Root is an autonomous remediation platform that keeps your container stack secure without forcing upgrades or rebasing. Security, platform, and engineering teams rely on Root to patch base images and application dependencies at the versions they already run, backed by signed proof (provenance, SBOM, VEX, attestation, malware scans).
Five capabilities that eliminate the CVE grind:
Secure Base Images by Default
Swap one line in your Dockerfile to pull Root Image Catalog (RIC) builds with 30-day registry SLA (7-day Enhanced) and 180-second average fix time.
In-Place Library Remediation
Keep pinned dependencies while Root Libraries delivers contracted fix-rate throughput (1–25+/week) with Critical/High priority and CISA KEV escalation.
Secure Base Images by Default
Every fix ships with provenance, attestation, SBOM (CycloneDX), VEX, malware scan, and before/after CVE delta for audit readiness.
of developer time reclaimed per person each week
average publish time for patched RIC images
immediate reduction in scanner noise after adopting RIC
backlog reduction in 6 months with 10 fixes/week Libraries plan
registry availability backed by Root's SLA and service credits
Pricing
Free
Community
500+ images
Continuous patching
No SLA
Paid
RIC
Container bundles ($14K–$66K)
or
unlimited per-seat (from $42K)
Add-On
Libraries
Contracted fix-rate tiers starting at $26K/year
Free
Bundle & Save
15% discount












