AXERA
Editions

Start where you are. Grow when you are ready.

Observe, Segment and NDR are license keys on the same operator install. Start with visibility, add enforcement, then detection and response. No redeploy, no second console.

Observe

See every flow

A live, accurate map of every connection in and out of your clusters, on any cluster network.

  • See what talks to what across every namespace and cluster
  • Trace each connection back to the process that opened it
  • Find the outbound connections nobody knew about, resolved to a destination name
  • Know which workloads are covered by policy and which are exposed
  • Watch traffic without installing a service mesh or changing your network plugin
Explore Observe

NDR

Detect & respond

Everything in Segment, plus detection and verified containment for the attacks that get through.

  • Get one incident naming the workload, the process and the destination
  • Run 18 detectors, each mapped to MITRE ATT&CK techniques
  • Contain a compromised workload with a targeted policy, on approval or automatically
  • Verify the containment held, and reopen only when it is safe
  • Turn an incident's observed traffic into a permanent policy fix
  • Ask an on-prem AI assistant to explain and rank incidents, with no data leaving the cluster
Explore NDR

Upgrade in place. Moving from Observe to Segment to NDR is a license key change on the same install, not a redeploy.

Licensing

Per cluster, one install, no surprises.

How it is licensed

Licensed per monitored cluster; editions are license keys on the same operator install.

Observe is available as a time-boxed evaluation license.

Where to get it

  • Red Hat Ecosystem Catalog / OperatorHub
  • Direct from Quasys

Pricing depends on cluster count and edition. Ask for a quote in the demo request and an engineer will reply with numbers, not a sales cycle.

FAQ

What teams ask before they evaluate.

Does Axera require a specific CNI?

No. The flow agent is CNI-agnostic (CNI is the cluster's network plugin) and works on OVN-Kubernetes, Cilium, Calico and others. Enforcement uses standard Kubernetes NetworkPolicy, and Istio AuthorizationPolicy where a mesh is present.

Is anything sent to the cloud?

Not unless you choose to. Axera is fully self-hosted: the operator, agents, data stores and console all run in your clusters. AI triage runs on-prem with Ollama by default; sending incident context to an external AI provider is an explicit opt-in you control.

Does it enforce automatically?

Segmentation is deploy-when-you-approve by default. NDR active response ships opt-in behind a master switch. You decide whether Axera contains a workload on its own, and every action is verified and auditable.

Do I need a service mesh?

No. Observe and Segment work without a mesh. If you run Istio (ambient or sidecar), Axera adds network-layer AuthorizationPolicy alongside NetworkPolicy.

How is it installed?

As a Red Hat certified operator from OperatorHub. One Axera custom resource deploys the whole platform. Helm is available for vanilla Kubernetes, and disconnected or air-gapped installs are supported.

Where does the data live?

In PostgreSQL and Kafka you control, external for production or in-cluster for evaluation. Nothing leaves your perimeter unless you route it to your SIEM.

See Axera on your own clusters.

A 20-minute lab walkthrough with an engineer, or a proof of concept on clusters you control. The PoC runs entirely inside your perimeter.