Greenbone

Osnabrück's open-source OpenVAS vulnerability scanner, with enterprise appliances on top

Quick Overview

Company Greenbone AG
Category Web Security
Headquarters Osnabrück, Germany
Founded 2008
EU Presence EU (Germany)
Data Location Germany
Open Source Yes
Compliance ISO 9001, ISO 27001
Pricing Free OpenVAS / Community Edition; Greenbone Enterprise appliances from OPENVAS BASIC at €2,524 per year
Free Option Free Community Edition (OpenVAS)
Replaces Tenable Nessus, Qualys VMDR, Rapid7 InsightVM

Detailed Review

Pros and Cons

Pros

  • Open-source scanning engine (OpenVAS/GVM), inspectable by anyone
  • Free Community Edition with no licence cost
  • Enterprise appliances with maintained feed from €2,524/year
  • ISO 9001 and ISO 27001 certified
  • German company, EU jurisdiction

Cons

  • Finds vulnerabilities; does not block attacks itself
  • Self-hosted use requires real in-house expertise
  • Enterprise appliance pricing is on top of the free core
  • Less polished interface than SaaS-first competitors

Alternatives to Greenbone

See all web security →

Frequently Asked Questions

What is Greenbone?

Greenbone builds on OpenVAS, the vulnerability scanning engine it has maintained as open source since the company's founding in 2008, and that lineage is the whole pitch: the scanning engine and its vulnerability tests can be inspected, self-hosted and run at no licence cost, rather than trusted on the vendor's word. OpenVAS Free and the Community Edition let anyone try the same core engine that the paid appliances run.

Where is Greenbone based?

Greenbone operates from Osnabrück, Germany, which places it under EU (Germany). Compliance: ISO 9001, ISO 27001.

What does Greenbone cost?

Free OpenVAS / Community Edition; Greenbone Enterprise appliances from OPENVAS BASIC at €2,524 per year. Free Community Edition (OpenVAS).

Who is Greenbone best for?

Organisations that want an open-source vulnerability scanner they can run themselves. An open-source scanning engine you can audit yourself, with a paid feed on top rather than instead of it.

What are the drawbacks of Greenbone?

Finds vulnerabilities; does not block attacks itself. Self-hosted use requires real in-house expertise. Enterprise appliance pricing is on top of the free core. Less polished interface than SaaS-first competitors.

Who worked on this review

Three people touch every tool page: one writes it, a second edits it, and a third checks the compliance and pricing claims against the vendor's own documentation.

Daniel Brandt
Written by

Daniel Brandt

Privacy & Compliance Researcher · Berlin, Germany

Checks the compliance claims: where the company is established, where the data sits, and what the DPA actually says.

Sebastiaan Smits
Edited by

Sebastiaan Smits

Founder & Editor · Netherlands

Selects the tools, writes the reviews, and checks where each company is actually established.

Marta Kowalczyk
Fact-checked by

Marta Kowalczyk

Senior Analyst, Infrastructure & Developer Tools · Warsaw, Poland

Covers hosting, developer tooling and the practical side of moving workloads to European providers.

Read our editorial process for how we source, verify and update these pages — and how we keep affiliate income separate from what we recommend.

Go to Greenbone