What Does Deepfactor Do?
SBOM, SCA, & Container Scans
Generate SBOMs, scan OSS dependencies and containers for vulnerabilities and licenses, gate builds during CI.
Learn More >
Runtime SCA
Prioritize SCA findings based on correlation with runtime usage behavior & reachability.
Learn More >
Container Runtime Security
Detect insecure file, network, and memory behavior to identify unknown vulnerabilities and achieve compliance with SOC2 Type 2 and other frameworks.
Learn More >
How Does Deepfactor Work?
$ dfctl scan deepfactor/my-service:tag1234
$ helm install df-webhook deepfactor/webhook
Whitepaper
SCA 2.0: A Framework to Prioritize Risk, Reduce False Positives, and Eliminate SCA Alert Fatigue
Software composition analysis (SCA) tools can overwhelm engineering and application security teams with too many false positives, causing alert fatigue. This whitepaper outlines the historical problems with legacy SCA tools and offer new ideas to remedy these shortcomings.
Read More >