The breach isn’t the problem. The spread is. →Free Assessment

Containment Assessment
Aviatrix Platform
YOU ARE HERE
Phase 1

Self-Score

Phase 2

Architecture Read

Five Free Policies

Deploy and Expand

Containment Assessment|Phase 1: Self-Score|vendor-neutral
Security Insight

All containment isn’t created equal.

Five properties separate a contained security incident from a catastrophic breach. Four harvest questions show whether your data is already leaving. Answer a few questions and see where your security stack has containment gaps — then download a report to share with your team, or continue to Phase 2 to measure the gaps from your own architecture.

Start Your Assessment
What you will get

Five minutes. Three things you can act on.

No sales call, no gated form, no vendor pitch. Answer a few questions and see where your security stack has gaps that matter.

01

Containment gaps

Five properties that separate a small, contained security ncident from a catastrophic breach. Each one maps to a real-world failure.

02

Harvest exposure

Four questions that reveal whether encrypted traffic is leaving unmonitored and who really controls the keys.

03

Provisional blast radius

The percentage of the estate an attacker can reach when containment properties are missing. Sized to your actual infrastructure.

“The AI threat landscape changed our timeline. We looked at our cloud environment and realized web application firewalls were the only thing standing between our workloads and the internet. That was not enough. We needed network-layer containment, and we needed it now — not on a future roadmap.
CISO, Major Connected-Vehicle Platform
Why Two Tracks

No containment means harvest risk.

Containment and harvest are two sides of the same exposure. A gap in one compounds the other: if outbound traffic is unrestricted, encryption alone is not enough. If data is already leaving, containment is already too late. This assessment scores both so you see the full picture.

Track 01Containment Gap
Track 02Harvest Exposure
The Architectural Divide

Your security stack was designed for a network that no longer exists.

Application modernization moved workloads into containers, serverless functions, and managed services. The network security controls protecting them still assume a world of fixed perimeters and predictable traffic flows.

Two doors open, one locked

Every cloud workload is born with two doors open, outbound to the internet and sideways to its neighbors, and only the front door locked.

What breaks

Assumption

Segmentation contains lateral movement.

Reality

Workloads communicate across segments by design. Lateral movement follows the application graph, not the network topology.

Assumption

Firewalls govern egress.

Reality

Cloud-native traffic leaves through NAT gateways, service endpoints, and API calls that never touch a firewall rule.

Assumption

Identity stops unauthorized access.

Reality

Most network security controls enforce at Layer 3/4. The identity of the workload — what it is, not just where it is — is invisible at the enforcement point.

This is what the assessment measures

Five containment properties test whether your security stack holds under these conditions. Four harvest questions test whether data is already leaving through the gaps. Most stacks fail on properties they were never designed to enforce.

Already know you have gaps? Phase 2: the Architecture Read measures reachability and containment time from your own data — the two variables that decide the improvement case, independent of how you price the assets.

Interactive Exposure Assessment

What do you want to measure first?

Both tracks reach the same destination: Phase 2 measures the exposure from your own architecture and sizes it in dollars. The order determines which gap you see first.

NoteNot sure you know every answer? That is fine. Some questions you will know immediately. Others you might not. Select “don’t know” and keep going — the assessment still scores your exposure with what you do know.

© 2026 Aviatrix. Phase 1 is a self-service diagnostic. Results are provisional reads, not measurements. A precise blast radius and Reachable Value at Risk require Phase 2: the Architecture Read.