Container security that knows every layer


Contentful
Halcyon
moneycorp

Maze has made it feel like we have a team of security engineers that I can confidently rely on for triaging vulnerabilities.

Nathan Cooke

Engineering Manager, Product Security, Alloy



A dedicated AI security
team for your containers


Automatically investigate and fix container vulnerabilities

They map every container, image, and registry into one clear picture of your environment through a read-only role with no sensors or EBPF to install.

Agents understand where
code meets cloud

Maze secures the full life of a container, from the code you write to the image it ships in to where it runs.

What you inherit

Agents investigate the base image, its layers, and every package inside.

What you run

Every image in your registries and every container, watched by agents.

What you write

Your code and the dependencies you build in, investigated with context from your cloud.


Container security that knows every layer

Frequently Asked Questions

See how Maze AI agents investigate and resolve cloud
vulnerabilities like your engineer would.

Container security is part of Maze Cloud. Agents map your containers, images, and registries, investigate every finding with context from your environment, and help you fix what’s exploitable. If you also run Maze Code, the two share context, so investigations get sharper on both sides.

Container scanners hand you every CVE in every layer and leave the triage to you. Maze investigates each finding the way a security engineer would, checking whether it’s exploitable in your environment, and closes what isn’t.

No. No sensors, no eBPF, nothing running alongside your workloads. All Maze needs is a read-only role. Agents continually check your environment to see which containers are live, which images they run, and how each one is exposed.

Containers running on EKS, ECS, and AKS, plus images in your registries, like Docker Hub and Azure Container Registry.

No. Maze ingests findings from the scanners you already run and investigates them. Your scanner keeps doing what it does. Maze adds the judgment on top.

No, Maze isn’t a runtime threat detection tool. We find, investigate, and fix exploitable vulnerabilities before anyone attacks them. If you need live attack detection, that’s a different tool, and Maze runs happily alongside it.

Most container CVEs arrive that way. Agents trace the finding to the layer it came from, then propose remediation options with the tradeoffs shown, like upgrading the base image or rebuilding to pull the patch, so you pick the fix that fits.

Agents generate and validate the fix, then route it to the developer or coding agent that owns the code. Your team stays in control of what merges.

Deployment can be done in under five minutes. All we need is a read-only role in your cloud environment and an API connection to one or more vulnerability scanners.

We aim to keep pricing simple and fair. Large language models aren’t cheap, but we’ve worked hard to optimize cost and performance to make sure our pricing is reasonable.

Yes, Maze is cloud-hosted in AWS. Customers can choose between multi-tenant and single-tenant hosting.

Maze has been built for enterprise from day one. We have passed our ISO 27001 accreditation and are currently in our SOC 2 Type 2 observation window.



One platform
for code & cloud



Resources