Security Stack Logo
Root Platform logo

Supply Chain SecurityContainer Security

Root Platform

CVE-first autonomous remediation for container images and open-source dependencies, delivering zero-CVE images and backported patches at pinned versions without forced upgrades.

Hardened Container ImagesAutonomous Vulnerability Remediation

Root Platform Overview

Root Platform is a container and open-source dependency security product built on a CVE-first remediation model: instead of rebuilding software from source or forcing version upgrades, it patches the exact versions a team already runs. Its core mechanism, Agentic Vulnerability Remediation (AVR), uses a fleet of specialized AI agents triggered by a Common Vulnerabilities and Exposures (CVE) publication to research, build, test, and ship a production-ready fix, typically in 15 to 40 minutes, with no breaking changes to the running stack.

The platform delivers fixes through two catalogs and a standalone patch stream. Root Image Catalog provides 2,000+ continuously remediated base images across Python, Node, Java, Go, and 40 more ecosystems as drop-in replacements pulled from cr.root.io. Root Library Catalog backports the smallest safe fix to pinned application dependencies, reaching transitive dependencies up to five layers deep. Root Patches ship reproducible artifacts for legacy systems that cannot be upgraded. Every artifact carries a Software Bill of Materials (SBOM), a Vulnerability Exploitability eXchange (VEX) statement, and Supply-chain Levels for Software Artifacts (SLSA) build provenance. Named customers include DeleteMe, SiXworks, and BigID.

SOC 2 Type II certified and Cyber Essentials certified, with SLSA Level 2 build provenance and Docker Hub Verified Publisher status. Root is a contributing member of the Cloud Native Computing Foundation (CNCF), a global member of OWASP, and a voting member of OASIS, contributing to supply chain security and attestation standards. Remediation is backed by tiered service level agreements with CISA Known Exploited Vulnerabilities (KEV) escalation, targeting DevOps, platform, and security teams in regulated sectors such as defense and FinTech.

Key Capabilities

mapped to solution categories
Autonomous Vulnerability Remediation

Applies OS and application patches to vulnerable systems automatically based on configurable risk thresholds, without requiring per-patch analyst approval.

Creates ITSM change records (ServiceNow, Jira Service Management), as part of the patch workflow, maintaining audit trail and change management compliance.

Hardened Container Images

Monitors managed SBOMs against the NVD, OSV, and vendor advisories, alerting when newly published CVEs match components in any tracked SBOM.

Signs image manifests with Sigstore/Cosign or Notary v2, enabling downstream consumers to verify image integrity and provenance before deployment.

Compliance

certifications
SOC 2 Type II

Integrations

compatible tools
Aikido SecurityAmazon ECRAqua SecurityAWSAzure Container RegistryClaude CodeCodexComposerDocker HubGoogle Container RegistryGradleJiraMavennpmNuGetPyPIServiceNowSlackTrivy

Implementation & support

Deployment model
CloudSaaS
Pricing structure
Free TierSubscription
Support channels
DocumentationEmail Support

Info last updated on June 26, 2026