SUSE Container Security Platform logo

SUSE Container Security Platform

Container SecurityCloud Workload Protection Platform (CWPP)Microsegmentation

Open-source container security providing Layer 7 firewall, deep packet inspection, and zero-trust runtime protection.

Vendor Information

SUSE logo

SUSE

Nuremberg, Germany

SUSE Container Security Platform Overview

SUSE Security (formerly NeuVector) is the only 100% open-source, zero-trust container security platform delivering full lifecycle protection from build to runtime for Kubernetes environments. Unlike proprietary container security solutions, SUSE Security provides end-to-end vulnerability scanning throughout the CI/CD pipeline and into production, with patented Deep Packet Inspection (DPI) technology and a true Layer 7 container firewall that secures east-west traffic between containers and pods.

The platform features automated behavioral learning that discovers application patterns and creates security policies, combined with AI-driven anomaly detection to identify and block network, packet, zero-day, and application attacks including Distributed Denial of Service (DDoS) and Domain Name System (DNS) threats. Security policies can be managed as code using Kubernetes Custom Resource Definitions (CRDs) enabling GitOps workflows, while automated compliance auditing using Docker Bench and Kubernetes Center for Internet Security (CIS) Benchmark tests generates risk scores and compliance reports for Payment Card Industry Data Security Standard (PCI-DSS), Health Insurance Portability and Accountability Act (HIPAA), and General Data Protection Regulation (GDPR).

Originally founded in 2015 and acquired by SUSE in October 2021 for $130M, SUSE Security was open-sourced in January 2022 making it the industry's first fully open-source container security platform. The platform integrates seamlessly with SUSE Rancher for multi-cluster security management and supports all major Kubernetes distributions including Red Hat OpenShift, VMware Tanzu, Amazon Elastic Kubernetes Service (EKS), Google Kubernetes Engine (GKE), and Azure Kubernetes Service (AKS), serving regulated industries including financial services, healthcare, and government sectors.

Key Capabilities

Standardized capabilities mapped to this product's security niche

Cloud Workload Protection Platform (CWPP)

Scans container image layers for OS package CVEs and application dependency vulnerabilities at build time, registry push, or pre-deployment, before execution.

Captures a continuous record of workload events (process, network, file, syscall), for forensic investigation: differentiation is event retention period, query performance, and contextual enrichment.

Enforces pod security standards, network policies, and RBAC controls across Kubernetes clusters, blocking non-compliant workload deployments and detecting policy drift.

Detects in-memory exploitation techniques (shellcode injection, heap spraying, ROP chains), in running workloads without relying on file-based signatures.

Monitors process execution, network connections, and file system activity in running workloads using a kernel agent, eBPF sensor, or sidecar container to detect behavioral anomalies and known attack patterns.

Microsegmentation

Agent-based enforcement installs a lightweight agent on each host and enforces policy at the OS network stack. Agentless relies on upstream network controls (SDN, firewall). Each has different coverage and operational tradeoffs.

Discovers actual application communication flows by observing traffic before policy creation, producing a dependency map that forms the basis for allow-list policy without manual documentation.

Evaluates proposed segmentation policies against observed traffic to identify what legitimate connections would be blocked, enabling policy validation without a production enforcement change.

Applies consistent microsegmentation policy to cloud VMs and containers alongside on-premises workloads, using cloud-native enforcement mechanisms (security groups, NSGs) under unified policy.

Enforces identity-based allow policies (user identity, workload identity, device posture), rather than IP-based rules, policy follows the workload regardless of network location.

Blocks SMB, RDP, and WMI connections between endpoints by default, preventing ransomware from moving laterally via common network shares and remote management protocols.

Integrations

Compatible tools and platforms

Amazon ECRAWSAWS EKSAzureAzure ACRAzure AKSAzure DevOpsBambooCircleCIDockerGCPGitHub ActionsGitHub Container RegistryGitLabGoogle Container RegistryGoogle GKEGrafanaHarborJenkinsKubernetesLDAPPagerDutyPrometheusRed Hat OpenShiftSAMLSigstore CosignSlackSUSE RancherSYSLOGVMware TanzuWebhook

Solution Details

Deployment Options

Where and how this solution can be deployed

CloudHybridOn-Premises

Support Channels

Available support and communication options

Community ForumDocumentationTechnical Account Manager (TAM)Ticketing Portal

Pricing Model

How this solution is priced

Community EditionCustom / EnterpriseSubscription

How to buy

This profile hasn’t been claimed yet. Contact the vendor directly for pricing and purchasing options.

Is this your company?

Claim Your Profile