
Supply Chain SecurityContainer Security
Root Platform
CVE-first autonomous remediation delivering zero-CVE images and backported patches in place.
Root Platform Overview
What it does
Root Platform is a container and open-source dependency security product built on a CVE-first remediation model: instead of rebuilding software from source or forcing version upgrades, it patches the exact versions a team already runs. Its core mechanism, Agentic Vulnerability Remediation (AVR), uses a fleet of specialized AI agents triggered by a Common Vulnerabilities and Exposures (CVE) publication to research, build, test, and ship a production-ready fix, typically in 15 to 40 minutes, with no breaking changes to the running stack.
How it works
The platform delivers fixes through two catalogs and a standalone patch stream. Root Image Catalog provides 2,000+ continuously remediated base images across Python, Node, Java, Go, and 40 more ecosystems as drop-in replacements pulled from cr.root.io. Root Library Catalog backports the smallest safe fix to pinned application dependencies, reaching transitive dependencies up to five layers deep. Root Patches ship reproducible artifacts for legacy systems that cannot be upgraded. Every artifact carries a Software Bill of Materials (SBOM), a Vulnerability Exploitability eXchange (VEX) statement, and Supply-chain Levels for Software Artifacts (SLSA) build provenance. Named customers include DeleteMe, SiXworks, and BigID.
Credentials and traction
Root Platform is SOC 2 Type II certified, ships SLSA build provenance with every artifact, and holds Docker Hub Verified Publisher status for its remediated base images. Root is a Contributing Member of the Cloud Native Computing Foundation (CNCF) and an OWASP Global Member, and it supports OASIS, contributing to supply chain security and attestation standards. Named customers include DeleteMe, SiXworks, and BigID, with adoption concentrated among DevOps, platform, and security teams in regulated sectors such as defense and FinTech.
Key Capabilities
mapped to solution categoriesApplies OS and application patches to vulnerable systems automatically based on configurable risk thresholds, without requiring per-patch analyst approval.
Creates ITSM change records (ServiceNow, Jira Service Management), as part of the patch workflow, maintaining audit trail and change management compliance.
Monitors managed SBOMs against the NVD, OSV, and vendor advisories, alerting when newly published CVEs match components in any tracked SBOM.
Signs image manifests with Sigstore/Cosign or Notary v2, enabling downstream consumers to verify image integrity and provenance before deployment.
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on June 26, 2026
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.