1M+ scans completed
Cumulative scan volume across SBOMs, container images, source repos, manifests, and live runtime agents — across every customer tenant, every region, since Safeguard launched.
Scan volume today
What the platform sustains, and what it has accumulated.
Hundreds of scans / minute sustained, with elastic burst capacity.
Steady-state at current customer base. Scales linearly per added tenant.
Crossed in 2026. Tracked via signed scan-result attestations.
By scan type
Where the volume comes from — SBOMs lead, container images follow.
How scans are counted
The rules behind the headline figure.
One scan = one signed attestation. Every scan emits an in-toto attestation signed by the regional cluster’s sigstore identity. The 1M+ figure is the cumulative count of those attestations across all tenants since the platform launched.
Re-scans count. A package re-scanned after a new CVE lands counts as a new scan — that’s the work being done. Continuous monitoring drives most of the volume; spot scans are a small fraction.
Customer attribution is hashed. The aggregate count is global; per-customer counts stay in each customer’s tenant. Nothing is cross-attributed in the public number.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.