Skip to content
@accuknox

AccuKnox

Zero Trust CNAPP that secures Code to Cloud.

AccuKnox

Zero Trust CNAPP for the AI Era

Runtime-first cloud, application, API, and AI security, built on eBPF and KubeArmor.

Website · Platform · Docs · Product Tour · Schedule a Demo

GitHub org KubeArmor Compliance Integrations

AccuKnox CNAPP platform overview

What AccuKnox does

Most CNAPP tools stop at posture scanning. They find the misconfiguration and leave the fix to you. AccuKnox blocks the attack at runtime, in the kernel, using eBPF and Linux Security Modules (AppArmor, BPF-LSM, SELinux) through our open source engine, KubeArmor.

One platform covers cloud, container, Kubernetes, application, API, and AI workloads, on any cloud, on-prem, or air-gapped. Zero Trust policies enforce "never trust, always verify" instead of alerting after the fact. Runtime blocking runs under 1% CPU overhead.

A DevSecOps team running 18,000+ assets across GCP, VMs, and Kubernetes cut alert noise by 85% after switching from a legacy CNAPP. A 200+ account financial services customer cut quarterly audit prep from 60 hours to under 5.


The platform, by domain

Each card links to the live product page. Screenshots are pulled straight from accuknox.com/platform.

Misconfiguration detection and drift prevention across AWS, Azure, GCP, and Oracle Cloud. Docs →

Runtime protection for VMs, containers, and serverless, with automated zero-trust policy generation. Docs →

Cluster posture plus in-line enforcement that stops zero-days before they spread. Includes Kubernetes Identity and Entitlement Management (KIEM) to kill excessive standing permissions. Docs →

Shift-left SAST, SCA, and DAST tied to runtime context, so teams fix what is actually exploitable. Docs →

Finds broken access control, broken authentication, and injection flaws across every exposed API. Docs →

Discovers, scans, and sandboxes every model, agent, and prompt path. Full module breakdown below. Docs →

Tracks sensitive data exposure, uncontrolled access, and exfiltration paths across cloud and AI stores. Docs →

Generates SBOM, HBOM, AIBOM, CBOM, and QBOM, with VEX and CSAF support for audit-ready provenance. Docs →

Detects and blocks leaked API keys, passwords, and credentials before they leave the environment. Docs →

45+ frameworks mapped and continuously audited, including HIPAA, GDPR, SOC 2, ISO 27001, and FedRAMP. Docs →

→ See the full platform, including CDR, SIEM, 5G security, and hybrid/private cloud coverage.


AI Security 2.0

AccuKnox Agentic AI security

Launched at RSA 2026. Eight modules, built on the open standards SPIFFE and OpenFGA, integrated with Amazon Bedrock, Gemini, Ollama, and vLLM.

Module What it does
AI Security Posture Management (AI-SPM) Live, agentless inventory of every model in use
Agentic AI Security Sandboxes every AI agent at the kernel level with eBPF and LSM
AI Detect & Respond (AI-DR) Reconstructs attack chains across prompts and tool calls
AI Guardrails, Stateful Prompt Firewall Filters, audits, and blocks malicious LLM prompts and responses
AI Red Teaming & Pen Testing Runs automated adversarial tests for prompt injection, hallucination, and toxicity
AI Identity Security Scopes permissions per agent and kills standing credentials
AI Model & Dataset Security (ModelArmor) Scans 5 model formats for backdoors and unsafe code
AI Compliance & Governance (AI-GRC) Assigns an EU AI Act risk tier instantly, mapped to your controls

A healthcare AI customer cut PII leak risk by 85% under HIPAA. An AI workload customer cut data leakage risk by 85% after deploying AI-SPM.

Explore AI Security →


Deploy anywhere

AccuKnox infrastructure coverage
Environment Coverage
Public cloud AWS, Azure, GCP, Oracle Cloud
Private cloud OpenStack, Red Hat OpenShift, VMware Tanzu, Nutanix, IBM Cloud
On-premise Full CNAPP stack, no external dependency
5G and IoT/Edge 89% uptime in production telecom deployments
AI and LLM assets Hugging Face, OpenAI, TensorFlow, Ollama, managed and private models

Resources

Documentation: Getting started · Deployment models · AI/ML support matrix · CI/CD support matrix · IaC support

Integrations: AWS · Azure · GCP · GitHub · GitLab · Jenkins · See all 30+ →

Use cases: Asset inventory · Cloud misconfigurations · Crypto mining detection · Shadow AI discovery · KIEM · Prompt firewall

Case studies: Banking & fintech · Healthcare · Telecom · Public sector · US DoD


Open source

KubeArmor     ModelArmor
  • KubeArmor — runtime security enforcement engine for containers, VMs, and nodes, built on eBPF and LSM. CNCF project, 1M+ downloads.
  • ModelArmor — open source runtime sandboxing for LLM and ML workloads. CNCF project.

→ All open source repos


Company

Incubated at SRI International (Stanford Research Institute). Backed by National Grid Partners, Dolby Family Ventures, Dreamit Ventures, Avanta Ventures, 5G Open Innovation Lab, and NVIDIA. Distributed through TD SYNNEX in North America and Carahsoft for the federal channel. Listed on AWS, Azure, Red Hat, and Oracle Cloud marketplaces.

Popular repositories Loading

  1. agentZ agentZ Public

    Zero-trust agentic AI platform. Supports SaaS and OnPrem (airgapped) deployments.

    TypeScript 48 10

  2. discovery-engine discovery-engine Public

    Discover least permissive security posture, Network Microsegmentation, and Application behaviour based on visibility/observability data emitted from policy engines..

    Go 35 37

  3. cilium-spire-tutorials cilium-spire-tutorials Public

    Tutorials about Cilium and SPIRE integration

    Shell 32 10

  4. k8sthreatmodeling k8sthreatmodeling Public

    Threat Modeling (based on STRIDE approach) for Kubernetes systems.

    HTML 26 10

  5. container-scan-action container-scan-action Public

    AccuKnox CI/CD Action for Container Security Scan

    19 5

  6. iac-scan-action iac-scan-action Public

    AccuKnox CI/CD Action for IaC Security Scan

    19 3

Repositories

Showing 10 of 110 repositories
  • accuknox-jobs Public

    AccuKnox jobs to handle execution and reporting of findings based on open source or in-house tools

    accuknox/accuknox-jobs's past year of commit activity
    Python 3 16 1 4 Updated Sep 9, 2026
  • help Public

    Help Documentation for AccuKnox

    accuknox/help's past year of commit activity
    HTML 5 12 0 0 Updated Sep 9, 2026
  • accuknox/aspm-scanner-cli's past year of commit activity
    Python 1 Apache-2.0 9 0 7 Updated Sep 9, 2026
  • agentZ Public

    Zero-trust agentic AI platform. Supports SaaS and OnPrem (airgapped) deployments.

    accuknox/agentZ's past year of commit activity
    TypeScript 48 Apache-2.0 10 30 (1 issue needs help) 3 Updated Sep 9, 2026
  • redTeam Public
    accuknox/redTeam's past year of commit activity
    Python 0 0 0 0 Updated Sep 8, 2026
  • policy-templates Public Forked from kubearmor/policy-templates

    Community curated list of System and Network policy templates for the KubeArmor and Cilium

    accuknox/policy-templates's past year of commit activity
    0 Apache-2.0 47 0 1 Updated Sep 8, 2026
  • accuknox/Azure-DevOp-Unified-Scan's past year of commit activity
    TypeScript 0 1 0 1 Updated Sep 8, 2026
  • accuknox/knoxctl-website's past year of commit activity
    Shell 0 5 0 0 Updated Sep 7, 2026
  • accuknox-cli-v2 Public

    Knoxctl Cli tool for AccuKnox

    accuknox/accuknox-cli-v2's past year of commit activity
    Go 1 13 3 5 Updated Sep 7, 2026
  • .github Public
    accuknox/.github's past year of commit activity
    1 0 0 0 Updated Sep 7, 2026