Security Stack Logo
Root Platform logo

Supply Chain SecurityContainer Security

Root Platform

CVE-first autonomous remediation delivering zero-CVE images and backported patches in place.

Hardened Container ImagesAutonomous Vulnerability Remediation

Root Platform Overview

What it does

Root Platform is a container and open-source dependency security product built on a CVE-first remediation model: instead of rebuilding software from source or forcing version upgrades, it patches the exact versions a team already runs. Its core mechanism, Agentic Vulnerability Remediation (AVR), uses a fleet of specialized AI agents triggered by a Common Vulnerabilities and Exposures (CVE) publication to research, build, test, and ship a production-ready fix, typically in 15 to 40 minutes, with no breaking changes to the running stack.

How it works

The platform delivers fixes through two catalogs and a standalone patch stream. Root Image Catalog provides 2,000+ continuously remediated base images across Python, Node, Java, Go, and 40 more ecosystems as drop-in replacements pulled from cr.root.io. Root Library Catalog backports the smallest safe fix to pinned application dependencies, reaching transitive dependencies up to five layers deep. Root Patches ship reproducible artifacts for legacy systems that cannot be upgraded. Every artifact carries a Software Bill of Materials (SBOM), a Vulnerability Exploitability eXchange (VEX) statement, and Supply-chain Levels for Software Artifacts (SLSA) build provenance. Named customers include DeleteMe, SiXworks, and BigID.

Credentials and traction

Root Platform is SOC 2 Type II certified, ships SLSA build provenance with every artifact, and holds Docker Hub Verified Publisher status for its remediated base images. Root is a Contributing Member of the Cloud Native Computing Foundation (CNCF) and an OWASP Global Member, and it supports OASIS, contributing to supply chain security and attestation standards. Named customers include DeleteMe, SiXworks, and BigID, with adoption concentrated among DevOps, platform, and security teams in regulated sectors such as defense and FinTech.

Key Capabilities

mapped to solution categories
Autonomous Vulnerability Remediation

Applies OS and application patches to vulnerable systems automatically based on configurable risk thresholds, without requiring per-patch analyst approval.

Creates ITSM change records (ServiceNow, Jira Service Management), as part of the patch workflow, maintaining audit trail and change management compliance.

Hardened Container Images

Monitors managed SBOMs against the NVD, OSV, and vendor advisories, alerting when newly published CVEs match components in any tracked SBOM.

Signs image manifests with Sigstore/Cosign or Notary v2, enabling downstream consumers to verify image integrity and provenance before deployment.

Compliance

certifications
SOC 2 Type II

Integrations

compatible tools
Aikido SecurityAmazon ECRAqua SecurityAWSAzure Container RegistryClaude CodeCodexComposerDocker HubGoogle Container RegistryGradleJiraMavennpmNuGetPyPIServiceNowSlackTrivy

Implementation & support

Deployment model
CloudSaaS
Pricing structure
Free TierSubscription
Support channels
DocumentationEmail Support

Info last updated on June 26, 2026

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.