Air-gapped • AI-enhanced • Container security

Pandoras Baux

An air-gapped container security platform with AI-powered vulnerability triage, network anomaly detection, and compliance auditing. Enterprise-grade protection at a fraction of the cost of commercial scanners — air-gap net-cut proven.

Zero internet required. Full SBOM generation, CVE matching, IDS integration, and CIS Docker Benchmark auditing — all running locally.

Capabilities

Complete container security lifecycle from vulnerability scanning to network threat detection.

Vulnerability scanning

SBOM generation via Syft with CVE matching via Grype. Bundled offline vulnerability database, finding deduplication, and severity classification across all container images.

Network anomaly detection

TCP/UDP connection tracking with Suricata IDS integration and network anomaly detection. 40+ custom security rules, behavioral baseline learning, and container-to-container communication matrix.

AI-powered triage

Local LLM integration via Ollama for context-aware vulnerability prioritization, natural language security queries, and automated remediation suggestions.

Compliance auditing

  • CIS Docker Benchmark v1.6 — 17 runtime security checks
  • Dockerfile security analysis — 18 static analysis rules
  • Runtime configuration audit — 8 security posture checks
  • Docker Compose analysis — 7 misconfiguration detectors
  • Kubernetes manifest analysis — 10 security checks

Network threat detection

  • Connection tracking with PCAP capture (eBPF-assisted where supported)
  • Suricata IDS with 40+ container-specific rules
  • Behavioral baseline learning (7-day window)
  • Alert deduplication via SHA-256 fingerprinting
  • Alert correlation engine for related security events

Architecture & security

Enterprise-grade platform designed for air-gapped and high-security environments.

Security posture

  • 100% air-gapped — net-cut proven, zero internet, bundled offline databases
  • Argon2id password hashing
  • ML-DSA-65 post-quantum digital signatures (FIPS 204) for license verification — validated air-gapped (dilithium-py)
  • SHA-256 tamper-evident audit chain · JWT authentication on all API endpoints (60-minute lifetime)
  • Data at rest via host full-disk encryption (FDE)
  • Systemd hardening (NoNewPrivileges, ProtectSystem, PrivateTmp) · non-root service account · TLS via reverse proxy

Technology stack

  • Flask 3.x + SQLAlchemy 2.x backend with REST API
  • React 18 + Vite + Tailwind CSS frontend dashboard
  • PostgreSQL 16 (recommended) or SQLite
  • Celery + Redis 7.x for async task processing
  • Ollama for local AI with configurable models

Web dashboard

  • Real-time vulnerability, network, and compliance metrics
  • Interactive network traffic visualization
  • Dockerfile and docker-compose paste-and-analyze tools
  • Integrated AI chat assistant for security queries

Offline updates

  • Offline CVE database update tool (export/import)
  • Offline Suricata rules update tool (export/import)
  • SHA-256 verification for all update packages
  • Self-extracting installer packages for deployment
All scanning and analysis happens locally. No container images or vulnerability data ever leaves your network.

Use cases

Where air-gapped container security creates immediate operational value.

Defense & intelligence

Secure containerized workloads on classified networks where cloud-based scanning tools are prohibited. Full vulnerability and compliance coverage without internet access.

Critical infrastructure

Monitor container deployments in OT/ICS environments with real-time network threat detection and behavioral baseline learning. Detect anomalies before they become incidents.

Healthcare & regulated

Maintain container security compliance in HIPAA-regulated environments without exposing PHI to third-party scanning services. Audit-ready CIS benchmark reports on demand.

Deployment tiers

Choose the deployment tier that matches your operational needs.

Scanner

CI/CD integration

  • SBOM generation (Syft)
  • CVE matching (Grype)
  • Offline vulnerability DB
  • Finding deduplication

Sentinel

Scanner + runtime protection

  • Everything in Scanner
  • Network anomaly detection
  • Suricata IDS integration
  • Behavioral baselines

Command

Full platform + AI

  • Everything in Sentinel
  • Web dashboard UI
  • AI-powered triage
  • Compliance auditing

Pricing

Enterprise-grade container security at a fraction of the cost of commercial alternatives.

Cost advantage

  • Substantially lower total cost than commercial scanners like JFrog Xray or Tenable
  • No per-node or per-container licensing fees
  • Perpetual licensing — no recurring subscriptions
  • Self-hosted — no cloud platform fees

What you get

  • Full platform deployment (Scanner, Sentinel, or Command)
  • Offline vulnerability database with update tooling
  • Comprehensive documentation suite
  • Deployment support and hardening guidance
Ready to secure your containers?

Email animusai.devops@gmail.com to request pricing, a demo deployment, or a security assessment.

Contact