Back to the registry
Agent passport

Panoptes: Container Vulnerability Drift Monitoring

Son Cha LLC · Cybersecurity & IT

No attestation published

Certification per AWS Marketplace.

Provenance reach4 of 12 layers traced

Evidence tier Source Confirmed · 4 captures on record

User ratingNot rated0 reviews on the listing
Runs onUnknownContainer
ProvenanceUnknown44% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on AWS Marketplace.

Most scanners look at an image once, at build or push. That's useful, but the CVE feed doesn't stop when you deploy. A package that was clean on Tuesday can pick up a critical on Friday, and the container already running in ECS or EKS has no idea.

Panoptes keeps one SBOM per deployed image digest and diffs new disclosures against that live inventory. If a previously-clean image becomes vulnerable, you get one alert for the fleet event, not one per replica. How fast you find out depends on the feed, not on when the next nightly scan happens to run.

Show the rest of the publisher’s description (1 more line)

It ships as a single container in your VPC. Generate SBOMs with the bundled agent (dpkg/apk today) or import CycloneDX/SPDX from Trivy, Syft, or whatever you already use. Metering is per digest, so a shared base image across fifty services is billed once. Growth covers up to 20 images. Business goes to 50, with more feeds and ticketing. Enterprise is a private offer if you need compliance exports and an SLA.

Highlights

Highlighted by the publisher on AWS Marketplace.

Watches images after they ship. When a new CVE lands, you hear about it then, not at the next cron job.

One alert per CVE against the fleet, not one per replica. You get paged for the event, not the replica count.

Runs in your VPC as a single container. Bring your own SBOMs or generate them with the bundled agent. Billed per image digest.

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Plans and pricing as listed

9 listed
Growth (up to 20 images)
  • Units
$500.00
P1M
Growth (up to 20 images)
  • Units
$5,000.00
P12M
Growth (up to 20 images)
  • Units
$10,000.00
P24M
Business (up to 50 images)
  • Units
$1,000.00
P1M
Business (up to 50 images)
  • Units
$10,000.00
P12M
Business (up to 50 images)
  • Units
$20,000.00
P24M
Enterprise (unlimited)
  • Units
$1,500.00
P1M
Enterprise (unlimited)
  • Units
$15,000.00
P12M
Enterprise (unlimited)
  • Units
$30,000.00
P24M

Refund terms

As stated by the publisher on AWS Marketplace.

We don't refund usage that already ran. If you were billed by mistake, or you never got the container running, email support@sonchallc.com within 30 days of the charge. Include your AWS account ID and the invoice. We'll check the metering records and sort it out. Private offers: sales@sonchallc.com.

Sources

Marketplace listingaws.amazon.comSource
App certificationaws.amazon.comSource
StandardEulaStandardEulaSource

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Paid
9 plans listed
Delivery
Container
Email support@sonchallc.com for product questions, setup, and Marketplace issues. Sales and private offers: sales@sonchallc.com. Security disclosures: security@sonchallc.com. Growth: community support, we answer as we can. Business: replies during US business hours (Pacific). Enterprise: named contact and an SLA, arranged as a private offer. Docs and the source live with the product. We don't run a phone line; email is the fastest way to reach someone who actually works on this.
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.