Real-time vulnerability intelligence
Know what’s vulnerable. Right now.
Rust Riders watches the packages actually installed across your fleet and shows you every CVE that affects them — in real time, with nothing to configure.
- jittered agent check-in interval
- 30–60 s
- typical mTLS gRPC call
- ~1–1.5 ms
- short-lived x509 certificates
- 7 days
- OCSP on every call, fail-closed
- 4-way
The problem
CVEs arrive faster than any team can triage by hand.
In the age of AI, CVEs flood in faster than any team can keep up with. The hard question isn’t “is there a new vuln” — it’s “are we affected, where, and how urgently, right now?” Stale scans and timed-out agents can’t answer fast enough.
Blue teams
A real-time answer to “am I exposed right now?” — across the entire fleet.
DevOps teams
A live, accurate inventory of what’s actually running — not what a stale scan remembers.
GRC teams
Audit-grade evidence that’s always current — not a point-in-time snapshot.
How it works
From installed package to answered question.
- 1
An agent reports
A lightweight Rust agent on each host reports installed software on a jittered 30–60 second interval. The jitter prevents thundering-herd spikes.
- 2
Trust is verified on every call
Communication is gRPC over mTLS — most calls take ~1–1.5 ms, so thousands of nodes stay responsive. Every call runs 4-way OCSP, fail-closed: revoke a host and it’s cut off fleet-wide, instantly.
- 3
Matched against refined CVE data
CVE data is a refined blend of NIST and OSV, with KEV and EPSS enrichment in progress.
- 4
Answered in real time
A real-time web app shows every CVE affecting your fleet — backed by a database that belongs to your organization alone.
Nothing to misconfigure
Licensing and auth use short-lived 7-day x509 certificates over our own PKI, with configuration baked into a certificate OID as bitflags. There’s no config file to get wrong — and no drift.
Why Rust Riders
Different by design.
Per-org database isolation
Every organization gets its own database, so cross-org contamination is architecturally impossible — not just a policy promise.
4-way OCSP, fail-closed
Trust is verified on every call. Revoke a host and it dies fleet-wide, instantly.
Unconfigurable by design
Configuration lives in the certificate, baked into an OID as bitflags. There’s no config file to get wrong — and no drift.
Hand-written, no AI
Every line written by hand. We have zero intent to be an “AI-built” company or chase the hype. Deterministic and explainable, on purpose.
BSD as a first-class citizen
Debian, RHEL, FreeBSD, OpenBSD, NetBSD, and DragonFly BSD — all as equals. We’re BSD contributors, and we promised we’d treat BSD as first-class.
Privacy by architecture
Independent hosting — not AWS, GCP, or Azure. No telemetry, no tracking, no data collection or sale. The only thing we hold on you is your email.
The proud no’s.
- ✗ no big-three cloud
- ✗ no Docker or Kubernetes
- ✗ no telemetry
- ✗ no tracking
- ✗ no data sales
- ✗ no AI
- ✗ no 6-digit TOTP
Platforms
BSD is a first-class citizen here.
Debian, RHEL, FreeBSD, OpenBSD, NetBSD, and DragonFly BSD — all as equals. We’re BSD contributors, and we promised we’d treat BSD as first-class. Almost no one else does.
- Debian
- RHEL
- FreeBSD
- OpenBSD
- NetBSD
- DragonFly BSD
Windows and macOS agents are on the roadmap.
Pricing
Flat and simple.
Free
forever, for up to 3 nodes.
$5/node/mo
flat, beyond that. No tiers, no surprises.
10%
of all profit goes to non-profits — and non-profits get a discount.
Planned pricing for general availability. Rust Riders is currently in private staging.
Help shape Rust Riders.
We’re roughly 80% ready and in private staging — the backend is fast and hardened, and the frontend is being polished. Pilot participants come in first.
Join the pilot program