Skip the next security product. Onboard engineers who understand the problem.
Palm Sec is a team of security and platform engineers. We build security observability and detection, secure AI systems, and test applications and cloud environments, using open-source tools like Tetragon, Cilium and Falco wherever they fit. It plugs into the systems you already run, and your team ends up owning it.
Security observability
- Which process opened that connection?
- Which pods are talking to the internet?
- Who assumed that role, and from where?
- What changed on the node before the alert?
- How do we collect events from 10K+ nodes?
AI security
- Which sandboxes actually hold up for agent-run code?
- Which emerging isolation technologies are worth adopting?
- How do we give developers MCP servers without handing over the keys?
- What does agent observability look like at scale?
What we work on
Security observability
Pipelines that carry security telemetry from every cluster and account to the places you investigate from.
Runtime event pipelines · Network flow pipelines · Cloud audit pipelines · Vector and Fluent Bit · OpenTelemetry · Prometheus and GrafanaSecurity data
Where security telemetry lives, how it is shaped, and how cheaply you can keep it.
ClickHouse · Elasticsearch · OpenSearch · OpenObserve · OCSFDetection engineering
Detections written, tested and versioned like code, for the tools you already run.
Tetragon TracingPolicies · Falco rules · KubeArmor policies · Cilium network policy · WAF rulesRuntime and cluster security
The runtime sensors and cluster policy that keep workloads in the state you intended.
Tetragon · Falco · KubeArmor · Cilium and Hubble · Custom eBPF · Kyverno · Trivy · KubescapePentesting and AppSec
Testing of applications, pipelines and identity, ending in findings your engineers can reproduce and fix.
Penetration testing · AI red teaming · SAST and DAST · StackHawk · StackRox · Snyk · Cloudflare WAF · AWS WAF · ModSecurity · Entra ID auditingAI security
Securing the applications, agents and tool integrations built on language models.
LangChain · Firecracker · Kata Containers · WASM sandboxes · MCP securityWhere teams usually start
See what is happening across your clusters
Process, network and cloud-account telemetry from Tetragon, Cilium and CloudTrail, collected and enriched in one pipeline.
Learn more →Keep security logs somewhere you control
ClickHouse, Elasticsearch or OpenSearch with schemas, retention and ingestion designed around how you investigate.
Learn more →Make detections reliable
TracingPolicies, Falco rules, KubeArmor, Cilium policy and WAF rules written as code, tested against real events and tuned to cut noise.
Learn more →Everything we work on
There are many options. We help choose technologies that will last and are relevant.
Security observability
Runtime event pipelinesNetwork flow pipelinesCloud audit pipelinesVector and Fluent BitOpenTelemetryPrometheus and Grafana
Detection engineering
Tetragon TracingPoliciesFalco rulesKubeArmor policiesCilium network policyWAF rules
How we work with your teams
We partner with enterprise, product, specialty, platform, developer and DevOps teams, and each step of an engagement is built with the people who will own the result.
- Enterprise security
- Product
- Specialty
- Platform
- Developers
- DevOps
- 1
Assess
We review your clusters, accounts and existing tooling with the people who run them, and agree a target design.
WithEnterprise securityPlatform
- 2
Pilot
One non-production environment, working end to end, built alongside the engineers who will maintain it.
WithDevOpsDevelopers
- 3
Roll out
Staged deployment through your own pipelines and change process, with results measured at each stage.
WithPlatformProduct
- 4
Hand off
Documentation, runbooks and a walkthrough, so the teams who own it can run it without us.
WithSpecialtyDevOps