Skip to content

Software Composition Analysis

OtterSight: Know what’s inside your software.

OtterSight scans your repos for vulnerabilities, outdated dependencies, and license risks. SBOM, CVE monitoring, and EU Vulnerability Database — in one tool.

GDPR compliant · Data on Hetzner DE · No customer code stored


How it works

Connect repo

Link your GitHub repo. OtterSight clones ephemerally — no source code is stored.

Automatic scanning

Syft generates the SBOM, Grype checks for CVEs, the EU Vulnerability Database provides current data.

Instant alerts

New vulnerability? Slack, Discord, Telegram, email, or 300+ other channels via Apprise.


The only SCA scanner with EU Vulnerability Database.

  • 20+ ecosystems via Syft: npm, pip, Go, Rust, Java, .NET, and more
  • CycloneDX 1.6 SBOMs for every repository
  • CVSS + EPSS + KEV scoring for prioritized vulnerabilities
  • EUVD integration — the only provider on the market
  • Version drift detection with automatic alerts
  • Multi-tenant: your team, your data, cleanly separated

Limited Time

Become a Founding Member

EUR 5/mo locked forever · 15 repos · Automatic daily monitoring · 100 spots only

Limited to 100 founding spots
Learn more & claim your spot

Get early access

Join the waitlist and be the first to know when new spots open up.

Founding Members: €5/mo locked forever — 100 spots only

No spam. We'll only email you when early access launches.