An agentless security scanner that reveals your infrastructure's CVE exposure and security posture — in the terminal or as a shareable web dashboard. Built for developers and sysadmins who want low-friction visibility.
Three steps from zero to a full security posture report. No agent installation, no persistent daemon, no configuration hell.
Scans all installed packages against the NVD/CVE database. Finds known vulnerabilities with CVSS scores, descriptions, and remediation links.
A 0–100 security posture score calculated from CVE severity, exposure surface, and configuration weaknesses. Instantly comparable over time.
Every scan generates a shareable web report link. Clean, readable by non-technical stakeholders — no terminal required to understand the findings.
A clean terminal output for developers and sysadmins. Color-coded severity, filterable results, and CSV export for integration with other tooling.
No persistent agent. No daemon running on your servers. Portray runs on-demand and exits cleanly — minimal footprint, maximum visibility.
Anthropic API integration explains findings in plain language — what each CVE means for your specific context, and what to fix first.
Portray is open-source under the MIT license. Use it freely for personal and commercial projects. Contributions, bug reports, and feature requests are welcome on GitHub.
Run Portray on your infrastructure, then book a call with our team to walk through remediation — we'll prioritize and guide you through every finding.
Discuss My Findings