Security Stack Logo
SUSE Security logo

Container Security

SUSE Security

Open-source container security with Layer 7 firewall, DPI, and zero-trust runtime protection.

SUSE Security Overview

What it does

SUSE Security (formerly NeuVector) is the only 100% open-source, zero-trust container security platform delivering full lifecycle protection from build to runtime for Kubernetes environments. Unlike proprietary container security solutions, SUSE Security provides end-to-end vulnerability scanning throughout the CI/CD pipeline and into production, with patented Deep Packet Inspection (DPI) technology and a true Layer 7 container firewall that secures east-west traffic between containers and pods.

How it works

The platform features automated behavioral learning that discovers application patterns and creates security policies, combined with AI-driven anomaly detection to identify and block network, packet, zero-day, and application attacks including Distributed Denial of Service (DDoS) and Domain Name System (DNS) threats. Security policies can be managed as code using Kubernetes Custom Resource Definitions (CRDs) enabling GitOps workflows, while automated compliance auditing using Docker Bench and Kubernetes Center for Internet Security (CIS) Benchmark tests generates risk scores and compliance reports for Payment Card Industry Data Security Standard (PCI-DSS), Health Insurance Portability and Accountability Act (HIPAA), and General Data Protection Regulation (GDPR).

Credentials and traction

Built on the open-source NeuVector project, SUSE Security's container platform is adopted by fintech firm Nova Credit, which uses it to help secure personal credit data for 5.6 million customers. The platform targets regulated industries such as financial services, healthcare, and government that require PCI-DSS, HIPAA, and GDPR auditing.

Key Capabilities

mapped to solution categories
Cloud Workload Protection Platform (CWPP)

Scans container image layers for OS package CVEs and application dependency vulnerabilities at build time, registry push, or pre-deployment, before execution.

Captures a continuous record of workload events (process, network, file, syscall) for forensic investigation of incidents in running workloads.

Enforces pod security standards, network policies and RBAC controls across Kubernetes clusters, blocks non-compliant or unscanned images at admission control, and detects policy drift on managed orchestrators (EKS, AKS, GKE, ECS, Fargate) using best-practice configuration templates.

Monitors process execution, network connections and file system activity in running workloads through a kernel agent, eBPF sensor or sidecar container to detect behavioral anomalies and known attack patterns, including runtime privilege escalation, container escape attempts and unusual outbound network activity. This is the agent-based workload protection archetype; kernel-based versus non-kernel detection methods and Windows versus Linux coverage vary across products.

Mitigates workload vulnerabilities in runtime through virtual patching, workload isolation and segmentation, and management of running services and processes.

Monitors critical operating system, application and configuration files on workloads for unauthorized changes, alerting on modifications that indicate tampering, persistence or compliance drift. Delivered through an agent on Windows and Linux hosts and, in some products, agentlessly; agentless and Windows coverage vary across products.

Microsegmentation

Enforces segmentation policy on the workload itself through a host agent or existing endpoint hooks (operating system firewall, eBPF, an EDR agent already deployed), so the policy travels with the workload across data center, cloud and endpoint locations and gives per-process visibility. Products differ in operating system coverage, resource overhead, kernel or user-mode operation, and whether an existing EDR agent can be reused instead of deploying a new one.

Discovers the actual north-south and east-west communication flows between workloads and devices by observing live traffic, producing the dependency data that allow-list policy is built from instead of hand-documented application maps. Products differ in flow sources (host agent, network sensors or switch telemetry, cloud flow logs, virtual switch) and therefore in how completely agentless assets are covered.

Evaluates proposed segmentation policies against observed traffic to identify what legitimate connections would be blocked, enabling policy validation without a production enforcement change.

Contains an active breach by cutting the paths ransomware and attackers use to spread: pre-staged containment policies that block peer-to-peer SMB, RDP, WMI and other administrative protocols between endpoints and servers, a firebreak around devices that cannot run security agents, and quarantine of compromised workloads that can be triggered from the console, by a severity-level switch, or by SIEM, SOAR and EDR during an incident. Products differ in whether containment can be staged by threat level and activated with a single switch, and in how quickly a quarantine reaches every enforcement point.

Proposes least-privilege allow-list rules automatically from observed flows, labels and templates, and manages them through the full lifecycle of creation, testing, enforcement, tuning and retirement, so segmentation is not built by writing rules by hand. Products differ in recommendation quality, template coverage for common applications and compliance zones, and support for iterative refinement before enforcement.

Extends the same segmentation policy model into Kubernetes and container environments, enforcing at pod, namespace and service level through CNI or eBPF hooks, sidecars or native NetworkPolicy objects, so container traffic is governed by the same labels and rules as virtual machines and bare metal instead of a separate container-only tool. Products differ in whether Kubernetes support is enforcement or visibility only, distribution coverage (managed cloud Kubernetes, OpenShift, self-managed), and Layer 7 awareness.

Produces prebuilt reports tailored to specific audiences and compliance frameworks that evidence segmentation controls for auditors (PCI DSS, HIPAA, NIS2, DORA and similar), together with diagnostics that show where observed traffic diverges from intended policy and why a given connection was allowed or blocked. Products differ in framework coverage, audience-specific report depth, and the quality of policy troubleshooting.

Detects threats from the product's own segmentation telemetry and enforcement points, for example intrusion detection and prevention on east-west traffic, anomalous flow and process behavior, and deception decoys, rather than relying solely on an external EDR or NDR to raise the alert. Products differ sharply by enforcement architecture: host-agent and hypervisor-based solutions with process or payload visibility can detect natively, while network- and NAC-based solutions without endpoint visibility generally cannot. Some pair detection with enforcement to virtually patch protected workloads.

Integrations

compatible tools
Amazon ECRAWSAWS EKSAzureAzure ACRAzure AKSAzure DevOpsBambooCircleCIDockerGCPGitHub ActionsGitHub Container RegistryGitLabGoogle Container RegistryGoogle GKEGrafanaHarborJenkinsKubernetesLDAPPagerDutyPrometheusRed Hat OpenShiftSAMLSigstore CosignSlackSUSE RancherSYSLOGVMware TanzuWebhook

Implementation & support

Deployment model
CloudHybridOn-Premises
Support channels
Community ForumDocumentationLive ChatPhone SupportTechnical Account Manager (TAM)Ticketing PortalTraining / Academy

Info last updated on September 7, 2026

Buyers

Start a shortlist with SUSE Security

Compare options, add your notes, and run informed evaluations.

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

Resources

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.