Principles We'll Apply Throughout
Zero Trust: Never trust, always verify โ even inside the cluster (โ Groot)
Supply Chain Security: You don't control your dependencies โ verify them (โ Gamora)
Security Observability: Siloed tools miss correlated attacks (โ Mantis)
Standard: NIST SP 800-207 ย |ย Framework: SLSA (OpenSSF)
Our tools: CNCF-first โ portable, community-driven, production-proven
- Graduated: Falco, OPA, Cilium, Prometheus, Kyverno, OpenTelemetry
- Incubating: Trivy, Sigstore