SANER COSP · 2026
Saner COSP Feature List
Saner Container Orchestration Security Platform, module by module — Kubernetes exposure, posture, entitlements and remediation in one console
01 SANER COSP PLATFORM
7 capabilities
FEATURE
AVAILABILITY
01
Unified platform for container orchestration security across asset exposure, posture management, posture anomaly detection, entitlement management, risk prioritization, cyber hygiene scoring, and remediation.
Yes
02
Centralized visibility into Kubernetes clusters, namespaces, nodes, workloads, services, identities, configurations, and security findings.
Yes
03
Continuous, scheduled scanning through Kubernetes API access to refresh inventory, posture findings, entitlement evaluations, and anomaly observations.
Yes
04
Cluster-level integration that collects metadata, resource configuration, entitlement information, and posture telemetry without requiring an agent on every node.
Yes
05
Account-level COSP dashboard with consolidated views across COAE, COPM, COEM, COPA, CORP, COHS, and CORM.
Yes
06
Role-based access and multi-user access through the Saner Platform.
Yes
07
Search, filters, drill-down views, interactive charts, and CSV export across supported dashboards and feature areas.
Yes
02 KUBERNETES CLUSTER SUPPORT
8 capabilities
FEATURE
AVAILABILITY
01
Onboard and secure standalone and on-premises Kubernetes clusters.
Yes
02
Onboard and secure Microsoft Azure Kubernetes Service (AKS) clusters.
Yes
03
Onboard and secure Amazon Elastic Kubernetes Service (EKS) clusters.
Yes
04
Onboard and secure Google Kubernetes Engine (GKE) clusters.
Yes
05
Apply the same core COSP security capabilities across standalone Kubernetes, AKS, EKS, and GKE environments.
Yes
06
Use Kubernetes cluster-level permissions and dedicated Kubernetes objects for secure discovery and security analysis.
Yes
07
Support onboarding through standard cluster deployment and OIDC-based methods.
Yes
08
Continuously refresh cluster inventory and findings based on configured scan schedules.
Yes
03 ASSET EXPOSURE — COAE
11 capabilities
FEATURE
AVAILABILITY
01
Continuously discover Kubernetes resources across clusters and namespaces, including nodes, pods, deployments, daemonsets, services, ingress resources, persistent volumes, persistent volume claims, ConfigMaps, and Secrets.
Yes
02
Maintain a centralized inventory of cluster-scoped and namespace-scoped resources with resource identifiers, types, status, and configuration details.
Yes
03
Visualize resource distribution across clusters, namespaces, resource types, images, and workloads.
Yes
04
Monitor the operational health of control plane components, worker nodes, namespaces, pods, containers, and images.
Yes
05
Identify internet-exposed services, externally reachable workloads, publicly exposed ingress configurations, and other publicly accessible resources.
Yes
06
Track trends and fluctuations in cluster-scoped resources, namespaced resources, images, and workloads over time.
Yes
07
Create and manage watchlists for critical or high-priority resources, with reasons recorded for traceability.
Yes
08
Search, filter, monitor, and export watchlisted resource data for analysis, reporting, and governance.
Yes
09
Apply tags and groups to organize resources and quickly filter related assets across the container environment.
Yes
10
Visualize relationships between container images, containers, workloads, namespaces, and other Kubernetes resources.
Yes
11
Export resource and exposure information to CSV for operational review and audit evidence.
Yes
04 POSTURE MANAGEMENT — COPM
12 capabilities
FEATURE
AVAILABILITY
01
Continuously evaluate Kubernetes resources and configurations to identify security misconfigurations and control failures.
Yes
02
Categorize findings by severity to help teams focus on critical and high-risk configuration issues.
Yes
03
Analyze posture findings by cluster, namespace, resource type, benchmark, rule, and compliance status.
Yes
04
View passed and failed posture checks with affected-resource counts and detailed evidence.
Yes
05
Track security issue and compliance trends over time to measure posture changes.
Yes
06
Assess Kubernetes configurations against supported CIS benchmark controls.
In progress
07
Assess Kubernetes workloads and resources against Pod Security Standards (PSS) controls.
In progress
08
Assess Kubernetes configurations against supported NIST benchmark controls.
In progress
09
Create and manage custom benchmarks by selecting security checks that reflect organizational requirements.
Yes
10
Monitor compliance status for default and custom benchmarks from consolidated dashboard views.
Yes
11
Initiate remediation for supported posture findings from the COPM workflow.
Yes
12
Export posture and compliance findings for reporting and further analysis.
Yes
05 ENTITLEMENT MANAGEMENT — COEM
11 capabilities
FEATURE
AVAILABILITY
01
Discover and inventory Kubernetes identities and access-control entities, including users, groups, service accounts, roles, cluster roles, role bindings, and cluster role bindings.
Yes
02
Provide granular visibility into permissions, policies, assignments, usage, and access relationships.
Yes
03
Visualize relationships among identities, roles, bindings, permissions, resources, and namespaces through an identity graph.
Yes
04
Identify excessive privileges and over-permissive Kubernetes RBAC assignments.
Yes
05
Detect unnecessary cluster-wide access, broad wildcard permissions, and privilege-escalation exposure.
Yes
06
Identify inactive or unused identities and entitlement entities to reduce dormant access risk.
Yes
07
Monitor entitlement entity counts, permission usage, and excessive-permission trends over time.
Yes
08
Detect and flag critical activities and high-privilege actions occurring within Kubernetes clusters.
Yes
09
Review event evidence, identity context, affected resources, and request details for critical activities.
Yes
10
Filter, search, and investigate entitlement findings and Kubernetes cluster events for troubleshooting and root-cause analysis.
Yes
11
Initiate remediation for supported identity and entitlement findings.
Yes
06 POSTURE ANOMALY — COPA
7 capabilities
FEATURE
AVAILABILITY
01
Continuously detect configuration and posture anomalies affecting Kubernetes resources.
Yes
02
Monitor anomalous and non-anomalous behavior to identify deviations from expected posture.
Yes
03
Analyze anomaly distribution by severity, category, cluster, namespace, and affected resource.
Yes
04
Use anomaly density to identify resources and areas with the greatest concentration of posture deviations.
Yes
05
Investigate individual COPA IDs with confidence, evidence, affected-resource counts, and detailed context.
Yes
06
Whitelist acceptable COPA rules or specific resources to reduce unnecessary findings while retaining governance context.
Yes
07
Initiate remediation for supported anomalies from the COPA workflow.
Yes
07 RISK PRIORITIZATION — CORP
10 capabilities
FEATURE
AVAILABILITY
01
Correlate COPM, COEM, and COPA findings with affected clusters, namespaces, workloads, identities, and resources.
Yes
02
Prioritize risks using severity, exploitability, technical impact, resource criticality, and exposure context.
Yes
03
Apply a structured security decision tree to classify issues into Act, Attend, Track*, and Track response categories.
Yes
04
Review prioritized risks by category, essential resource, namespace, affected resource type, and action priority.
Yes
05
Assign and use mission criticality to reflect the business or operational importance of affected resources and namespaces.
Yes
06
Map risks to MITRE ATT&CK tactics and techniques to explain potential adversary behavior.
Yes
07
Associate mapped risks with MITRE mitigations and recommended remediation measures.
Yes
08
Show affected resources and namespaces for each mapped risk and drill down into detailed findings.
Yes
09
Redirect prioritized risks to CORM so teams can initiate remediation within the same workflow.
Yes
10
Export and report prioritized risk information for governance and stakeholder review.
Yes
08 HYGIENE SCORE — COHS
9 capabilities
FEATURE
AVAILABILITY
01
Calculate a consolidated cyber hygiene score for container orchestration resources using COPM, COEM, and COPA security dimensions.
Yes
02
Present Global, Local, and overall Cyber Hygiene Scores on a 0-100 scale for straightforward interpretation.
Yes
03
Provide resource-level cyber hygiene scores with namespace, status, Local Score, Global Score, and overall score details.
Yes
04
Aggregate scores at namespace level to compare security posture across application and operational boundaries.
Yes
05
Aggregate scores at cluster level to identify stronger and weaker Kubernetes environments.
Yes
06
Provide account and organization-level rollups across accessible clusters and environments.
Yes
07
Show module-wise score distribution to identify whether posture, anomaly, or entitlement issues are reducing hygiene.
Yes
08
Track historical score changes and trends to assess whether remediation is improving security posture.
Yes
09
Identify leading contributors to score degradation and export score data for analysis.
Yes
09 REMEDIATION MANAGEMENT — CORM
10 capabilities
FEATURE
AVAILABILITY
01
Centralize remediation of supported COPM, COEM, and COPA findings.
Yes
02
Provide guided remediation workflows with issue context, affected resources, and recommended corrective action.
Yes
03
Create remediation tasks for selected findings and track them through approval and execution states.
Yes
04
Schedule remediation jobs for an approved maintenance window.
Yes
05
Configure automation rules to remediate eligible findings automatically when defined conditions are met.
Yes
06
Monitor remediation job status and review successful, failed, pending, and in-progress activities.
Yes
07
Use patch-aging insights to identify older or high-risk unresolved findings.
Yes
08
Use patching-impact analysis to prioritize remediation that addresses the greatest number of affected resources.
Yes
09
Roll back supported applied remediations when a change must be reversed.
Yes
10
Review remediation history and outcomes for operational tracking and audit evidence.
Yes
10 ORGANIZATION DASHBOARD
2 capabilities
FEATURE
AVAILABILITY
01
Provide an organization-wide COSP dashboard that consolidates cluster inventory, exposure, posture, entitlement, anomaly, risk, hygiene, and remediation insights across accounts.
In progress
02
Enable organization-level drill-down from aggregated metrics to accounts, clusters, namespaces, and affected resources.
In progress
11 REPORTS
4 capabilities
FEATURE
AVAILABILITY
01
Generate predefined COSP reports covering resources, exposure, posture, entitlements, anomalies, prioritized risks, cyber hygiene, and remediation.
Yes
02
Create custom report views using selected data fields, filters, and stakeholder-specific criteria.
Yes
03
Generate cluster overview and detailed Kubernetes resource reports.
Yes
04
Export report data for offline analysis, documentation, and audit support.
Yes
12 ORGANIZATION REPORTS
2 capabilities
FEATURE
AVAILABILITY
01
Create organization-level report views that consolidate COSP information across accessible accounts and clusters.
Yes
02
Use organization reports to compare security posture, risks, and remediation progress across environments.
Yes
13 ALERTING
3 capabilities
FEATURE
AVAILABILITY
01
Configure alerts for selected COSP events, findings, risk conditions, and remediation activities.
Yes
02
Send email notifications based on configured alert rules and conditions.
Yes
03
Use alert context to navigate to the relevant finding or workflow for investigation and action.
Yes
14 AUDIT LOGGING
3 capabilities
FEATURE
AVAILABILITY
01
Track user and administrative activities performed within the Saner Platform and COSP workflows.
Yes
02
Search and filter audit records to investigate changes, access, and actions.
Yes
03
Export audit log information for governance, reporting, and compliance evidence.
Yes
15 SANER PLASMA FOR COSP
3 capabilities
FEATURE
AVAILABILITY
01
Use the Saner Plasma AI assistant to interact with COSP information through natural language questions.
Yes
02
Summarize relevant container security findings and help users navigate to related findings.
Yes
03
Assist users in understanding security context and recommended next actions.
Yes
16 INTEGRATION WITH SANER CNAPP
2 capabilities
FEATURE
AVAILABILITY
01
Onboard supported Kubernetes clusters to COSP by reusing applicable cloud credentials.
Yes
02
Connect cloud-account context with Kubernetes cluster security for a more unified cloud view.
Yes
17 COSP AGENT
2 capabilities
FEATURE
AVAILABILITY
01
Deploy a COSP agent to extend visibility into configuration and security conditions within Kubernetes applications.
In progress
02
Detect application-level Kubernetes misconfigurations that are not fully observable through control-plane configuration.
In progress
18 NODE PROTECTION — CONP
18 capabilities
FEATURE
AVAILABILITY
01
Protect the operating systems of eligible control-plane and worker nodes while COSP secures Kubernetes resources, workloads, RBAC, and cluster configuration.
In progress
02
Discover eligible Kubernetes nodes through COSP and automatically deploy the Saner CONP agent through the cluster's DaemonSet delivery path.
In progress
03
Maintain a live inventory of control-plane nodes, worker nodes, operating systems, installed applications, packages, and services.
In progress
04
Map each protected node to its related cluster and environment so host-level risk retains Kubernetes operational context.
In progress
05
Identify internet-reachable nodes, exposed services, listening ports, reachability, privilege, permissions, configuration state, and usage context.
In progress
06
Watchlist high-consequence nodes to maintain focused monitoring and prioritization.
In progress
07
Continuously monitor nodes for configuration drift, posture anomalies, changing exposure paths, and patch-state changes.
In progress
08
Use anomaly confidence and whitelisting to focus investigation on meaningful node-level deviations.
In progress
09
Detect operating system and package vulnerabilities on Kubernetes nodes and retain affected-node context for remediation.
In progress
10
Prioritize missing patches using severity, affected-node count, exposure, and potential security impact.
In progress
11
Create guided patching and remediation tasks with scheduling controls, approval workflows, patch-aging views, impact tracking, and verified closure status.
In progress
12
Evaluate node configurations through scheduled or on-demand hardening checks and classify controls as passed, failed, or unchecked.
In progress
19 IMAGE AND REGISTRY SCANNING
5 capabilities
FEATURE
AVAILABILITY
01
Scan container images to identify known vulnerabilities before or after deployment.
In progress
02
Detect CVEs in operating system packages and other supported components contained in images.
In progress
03
Present image vulnerability severity, affected components, available fixes, and remediation guidance.
In progress
04
Scan supported container registries to inventory images and identify vulnerable image versions.
In progress
05
Relate vulnerable images to running Kubernetes workloads and affected clusters or namespaces.
In progress
20 ATTACK PATH ANALYSIS
4 capabilities
FEATURE
AVAILABILITY
01
Correlate exposure, misconfiguration, entitlement, anomaly, image, node, and workload risks to identify feasible Kubernetes attack paths.
In progress
02
Visualize how an attacker could move across connected identities, resources, workloads, namespaces, and nodes.
In progress
03
Prioritize attack paths using exploitability, reachability, mission criticality, and potential impact.
In progress
04
Recommend remediation actions that break the highest-risk attack paths and reduce overall exposure.
In progress
21 COSP ADMISSION CONTROLLER
4 capabilities
FEATURE
AVAILABILITY
01
Evaluate Kubernetes deployment requests against defined security and compliance policies before admission.
In progress
02
Allow, warn, or block deployments based on policy outcomes and configured enforcement mode.
In progress
03
Enforce guardrails for insecure configurations, excessive privileges, unapproved images, and other supported deployment risks.
In progress
04
Record admission decisions and policy evidence for investigation and governance.
In progress
