
Container SecurityAI Security
Phoenix
Automated moving target defense for Kubernetes and AI workloads via continuous pod rotation.
Phoenix Overview
What it does
Phoenix is an Automated Moving Target Defense (AMTD) platform for Kubernetes and AI inference workloads that removes the static attack surface attackers depend on. Delivered as a Kubernetes Operator, it continuously mutates cluster topology: pods are replaced at configurable or telemetry-driven intervals with randomized UUIDs and internal IPs, while service endpoints, labels, and routing paths shift dynamically. The approach applies chaos-engineering principles to defense, so the reconnaissance an attacker gathers goes obsolete before it can be used.
How it works
The platform installs as a zero-agent Kubernetes Operator, with no sidecars, DaemonSets, or application code changes. The Falco runtime-security project provides the detection layer: when it flags suspicious activity such as an unexpected shell in a container, Phoenix triggers an immediate panic mutation that rotates the affected workload and tags compromised pods for isolation and forensics rather than deletion. Between events, pods rotate on configurable schedules, self-healing regeneration rebuilds them from known-good baselines, and time-bound network policies continuously expire routing paths. Runtime overhead is engineered to stay near 1 to 2 percent.
Credentials and traction
Phoenix Core, the Kubernetes engine, is open source under the Server Side Public License, with commercial editions adding AI inference protection and NVIDIA NIM optimizations. The founding team has published peer research during 2025 formalizing infrastructure-native AMTD for both Kubernetes and AI inference workloads. R6 Security is an early-stage specialist targeting cloud-native and MLOps security teams that protect container clusters and GPU-backed AI inference pipelines against reconnaissance, lateral movement, and model theft.
Key Capabilities
mapped to solution categoriesContinuously varies network paths, IP addresses, and network configurations so attackers cannot reliably map or target stable routes to protected systems, rendering previously collected reconnaissance obsolete.
Limits lateral movement and code execution even when identities or credentials are compromised, reducing the blast radius of ransomware and destructive attacks.
Extends runtime randomization beyond laptops to servers, virtual desktops, cloud and container environments, software-defined networks, and OT gateways, including systems that cannot easily be patched or reimaged.
Schedules and triggers randomization events randomly, routinely, or on demand, including reconfiguration driven by predictive threat intelligence inputs, with AI and machine learning continuously adapting defenses in real time.
Integrations
compatible toolsImplementation & support
Info last updated on August 25, 2026
Buyers
See how Phoenix fits your stack
Add Phoenix to your shortlist and unlock all evaluation tools.
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.