Pandoras Baux
An air-gapped container security platform with AI-powered vulnerability triage, network anomaly detection, and compliance auditing. Enterprise-grade protection at a fraction of the cost of commercial scanners — air-gap net-cut proven.
Capabilities
Complete container security lifecycle from vulnerability scanning to network threat detection.
Vulnerability scanning
SBOM generation via Syft with CVE matching via Grype. Bundled offline vulnerability database, finding deduplication, and severity classification across all container images.
Network anomaly detection
TCP/UDP connection tracking with Suricata IDS integration and network anomaly detection. 40+ custom security rules, behavioral baseline learning, and container-to-container communication matrix.
AI-powered triage
Local LLM integration via Ollama for context-aware vulnerability prioritization, natural language security queries, and automated remediation suggestions.
Compliance auditing
- ✓CIS Docker Benchmark v1.6 — 17 runtime security checks
- ✓Dockerfile security analysis — 18 static analysis rules
- ✓Runtime configuration audit — 8 security posture checks
- ✓Docker Compose analysis — 7 misconfiguration detectors
- ✓Kubernetes manifest analysis — 10 security checks
Network threat detection
- ✓Connection tracking with PCAP capture (eBPF-assisted where supported)
- ✓Suricata IDS with 40+ container-specific rules
- ✓Behavioral baseline learning (7-day window)
- ✓Alert deduplication via SHA-256 fingerprinting
- ✓Alert correlation engine for related security events
Architecture & security
Enterprise-grade platform designed for air-gapped and high-security environments.
Security posture
- ✓100% air-gapped — net-cut proven, zero internet, bundled offline databases
- ✓Argon2id password hashing
- ✓ML-DSA-65 post-quantum digital signatures (FIPS 204) for license verification — validated air-gapped (dilithium-py)
- ✓SHA-256 tamper-evident audit chain · JWT authentication on all API endpoints (60-minute lifetime)
- ✓Data at rest via host full-disk encryption (FDE)
- ✓Systemd hardening (NoNewPrivileges, ProtectSystem, PrivateTmp) · non-root service account · TLS via reverse proxy
Technology stack
- ✓Flask 3.x + SQLAlchemy 2.x backend with REST API
- ✓React 18 + Vite + Tailwind CSS frontend dashboard
- ✓PostgreSQL 16 (recommended) or SQLite
- ✓Celery + Redis 7.x for async task processing
- ✓Ollama for local AI with configurable models
Web dashboard
- ✓Real-time vulnerability, network, and compliance metrics
- ✓Interactive network traffic visualization
- ✓Dockerfile and docker-compose paste-and-analyze tools
- ✓Integrated AI chat assistant for security queries
Offline updates
- ✓Offline CVE database update tool (export/import)
- ✓Offline Suricata rules update tool (export/import)
- ✓SHA-256 verification for all update packages
- ✓Self-extracting installer packages for deployment
Use cases
Where air-gapped container security creates immediate operational value.
Defense & intelligence
Secure containerized workloads on classified networks where cloud-based scanning tools are prohibited. Full vulnerability and compliance coverage without internet access.
Critical infrastructure
Monitor container deployments in OT/ICS environments with real-time network threat detection and behavioral baseline learning. Detect anomalies before they become incidents.
Healthcare & regulated
Maintain container security compliance in HIPAA-regulated environments without exposing PHI to third-party scanning services. Audit-ready CIS benchmark reports on demand.
Deployment tiers
Choose the deployment tier that matches your operational needs.
Scanner
CI/CD integration
- ✓SBOM generation (Syft)
- ✓CVE matching (Grype)
- ✓Offline vulnerability DB
- ✓Finding deduplication
Sentinel
Scanner + runtime protection
- ✓Everything in Scanner
- ✓Network anomaly detection
- ✓Suricata IDS integration
- ✓Behavioral baselines
Command
Full platform + AI
- ✓Everything in Sentinel
- ✓Web dashboard UI
- ✓AI-powered triage
- ✓Compliance auditing
Pricing
Enterprise-grade container security at a fraction of the cost of commercial alternatives.
Cost advantage
- ✓Substantially lower total cost than commercial scanners like JFrog Xray or Tenable
- ✓No per-node or per-container licensing fees
- ✓Perpetual licensing — no recurring subscriptions
- ✓Self-hosted — no cloud platform fees
What you get
- ✓Full platform deployment (Scanner, Sentinel, or Command)
- ✓Offline vulnerability database with update tooling
- ✓Comprehensive documentation suite
- ✓Deployment support and hardening guidance
Email animusai.devops@gmail.com to request pricing, a demo deployment, or a security assessment.