Who trusts Getup
The problem goes beyond known vulnerabilities. It lies in the images and components you run without knowing who built them, with what, and why.
You trust it because "it's the standard." But without traceability, there is no safety, only habit.
A “zero-CVE” image means nothing if:
It is not enough to be "CVE-free." A secure image needs to be auditable and traceable.
What criteria define a
production-ready image?
Criterion
Getup Image
Attack surface (CVEs)
CVEs resolved in the base,
daily.
Base provenance
Built with total control and guaranteed traceability.
Image signature
Signed with Cosign.
SBOM
Complete SBOM integrated into the build process.
Minimum runtime
Minimal image: only what is necessary for safe execution.
Security starts at the first build!
Fixes applied in the build
Minimal, regularly updated images to deliver virtually zero CVEs and a drastically reduced attack surface from day one.
Automatic and daily builds
Updates applied automatically based on upstream changes; no scripts, no manual intervention.
Integrated SBOM, signing, and provenance
Each image includes SBOM and provenance history, ready
for audit at any
time.
Mirror for your registry, with webhook support
Images can be mirrored to your registry. A webhook notifies your pipeline when a new version with security fixes is available.
SLA for critical and high vulnerabilities
Corrections applied in up to 7 days, with deadlines guaranteed by enterprise-level SLAs.
by participating, you:
Eliminates the burden of managing
CVEs.
Reduces friction with audits and the supply chain.
Collaborates directly with our engineering team.
Powered by Getup
Social


