Veirox

Product — Secure

Manage vulnerabilities, software inventories, and compliance readiness across your estate.

Scan with the tools you already trust, track every finding to a decision, know exactly what you run, and show real evidence for the frameworks you care about — all inside your own network.

Runs entirely inside your network

The scanning, the findings, and the evidence stay on your own infrastructure, because the product itself runs there. Nothing about your code, images, or infrastructure state is sent anywhere else to be assessed.

Find what's actually wrong, with the scanners you already trust

Vulnerabilities and misconfigurations across your container images, source code, open-source dependencies, and infrastructure-as-code, using established open-source scanners — Trivy, Grype, Syft, Semgrep, Checkov, and Prowler — under one consistent view instead of a separate tool per surface.

Catch a secret before it becomes an incident

Scan your repositories for exposed credentials and keys with gitleaks. A match is never stored or shown in full — enough to identify and revoke it, and nothing more.

Know exactly what you ship

A running inventory of every open-source component across your estate, with its license risk classified automatically. Export it as a CycloneDX or SPDX bill of materials whenever a customer or an auditor asks for one.

A finding becomes a tracked issue, not a line in a report

Every result gets a severity, an owner, and a status, with the full history kept. Deciding what to do about it — fix it, or accept the risk for a limited time — is a decision a person makes and records; nothing changes on its own.

Fixing a finding still goes through the same approval every other action on your infrastructure does — Veirox never applies a change unattended.

See what you can back up, against the frameworks that matter

Map the evidence you already collect — scan results, software inventories, infrastructure configuration — against the controls in recognized frameworks like SOC 2 and the CIS benchmarks, and see exactly which ones you can support today.

An assessment runs when you choose to run one, not continuously in the background. It produces readiness evidence for your own audit process — never a certification, and never a claim about your legal compliance status.

Accepted risk expires on its own

When a team decides to accept a risk instead of fixing it right away, that decision is time-boxed from the start. It lifts itself when the window closes, so an exception never quietly becomes permanent because nobody remembered it.