Ortelius connects the software inventory in your SBOMs with Helm and deployment metadata to map open-source packages and versions to the endpoints and where they are running. Ortelius then continuously monitors that inventory for newly disclosed vulnerabilities. Already have an SBOM? We consume it. Don’t have one? We will generate it. Ortelius maps software inventory to newly disclosed vulnerabilities within 10 minutes of reporting —so when the next critical CVE appears, you can quickly determine whether you have it, which application contains it, and exactly where it is deployed.
Modern software relies on hundreds or thousands of open-source packages, containers, and microservices. Pre-deployment scans provide only a point-in-time view and often generate significant noise without showing what actually reached production. Post-deployment agent-based scanning can fill that gap, but deploying and maintaining agents across every environment is expensive, resource-intensive, and operationally heavy.
Your CI/CD pipeline already knows what was built and where it was deployed. Ortelius connects SBOM package and version data with Helm and deployment metadata to map software to artifacts, environments, and endpoints—so when a new CVE appears, you already know where the affected software is running.
Do we use it? - Ortelius searches the SBOM inventory for the affected package and version.
Which artifact is impacted? - Ortelius maps packages and dependencies to artifact versions.
Where is that exact version running? - Ortelius uses Helm and deployment metadata to connect the OS package version to its deployed endpoints.
What actually needs to be fixed? - - Teams get the package, version, application, deployment, and ownership context needed to act.
Where is the affected software actually running?
Once your SBOM and deployment metadata is collected, Ortelius continuously correlates its packages against vulnerability intelligence. When a new CVE is disclosed tomorrow, next month, or next year, Ortelius can identify the software that contains the affected dependency and where it is installed across your production endpoints.
Bring the SBOMs your development teams already produce. Ortelius consumes standard SBOM formats including SPDX and CycloneDX. If an SBOM doesn’t exist, Ortelius will use the open-source Syft tool to generate one.
Different teams can continue using different development and security tools while Ortelius provides a common software inventory.
This is where Ortelius goes beyond basic SBOM management. An SBOM tells you what is inside the software. Deployment evidence tells you where that software went.
Ortelius combines SBOM data with Helm charts and deployment metadata to maintain the relationships between packages, component versions, applications, deployments, environments, and endpoints.
Software doesn’t stop becoming vulnerable after it ships. A package may have no known vulnerabilities when an application is released and have a critical CVE disclosed days, months, or even years later. The application didn’t change. The threat did.
Ortelius continuously evaluates the packages in its software inventory against newly disclosed vulnerability information. Your SBOM becomes more than a compliance artifact. It becomes the foundation for continuous post-deployment vulnerability monitoring.
When a new vulnerability appears, knowing the package name is only the beginning.
Ortelius uses its software relationships to trace the affected package through the application and deployment chain.
Instead of:
CVE → Start Investigation
Ortelius gives you:
CVE → Affected Package + Version → Artifact → Deployment → Endpoint
That means security and development teams can quickly understand the real exposure and prioritize the systems that actually require attention.
Post-deployment open-Source vulnerabilitie are the new security gap and attack surface. Learn how Ortelius fixes the gap and helps team detect and remediate fast.
Help strengthen open-source software security by becoming an Ortelius Pathfinder. Onboard your favorite open-source or private project into Ortelius, connect its software supply chain and deployment data, and help demonstrate a better way to find and fix vulnerabilities in software already running in production. Earn Bronze, Silver, and Gold Pathfinder badges as you expand the Ortelius ecosystem and help show others the path toward stronger software supply chain security.
From discovering where open-source packages are being used, to federating OpenSSF Scorecard and Post-Deployment Vulnerability Detection Platform data, Ortelius serves as a central hub for managing, evaluating, and responding to vulnerabilities, and understanding the risk associated to consuming open-source packages from code to cloud.
Get started with Ortelius using the free SaaS version. Take a quick tutorial and see it in action.
Abraham Ortelius made his name by collecting data from scientists, geographers, and cartographers of his time and transforming it into what the world now knows as a world Atlas. His Atlas, titled Theatrum Orbis Terrarum (Theatre of the World), was published on May 20, 1570. His Atlas disrupted the way the world was seen, with the first concepts imagining continental drift. Also of interest are the sea monsters shown in the water – mythical creatures that were a subject of fascination in Ortelius’ generation.
Ortelius also in some ways created on open source community of his day. To accomplish his goal, he was the first cartographers to give credit to his fellow scientists by adding their names to the Atlas. Ortelius was known to have corresponded with other professionals throughout Europe and pulled together their knowledge to create his publication and a truly global view of the world.
Thank you Abraham Ortelius for showing us the way.