Open-source vulnerability management. One binary. No Docker tax.

RiskRancher Core ingests Qualys, Nessus, Trivy, or any scanner export through a no-code Adapter Builder, then tracks remediation in an air-gapped ticket dashboard — without Postgres, Redis, or a Kubernetes hobby project.

Download Free CoreView on GitHub
Apache 2.0 · Single binary + SQLite · Zero telemetry
RiskRancher vulnerability management dashboard

Stop writing glue code for every scanner.

The painful part of vulnerability management isn't finding issues — it's normalizing every tool's JSON into something your team can actually work. RiskRancher does that in the UI.

No-code Adapter Builder

Map any scanner in the UI — no custom parsers.

Upload a Qualys, Nessus, Trivy, Dependabot, or any JSON/CSV export. Point at the findings array, map title / asset / severity, save the adapter, and ingest. No one-off Python scripts. No waiting on an integration roadmap.

No-code Adapter Builder
100% Air-Gapped

Your findings never leave your machine.

Single Go binary — no microservices, no Docker Compose fleet.

Embedded SQLite database on your disk. Completely offline.

Zero telemetry. Zero outbound API calls. Audit-friendly by design.

Air-gapped single binary
Ticket workflow

Group findings by asset and get them fixed.

Deduplicate noise into manageable tickets, track severity and SLA status, and keep security and engineering in one place — so scanner output becomes remediation work, not another spreadsheet.

Asset-based ticket grouping

Start free. Upgrade when the work grows.

Core is Apache 2.0 forever. Auditor ($1,999/yr) turns findings into branded reports for pentesters. Pro ($4,999/yr) adds team automation — flat fee, unlimited assets.

See pricing

From scanner export to tickets in minutes.

Get the Free Core Binary
Linux · macOS · Windows · Zero telemetry

Common Questions

Is RiskRancher really 100% air-gapped?

Yes. RiskRancher is a single binary with zero external API calls. It stores everything in a local SQLite database on your own hardware.

What is the difference between CORE, Auditor, and PRO?

CORE is the free Apache 2.0 engine (ingest, tickets, no-code Adapter Builder). Auditor ($1,999/yr) adds findings↔branded report workflows for pentesters. PRO ($4,999/yr) adds auto-assign, exception pipelines, suppressions, and team automation.

How does the offline licensing work?

We use RSA-signed license keys. Your machine validates the signature locally using our public key—no internet ping required.

Can I import data from Qualys or Tenable?

Yes. Use the no-code Adapter Builder: upload a sample Qualys, Nessus, Trivy, or any JSON/CSV export, map title/asset/severity in the UI, and ingest. No custom parser code required.