Cloud & Container Security

ELYRA module

ELYRA
Container image analysis, remediation, audit and compliance.

ELYRA is the SerenityForesight operational interface for image scanning, deep SBOM assessment, licenses verification, guided remediation and production of traceable technical evidence supporting audit and regulatory compliance.

Overview

A proactive tool to reduce application exposure

ELYRA is designed to manage the technical security lifecycle of container images in a clear flow: upload, scanning, classification of findings, optimization and comparison between the 'initial state' and the 'remediated state'.

The goal is not only to display a list of CVEs, but to turn analysis into a controlled, traceable workflow which can be understood by technical teams as well as security, governance and compliance stakeholders.

Every step is built to produce verifiable outputs: reports, SBOM, audit trail, license checks and before/after remediation results, with evidence mapped directly in the portal.

ELYRA has also been developed to help organizations demonstrate, through tangible technical evidence, alignment with major European regulations and other frameworks of interest for their operating context, such as NIS2, DORA, GDPR and the AI Act.

  • Guided image upload and scanning
  • Correlation between vulnerabilities, components, licenses and risk
  • Final audit with evidence of the achieved reduction
  • Integrated regulatory compliance, traceable in the portal

ELYRA capabilities, organized by operational process.

Security Scan & Audit

Scanning interface integrated into the portal: image upload, live logs, technical findings, SBOM, license status and initial audit mapped to relevant regulations.

Security Remediation

Remediation execution, review of optimized results, updated audit and secured archive download with comparison between baseline and final state.

SBOM Intelligence

Generation of a deep SBOM that does not stop at first-level findings: it indeed reconstructs full chains of components, packages, libraries, transitive dependencies and technical relationships inside the image.

License Intelligence

Analysis of detected software licenses, validation of their status and support for assessing compatibility, obligations and potential usage concerns.

Compliance Evidence

Mapping of findings and technical evidence to European regulatory requirements and frameworks, supporting audits, internal reviews and governance documentation.

Risk Evidence

Results summary with comparable metrics, vulnerability status, license impact and support for risk-based decisions.

Live Execution Log

Monitoring of job status during scanning and remediation, with technical events useful for operational troubleshooting and activity reconstruction.

Secured Artifact

Production of the final remediated output, with updated report, recalculated SBOM and package ready for verification or controlled deployment.

Operational flow

From scan to remediated result

The ELYRA process starts from the source image and builds a technical baseline: detected components, vulnerabilities, licenses, potential secrets, image size, dependency chains and SBOM status.

The remediation then applies an optimization process aimed at reducing unnecessary components and exposed surface, while preserving traceability of results and their link to findings, licenses and regulatory requirements.

The final result is ultimately compared with the initial baseline, making clear what are the changes, what is the achieved exposure reduction and what are the evidences which can be reused in audit processes.

  • Initial baseline before remediation
  • Deep SBOM with transitive dependencies and complete chains
  • License verification and compliance-requirement traceability
  • Final results with updated audit and controlled download
SerenityForesight report

Audit and traceability

Technical outputs for security review and compliance

ELYRA results are designed to be used both during technical work and review activities: findings, severity, involved components, SBOM, licenses, remediation status and compliance references remain consistently available in the portal.

This approach helps document the improvement achieved, supports internal validation and reduces the time required to prepare evidence for technical stakeholders, audits, DevSecOps processes as well as checks related to applicable European regulations.

The SBOM is not treated as a static attachment: it becomes an intelligence base to reconstruct relationships, dependencies, full chains and licensing implications, going beyond a limited view of the most immediate findings only.

  • Before/after remediation reports
  • Updated SBOM after optimization with complete dependency chains
  • License verification, validity and associated obligations
  • Structured evidence for audit trail, technical review and compliance