Back to the registry
Agent passport

Docker Hardened Images (DHI) Enterprise

Docker, Inc. · Cybersecurity & IT

No attestation published

Certification per AWS Marketplace.

Provenance reach4 of 12 layers traced

Evidence tier Source Confirmed · 4 captures on record

User ratingNot rated0 reviews on the listing
Runs onUnknownSaaS
ProvenanceUnknown44% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on AWS Marketplace.

Docker Hardened Images (DHI) provide access to 1,000+ hardened, minimal images that give every team a safer starting point for modern software. By dramatically reducing inherited vulnerabilities, offering complete transparency, and fitting seamlessly into existing workflows, DHI ensures teams can build securely from the first line of code.

For organizations that need guaranteed security and long-term stability, the DHI Enterprise provides enhanced assurances through SLA-backed remediation, FIPS/STIG-ready images, and customizable hardened images. To support applications that must outlive upstream distributions, DHI ELS offers multi-year extended lifecycle protection, keeping critical workloads safe long after official support ends.

Show the rest of the publisher’s description (9 more lines)

Minimal, hardened images with near-zero CVEs

Signed SBOMs and VEX statements

SLSA Build Level 3 provenance

Full CVE visibility with continuous patching

Compatibility with Alpine and Debian

Image Customizations

CVE Remediation SLAs

FIPS and STIG-compatible Images

Extended Lifecycle Support for patching of EOL images for up to 5 years

Highlights

Highlighted by the publisher on AWS Marketplace.

Critical CVE fixes SLA < 7 days

FIPS/STIG variants

Supports PCI DSS, CMMC, CIS

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Compliance

Government
  • FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27

Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.

Vendor

External enrichment

CompanyDocker, Inc.Automated

Plans and pricing as listed

6 listed
DHI Enterprise
  • Units
$1.00
P12M
DHI Enterprise
  • Units
$1.00
P24M
DHI Enterprise
  • Units
$1.00
P36M
DHI Select
  • Units
$1.00
P12M
DHI Select
  • Units
$1.00
P24M
DHI Select
  • Units
$1.00
P36M

Refund terms

As stated by the publisher on AWS Marketplace.

No refunds

Sources

Marketplace listingaws.amazon.comSource
App certificationaws.amazon.comSource
CustomEulaCustomEulaSource

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Paid
6 plans listed
Delivery
SaaS
https://www.docker.com/support/ Docker Support for DHI Enterprise includes the following features: SLA-Backed CVE Remediation: Critical and high vulnerabilities are remediated within 7 days, ensuring rapid response to security threats. Compliance Variants: Access to FIPS and STIG compliant image variants for regulatory and security requirements. Custom Hardening & All-Package Builds: Support for custom hardening and builds that include all required packages. Premium Support & Technical Account Manager (TAM) Options for additional fee: Premium Support is available (with pricing based on ARR), providing enhanced support and guidance. TAMs (Designated or Dedicated) can be added for personalized technical assistance (Premium Support required first). Extended Lifecycle Support (ELS): Option to extend security patching for DHI repositories up to 5 years past upstream EOL (requires corresponding DHI SKU). Professional Services: Access to expert guidance, workshops, accelerator programs, environment validation, and CI/CD integration support.
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.