Sovereign · On-Premises · Swiss-built

sovereign kubernetes security and compliance that stays inside your infrastructure.

Continuous runtime security, contextual vulnerability management, and automated compliance.

fully on-premises · air-gap capable · zero data egress

sovereign by design zero data egress air-gap capable kubernetes-native ai-assisted security continuous compliance runtime protection
scanning
continuous
247 nodes monitored · 0 egress
94 %
of organizations had a Kubernetes security incident last year
CNCF / Red Hat
277 d
average time to detect a container security incident
IBM Report
4.5 M
CHF average cost of a data breach in Europe
IBM Cost of a Breach
The Platform

one platform. your infrastructure. nothing leaves.

Every capability runs inside your environment: from runtime detection to compliance auditing. No SaaS backend, no telemetry phoning home.

Runtime Security

Real-time detection of threats inside running containers and pods.

Contextual Vulnerability Mgmt

CVE triage with deployment context. Focus on what's actually exploitable.

Attack Path Discovery

Visualize lateral movement paths and blast radius across your cluster.

Admission Control

Block non-compliant workloads at deploy time, before they ever run.

AI

AI-assisted Security

AI-generated VEX statements, dynamic recommendations, and automated triage.

Compliance Audits

Automated checks against FINMA, DORA, NIS-2, BSI C5, CIS & NIST SP 800-190.

Security Monitoring

Continuous cluster-wide monitoring with alerting and event correlation.

Zero Data Egress

All processing stays on-premises. Data never leaves your environment.

Air-Gap Support

Full functionality in isolated, fully disconnected environments.

Compliance Coverage

aligned with the regulations,
best practices and frameworks you answer to.

Every organization has its own rulebook. cenroq maps your Kubernetes posture to the ones that apply to you.

FINMA
Financial market supervision
regulated financial services
DORA
Digital operational resilience
ICT risk in finance
NIS-2
Network & information security
critical infrastructure
SOC 2
Service organization controls
security & availability
FedRAMP
Cloud security authorization
public-sector cloud
IKT
ICT minimum standard
critical infrastructure
NIST CSF
NIST Cybersecurity Framework
critical infrastructure
BSI C5
Cloud computing controls
cloud service assurance
CIS
Kubernetes benchmark
hardening best practice
Events

where you can find us.

Conferences, contests, community meetups. If you run clusters, we are probably in the room.

Upcoming

Attendee
Aug 1–62026

Black Hat USA 2026

Las Vegas, USA

The 29th edition of the industry’s longest-running briefings, back at Mandalay Bay. We are on the floor all week. Find us between sessions.

Event site →
Contest Organizer
Aug 6–92026

DEF CON 34

Las Vegas, USA

We run the Container Security CTF at LVCC West Hall: a cooperative learning track from Friday to Sunday, and a competitive Kubernetes tournament on Saturday.

Contest site →
OrganizerSponsor
Aug 7–92026

Kubernetes CTF at DEF CON

Las Vegas, USA

Every player gets their own cluster and a chain of container-escape challenges. Built and sponsored by us, open to anyone at the conference.

Follow on LinkedIn →
Speaker
Sep 152026

Cloud Native Computing Meetup

Zurich, Switzerland

Community evening at the VSHNtower. Talks only, no product pitches. House rule, and we like it that way.

Meetup page →
Attendee
Sep 172026

Swiss Cloud Native Day 2026

Bern, Switzerland

Third edition, up on the Gurten. The Swiss cloud-native community in one room for a day.

Event site →
Speaker
Sep 23–242026

German OWASP Day 2026

Karlsruhe, Germany

Talk on the new OWASP Kubernetes Top 10: what actually changed, and what it means for a cluster you already run.

Program →
Attendee
Oct 12–162026

ECSC 2026

Bochum, Germany

The European Cybersecurity Challenge, where national teams of 14- to 24-year-olds compete for the continental title. Worth watching who comes through.

Event site →
Attendee
Oct 20–232026

hack.lu 2026

Luxembourg, Luxembourg

The 20th edition of Luxembourg’s open, research-driven security conference.

Event site →
Attendee
Oct 27–292026

it-sa Expo&Congress 2026

Nuremberg, Germany

Europe’s largest IT security trade fair, with close to a thousand exhibitors across five halls.

Event site →
Organizer
November2026

Security Native Europe

Zurich, Switzerland

A CNCF community group we help run, moving between European cities. Open exchange on securing everything from cloud to IoT. Date to be confirmed.

Group page →
Open Source

built on open foundations.

kubeapt, our Kubernetes Admission Policy Toolkit, and our open policy bundles are free to use, inspect and contribute to (Apache-2.0). Start hardening admission control today.

$ kubeapt scan
→ auditing admission posture...
Pod Security Admission · 9/12 enforced
evaluated locally · 0 bytes egressed

see cenroq run in your cluster.

Book a 30-minute technical demo with our team. No sales deck. A live look at the platform.