A SECURITY PROGRAM, ON YOUR TERMS
Your scanners.
Your infrastructure.
Your call.
Build the security stack you actually need. Mix and match open-source scanners, connect your own machines, and keep your findings private.
Free to self-host. No per-repository pricing. Apache 2.0.
PR events → Scans → Reports → Risk policies
A Compose file is the package.
Publish versioned scanners to a private workspace or submit them to the community registry.
Compute stays in your hands.
Choose runner locations and labels. Review scanner digests before allowing execution.
Security that fits your context.
Use OPA triage policies, DefectDojo report imports, and optional local Ollama summaries.
BETTER TOGETHER
The scanner registry0
Reviewed packages. Portable tooling. A stack you can make your own.
Loading scanner registry…
NEED A HAND WITH THE BIGGER PICTURE?
Meet MayoASPM.
Explore managed security tooling and additional help building your security program.