Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
The build-deploy-runtime split is where hidden SKUs live; look for a stage-by-stage licensing map, not 'full lifecycle' marketing.
eBPF-based sensing is the current standard for overhead/safety; strong answers give measured overhead and an explicit, configurable fail-open/closed answer.
In-use/reachability filtering plus layer attribution is what turns thousands of image CVEs into an actionable list — look for both, with a measured noise-reduction figure.
Look for signature verification plus policy-as-code with a real audit-then-enforce rollout path — day-one blocking without audit mode breaks deployments and gets disabled.
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
Drift detection is container-native security's core advantage; strong answers pair it with graduated response and explicit false-positive guardrails.
Cluster misconfiguration is as exploited as workload vulnerabilities; look for genuine KSPM depth, not a CIS-benchmark checkbox.
Serverless containers can't host a node sensor; honest answers state exactly what coverage remains there rather than claiming uniform protection.
Look for detection plus the remediation path (external secrets operator integration) — finding baked-in secrets without a migration story just documents the problem.
Container/pod-count-based pricing interacts awkwardly with autoscaling — ask explicitly how the vendor handles pricing for a highly elastic workload rather than assuming a static count.
Ephemeral containers make forensic capture time-sensitive — ask for a specific pre-termination evidence-capture mechanism and a real customer incident example, not just a generic 'we log everything' claim.
Ask for real evidence of PCI assessor acceptance, not just a generic 'PCI-ready' marketing claim — this is a concrete, checkable claim worth pressing on.
Look for genuine integration into a unified risk view; a standalone container dashboard disconnected from the broader AppSec/VM picture creates real reconciliation burden.
A false positive on runtime detection with automated response (e.g., killing a container) can cause real production outages — ask for a real, customer-validated false-positive figure and a safe rollout-tuning process.
Trend-over-time reporting is a distinct capability from a real-time dashboard — confirm this exists as a maintained, exportable report.
Namespace-isolation validation is a distinct capability from image/runtime scanning — a vendor should give a specific answer on how cross-namespace access is detected or prevented, not assume namespace boundaries are self-enforcing.
Strong answers give a concrete, customer-validated timeline for a realistic existing-footprint scenario (not a greenfield cluster) and are honest about the customer-side configuration effort required.