Security Center

Findings are cheap. Decisions are the product.

Any scanner will hand you four thousand findings. The Security Center turns them into a short list of things to do, and remembers the calls you already made so they do not come back on tomorrow's scan.

platform.ankra.app/organisation/security
67%
clear
Fleet security

Action required

18 actionable · 7 fixable

5 acknowledged · 6 accepted

Critical

2

8 observed

High

4

9 observed

Fixable severe

7

with a fix

Coverage

83%

5 fresh · 1 stale

CriticalCVE-2026-1000openssl3 clusters · 6 workloadsOpen
HighCVE-2026-2000stdlib2 clusters · 4 workloadsAcknowledged
MediumCVE-2026-3000requests1 cluster · 2 workloadsAccepted risk
Fix top findings with AIAccept risk · expires 90d
The problem

A scanner observes. A team has to decide.

Scanning is solved and mostly free. What is missing is everything that happens after the report lands.

The same triage, nightly

You judge an unfixable CVE in a base image, and the next scan presents it again, unchanged, to whoever opens the report next.

Counted once per cluster

One CVE in one shared base image becomes a hundred rows, so the total tells you about your image sprawl rather than your risk.

Severity is not priority

A fixable high in something you shipped yesterday usually outranks an unfixable critical in a base image you do not control.

Decisions

What a finding has to become

Acknowledging a finding means you have read it, and it stays actionable. Only an accepted risk leaves the count, and only with all four of these attached.

A reason, written down

Accepting a risk requires a written justification captured at the moment you had the context, not reconstructed from a Slack thread four months later.

A review date that expires

Every acceptance carries a deadline of at most a year, and can expire itself automatically the moment a fixed version becomes available.

A scope that outlives the pod

Ankra deploys your add-ons, so it can attribute a finding to the add-on that introduced it. Accept the risk once and it applies across the organisation, including clusters you create later.

A preview before you commit

Before a policy is written you see how many occurrences, findings, and clusters it touches, what it deliberately excludes, and what your actionable count becomes.

The surface

Six views over one fleet

Organisation-wide by default, with the same detail available per cluster.

Overview

The fleet scorecard: what share of scanned clusters carry no actionable critical or high findings, a plain-language verdict, and the remediation candidates ranked by severity, fix availability, and reach.

Findings

Every logical finding across the organisation, deduplicated across clusters and workloads. Filter by status, severity, cluster, add-on, namespace, or whether a fix exists at all.

Clusters

Per-cluster posture and scanner freshness, so a cluster that stopped reporting three weeks ago cannot quietly look clean.

Policies

The accepted-risk decisions you have made, with their review dates and lifecycle, alongside Kyverno pod-security violations per cluster.

Network Exposure

NetworkPolicy over-privilege scored for ingress and egress: unprotected workloads, rules broad enough to admit everything, and what to tighten first.

Compliance

CIS and NSA/CISA benchmark pass rates per cluster, plus Trivy configuration audit, exportable as an evidence report.

Blast radius

The axis a CVE count cannot see

Severity describes how bad a vulnerability is in the abstract. It says nothing about what an attacker reaches from the pod that has it.

Scored, not guessed

Each cluster gets separate ingress and egress over-privilege scores, counting the workloads no policy covers and the rules broad enough to admit everything.

Named and fixable

Every finding names the namespace, the workload, and the offending rule, and says what to tighten, so it maps onto a change rather than a worry.

Evidence

Compliance you can hand to an auditor

Benchmark pass rates per cluster per framework, plus an export that carries the decisions rather than just the numbers.

Benchmarks and config audit

CIS Kubernetes and NSA/CISA results as pass rates per cluster, with Trivy's configuration audit as a second axis. Frameworks are discovered from what Trivy publishes rather than hardcoded.

The evidence report

CSV or JSON over a date window: posture history per cluster, every disposition with its reason and review date and author, an audit summary, benchmark results, and attestations covering MFA, SOPS, and baseline coverage.

Getting started

One action to switch it on

The Security Center reads from tooling that runs in your cluster. Installing it is a single action, and nothing starts blocking workloads on its own.

Install the baseline

One click installs pinned Trivy Operator and Kyverno with the pod-security baseline policy set on the cluster you choose.

Audit before enforce

Kyverno arrives in audit mode, so violations surface without blocking anything. Switching a cluster to enforce is a separate, deliberate step.

Scoped access

Reading, acknowledging, and writing accepted-risk policies are three separate permissions, and the evidence export additionally requires audit access.

Get started

From prompt to production.
No tickets in between.

Describe what you want to ship and let Ankra's AI generate, deploy, and operate it. Free forever for small teams.

Free forever tierNo credit cardZero lock-in