MAYA - AI Agent
Team Leader of AI Agents
Remediation Agent
Runs a dry run, waits for your approval, then fixes it
Evidence Collector
Collects your SOC 2, ISO 27001 and DPDP proof from the tools you already use
IP Scanner
Checks every public address for open ports, known CVEs and weak TLS
DAST (Public + Private)
Tests your APIs for 300+ vulnerability classes, inside and outside the network
CSPM
1,000+ checks across AWS, Azure and Google Cloud, mapped to your frameworks
Cloud Cost Optimization
Rightsizing and idle detection - customers cut cloud spend 28% on average
Integrations
20+ Integrations with your favorite tools
Asset Management
Finds vulnerabilities on your laptops and servers
ECR Container Image Scanning
Scans every ECR image for CVEs before it reaches production
Cloud Security
Keeping AWS, GCP and Azure locked down
AI Governance
Using AI at work without losing control of it
Data Privacy
DPDP, GDPR and looking after personal data
GRC
Audits, controls and staying ready for them
FinOps
Spending less on cloud without breaking things
API Security
Finding holes in your APIs before anyone else
ECR Container Image Scanning Secure your containers from the inside out.
Scan every container image in your Amazon ECR repositories for known CVEs, misconfigurations, and compliance violations - before they reach production.
ECR Container Image Scanning at a glance
- What it does
- Scan every container image in your Amazon ECR repositories for known CVEs, misconfigurations, and compliance violations - before they reach production.
- In one line
- Scan every ECR image for CVEs before they reach production.
- Human control
- It scans the image, not the running container.
- Setup
- About 15 minutes, read-only access, no credit card.
- Pricing
- Free first scan; Pro from $99/month; Enterprise from $10,000/year. See pricing.
The flaw is not in your code. It is in the base image.
You pinned a base image months ago and it has been rebuilt into every release since. Your own code gets reviewed. The packages you inherited from that image do not, and one of them now has a fix you have never heard of.
Four steps to done.
- 01ECR Connect
Connect your Amazon ECR registry in minutes. No agents, no pipeline changes - just IAM role access.
- 02Image Scanning
Scan all images across all repositories for known CVEs, outdated packages, and misconfigured layers.
- 03CVE Detection
Cross-reference findings against the National Vulnerability Database for accurate CVE identification and CVSS scoring.
- 04Report & Prioritize
Get severity-sorted findings with base image recommendations and specific package-level fix guidance.
Everything included.
Scans all images across all ECR repositories
CVE detection with CVSS scoring and NVD cross-reference
Critical, High, Medium, Low severity classification
Base image upgrade recommendations to reduce attack surface
Package-level remediation guidance for every finding
Historical scan comparison to track remediation progress
It scans the image, not the running container.
Images are read from your registry and compared against the vulnerability feed, so a scan costs your cluster nothing. Each finding names the package, the version that fixes it, and whether the flaw is known to be exploited - so you rebuild what matters first.
- It reads images in your registry. It does not attach to running containers.
- A flaw in a base image needs a rebuild. There is no patch we can apply to an image for you.
- It matches package versions against a public feed, so a vendor backport can look unpatched until the feed catches up.
Common questions about ECR Container Image Scanning.
Scan every container image in your Amazon ECR repositories for known CVEs, misconfigurations, and compliance violations - before they reach production. Scan every ECR image for CVEs before they reach production.
1. ECR Connect: Connect your Amazon ECR registry in minutes. No agents, no pipeline changes - just IAM role access. 2. Image Scanning: Scan all images across all repositories for known CVEs, outdated packages, and misconfigured layers. 3. CVE Detection: Cross-reference findings against the National Vulnerability Database for accurate CVE identification and CVSS scoring. 4. Report & Prioritize: Get severity-sorted findings with base image recommendations and specific package-level fix guidance.
It reads images in your registry. It does not attach to running containers. A flaw in a base image needs a rebuild. There is no patch we can apply to an image for you. It matches package versions against a public feed, so a vendor backport can look unpatched until the feed catches up.
Connecting takes about 15 minutes with read-only access. No credit card and no sales call are needed to run the first scan.
It is included in DeDups: one full scan of one AWS account is free with no card, Pro is $99 a month plus published per-unit rates, and Enterprise starts at $10,000 a year. All rates are on the pricing page.
Ready to try ECR Container Image Scanning?
15 minutes to connect. No credit card. No sales call required.