Use cases / Regulated workloads
Use case · Regulated workloads
Automation your security team can sign off on.
Predictable behaviour, an approved list of fixes, no data leaving your network, and a signed record. The things a security review asks for are built in.
What it takes off your plate
01
Predictable by design
No AI model touches your cluster. The same input always gives the same result.
02
Audit bundle in one command
A file list, an audit log and outcomes, exported locally. Nothing is sent out.
03
Bring your own model
Optional AI features on your own endpoint: OpenAI, Anthropic, or a model you host.
In practice
Every fix leaves a record
Detection, cause, policy decision, fix and verification — written down, signed and exportable.
See a real example: a weak certificate key, caught and escalated
fix record · prod-eu-1VERIFIED
10:34:12DETECTCrashLoopBackOff · payments-api · OOMKilled 137
10:34:48CAUSEmemory limit 512Mi vs p99 working set 780Mi
10:35:02POLICYlimit-raise ≤ 2× · namespace payments · auto-approved
10:35:19FIXpatched limits 512Mi → 1Gi, rollout restarted
10:41:30VERIFY0 restarts, error rate 0.02%, 6 min observed
signed by workload identity · srenix-fixer@prod-eu-1
Works with what you run
Cloud
AWS · GCP · Azure
K8s distros
Kubernetes · EKS · GKE · AKS · k3s · OpenShift · RKE2
Observability & ticketing
Prometheus · Alertmanager · Grafana · Loki (paid) · OTLP (paid) · OpenProject · Jira · ServiceNow · Slack
K8s-native infra
Vault · cert-manager · CNPG · Rook/Ceph · External Secrets · Kong · ArgoCD · Cloudflare
Trigger sources
K8s informers · Alertmanager polling · Webhook (HMAC) · CronJob resync
AI providers
OpenAI · Anthropic · In-cluster vLLM
On-call should be quieter every week
Helm install in 5 minutes. No telemetry exfiltration. No per-investigation surprises.