The Platform

sovereign kubernetes security and compliance that stays inside your infrastructure.

Continuous runtime security, contextual vulnerability management, and automated compliance: fully on-premises, air-gap capable, zero data egress.

Your environment · nothing leaves
YOUR INFRASTRUCTURE · AIR-GAPPED Kubernetes nodes cenroq runtime · scan · audit External cloud / vendor SaaS no data egress
Capabilities

everything you need to secure and prove.

Every capability runs in a single Kubernetes-native platform: fully on-premises, with no SaaS backend and nothing leaving your environment.

Capability 01 / 06

Runtime Security

Real-time detection of threats inside running containers and pods, mapped to MITRE ATT&CK for Containers.

  • Behavioral detection inside running pods
  • Mapped to MITRE ATT&CK for Containers
  • Alerts the moment behavior deviates
runtime · live eventspod/api-7f9 · process startedpod/cache-2c · network connect! shell spawned in containerMITRE T1059 · Command & Scriptingpod/web-3a · file read /etcDETECTIONAnomalous exec contained in 0.4s
Capability 02 / 06

Contextual Vulnerability Management

CVE triage with deployment context: prioritize what is actually reachable and exploitable, not raw scanner noise.

  • Reachability-aware CVE prioritization
  • Cuts scanner noise to what matters
  • Linked to the workloads actually affected
vulnerabilities · prioritizedCVE-2025-1042 · opensslREACHABLECVE-2024-8821 · glibcCVE-2024-3310 · zlibCVE-2023-9907 · curl142 findings → 7 reachable✓ noise reduced by 95%
Capability 03 / 06

Attack Path Discovery

Map lateral-movement paths and blast radius across the cluster graph, before an attacker does.

  • Visualizes lateral-movement paths
  • Shows blast radius across the cluster
  • Highlights the riskiest route to your secrets
attack paths · graphingresssvc-acctsecretscritical path → secrets store (3 hops)
Capability 04 / 06

Admission Control

Enforce policy at deploy time: block non-compliant or risky workloads before they ever reach the cluster.

  • Policy enforced at deploy time
  • Blocks risky workloads pre-cluster
  • Guardrails without slowing delivery
admission · deploy gatekind: Deploymentimage: app:latestsecurityContext.privileged: truerunAsRoot: trueADMISSION BLOCKEDpolicy: no-privileged-containers · enforced
Capability 05 / 06

AI-assisted Security

AI-generated VEX statements, dynamic recommendations and automated triage that cut analyst workload.

  • AI-generated VEX statements
  • Automated triage of findings
  • Recommended fixes, in context
ai · assisted triageCVE-2025-1042 · status: not affectedAI RECOMMENDATIONVEX generated: dependency notreachable in this deployment.Suggested: suppress · document · close✓ analyst time saved: ~40 min / finding
Capability 06 / 06

Compliance Audits

Automated checks against FINMA, DORA, NIS-2, IKT-Minimalstandard, BSI C5, CIS Benchmark and NIST SP 800-190.

  • Mapped to the frameworks you answer to
  • Always audit-ready evidence
  • Export reports on demand
compliance · evidenceFINMA · operational resiliencepassDORA · ICT risk mgmtpassNIS-2 · incident handlingreviewCIS Benchmark · hardeningpassposture: 94% alignedExport evidence
How it works · Continuous monitoring

deploy. monitor. prove.

This is how the continuous version runs: once deployed, cenroq stays always-on inside your cluster.

1

Deploy in your cluster

Install via Helm into any Kubernetes environment: cloud, on-prem or air-gapped. No external connectivity required.

2

Monitor continuously

cenroq watches runtime behavior, scans workloads and discovers attack paths. All processing stays inside your boundary.

3

Prove compliance

Export audit-ready evidence against your frameworks on demand, turning supervisory reviews into a report, not a project.

Ways to engage

one-time assessment or continuous monitoring.

Start with a point-in-time snapshot, or run cenroq as always-on assurance. Same platform, two commitments.

One-Time Assessment

Security Snapshot

Fixed-scope engagement
Continuous Monitoring

Always-On Assurance

Ongoing subscription
Deployment
Client-side binary, run on demand
Deployed into your Kubernetes cluster
Cadence
Point-in-time audit
Real-time, continuous
Cluster scan & posture analysis
Compliance gap analysis
Runtime threat detection
Automated re-checks on change
AI-assisted VEX & triage
Output
Findings report + remediation roadmap
Live dashboard + board-ready reporting
Best for
Audit prep · M&A due diligence
Regulated enterprises · critical infrastructure
Open Source

start with our open-source toolkit.

New to cenroq? Start with kubeapt and our open policy bundles: free, self-hosted, Apache-2.0. Step up to continuous monitoring and compliance when you are ready.

$ kubeapt scan
→ auditing admission posture...
Pod Security Admission · 9/12 enforced
evaluated locally · 0 bytes egressed

see the platform in your own cluster.

Book a 30-minute technical demo with our team. A live walkthrough and a straight answer on your posture.