it is installed across your production endpoints.

Ortelius SBOM Collection

Ortelius Post-Deployment Vulnerability Detection

Collect


Bring the SBOMs your development teams already produce. Ortelius consumes standard SBOM formats including SPDX and CycloneDX. If an SBOM doesn’t exist, Ortelius will use the open-source Syft tool to generate one.

Different teams can continue using different development and security tools while Ortelius provides a common software inventory.

Map


This is where Ortelius goes beyond basic SBOM management. An SBOM tells you what is inside the software. Deployment evidence tells you where that software went.

Ortelius combines SBOM data with Helm charts and deployment metadata to maintain the relationships between packages, component versions, applications, deployments, environments, and endpoints.

Monitor


Software doesn’t stop becoming vulnerable after it ships. A package may have no known vulnerabilities when an application is released and have a critical CVE disclosed days, months, or even years later. The application didn’t change. The threat did.

Ortelius continuously evaluates the packages in its software inventory against newly disclosed vulnerability information. Your SBOM becomes more than a compliance artifact. It becomes the foundation for continuous post-deployment vulnerability monitoring.

Quickly Pinpoint


When a new vulnerability appears, knowing the package name is only the beginning.

Ortelius uses its software relationships to trace the affected package through the application and deployment chain.

Instead of:

CVE → Start Investigation

Ortelius gives you:

CVE → Affected Package + Version → Artifact → Deployment → Endpoint

That means security and development teams can quickly understand the real exposure and prioritize the systems that actually require attention.

Ortelius Use Cases

Defend Live Systems - Post-Deployment

Read more …

Gain Live System Visability using a Digital Twin

Read more …

Track Compliance and OpenSSF Scores

Read more …

Why Ortelius, and Why Now?


Post-deployment open-Source vulnerabilitie are the new security gap and attack surface. Learn how Ortelius fixes the gap and helps team detect and remediate fast.

Pathfinder

On-board an Open Source Project and Earn a Pathfinder Badge


Help strengthen open-source software security by becoming an Ortelius Pathfinder. Onboard your favorite open-source or private project into Ortelius, connect its software supply chain and deployment data, and help demonstrate a better way to find and fix vulnerabilities in software already running in production. Earn Bronze, Silver, and Gold Pathfinder badges as you expand the Ortelius ecosystem and help show others the path toward stronger software supply chain security.

Ortelius

Sign-up and Get Started Managing Post Deployment CVEs


From discovering where open-source packages are being used, to federating OpenSSF Scorecard and Post-Deployment Vulnerability Detection Platform data, Ortelius serves as a central hub for managing, evaluating, and responding to vulnerabilities, and understanding the risk associated to consuming open-source packages from code to cloud.

Get started with Ortelius using the free SaaS version. Take a quick tutorial and see it in action.

Pull Request Encouraged - Become a Committer


Contribute

Read more …

Open an Issue

Read more …

Attend Out Community Meetings and Events

Read more …

Our Inspiration


Abraham Ortelius

Abraham Ortelius

Abraham Ortelius made his name by collecting data from scientists, geographers, and cartographers of his time and transforming it into what the world now knows as a world Atlas. His Atlas, titled Theatrum Orbis Terrarum (Theatre of the World), was published on May 20, 1570. His Atlas disrupted the way the world was seen, with the first concepts imagining continental drift. Also of interest are the sea monsters shown in the water – mythical creatures that were a subject of fascination in Ortelius’ generation.

A Thought Leader in Sharing

Ortelius also in some ways created on open source community of his day. To accomplish his goal, he was the first cartographers to give credit to his fellow scientists by adding their names to the Atlas. Ortelius was known to have corresponded with other professionals throughout Europe and pulled together their knowledge to create his publication and a truly global view of the world.

Thank you Abraham Ortelius for showing us the way.