Declarative Continuous Compliance for Kubernetes

Your image scans are already out of date

Image scans show what was deployed. Containers drift—packages added, files modified, certs expired. Reel captures what's actually running, continuously, so your security posture reflects reality.

See Reel in action

terminal

CRIU Checkpoints

Freeze a running container's complete state—memory, processes, file descriptors, network connections. When something goes wrong, you have the exact moment captured for analysis.

Captured State
Complete
Memory
2.4 GB
Processes
23
Network
12 conn
Files
47 fd
chk-api-server-20241210-143022
2024-12-10 14:30
+42 filesCurrent
2024-12-10 08:30
+15 files
2024-12-09 20:30
+8 files

Filesystem Layers

Containers drift from their images. See exactly what changed since deployment—files added, configs modified, binaries installed at runtime. The diff between your scanned image and running container is your blind spot.

Security Scanning

Your CI pipeline scanned the image. But what's running now? Reel scans live containers—SBOM, CBOM, malware, IoCs—continuously. Same tools, real-time results.

SBOM

312 packages

Packages, vulnerabilities, licenses

CBOM

8 certificates

Certificates, keys, weak crypto

Malware

0 threats

Known threats via ClamAV

Files

4 indicators

SUID/SGID binaries, hidden files, suspicious locations

Define schedules in Kubernetes annotations

Reel runs as a DaemonSet in your cluster. Define capture schedules directly in your deployment manifests—GitOps-friendly, version controlled with your code.

Your Pods
app
api
worker
Reel
Reel Agent
Active
Evidence Artifacts
Checkpoints
Layers
SBOM
CBOM
Malware

Annotation-Driven Scheduling

Export checkpoints, SBOM, CBOM, and malware scans to your S3 evidence vault on a schedule. All artifacts are immutable and timestamped for audit trails.

deployment.yaml
1
2
3
4
5
6
7
metadata:
annotations:
reel.io/schedule: |
0 */6 * * * | export checkpoint
next | export sbom
next | export cbom
*/5 * * * * | export malware

Built on proven technology

KubernetesKubernetes
containerdcontainerd
CRI-OCRI-O
CRIUCRIU
TrivyTrivy
ClamAVClamAV
reel

Never lose evidence again

Coming soon. Deploys in minutes. Join the waitlist for early access.