Security Stack Logo
Phoenix logo

Container SecurityAI Security

Phoenix

Automated moving target defense for Kubernetes and AI workloads via continuous pod rotation.

Phoenix Overview

What it does

Phoenix is an Automated Moving Target Defense (AMTD) platform for Kubernetes and AI inference workloads that removes the static attack surface attackers depend on. Delivered as a Kubernetes Operator, it continuously mutates cluster topology: pods are replaced at configurable or telemetry-driven intervals with randomized UUIDs and internal IPs, while service endpoints, labels, and routing paths shift dynamically. The approach applies chaos-engineering principles to defense, so the reconnaissance an attacker gathers goes obsolete before it can be used.

How it works

The platform installs as a zero-agent Kubernetes Operator, with no sidecars, DaemonSets, or application code changes. The Falco runtime-security project provides the detection layer: when it flags suspicious activity such as an unexpected shell in a container, Phoenix triggers an immediate panic mutation that rotates the affected workload and tags compromised pods for isolation and forensics rather than deletion. Between events, pods rotate on configurable schedules, self-healing regeneration rebuilds them from known-good baselines, and time-bound network policies continuously expire routing paths. Runtime overhead is engineered to stay near 1 to 2 percent.

Credentials and traction

Phoenix Core, the Kubernetes engine, is open source under the Server Side Public License, with commercial editions adding AI inference protection and NVIDIA NIM optimizations. The founding team has published peer research during 2025 formalizing infrastructure-native AMTD for both Kubernetes and AI inference workloads. R6 Security is an early-stage specialist targeting cloud-native and MLOps security teams that protect container clusters and GPU-backed AI inference pipelines against reconnaissance, lateral movement, and model theft.

Key Capabilities

mapped to solution categories
Automated Moving Target Defense (AMTD)

Continuously varies network paths, IP addresses, and network configurations so attackers cannot reliably map or target stable routes to protected systems, rendering previously collected reconnaissance obsolete.

Limits lateral movement and code execution even when identities or credentials are compromised, reducing the blast radius of ransomware and destructive attacks.

Extends runtime randomization beyond laptops to servers, virtual desktops, cloud and container environments, software-defined networks, and OT gateways, including systems that cannot easily be patched or reimaged.

Schedules and triggers randomization events randomly, routinely, or on demand, including reconfiguration driven by predictive threat intelligence inputs, with AI and machine learning continuously adapting defenses in real time.

Integrations

compatible tools
ArgoCDFalcoFluxGrafanaNVIDIA NIMPrometheus

Implementation & support

Deployment model
CloudOn-Premises
Support channels
Community ForumDocumentation

Info last updated on August 25, 2026

Buyers

See how Phoenix fits your stack

Add Phoenix to your shortlist and unlock all evaluation tools.

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

Resources

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.