Skip to main content

CVE prioritisation from the runtime up

Runtime security for Kubernetes. From the runtime up.

bifrost starts from runtime: it knows which CVEs are actually reachable, protects against the rest, and instantly knows your exposure to the next discovered vulnerability.

Up to 90% fewer CVEs to triage

Under 1% CPU overhead in production

Zero manual profile writing

Every build gets a fresh profile and refreshed verdicts

Learn

Every container, down to what it does when it runs

bifrost learns what deploys where, down to each container underpinning every service you run. For every container it learns five things: which environment it runs in and how it is configured, where it was built, what it contains, which CVEs it carries, and the syscalls, files and connections it uses doing its job. That learning becomes the verdict on every CVE, the security profile for every workload, and the answer when the next CVE is discovered.

  • One label and one annotation: every build is observed in pre-production, with no code changes
  • Behaviour recorded per container: system calls, file access, process activity and network connections
  • Every environment a build passes through is in the picture, from staging to production
  • Developers spot unexpected behaviour before it reaches production; security teams see which services carry the largest behavioural footprint
bifrost detailed workload behaviour view showing system calls, file access, and network connections
bifrost CVE prioritisation view showing vulnerabilities with a verdict from runtime context

Prioritise

Every CVE, with a verdict

Every CVE is verdicted against what actually runs: reachable, mitigated by the profile, or never loaded. One view across every environment and every service, from staging to production. bifrost does the triage, so there is no manual triaging: what reaches you is a short list, and each verdict arrives with the evidence behind it.

  • SBOMs ingested every deploy: always an up-to-date picture of what's live
  • SBOMs re-scanned through the day: new CVEs matched against your inventory automatically
  • Every build tracked into every environment: for a given CVE you see which services and clusters carry it, so you know where to fix first
  • Every verdict carries its evidence: the behaviour observed, the profile applied, the package loaded or not
  • Focus on what is reachable and not yet protected

Protect

Anything outside the profile is blocked

Every workload in production gets its own security profile, generated from its learned behaviour and enforced at the kernel. Protection is a ramp with three modes: observe, where bifrost learns and nothing is blocked; detect, where the profile is applied and deviations are reported; and enforce, the destination, where anything outside the profile is blocked, including exploits nobody has discovered yet.

  • Profiles generated automatically from learned behaviour, fresh with every build: zero manual profile writing
  • No rules to rot: manual regimes run from ~200 to 10,000 rules that go stale the moment the software changes
  • Every blocked event raises an alert with its full context: what happened, in which workload, and why it fell outside the profile
  • SIEM-ready integrations: pipe alerts straight into your SOC workflow

Under the hood: each security profile is an AppArmor profile, enforced by the Linux kernel's security module rather than by a sidecar or a proxy.

bifrost runtime event showing behaviour outside the security profile, blocked at the kernel

Answer

The next CVE, before it is asked

When a new CVE is discovered, bifrost already knows where you have it, how exposed it is, and how well protected you already are. If the profile blocks the path, the answer is protected, with the evidence. If not, the remedies. No new build and no new scan: the answer comes from what bifrost already knows, every build tracked into every environment and every active SBOM re-scanned through the day.

Higher-quality prioritisation, no manual triaging, deep runtime understanding, and kernel-level protection, fully automated with bifrost.

Where you start decides what you can know

Scanners start from the image and stop there. bifrost starts from runtime and works up: knowledge, verdicts, protection, answers.

CapabilityScanners (start from the image)bifrost (starts from runtime)
CVE detectionYes: finds every known CVE in the imageYes: SBOMs ingested every deploy, re-scanned through the day
ReachabilityNo: never reaches runtime, so every finding arrives without the context to verdict itYes: every CVE verdicted against what actually runs
MitigationNo: the only remedy is a patchYes: the security profile blocks paths the workload never uses
PrioritisationBy CVSS score onlyBy verdict: reachable, mitigated by the profile, or never loaded
NoiseHigh: hundreds or thousands of findingsLow: a short reachable list, with the evidence attached
UpdatesPeriodic scansEvery build, plus SBOMs re-scanned through the day

Two other starting points: detect-and-respond tools start at runtime too, but only watch and report, leaving the acting to you after the fact. Manual policy engines start from a rulebook someone has to write, anywhere from ~200 to 10,000 rules that rot the moment the software changes.

Built for production

Designed for production clusters: a DaemonSet per node, kernel-level enforcement, and under 1% CPU overhead.

Enforcement

AppArmor LSM

Deployment

DaemonSet

Resource usage

< 200MB RAM per node

Performance impact

< 1% CPU

SBOM formats

CycloneDX, SPDX

CVE discovery

SBOM scanned several times a day

Built for security-conscious teams

Built on research, engineered for production, hosted where your data belongs.

Research-founded

Born from a joint EU research project at Lund University, then shaped into a product by engineers with real-world production experience. Research depth, practical edge.

Sovereign by choice

Run bifrost where your compliance posture demands, from a Swedish-owned sovereign cloud outside US jurisdiction to your own infrastructure. GDPR-compliant by design.

Swedish-owned

Researched, developed, and funded by Swedish individuals. Patented runtime profiling technology, built in Sweden for European and global teams.

Kernel-level enforcement

Built on AppArmor, a Linux Security Module trusted in production for 20+ years. Enforcement at the kernel means stronger isolation and inherent protection of sensitive data.

Data residency

Your data stays where you want it

Run bifrost in the jurisdiction and ownership model your compliance posture demands. Same platform, four deployment options, from a sovereign European cloud to your own infrastructure.

Swedish hosted

Managed service on Swedish-owned and controlled cloud.

  • Outside US jurisdiction
  • GDPR and NIS2 ready
  • Full data sovereignty

European hosted

EU region of a global hyperscaler.

  • Familiar, proven scalability
  • EU data residency
  • GDPR compliant

Private cloud

Single-tenant, managed by bifrost in your infrastructure.

  • Dedicated single-tenant instance
  • Runs in your own infrastructure
  • Fully managed by bifrost
Coming soon

On-premise

Runs entirely in your environment

  • Data never leaves your network
  • Air-gap compatible
  • Self-hosted by your organisation

Not sure which fits? Talk to us about your residency requirements

Your security is our security

bifrost is built with data minimisation and privacy at its core.

Data minimisation

The bifrost agent collects behavioural metadata: system calls, file access patterns, network connections, never application data or personal information.

EU data residency

All data is processed and stored within the EU. GDPR-compliant by design.

Encryption

All data in transit and at rest is encrypted.

Minimal-privilege agent

The bifrost agent runs as a read-only DaemonSet with minimal privileges. No access to your application data.

NIS2 evidence

Continuous enforcement produces continuous evidence. Security profiles and CVE verdicts give you evidence that maps to NIS2's technical security measures.

ISO 27001

ISO 27001 certification in progress. Contact us for our current security documentation.

A lookup, not a war room

The next CVE, answered from what bifrost already knows. See it on your stack: a 30-minute demo, or 14 days on your own cluster.