Softwr

Cybersecurity · head to head

Grype vs Hanwha Vision

Grype logo

Grype

Cybersecurity

Vulnerability scanner for container images and filesystems

From
Free
Rated
-
Hanwha Vision logo

Hanwha Vision

Cybersecurity

Korean camera maker whose Wisenet WAVE VMS licences are perpetual per channel with no annual renewal

From
On request
Rated
-

The short version

  • Only Grype has a free tier, so it costs nothing to try first.
  • Each has a real cost: Grype depends on public vulnerability databases, so coverage and false positives vary by ecosystem; Hanwha Vision nDAA compliance is confirmed per model and per bill of materials rather than across the brand, and TAA status depends on whether a specific unit was made in Korea or Vietnam, so a buyer with procurement obligations must get both stated on the quote rather than relying on a brand-level claim.
  • They diverge on capability: Grype covers Image and filesystem scanning, Hanwha Vision covers Wisenet WAVE VMS.
  • Prices and features above were last checked on 1 September 2026.

Where they differ

Only the attributes on which Grype and Hanwha Vision actually diverge.

Attributes where Grype and Hanwha Vision differ
AttributeGrypeHanwha Vision
Starting priceFreeOn request
Pricing modelOpen source, no licence feeOne-time purchase
Free tierYesNo
PlatformsLinux, macOS, Windows, DockerWindows, Linux, Web, iOS, Android

Identical on both: user rating (Not yet rated), category (Cybersecurity).

What each one covers

Drawn from each product's published feature list. An absence here means we hold no record of it - not that the product lacks it.

Only in Grype

  • Image and filesystem scanning
  • SBOM-driven
  • Wide ecosystem coverage
  • Pipeline friendly

Only in Hanwha Vision

  • Wisenet WAVE VMS
  • On-camera AI
  • NDAA and TAA positioning
  • Multi-site management
  • Open platform
  • Wisenet cameras and recorders
  • Cybersecurity hardening
  • Integration licences

What people use each for

The jobs each tool is most often brought in to do.

Grype

  • Re-scanning stored SBOMs as new CVEs are published, without rebuilding imagesnot Hanwha Vision
  • Failing CI when a build introduces a known vulnerabilitynot Hanwha Vision
  • Auditing what is actually installed inside a third-party imagenot Hanwha Vision

Hanwha Vision

  • A federal agency or federal contractor whose procurement rules exclude Section 889 covered manufacturersnot Grype
  • A school district that wants a fixed one-time software cost rather than a per-camera monthly subscriptionnot Grype
  • A site running 200 cameras for a decade where a cloud subscription would cost several times a perpetual licencenot Grype
  • An integrator standardising on one manufacturer for cameras, recorders and VMS to simplify supportnot Grype

Where each one falls short

Documented limitations, not opinions. Every one is a constraint you would hit in normal use.

Grype

  • Depends on public vulnerability databases, so coverage and false positives vary by ecosystem
  • No triage, exception tracking or reporting UI — that is Anchore’s commercial product
  • Overlaps heavily with Trivy, and most teams pick one rather than running both

Hanwha Vision

  • NDAA compliance is confirmed per model and per bill of materials rather than across the brand, and TAA status depends on whether a specific unit was made in Korea or Vietnam, so a buyer with procurement obligations must get both stated on the quote rather than relying on a brand-level claim.
  • Perpetual licences mean you own the servers, storage and patching, so the cost avoided on subscription reappears as IT labour and a hardware refresh every five to seven years.
  • Hanwha publishes no list pricing and sells through distributors, so the perpetual-versus-subscription comparison it wins on paper still requires a distributor quote to verify.
  • Wisenet WAVE is a solid mid-market VMS but does not match Genetec or Milestone on enterprise features such as federation across independently owned systems, scripted operator procedures or deep access control unification.
  • Hanwha Vision is part of Hanwha Group, a large Korean conglomerate spanning defence, chemicals and finance, so the video business is one line among many and roadmap priority is set at a corporate level well above the security division.

Pricing, plan by plan

Grype

Free
  • GrypeFree
    • Full functionality
    • No usage limits
    • Community support

Hanwha Vision

On request
  • Wisenet WAVE channel licence$undefined/year
    • Perpetual per-channel licence that does not expire once activated
    • No annual renewal fee to keep the system running
    • Sold singly and in 4, 8, 16, 24 and 48 channel bundles

Which should you pick?

Choose Grype if

  • You need image and filesystem scanning.
  • You want to start without paying.
  • You work on Linux, macOS, Windows, Docker.
  • You also want sbom-driven.

Choose Hanwha Vision if

  • You need wisenet wave vms.
  • You work on Windows, Linux, Web, iOS, Android.
  • You also want on-camera ai.

Questions people ask

Is Grype or Hanwha Vision better?
Neither clearly leads. Grype starts at Free and Hanwha Vision at On request, and user ratings are close enough to be indistinguishable. Choose on capability and platform support.
Which is cheaper, Grype or Hanwha Vision?
Grype has a free tier; the other does not. Paid plans start at Free for Grype and On request for Hanwha Vision.
Does Grype or Hanwha Vision run on more platforms?
Grype runs on Linux, macOS, Windows, Docker. Hanwha Vision runs on Windows, Linux, Web, iOS, Android.
Can I use Grype for free?
Yes. Grype has a free tier, so you can try it without paying. Hanwha Vision starts at On request.
What is Grype best used for?
Grype is most often used for re-scanning stored sboms as new cves are published, without rebuilding images, failing ci when a build introduces a known vulnerability, auditing what is actually installed inside a third-party image. Of those, re-scanning stored sboms as new cves are published, without rebuilding images and failing ci when a build introduces a known vulnerability are not what Hanwha Vision is typically brought in for.
What can Grype do that Hanwha Vision cannot?
Grype covers Image and filesystem scanning, SBOM-driven, Wide ecosystem coverage, Pipeline friendly. Hanwha Vision covers Wisenet WAVE VMS, On-camera AI, NDAA and TAA positioning, Multi-site management.

Answered from the vendors’ own pages

Grype: Is Grype free?

Yes, open source from Anchore. Anchore Enterprise is the paid platform around it.

Hanwha Vision: Is Hanwha Vision NDAA compliant?

Hanwha is a South Korean manufacturer and is not among the Section 889 covered entities, which are Hikvision, Dahua, Huawei, ZTE and Hytera, and its cameras do not use banned Chinese system-on-chip processors. Confirm compliance per model on the quote.

Grype: What is the difference between Grype and Syft?

Syft generates the software bill of materials; Grype matches that inventory against vulnerability data. They are designed to be used together.

Hanwha Vision: Are Wisenet WAVE licences subscriptions?

No. Channel licences are perpetual and do not expire once activated, with no annual renewal fee.

Grype: Grype or Trivy?

They cover similar ground. Trivy is broader out of the box, including misconfiguration and secret scanning; Grype pairs more cleanly with an SBOM-first workflow.

Hanwha Vision: Is Wisenet WAVE the same as Nx Witness?

It is built on the Network Optix platform, so the two share a common core, with Hanwha adding its own camera integration and support.

Hanwha Vision: Is Hanwha TAA compliant?

Many models are, manufactured in South Korea and Vietnam, but TAA is a per-unit question tied to manufacturing origin, so it must be verified model by model.

Share

Related pages

Other head to heads