Container Dependency Firewall
Every Docker and OCI image layer is scanned for malware, secrets and vulnerable OS packages before it reaches developers or a production node.
EU-based company · Software supply chain security since 2018.
Easy setup, no changes to your workflow
Log in once and pull as before. Your tooling never notices. Docker, crane and oras talk to the firewall the same way they talk to any registry. From then on, every image your team pulls is checked against your rules.
# Log in to a specific firewalldocker login <firewall-host> \-u <namespace>/<firewall-id> -p <token># Pull an image from the firewalldocker pull <firewall-host>/alpine:3.20
What the firewall checks on every pull
- Block images with known CVEs
- Bytesafe matches every installed OS package against current advisory data. Set a CVSS or EPSS threshold, and images with vulnerabilities above it are blocked.
- Find malware and secrets in every layer
- Every layer is scanned, and findings apply to the whole image. A secret key committed in an early layer is still reported when a later layer deletes the file, because the layer holding it still ships.
- Delay newly published tags
- Set a minimum age, and a tag published this morning is held until it has been public for that long. It is the same safety delay Bytesafe applies to new package versions, based on the image's own build date.
- Block by name, tag, age or source
- Match on repository, tag, release age or upstream, then block or log. When a team needs a blocked image, grant a time-limited exception from the block entry.
Findings grouped by the build step that introduced them
Each build step carries its own severity counts, so you can tell a finding that came with the base image from one your build added.

Package inventory read from the image
Inventory comes from the package databases inside the image.

Supported OS package formats
Three package formats, covering the base images almost every container starts from.
- apk
- Alpine
- dpkg
- Debian, Ubuntu, and distroless images
- rpm
- RHEL, Fedora, CentOS, SUSE
Offer now
50% off your base fee for 3 months + €100 usage credit.
Creat policies from simple rules
Match on repository name, tag, release age, upstream or upstream type. Add malware, secrets and vulnerability checks on top. Each rule blocks, logs, or both.

Logs show the image, the rule and the user
Blocked pulls list the image, the tag, the rule and the user. Exceptions can be granted from the block details and expire on a date you set.


Works with any OCI registry
Docker Hub, GitHub Container Registry, Amazon ECR, Google Artifact Registry, Artifactory, Harbor, or a registry you run yourself. Each one is configured as an upstream with its own credentials.
Frequently asked questions
Common questions from security and platform teams.
Do I have to change my Dockerfiles?
Does it work with Kubernetes?
What happens on the first pull of an image nobody has pulled before?
A CVE is published three months after an image was scanned. Is it caught?
How are multi-arch images handled?
Which OS package formats are supported?
Which registries can it proxy?
Can someone pull a blocked layer directly?
Which clients work with the firewall?
Does it replace my container registry?
Bytesafe Platform
Software Supply Chain Security and Transparency
Three products that block risky packages at install, collect supplier transparency documents, and analyze them.
Dependency Firewall
Block vulnerable and malicious packages before they reach your developers. Sits in front of your existing repository.
You are on this pageTrust Repository
Collect SBOM, VEX and end-of-life documents from your suppliers, and publish your own to your customers.
Product pageSBOM Observer
Analyze SBOMs for vulnerabilities, license risks, and compliance. Continuous monitoring across your software portfolio.
Product page
Book a demo
A 30-minute session where we pull a real image through a firewall with your rules. Your registries stay where they are.