CVE prioritisation from the runtime up
Runtime security for Kubernetes. From the runtime up.
bifrost starts from runtime: it knows which CVEs are actually reachable, protects against the rest, and instantly knows your exposure to the next discovered vulnerability.
Up to 90% fewer CVEs to triage
Under 1% CPU overhead in production
Zero manual profile writing
Every build gets a fresh profile and refreshed verdicts
Learn
Every container, down to what it does when it runs
bifrost learns what deploys where, down to each container underpinning every service you run. For every container it learns five things: which environment it runs in and how it is configured, where it was built, what it contains, which CVEs it carries, and the syscalls, files and connections it uses doing its job. That learning becomes the verdict on every CVE, the security profile for every workload, and the answer when the next CVE is discovered.
- One label and one annotation: every build is observed in pre-production, with no code changes
- Behaviour recorded per container: system calls, file access, process activity and network connections
- Every environment a build passes through is in the picture, from staging to production
- Developers spot unexpected behaviour before it reaches production; security teams see which services carry the largest behavioural footprint


Prioritise
Every CVE, with a verdict
Every CVE is verdicted against what actually runs: reachable, mitigated by the profile, or never loaded. One view across every environment and every service, from staging to production. bifrost does the triage, so there is no manual triaging: what reaches you is a short list, and each verdict arrives with the evidence behind it.
- SBOMs ingested every deploy: always an up-to-date picture of what's live
- SBOMs re-scanned through the day: new CVEs matched against your inventory automatically
- Every build tracked into every environment: for a given CVE you see which services and clusters carry it, so you know where to fix first
- Every verdict carries its evidence: the behaviour observed, the profile applied, the package loaded or not
- Focus on what is reachable and not yet protected
Protect
Anything outside the profile is blocked
Every workload in production gets its own security profile, generated from its learned behaviour and enforced at the kernel. Protection is a ramp with three modes: observe, where bifrost learns and nothing is blocked; detect, where the profile is applied and deviations are reported; and enforce, the destination, where anything outside the profile is blocked, including exploits nobody has discovered yet.
- Profiles generated automatically from learned behaviour, fresh with every build: zero manual profile writing
- No rules to rot: manual regimes run from ~200 to 10,000 rules that go stale the moment the software changes
- Every blocked event raises an alert with its full context: what happened, in which workload, and why it fell outside the profile
- SIEM-ready integrations: pipe alerts straight into your SOC workflow
Under the hood: each security profile is an AppArmor profile, enforced by the Linux kernel's security module rather than by a sidecar or a proxy.

Answer
The next CVE, before it is asked
When a new CVE is discovered, bifrost already knows where you have it, how exposed it is, and how well protected you already are. If the profile blocks the path, the answer is protected, with the evidence. If not, the remedies. No new build and no new scan: the answer comes from what bifrost already knows, every build tracked into every environment and every active SBOM re-scanned through the day.
Higher-quality prioritisation, no manual triaging, deep runtime understanding, and kernel-level protection, fully automated with bifrost.
Where you start decides what you can know
Scanners start from the image and stop there. bifrost starts from runtime and works up: knowledge, verdicts, protection, answers.
| Capability | Scanners (start from the image) | bifrost (starts from runtime) |
|---|---|---|
| CVE detection | Yes: finds every known CVE in the image | Yes: SBOMs ingested every deploy, re-scanned through the day |
| Reachability | No: never reaches runtime, so every finding arrives without the context to verdict it | Yes: every CVE verdicted against what actually runs |
| Mitigation | No: the only remedy is a patch | Yes: the security profile blocks paths the workload never uses |
| Prioritisation | By CVSS score only | By verdict: reachable, mitigated by the profile, or never loaded |
| Noise | High: hundreds or thousands of findings | Low: a short reachable list, with the evidence attached |
| Updates | Periodic scans | Every build, plus SBOMs re-scanned through the day |
Two other starting points: detect-and-respond tools start at runtime too, but only watch and report, leaving the acting to you after the fact. Manual policy engines start from a rulebook someone has to write, anywhere from ~200 to 10,000 rules that rot the moment the software changes.
Built for production
Designed for production clusters: a DaemonSet per node, kernel-level enforcement, and under 1% CPU overhead.
Enforcement
AppArmor LSM
Deployment
DaemonSet
Resource usage
< 200MB RAM per node
Performance impact
< 1% CPU
SBOM formats
CycloneDX, SPDX
CVE discovery
SBOM scanned several times a day
Platform architecture
Pre-prod clusters
Production clusters
bifrost Engine (EU hosted)
Integrations
Built for security-conscious teams
Built on research, engineered for production, hosted where your data belongs.
Research-founded
Born from a joint EU research project at Lund University, then shaped into a product by engineers with real-world production experience. Research depth, practical edge.
Sovereign by choice
Run bifrost where your compliance posture demands, from a Swedish-owned sovereign cloud outside US jurisdiction to your own infrastructure. GDPR-compliant by design.
Swedish-owned
Researched, developed, and funded by Swedish individuals. Patented runtime profiling technology, built in Sweden for European and global teams.
Kernel-level enforcement
Built on AppArmor, a Linux Security Module trusted in production for 20+ years. Enforcement at the kernel means stronger isolation and inherent protection of sensitive data.
Data residency
Your data stays where you want it
Run bifrost in the jurisdiction and ownership model your compliance posture demands. Same platform, four deployment options, from a sovereign European cloud to your own infrastructure.
Swedish hosted
Managed service on Swedish-owned and controlled cloud.
- Outside US jurisdiction
- GDPR and NIS2 ready
- Full data sovereignty
European hosted
EU region of a global hyperscaler.
- Familiar, proven scalability
- EU data residency
- GDPR compliant
Private cloud
Single-tenant, managed by bifrost in your infrastructure.
- Dedicated single-tenant instance
- Runs in your own infrastructure
- Fully managed by bifrost
On-premise
Runs entirely in your environment
- Data never leaves your network
- Air-gap compatible
- Self-hosted by your organisation
Not sure which fits? Talk to us about your residency requirements
Your security is our security
bifrost is built with data minimisation and privacy at its core.
Data minimisation
The bifrost agent collects behavioural metadata: system calls, file access patterns, network connections, never application data or personal information.
EU data residency
All data is processed and stored within the EU. GDPR-compliant by design.
Encryption
All data in transit and at rest is encrypted.
Minimal-privilege agent
The bifrost agent runs as a read-only DaemonSet with minimal privileges. No access to your application data.
NIS2 evidence
Continuous enforcement produces continuous evidence. Security profiles and CVE verdicts give you evidence that maps to NIS2's technical security measures.
ISO 27001
ISO 27001 certification in progress. Contact us for our current security documentation.
A lookup, not a war room
The next CVE, answered from what bifrost already knows. See it on your stack: a 30-minute demo, or 14 days on your own cluster.