Every Vulnerability, One Prioritised List.

Reysys scans your container images, GitLab repositories and Kubernetes clusters, then scores every finding across CVE, CVSS, EPSS, SSVC and KEV — so your team works down one ranked list instead of thousands of alerts.

Runs as SaaS or self-hosted, in your infrastructure.

The Reysys Action Report ranking packages by exploitability, each row showing KEV and EPSS signals, the CVEs it closes and the upgrade command that fixes them

Your Environment, Your Rules

Reysys runs two ways, with the same scanning and scoring engine in both.

SaaS

Connect your registry, GitLab and clusters. Nothing to operate.

Self-hosted

Deploy the full platform into your own infrastructure. Images, findings and inventory never leave your perimeter, and you decide where it runs.

For teams under national data-residency requirements, self-hosted keeps every artifact and every finding inside infrastructure you control. A separate enrichment service downloads the public vulnerability databases — CVE, KEV and EPSS — so the only thing crossing your boundary is reference data coming in.

One Console, From Image To Cluster

Most teams run one scanner for images, another for repositories and a third for clusters. Three tools, three backlogs, no shared sense of what matters. Reysys analyses all three against the same signals and produces a single ranked list, with the fix attached to each finding.

The Reysys Security Console overview: an Action Report banner, sections for images and packages, source repositories, vulnerabilities, Kubernetes and layers, and panels listing the riskiest images and those with known-exploited vulnerabilities

What Reysys Scans

Three sources, one scan, one ranked backlog.

Container images

Harbor registries: every layer, package and dependency in the images you build and pull.

Source repositories

GitLab projects and their manifests, so fixes land where the code lives.

Kubernetes clusters

Running workloads mapped back to the images and packages behind them, via an agent deployed in-cluster.

How Every Finding is Scored

Six signals, weighed together. Severity alone decides nothing.

CVE

The identifier for the vulnerability itself, traced back to the package and image that introduced it.

CVSS

How severe the vulnerability could be if someone exploited it.

EPSS

The probability that it will actually be exploited in the next thirty days.

KEV

Whether CISA has recorded it being exploited in the wild, not just in theory.

SSVC

The decision framework that turns those signals into an action rather than a number.

CWE

The class of weakness behind the finding, so recurring patterns across your estate become visible.

The result is an order that matches reality: a CVSS 9.8 with no exploit activity ranks below a CVSS 6.5 that appears in KEV.

From Finding to Fix

The report is the workflow. Four steps from a ranked list to a verified fix.

Prioritise

Every finding is ranked by exploitability rather than severity alone, so the top of the list is the work that actually matters.

Group

Findings are grouped by package, so you see one item to fix instead of every CVE it contains.

Remediate

Each group carries the upgrade command that closes it, and the list of CVEs that command resolves.

Verify

Rescan the repository, registry or cluster and the report reflects what actually changed.

Coming soon: a security graph connecting images, packages, workloads and identities, so you can trace a finding through everything it touches.

FAQ

Does Reysys replace my existing scanner?
It can. Reysys ingests findings across images, repositories and clusters, so most teams consolidate rather than add another tool to the stack.
How is Reysys different from a CVSS-only scanner?
CVSS describes how bad a vulnerability could be. EPSS and KEV describe whether anyone is actually exploiting it. Reysys weighs both, so the list you work down reflects real risk instead of theoretical severity.
Which repositories are supported?
GitLab today. Findings are traced back to the specific repository and manifest that introduced the package.
Do I need to install anything in my cluster?
Yes. A Reysys agent runs inside your Kubernetes cluster and maps running workloads back to the images and packages behind them. Your registry and GitLab connect from the console.
Can we run Reysys in our own infrastructure?
Yes. Reysys deploys self-hosted, running the same engine as the SaaS version inside your environment. Images, findings and cluster inventory stay there. A separate enrichment service downloads the public vulnerability databases — CVE, KEV, EPSS — so the only thing crossing your boundary is reference data coming in. Your artifacts never go out.
How often is vulnerability data refreshed?
Results update when you rescan. Run a scan against your repository, registry or cluster and any change since the last run — new packages, new images, new workloads — is reflected in the report.

See your first prioritised report

Connect a registry, a GitLab project or a cluster and Reysys returns a ranked list of what to fix — with the commands to fix it.

Request a demo