Skip the next security product. Onboard engineers who understand the problem.
Palm Sec is a team of security and platform engineers. We build security observability and detection on open-source tools like Tetragon, Cilium and Falco, connect it to the systems you already run, and leave your team owning it.
Security observability
- Which process opened that connection?
- Which pods are talking to the internet?
- Who assumed that role, and from where?
- What changed on the node before the alert?
What we work on
Security observability
Know what is running, what it talks to, and who did what, across every cluster and account.
Tetragon · Cilium and Hubble · Custom eBPF · Vector and Fluent Bit · OpenTelemetry · Prometheus and GrafanaSecurity data
Where security telemetry lives, how it is shaped, and how cheaply you can keep it.
ClickHouse · Elasticsearch · OpenSearch · OCSF · Kafka and MSKDetection engineering
Detections written, tested and versioned like code, for the tools you already run.
Tetragon TracingPolicies · Falco rules · KubeArmor policies · Cilium network policy · WAF rulesRuntime and cluster security
Runtime tooling and policy that keep clusters in the state you intended.
Falco · KubeArmor · Kyverno · Trivy · KubescapeAWS security
Account-level telemetry and guardrails for organizations with many accounts.
CloudTrail · GuardDuty and Security Hub · IAM and Organizations guardrailsKubernetes platform
The clusters and delivery machinery the security tooling runs on.
Amazon EKS · Karpenter · Argo CD and GitOps · TerraformWhere teams usually start
See what is happening across your clusters
Process, network and cloud-account telemetry from Tetragon, Cilium and CloudTrail, collected and enriched in one pipeline.
Learn more →Keep security logs somewhere you control
ClickHouse, Elasticsearch or OpenSearch with schemas, retention and ingestion designed around how you investigate.
Learn more →Make detections reliable
TracingPolicies, Falco rules, KubeArmor, Cilium policy and WAF rules written as code, tested against real events and tuned to cut noise.
Learn more →How an engagement runs
- 1
Assess
We review your clusters, accounts and existing tooling, and agree a target design.
- 2
Pilot
One non-production environment, working end to end.
- 3
Roll out
Staged deployment through your pipelines, with results measured.
- 4
Hand off
Documentation, runbooks and a walkthrough, so your team runs it.