Unlike our competitors, you can integrate STRATUM quickly and easily into your existing ecosystem and not worry about significant security or compliance changes. Everything surrounding our small surface area is from Platform One’s Iron Bank or from your own vetted and approved Linux operating system.

FIPS Compliance note: STRATUM’s Continuum Mesh uses FIPS-approved cryptographic algorithms through the Go FIPS 140-3 Crypographic Module.
Our supply chain is the Department of War’s Iron Bank container image repository. We are using the security-oriented Alpine Linux container image. This image has FIPS compliance, NIST/RMF compliance configuration, and a vulnerability remediation pipeline.
https://p1.dso.mil/iron-bank


For our base container image:
Iron Bank repository link
Vulnerability Asessment Tracker link
Download all scans and reports
View all known CVEs, findings, and justifications for this image
SBOM: Download spdx
SBOM: Download CycloneDX
Your Datacenter Is an Application. Scan It Like One.
Using our internal DevSecOps pipeline, below is a vulneraility scan and SBOM of the STRATUM Enterprise container that includes the base Alpine Linux and STRATUM software. To ensure security of our Enterprise customers, these require a login. Contact us for more details.
Grype vulnerability scan results
Syft SBOM results