Base image management platform

From security finding to governed fix.

See where base images are used. Set the approved path forward. Get the fix into your teams’ normal workflow.

Live control plane
Repository estate37 image references
Published policyApproved destination
Reviewable changePull request ready

The governance loop

One continuous route from risk to resolution.

Updating one image is simple. Keeping every base image current across an organization is not. BIMP closes the operational gap between security, platform and development teams.

  1. 01

    Discover

    Find base-image references across the repositories and branches you choose.

  2. 02

    Decide

    Apply published policy and identify the approved destination for each image.

  3. 03

    Explain

    Show the health, policy and remediation state behind every decision.

  4. 04

    Remediate

    Open or update a reviewable pull or merge request in the team's workflow.

  5. 05

    Handle exceptions

    Capture time-bound snooze requests with context, review and expiry.

  6. 06

    Prove

    Retain who decided what, why it changed and what happened next.

The organization view

Know what needs attention now.

See organizational health, active security work, pending decisions and unmanaged images together—so each team can move from posture to action.

BIMP organization overview showing health score, security incidents, tasks to review and unmanaged images
BIMP provides one live view of repository health and operational follow-through.

What to expect

Control without taking control away.

BIMP puts policy and remediation into the tools and delivery controls your organization already trusts.

A current inventory

Track supported Dockerfiles, Compose files, devcontainer definitions and conventional Helm values. Start with visibility, then introduce policy in stages.

Policy teams can act on

Create versioned Policy Groups, scope them to the right repositories and branches, and preview their impact before publishing.

Ready-to-review remediation

Deliver the approved replacement through GitHub pull requests or GitLab merge requests, with the rationale and review metadata teams need.

Controlled exceptions

Turn delays into explicit, expiring decisions—not context that disappears into chat or an untracked ticket.

Visibility and evidence

Follow repository health, ownership, incidents and remediation progress, backed by an audit record of every decision.

Clear boundaries

Built to orchestrate—not replace.

BIMP is a base-image governance and remediation platform that works with the image providers, registries, code hosts and delivery controls you choose.

BIMP is not a vulnerability scanner, base-image provider, or replacement for security review, CI, testing, approval or deployment.

Make remediation business as usual

Move from finding base-image problems to governing and fixing them.

Without creating another queue for developers to watch.

Join the closed beta