What you inherit
Agents investigate the base image, its layers, and every package inside.

Maze has made it feel like we have a team of security engineers that I can confidently rely on for triaging vulnerabilities.



Agents investigate the base image, its layers, and every package inside.
Every image in your registries and every container, watched by agents.
Your code and the dependencies you build in, investigated with context from your cloud.
Maze agents understand your containers from code to cloud. They stay up to date on what’s running, close the findings on what isn’t, and help you fix what’s exploitable.
See how Maze AI agents investigate and resolve cloud
vulnerabilities like your engineer would.
Container security is part of Maze Cloud. Agents map your containers, images, and registries, investigate every finding with context from your environment, and help you fix what’s exploitable. If you also run Maze Code, the two share context, so investigations get sharper on both sides.
Container scanners hand you every CVE in every layer and leave the triage to you. Maze investigates each finding the way a security engineer would, checking whether it’s exploitable in your environment, and closes what isn’t.
No. No sensors, no eBPF, nothing running alongside your workloads. All Maze needs is a read-only role. Agents continually check your environment to see which containers are live, which images they run, and how each one is exposed.
Containers running on EKS, ECS, and AKS, plus images in your registries, like Docker Hub and Azure Container Registry.
No. Maze ingests findings from the scanners you already run and investigates them. Your scanner keeps doing what it does. Maze adds the judgment on top.
No, Maze isn’t a runtime threat detection tool. We find, investigate, and fix exploitable vulnerabilities before anyone attacks them. If you need live attack detection, that’s a different tool, and Maze runs happily alongside it.
Most container CVEs arrive that way. Agents trace the finding to the layer it came from, then propose remediation options with the tradeoffs shown, like upgrading the base image or rebuilding to pull the patch, so you pick the fix that fits.
Agents generate and validate the fix, then route it to the developer or coding agent that owns the code. Your team stays in control of what merges.
Deployment can be done in under five minutes. All we need is a read-only role in your cloud environment and an API connection to one or more vulnerability scanners.
We aim to keep pricing simple and fair. Large language models aren’t cheap, but we’ve worked hard to optimize cost and performance to make sure our pricing is reasonable.
Yes, Maze is cloud-hosted in AWS. Customers can choose between multi-tenant and single-tenant hosting.
Maze has been built for enterprise from day one. We have passed our ISO 27001 accreditation and are currently in our SOC 2 Type 2 observation window.
Triage and remediate CVEs in containers and VMs, and catch zero-days before scanners see them.
Find, triage, and remediate CVEs in third-party code, using your existing scanner or ours.
Find and fix business-logic vulnerabilities that SAST misses, or triage results from your existing scanner.
Everyone uses AI now. What makes Maze different, and how is the platform built for AI agents?
Why we’re building Maze to be a security company that thinks differently.
Security research, blogs, video, and more from security leaders and the Maze team.