Least-privilege segmentation, from real traffic.
Axera Segment writes NetworkPolicy from what your workloads actually do — then gives you the lifecycle, governance and mesh support to run it in production.
Enforcement you can trust in production.
Policy from observed traffic
Synthesize least-privilege NetworkPolicy from real east-west and egress flows — no hand-written YAML, no guesswork.
Full lifecycle
Draft, deploy, version and one-click rollback. Soft-delete with retention so a removed policy is recoverable.
Firewall-style rules
Author rules the way a network team thinks — source, destination, port, protocol — and let Axera compile them to correct NetworkPolicy.
Service-mesh L3/L4
Generate Istio AuthorizationPolicy for ambient and sidecar meshes, alongside L3/L4 NetworkPolicy — one graph, both layers.
Shift-left
Scan Git repositories and recommend policy before workloads go live, so segmentation is a pull request, not a post-incident scramble.
Governance & GitOps
Approval gates, multi-cluster fan-out and GitOps delivery keep enforcement auditable and consistent.
Service-mesh L3/L4 (Istio AuthorizationPolicy for ambient & sidecar) and Shift-Left Git scanning are part of Segment — one edition covers both the mesh layer and pre-live policy.