Scutiva OSS
Self-hosted, agentless security posture and SBOM for Linux fleets.
Scutiva is an open-source, self-hosted security operations portal for Linux hosts. You add a server with SSH credentials, pin its host fingerprint, and Scutiva installs its toolchain remotely. No agent to deploy or maintain, no hosted control plane, nothing leaves your infrastructure.
From there it runs Lynis posture checks, generates a software bill of materials with Syft, correlates package vulnerabilities with Grype, and scans filesystems with Trivy for vulnerabilities, misconfigurations, secrets and licence signals. Findings land in a live operator workflow with dashboards and generated reports.
It is deliberately not an external attack-surface scanner. Its pitch is authenticated evidence about what is actually installed, which is the question most vulnerability tools answer by guessing from the outside. MIT licensed; pull requests welcome.
- Agentless onboarding: add a host with SSH credentials and pin its fingerprint.
- Remote toolchain installer puts the scanners on the box for you.
- Application-root discovery, SBOM generation and CVE correlation.
- Linux posture and hardening audit.
- Filesystem scans for vulnerabilities, misconfigurations, secrets and licence signals.
- PostgreSQL-backed scheduler and worker queue, no extra infrastructure.
- Findings workflow, dashboards and generated reports.
| Item | Layer | Component |
|---|---|---|
| 01 | Framework | Django with split settings |
| 02 | Database | PostgreSQL for storage and for the worker queue, using FOR UPDATE SKIP LOCKED |
| 03 | Remote access | Paramiko over SSH with pinned host fingerprints; no agent on the host |
| 04 | Scanners | Lynis (posture), Syft (SBOM), Grype (CVE correlation), Trivy (filesystem, secrets, misconfigurations, licences) |
| 05 | Front end | HTMX, Alpine.js, Tailwind CSS |
| 06 | Hosting | Self-hosted only; there is no Scutiva cloud |
Integrations
Tell us what to build.
A web app, a mobile app, a platform, an integration nobody else wants to touch. Send the brief, we reply with questions, a scope and a price.