Skip to content
Self-hosted container security

Find what matters. Fix it before it ships.

Scan images and Helm charts, prioritize what is fixable, and keep evidence and team context in one security workflow you control.

No account required for your first public image scan.

A scanner that fits the way you ship.

Trivy + Xray
Self-hosted by design
OIDC-ready
Built for CI/CD
A workflow you can see

Security that moves with the release.

Every stage stays connected—from the artifact entering your environment to the evidence your team uses to ship.

image
analyze
verdict
PullPrioritizeDecide
Fixable findingslive

CVE-2026-46595

golang.org/x/crypto

critical

0.52.0

CVE-2026-39821

golang.org/x/net

high

0.55.0

CVE-2026-34182

libcrypto3

high

3.5.7-r0

Watchlist

payments:release

scheduled

Your registry credentials, identity model, policy decisions, and evidence stay inside the environment you operate.

CVE intelligence

Your scan is a snapshot. Your risk picture should not be.

Track what changed after the scan, understand the policy impact, and know when a rescan is the only answer that closes the loop.

7,412CVE records tracked
LiveSource history
ScopedPolicy impact

Example workspace

Intelligence stream

Live posture

Rejected by source. The current intelligence posture no longer treats this finding as affected. The original scan result remains available for audit.

Open CVE-2026-46595
JustScan CLI

One command between build and deploy.

Bring the same scan engine and organization policies into a laptop, build runner, or release job—without rebuilding the workflow in shell scripts.

Local images. Stream from Docker or Podman without publishing first.

Registry + archive scans. Submit remote images, saved OCI archives, or HTTPS URLs.

CI-native verdicts. Wait for the server policy and use predictable exit codes.

justscan · pipeline

$ justscan scan ghcr.io/acme/api:release

01Resolving image manifest
02Submitting artifact to JustScan
03Scanning packages and policies
04Writing organization result
Policy passedexit 0

9 fixable findings · result saved to Platform

GitOps discovery

Follow the source of truth.

Turn the manifests that describe production into a living inventory of what needs to be scanned, reviewed, and watched.

platform/production

main · synced just now

connected

apps/api/deployment.yaml

api:2.4.0

apps/web/values.yaml

web:2.4.0

workers/scan/kustomization.yaml

scanner:stable

Discovered workloads

api3 critical
webpolicy passed
scannerscan queued
3 manifests3 images
DiscoverScanEnforce policy
01

Connect

Point JustScan at the repository and branch your platform team already owns.

02

Discover

Resolve declared images from supported manifests into reviewable workloads.

03

Keep current

Scan immediately or schedule recurring repository discovery and analysis.

Coming soon

Collect closer to where workloads run.

Collectors are the next step in extending JustScan into distributed and restricted environments while keeping policy and review centralized.

Distributed environmentsCentral policyPlanned capability

This preview reflects the product direction currently being planned. Availability and final scope may change.

JustScancontrol plane
Kubernetes
Edge
Private cloud
Air-gapped
FAQ

Questions, answered.

The short version of how JustScan fits into your infrastructure and release workflow.

Yes. You deploy JustScan with Docker Compose or Helm and keep the application, scan data, credentials, and security workflow inside infrastructure you control.

Start without setup

Start with one image. Build the workflow when you’re ready.

Run a public scan without an account, then keep the result when it becomes part of your team’s release process.