From blind spot to breach containment — in one control plane.
Most teams buy visibility, segmentation, and detection from three vendors and stitch them across two consoles and a SIEM. Axera is a single Red Hat–certified operator that does all three — license-driven, CNI-agnostic, on infrastructure you control.
Observe
Real-time east-west and egress topology on any CNI — verdict-aware and process-attributed — with coverage and monitoring analytics.
Segment
Turn observed traffic into NetworkPolicy you can trust: draft → deploy → version → rollback, firewall-style rules, service-mesh L3/L4, shift-left, governance, multi-cluster.
NDR
Process-attributed incidents, MITRE ATT&CK kill-chain fusion, and AI triage — plus active containment that isolates the workload and verifies it stayed contained.
Three license tiers on one operator install. Upgrade Observe → Segment → NDR without redeploying.
Start where you are. Grow when you’re ready.
Each edition is a license tier on the same operator install. Start with visibility, add enforcement, then detection and response — no redeploy, no second console.
Full visibility into east-west and egress traffic on any CNI.
- Real-time topology (any CNI)
- Verdict-aware, process-attributed flows
- Egress with destination IP + reverse-DNS
- Coverage and policy monitoring analytics
- eBPF-based flow + process telemetry
Least-privilege NetworkPolicy synthesized from what actually runs.
- NetworkPolicy from observed traffic
- Lifecycle: draft → deploy → version → rollback
- Firewall-style rule authoring
- Service-mesh L3/L4 (Istio ambient + sidecar)
- Shift-left: scan Git repos → pre-live policy
- Governance gates + multi-cluster / GitOps
Network Detection & Response, purpose-built for Kubernetes.
- Process-attributed incidents
- MITRE ATT&CK kill-chain fusion
- DNS, mesh/identity and runtime detections
- Context-rich AI triage
- Active containment (NetworkPolicy / ANP)
- Closed-loop verification + auto-response
Not sure which edition? Start with Observe — you can upgrade in place.
Observe. Govern. Operate.
Three moves, one operator.
Observe
See every east-west and egress flow — verdict-aware and process-attributed — across any CNI.
Govern
Turn that traffic into least-privilege policy you review, version and roll back.
Operate
Detect process-attributed threats, contain them automatically, and verify the fix.
See Axera on your own clusters.
A short technical demo on your environment — visibility, segmentation and NDR from one operator.