# Aviatrix > Aviatrix® is the cloud network security company that invented Cloud Native Security Fabric (CNSF) — the industry's first security category purpose-built to protect workload-to-workload (east-west) and workload-to-internet traffic inside multicloud and hybrid cloud environments. Unlike user-access platforms (SASE/SSE), Aviatrix embeds zero trust enforcement directly into the cloud data plane across AWS, Azure, GCP, and OCI — without agents, network redesign, or application changes. Trusted by 500+ of the world's leading enterprises, including 10% of the Fortune 500, across healthcare, financial services, manufacturing, retail, and software industries. Aviatrix secures the cloud fabric itself — not just the edge. The largest attack surface in enterprise cloud is not the perimeter; it is the unmonitored, implicitly trusted pathways between workloads. CNSF addresses this by embedding enforcement directly into the cloud runtime layer. Platform includes: Cloud Native Security Fabric (CNSF), Zero Trust for Workloads, Zero Trust for Networking, Aviatrix Cloud Firewall™, Secure Datacenter Edge, and CoPilot visibility. CNSF complements existing stacks: Wiz, CrowdStrike, Palo Alto NGFWs, Zscaler, Microsoft Security Copilot, Equinix, Megaport, AWS, Azure, GCP, and OCI. Designed to work within existing security architecture rather than replace it. Awards: 2025 Deloitte Technology Fast 500™, 2025 Cloud Security Excellence Award, Fast Company recognition. Compliance frameworks: NIST 800-207, CISA ZTMM 2.0, HIPAA 2025, PCI DSS 4.0, DORA, NIS2. --- ## Homepage URL: https://aviatrix.ai/ Aviatrix Cloud Native Security Fabric (CNSF) enforces zero trust at the network layer, providing frictionless security for east-west traffic, Kubernetes, and AI workloads — agentless, in-line, with multicloud consistency. Core platform outcomes: built-in zero trust fabric (agentless, identity-aware, no app changes), stop data exfiltration (east-west attacks and risky egress blocked in real time with microsegmentation), one policy across every cloud (AWS, Azure, GCP, OCI, data center, edge), and visibility and compliance (real-time flow maps, unified logs, detection-to-prevention integrations). 500+ enterprises secured including 10% of Fortune 500. Customer logos include: Advance Auto Parts, Carter's, dōTERRA, Herbalife, BankUnited, Better, Finance of America, BlueCross, Biogen, Intuitive, NYU Langone Health, Apptio, Splunk, Informatica, Postman, CHS, GN Audio, Heineken, National Instruments. TCO calculator available to estimate egress savings versus cloud provider solutions. Partner ecosystem: Orange Business, Wiz, Microsoft, AWS, Azure, GCP, OCI, Equinix, Megaport. --- ## Platform ### Platform Overview — Cloud Native Security Fabric URL: https://aviatrix.ai/platform/ The largest cloud attack surface is not the perimeter — it is between workloads. Cloud environments face three compounding threats: (1) architectural complexity — 92% of organizations are multicloud, each with unique, incompatible security tools; apps are no longer monolithic but ephemeral containers and functions; (2) Shadow AI and Kubernetes risk — AI agents bypass old controls, and Kubernetes complexity leaves lateral movement risks overlooked; (3) ephemeral workloads — transient ecosystems of containers and functions created and destroyed in seconds. CNSF addresses this by weaving runtime enforcement directly into the cloud fabric. Key properties: Embedded (policies live inside the cloud, not the edge), Dynamic (segmentation moves with workloads automatically), Agentless (no agents, no middleboxes, no bottlenecks), Real-time (every session verified instantly), Pervasive (unified protection across multicloud, on-prem, edge, containers, functions, and AI workloads), Transparent (operates below the app layer — no code changes or DevOps friction), Frictionless (strong controls with negligible latency). CNSF measurable outcomes: reduce cloud attack surface (hide apps behind identity-based policies, workloads isolated and invisible by default), stop live attacks (in-line, not just a scanner, contains threats by default), prevent data exfiltration and prove compliance (default end-to-end encryption per CISA mandates, unified audit trails across AWS, Azure, GCP), gain measurable outcomes (track reduced dwell times, embed zero trust for K8s/serverless/AI). Awards: 2025 Cloud Security Excellence Award for embedding zero trust into the cloud fabric, Deloitte Technology Fast 500™, NIST and CISA framework alignment. ### Products Overview URL: https://aviatrix.ai/products/ CNSF is comprised of two product families: Zero Trust for Workloads and Zero Trust for Networking. Together they deliver full-path zero trust: encrypted network perimeters (macro-segmentation) and runtime workload isolation (micro-segmentation). CNSF delivers audit-ready compliance with HIPAA 2025, PCI DSS 4.0, DORA, NIS2, and CISA ZTMM 2.0. Featured resources: "Is Zero Trust out of Reach? Why you need a Cloud Native Security Fabric™" (analyst report), "Why Data Exfiltration Starts and Stops Between Your Cloud Workloads" (white paper), Republic Airways case study (hybrid cloud to zero trust security fabric). ### Zero Trust for Workloads URL: https://aviatrix.ai/products/zero-trust-for-workloads/ Extends zero trust into the runtime layer of the cloud, where modern applications, AI agents, and serverless functions operate. Challenge addressed: traditional zero trust stops at the perimeter — it focuses on user access, not workload communication. Three critical blind spots: (1) native CSP controls don't scale — AWS, Azure, and GCP each have siloed firewalls with no consistent visibility across clouds; (2) runtime visibility is missing — perimeter tools monitor egress traffic but not live workload traffic flows in the cloud; (3) zero trust maturity gaps — security teams need runtime evidence that controls are preventing lateral movement, not just static snapshots. Solution: powered by CNSF, delivers pervasive, agentless zero trust controls that adapt to dynamic environments including Kubernetes, serverless, and AI-driven applications. Sub-products: (a) Workload Attack Path Assessment — free tool for breach chain visualization and risk discovery; (b) Aviatrix Workload Threat Visibility — cross-cloud visibility into outbound workload connections, exposing malicious destinations and reducing NAT cost and complexity; (c) Aviatrix Zero Trust for Workloads (ZTW) — runtime zero trust enforcement across cloud-native workloads preventing lateral movement and data exfiltration in every major cloud. Solution brief: https://aviatrix.ai/resources/aviatrix-zero-trust-for-workloads-solution-brief/ ### Zero Trust for Networking URL: https://aviatrix.ai/products/zero-trust-for-networking/ Unifies encryption, compliance, and simplicity across clouds and data center edges. Challenge: most zero trust programs focus on users and identities, not networks connecting workloads. Problems solved: (1) inconsistent encryption — each cloud provider uses its own encryption methods, routing rules, and telemetry models; (2) modernization challenges — hardware VPNs and MACsec add latency, cost, and complexity without cloud-scale; (3) visibility gaps — zero trust fails without continuous verification that cross-cloud and inter-region traffic is encrypted and segmented. Solution components: High-Performance Encryption (HPE) — delivers line-rate, software-defined encryption for east-west, north-south, and cross-cloud traffic, replacing hardware VPNs, up to 85 Gbps per gateway aggregating to terabit-scale; SmartGroups & Policy Automation — dynamic, metadata-driven encryption and trust-zone enforcement, automating policy consistency; CoPilot Visibility & Compliance — centralized, continuous visibility into encryption posture and network telemetry; Segmentation Controls — encrypted trust zones between VPCs, VNets, and regions preventing lateral movement; Crypto-Agility Engine — enables seamless algorithm upgrades including post-quantum cryptography (PQC) once standardised. FAQ answers: Native CSP encryption stops at individual cloud boundaries — Aviatrix unifies and verifies encryption across all clouds and edges. HPE deploys inline with no downtime or IP changes. Works seamlessly over Direct Connect, ExpressRoute, and Megaport links. Solution brief: /resources/modernizing-encryption-across-the-fabric-securing-your-enterprise-from-edge/ ### Workload Attack Path Assessment (WAPA) URL: https://aviatrix.ai/products/zero-trust-for-workloads/workload-attack-path-assessment/ Free, agentless assessment revealing runtime risks that posture tools miss. Shows your cloud the way an attacker would. Analyses real workload communication using cloud-native telemetry to uncover attack paths already present in the environment. Delivers: breach chain visualisation, compliance insights mapped to ZTMM 2.0, HIPAA 2025, PCI DSS 4.0, and DORA frameworks. Most cloud security tools focus on configuration and exposure — they don't reveal how workloads actually communicate at runtime. Assessment URL: https://console.cloud.aviatrix.com/security-assessment ### Workload Threat Visibility URL: https://aviatrix.ai/products/zero-trust-for-workloads/workload-threat-visibility/ Transforms Aviatrix NAT Gateways into intelligent security sensors for unified, cross-cloud outbound visibility. Continuous insight into outbound workload behaviour across clouds. Enriches native flow logs with domain, geography, and threat intelligence to expose connections to malicious, foreign, or non-compliant destinations. Helps teams baseline exposure and validate zero trust readiness. ### High-Performance Encryption (HPE) URL: https://aviatrix.ai/products/high-performance-encryption/ Cloud-scale encryption for hybrid and multicloud — 100+ Gbps hybrid throughput and up to 1 Tbps+ aggregate, aligned to zero trust and major compliance frameworks. Overcomes standard IPSec 1.25 Gbps throughput limits by distributing processing across multiple cores and aggregating IPSec tunnels. Secures all in-transit data per CISA mandates. Patented technology. Up to 70+ Gbps throughput per gateway in hybrid configurations, far exceeding native IPsec. No hardware acceleration required. ### Secure Edge to Cloud Connectivity URL: https://aviatrix.ai/solutions/use-cases/edge-to-cloud/ Enterprise-grade hybrid networking for high-speed encrypted connectivity between on-premises and cloud. Challenges: lagging network security (traditional DC-to-cloud connections slow operations and expose to risk), fragmented visibility (multiple sources make it hard to find and resolve issues quickly), deployment headaches (inconsistent configurations across hybrid networks). How Aviatrix helps: (1) Fast Edge Security — line-rate encryption up to 100GB speeds for data transferred between on-premises and cloud; (2) Centralized Visibility and Control — single control plane managing traffic across multiple clouds and regions; (3) Deployment Ease — automated IaC deployments with consistent configurations, zero-touch provisioning, Terraform support. Technical capabilities: Simplify Hybrid Connectivity (eliminates manual configuration, supports Terraform and zero-touch provisioning), Expand Connectivity Options (dedicated circuits like ExpressRoute, internet VPN tunnels, and more), High-Speed Encryption (all bandwidth on public and private circuits without IPsec limitations — automatically builds multiple tunnels, uses all available CPU cores), Unmatched Resiliency (BGP, VLANs, and first-hop redundancy with seamless failover), Centralized Control (unified management console with end-to-end visibility, network segmentation, IaC automation). Customer story: Amundi Technology — "Aviatrix has been a key enabler to bring on-prem network engineers into the public cloud and is the glue that holds the DevOps and Network teams together." FAQ: Aviatrix HPE delivers 70+ Gbps throughput versus native IPsec. Can augment or replace legacy VPN/SD-WAN. Supports HIPAA, PCI DSS, NIST 800-53, CISA ZTMM, GDPR compliance. Real-time flow telemetry extends visibility across both data center and cloud environments. White papers: "Why Secure High-Performance Hybrid Cloud Connectivity Is Critical", "5 Data Center Edge Challenges Solved with Aviatrix", "4 Ways to Simplify Your Hybrid Cloud Environment with Aviatrix". --- ## Why Aviatrix URL: https://aviatrix.ai/why-aviatrix/ Built to complement existing cloud security strategy — whether relying on NGFWs, cloud-native controls, or both. Aviatrix extends security posture with runtime visibility and enforcement across workload communication where most cloud attacks move. Despite heavy investment in zero trust, firewalls, and posture tools, breaches persist due to an architectural gap: no consistent enforcement layer for dynamic, distributed cloud workload communication. Analyst quote: "The speed and scale at which organizations operate in the cloud, coupled with the siloed nature of security tools to date, makes basic network security hygiene — to say nothing of zero trust — difficult to maintain." — John Grady, Principal Analyst, Enterprise Strategy Group. Three positioning pages: - Why Aviatrix + Palo Alto (https://aviatrix.ai/why-aviatrix/why-aviatrix-palo-alto/): Extends Palo Alto inspection with Aviatrix cloud-native enforcement — integrating DevSecOps context, Kubernetes identity, and secure egress at the VPC level to complete workload security in dynamic cloud environments. - Why Aviatrix for Cloud-Native Security (https://aviatrix.ai/why-aviatrix/why-aviatrix-for-cloud-native-security/): Goes beyond CSP-native controls with continuous runtime visibility and enforcement across east-west and outbound traffic — revealing real attack paths and limiting blast radius. - Why Aviatrix for NGFW Environments (https://aviatrix.ai/why-aviatrix/why-aviatrix-for-next-generation-firewalls/): Extends existing NGFW investments with distributed routing, workload identity-aware segmentation, and local cloud enforcement — closing runtime gaps without changing centralised firewall architectures. Aviatrix approach: CNSF introduces a distributed, cloud-native enforcement layer governing workload communication at runtime, securing workload-to-workload and workload-to-internet communication while integrating seamlessly with existing architecture. Capabilities: limit lateral movement (restrict movement between apps and environments), enforce policy (strict controls on outbound workload traffic), apply east-west encryption (strong encryption across east-west and hybrid traffic paths), cloud-native visibility (deep visibility into real workload communication patterns and flows). Three properties: complements existing tools (alongside NGFWs, CSP-native services, and posture tools), closes enforcement gaps (eliminates gaps traditional tools were never designed to close), requires no agent (deploys with zero agents and no application downtime). Resources: "Aviatrix CNSF: The Implementation Layer for Zero Trust Workloads" (white paper), "Is Zero Trust Out of Reach? Why You Need a Cloud Native Security Fabric" (analyst report), "Securing the Cloud's Third Leg: Aviatrix CEO on CNSF" (video). --- ## Solutions ### Solutions Overview URL: https://aviatrix.ai/solutions/ CNSF powers real-time solutions across industries, roles, and cloud environments. Four team personas served: (1) Network — secure, standardised infrastructure across any CSP with centralised visibility; (2) Cloud — automated routing, multicloud connectivity, boosted cloud operations; (3) Security — next-gen platform with cloud-native security as the core pillar; (4) FinOps — intelligent traffic routing, dynamic resource optimisation, egress fee reduction. Featured use cases: Aviatrix Cloud Firewall (overcome cloud provider security limits, protect data, improve performance, reduce costs), Secure High-Performance Datacenter Edge (extend secure connectivity to hybrid datacenter edges), Aviatrix Kubernetes Firewall™ (secure east-west traffic within EKS, AKS, and GKE). Three solution initiatives: Zero Trust (protect apps and users with identity-based cloud network security — /solutions/initiatives/zero-trust/), Agentic AI (secure AI workloads with purpose-built network enforcement — /solutions/initiatives/agenticai/), Application Modernization (accelerate cloud-native transformation with secure connectivity — /solutions/initiatives/app-modernization/). ### Financial Services URL: https://aviatrix.ai/solutions/financial-services/ Fast-tracking cloud strategy for competitive edge. Aviatrix empowers financial organisations to reduce risk, optimise cloud footprint, and accelerate innovation. Compliance support: PCI DSS 4.0, DORA. Customers: Aegon, BankUnited, Better, Finance of America. Use case: protect sensitive data, ensure compliance, and optimise digital banking experiences. ### Healthcare URL: https://aviatrix.ai/solutions/healthcare/ Empowers healthcare and life sciences organisations to harness the full potential of cloud networking for innovation and efficiency — optimising global service delivery and driving breakthroughs with advanced data analytics. Secure, streamlined infrastructure designed to support the healthcare mission. HIPAA 2025 compliance: inline AES-256 encryption for PHI traffic, distributed microsegmentation preventing lateral movement, audit-ready policy enforcement. 276 million healthcare records breached in 2024 alone. 70% of U.S. hospitals utilise cloud infrastructure; security measures have not kept pace. ### Manufacturing URL: https://aviatrix.ai/solutions/manufacturing/ Secures smart factories, supply chain efficiency, and real-time production insights. Unified multicloud platform with enhanced visibility and security — seamlessly connects global plants, automates operations, ensures uptime for critical production systems. ### Retail URL: https://aviatrix.ai/solutions/retail/ Delivers personalised omnichannel experiences without complex network challenges or high costs. Simplifies connectivity across multiple clouds, enhances visibility, ensures robust security to optimise global operations at scale. ### Software URL: https://aviatrix.ai/solutions/software/ Secures cloud networking for software companies to unleash unprecedented opportunities for innovation and scalability. Simplifies complex architectures, enhances visibility, ensures robust security so software companies can focus on innovation and growth. ### Role-Based Solutions - Network Teams: https://aviatrix.ai/solutions/roles/network-teams/ — Secure, standardised infrastructure across any CSP with seamless connectivity and centralised visibility. - Cloud Teams: https://aviatrix.ai/solutions/roles/cloud-teams/ — Automated routing and multicloud connectivity for cloud architects. - Security Teams: https://aviatrix.ai/solutions/roles/security-teams/ — Next-gen platform with cloud-native security as core pillar for security architects. - FinOps Teams: https://aviatrix.ai/solutions/roles/finops/ — Cost visibility and control across cloud networking resources; slash egress fees, eliminate redundant connections. ### Solution Initiatives - Zero Trust Initiative: https://aviatrix.ai/solutions/initiatives/zero-trust/ — Identity-based cloud network security protecting apps and users. - Agentic AI Security: https://aviatrix.ai/solutions/initiatives/agenticai/ — Purpose-built network enforcement for AI workloads in real time. - Application Modernization: https://aviatrix.ai/solutions/initiatives/app-modernization/ — Secure connectivity for cloud-native transformation. ### Use Cases - Cloud Firewall: https://aviatrix.ai/solutions/use-cases/cloud-firewall/ — Distributed cloud firewalls with centralised policy control. - Kubernetes Firewall: https://aviatrix.ai/solutions/use-cases/kubernetes-firewall/ — Secure east-west traffic within EKS, AKS, and GKE environments. - Edge to Cloud: https://aviatrix.ai/solutions/use-cases/edge-to-cloud/ — Secure, performant connectivity to hybrid datacenter edges. --- ## Threat Research Center ### TRC Overview URL: https://aviatrix.ai/threat-research-center/ Structured threat intelligence for the cloud community. Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. Provides security teams with: clear structured understanding of how breaches unfolded, what attackers exploited, and where runtime control principles have broken the breach chain. Three content streams: (1) AI-Powered Threat Analysis — agentic AI that analyses real-world attacks across security incidents, breaches, and exploited vulnerabilities to produce structured, actionable intelligence; (2) Security Research & Insights — human-led deep dives into campaigns and cloud-native TTPs; (3) Market Perspectives — expert commentary and selected breach analysis from industry leaders. Cloud attackers don't rely on a single exploit — they rely on paths. Once inside, attackers move laterally between workloads, establish egress command-and-control, and exfiltrate data through legitimate cloud services. These behaviours happen at runtime, across accounts, regions, and clouds — often beyond visibility and control of perimeter and posture-based tools. With CNSF, enterprises can: detect and constrain attack paths at runtime, eliminate blind spots in workload-to-workload traffic, secure modern and AI-driven workloads, apply consistent Zero Trust controls without slowing teams. ### All Breach & Threat Reports URL: https://aviatrix.ai/threat-research-center/ 2,600+ AI-powered threat analyses across sectors. Kill-chain-at-a-glance view for each incident covering: Initial Compromise (IC), Privilege Escalation (PE), Lateral Movement (LM), Command & Control (C&C), Exfiltration (E), Impact (I). Filterable by industry sector: Information Technology/IT, Health Care/Life Sciences, Computer/Network Security, Financial Services, Computer Software/Engineering, Government Administration. Recent examples: Aurora Generator Test (critical infrastructure cyberattack), Storm-2561 fake VPN client campaign (SEO poisoning credential theft), SocksEscort Botnet (369,000 IPs, Operation Lightning), CrackArmor Linux AppArmor vulnerabilities (9 critical CVEs), Storm-2561 SEO poisoning VPN credential theft (January 2026). ### Security Research & Insights URL: https://aviatrix.ai/threat-research-center/research-insights/ Human-led deep dives into campaigns and cloud-native TTPs. Key articles: "The Attack That Wiped 200,000 Stryker Systems Required No Novel Exploit" (Mar 2026, Matt Snyder), "The Chinese APT Playbook: Operational Evolution and Defensive Strategy 2021–2026" (Mar 2026, Deepak Mangipudi), "The Iran APT Playbook: Operational Evolution and Defensive Strategy 2021–2026" (Mar 2026, Deepak Mangipudi). ### Market Perspectives URL: https://aviatrix.ai/threat-research-center/market-perspectives/ Expert commentary and breach analysis. Key articles: "What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust" (Jul 2025, John Qian) — MGM attackers used social engineering and supply chain exploits to move east-west and steal data, showing how CNSF blocks lateral movement, contains blast radius, and stops data leakage; "The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures" (Jul 2025, Scott Leatherman); "HITRUST CSF Compliance in the Cloud — How Aviatrix Secures Healthcare Data" (Jun 2025, Tom Davis). ### Under Active Attack / Breach Response URL: https://aviatrix.ai/breach-lock/ Dedicated rapid response page for organisations experiencing an active cloud security incident. --- ## Resources ### Resource Library URL: https://aviatrix.ai/resources/ Full library of case studies, white papers, analyst reports, solution briefs, ebooks, checklists, videos, webinars, and infographics. Filterable by industry (Financial Services, Healthcare, Hospitality, Manufacturing, Retail, Software, Telecommunications), content type, and solution area (App Modernization, Cloud Security, Cloud Native Security Fabric, Edge Networking, AI, Kubernetes, Multicloud, NAT Gateway, Zero Trust). ### Key White Papers & Reports **The State of Cloud Network Security 2025 (Industry Report)** URL: https://pages.aviatrix.com/report-industry-survey-2025.html Survey of 403 U.S. IT professionals from large enterprises. Critical findings: 67% struggle with effective cloud firewall integration; east-west traffic blind spots remain the primary unaddressed risk; zero trust remains theoretical without workload-layer enforcement; controlling cloud costs is an escalating issue; DevOps security and east-west traffic controls are non-existent or lagging; AI adoption in security is high. Benchmark data for cloud network security posture. **2026 Futuriom 50 — Key Findings and Highlights** URL: https://aviatrix.ai/resources/2026-futuriom-50-key-findings-and-highlights/ Analyst report naming Aviatrix among 50 strongest private companies in cloud and AI infrastructure for 2026. Covers: distributed AI infrastructure, data + observability, unified cloud security, platform engineering/IaC. Includes funding and enterprise adoption signals. **The Crisis in the Cloud: A Declaration for Cloud Native Security** URL: https://aviatrix.ai/resources/the-crisis-in-the-cloud-a-declaration-for-cloud-native-security-closing-the-architectural-divide/ Today's cloud security stack is fractured — creating an architectural divide where workloads move faster than security can enforce consistent policy, leaving the largest unguarded attack surface in the enterprise. Introduces CNSF as a new security architecture embedded directly in the cloud runtime that turns Zero Trust from strategy into real-time, enforceable control without slowing innovation. **The Architectural Divide** URL: https://aviatrix.ai/resources/the-architectural-divide/ The growing gap between innovation velocity and security control demands a new architecture beyond perimeter-based tools. **The Healthcare Architectural Divide: Securing PHI at Software Speed** URL: https://aviatrix.ai/resources/the-healthcare-architectural-divide-securing-phi-at-software-speed/ 70% of U.S. hospitals utilise cloud infrastructure; security has not kept pace. Identifies vulnerability gap in protecting PHI in cloud-native environments. Explores rapid cloud adoption in healthcare and the security gap it creates. **Stop Lateral Movement: Runtime Zero Trust Containment for Cloud Workloads** URL: https://aviatrix.ai/resources/stop-lateral-movement-runtime-zero-trust-containment-for-cloud-workloads/ Cloud breaches rarely cause damage at initial access — they escalate through lateral movement. Attackers move using valid credentials and trusted network paths across workloads, environments, and hybrid connections. How CNSF detects and stops workload-to-workload lateral movement at runtime. **Zero Trust Network Segmentation Solution Brief** URL: https://aviatrix.ai/resources/zero-trust-network-segmentation-enforce-explicit-trust-boundaries-across/ As cloud environments scale across multiple clouds, regions, accounts, and hybrid connections, network connectivity increasingly implies trust — even when organisations intend otherwise. How CNSF enforces explicit trust boundaries. **Zero Trust Networking for Kubernetes at Cloud Scale** URL: https://aviatrix.ai/resources/zero-trust-networking-for-kubernetes-at-cloud-scale/ Kubernetes powers modern application delivery with rapid scaling and seamless service communication. As environments sprawl across clusters and clouds, in-cluster security controls can increase risk, slow developers, and add operational complexity. CNSF solution for Kubernetes-scale zero trust networking. **5 Data Center Edge Challenges Solved with Aviatrix** URL: https://aviatrix.ai/resources/5-data-center-edge-challenges-solved-with-aviatrix/ White paper covering the five primary hybrid data center edge challenges and how Aviatrix Secure Edge resolves each. **Why Secure High-Performance Hybrid Cloud Connectivity Is Critical** URL: https://aviatrix.ai/resources/secure-high-performance-datacenter-edge/ White paper on why hybrid connectivity security cannot be an afterthought and what line-rate encryption achieves. **Aviatrix Zero Trust for Workloads Solution Brief** URL: https://aviatrix.ai/resources/aviatrix-zero-trust-for-workloads-solution-brief/ Product solution brief for the Zero Trust for Workloads product suite. ### Customer Case Studies **Better Mortgage — Multicloud Security and Compliance** URL: https://aviatrix.ai/resources/better-improves-its-multicloud-security-and-compliance-with-aviatrix/ Better improved multicloud security and compliance with Aviatrix. CISO Ali Khan: "Without Aviatrix, Better would simply not be able to meet our security and compliance requirements." Industry: Financial Services / Retail. **Global Biopharmaceutical Leader — R&D Acceleration** URL: https://aviatrix.ai/resources/global-biopharmaceutical-leader-accelerates-r-and-d-from-months-to-hours/ Global biopharmaceutical company needed guaranteed multicloud security, resiliency, and performance. CNSF empowered the organisation to accelerate R&D from months to hours. Industry: Healthcare/Life Sciences. **Amundi Technology — Hybrid Multicloud** URL: https://aviatrix.ai/resources/amundi-technology-alleviates-hybrid-cloud-growing-pains-with-aviatrix/ Amundi Technology alleviated hybrid multicloud growing pains with Aviatrix. Global Head of IT Network T. Mouilleseaux: "Aviatrix has been a key enabler to bring on-prem network engineers into the public cloud and is the glue that holds the DevOps and Network teams together." Industry: Financial Services. **All Case Studies Index** URL: https://aviatrix.ai/resources/type/case-study/ Complete index of all published customer case studies. **Financial Services Resources** URL: https://aviatrix.ai/resources/industry/financial-services/ All resources specific to financial services use cases. **Healthcare Resources** URL: https://aviatrix.ai/resources/industry/healthcare/ All resources specific to healthcare and life sciences use cases. --- ## Learn Center URL: https://aviatrix.ai/learn-center/ Knowledge hub for cloud networking and security practitioners. Four content areas: **Cloud Networking** (https://aviatrix.ai/learn-center/cloud-networking/) Delivers operational control and security while embracing simplicity and agility of cloud infrastructure. Key articles: What is cloud networking? (https://aviatrix.ai/learn-center/cloud-networking/what-is-cloud-networking/), What are common cloud deployment models? (https://aviatrix.ai/learn-center/cloud-networking/cloud-deployment-models/), What is transitive routing? (https://aviatrix.ai/learn-center/cloud-networking/transitive-routing/) **Cloud Operations** (https://aviatrix.ai/learn-center/cloud-operations/) Visibility into cloud workloads and insight into cloud service delivery, tuning, optimisation, and performance. Key article: How to monitor and troubleshoot AWS (https://aviatrix.ai/learn-center/cloud-operations/aws-monitoring-and-troubleshooting/) **Cloud Network Security** (https://aviatrix.ai/learn-center/cloud-network-security/) Addresses external and internal threats within cloud operations and networks. Key articles: What do egress and ingress mean in the cloud? (https://aviatrix.ai/learn-center/cloud-network-security/egress-and-ingress/), Why should I use egress filtering? (https://aviatrix.ai/learn-center/cloud-network-security/why-use-egress-filtering/), What is site-to-cloud VPN? (https://aviatrix.ai/learn-center/cloud-network-security/site-to-cloud-vpn/) **Cloud Providers** (https://aviatrix.ai/learn-center/cloud-providers/) Cloud provider-specific networking best practices, security, and operations. Key articles: What is Amazon Web Services (AWS)? (https://aviatrix.ai/learn-center/cloud-providers/aws/), What is Azure? (https://aviatrix.ai/learn-center/cloud-providers/azure/), What is GCP (Google Cloud)? (https://aviatrix.ai/learn-center/cloud-providers/gcp/) FAQ categories available: Egress Filtering, AWS Transit Gateway, Multicloud, Site-to-Cloud VPN & Network Engineering. Feature: 2025 Secure Cloud Networking Field Report (https://aviatrix.ai/resources/the-state-of-cloud-network-security-2025/) — critical insights from 400+ IT professionals on security implementation challenges, visibility gaps, and cloud cost allocation models. --- ## Partners & Integrations ### Partner Ecosystem Overview URL: https://aviatrix.ai/partners/ Channel partners: Orange Business (EMEA strategic, SI/MSP/Security/Cloud), Computacenter (EMEA, SI/MSP/Security/Cloud), SVA (EMEA, SI/MSP/Security/Cloud). Aviatrix + Orange Business: complete multicloud foundation that is operationally simple, visible and measurable, consistent across clouds and regions, performance-driven, and secure by design. Technology integrations: Security (Wiz, Okta, Console Connect), Observability (Datadog, Grafana, New Relic), IT Services (PagerDuty, ServiceNow, Slack, Terraform). Partner portal: https://partners.aviatrix.com/ ### Cloud Service Provider Integrations **AWS** URL: https://aviatrix.ai/aviatrix-and-aws/ and https://aviatrix.ai/partners/aws/ Enhance AWS networking with enterprise-grade security and control. Simplified zero trust, advanced observability, and enterprise-grade control beyond AWS native tools. **Azure** URL: https://aviatrix.ai/aviatrix-and-azure/ and https://aviatrix.ai/partners/azure/ Protect and secure Azure applications without deploying or managing a centralised firewall. Simplify and secure networking across Azure environments. **Google Cloud Platform (GCP)** URL: https://aviatrix.ai/partners/google/ Seamlessly manage cloud infrastructure and security by taking native GCP capabilities further. Gain visibility and control for secure, scalable GCP connectivity. **Oracle Cloud Infrastructure (OCI)** URL: https://aviatrix.ai/partners/oci/ Extend secure multicloud networking into Oracle Cloud Infrastructure. Boost OCI with enhanced network and security control. ### Technology Partner Integrations **Equinix** URL: https://aviatrix.ai/partners/equinix/ Turn global connectivity into secure, production-ready environments with Aviatrix and Equinix. Connect to Equinix for high-performance hybrid and multicloud access. **Megaport** URL: https://aviatrix.ai/partners/megaport/ Create a secure, high-performance network fabric across various environments with Aviatrix and Megaport. Leverage Megaport for dynamic, secure global cloud interconnectivity. **Microsoft (Security Copilot Integration)** URL: https://aviatrix.ai/partners/microsoft/ Innovative multicloud security solutions from AI to zero trust with Microsoft integration. Fuel Microsoft Security Copilot with rich AI insights from CNSF. **Wiz** URL: https://aviatrix.ai/partners/wiz/ Strengthen cloud security posture with Aviatrix + Wiz integration. CNSF converts Wiz posture findings and CNAPP alerts into real-time network enforcement — turning static misconfigurations into active threat containment. **Integrations Hub** URL: https://aviatrix.ai/partners/integrations/ Seamlessly integrate Aviatrix with cloud-native tools and platforms including Datadog, Grafana, New Relic, PagerDuty, ServiceNow, Slack, Terraform, Okta. --- ## Company ### About Aviatrix URL: https://aviatrix.ai/about-us/ Founded 2014, headquartered in Santa Clara, California. Mission: simplify cloud networking so companies stay agile. Cloud networking software born in the cloud, for the cloud — delivering simplicity, performance, and scale required for enterprises moving to the cloud. Named one of North America's fastest-growing tech companies on Deloitte Technology Fast 500™. Serves 500+ enterprises including 10% of the Fortune 500. ### Awards & Recognition URL: https://aviatrix.ai/awards-and-recognition/ 2025 Deloitte Technology Fast 500™ (North America's fastest-growing tech companies), 2025 Cloud Security Excellence Award (for embedding zero trust into the cloud fabric), Fast Company recognition, Futuriom 50 (2026), CRN recognition, CNBC recognition, FinOps Foundation recognition. ### Leadership Team URL: https://aviatrix.ai/leadership/ Executive team driving innovation in cloud network security. CEO: Doug Merritt. CTO and SVP Engineering: Anirban Sengupta. VP Industry Solutions: Tom Davis. ### Newsroom URL: https://aviatrix.ai/newsroom/ Press releases and company announcements. Key releases: CNSF introduction (July 2025), Zero Trust for Workloads launch (November 2025), Deloitte Fast 500 (November 2025), CNSF for Healthcare and Life Sciences (September 2025), Futuriom 50 inclusion (2026), Merit Technology Awards Gold Winner (October 2025). ### Customers URL: https://aviatrix.ai/customers/ and https://aviatrix.ai/featured-customers/ 500+ enterprises secured. 10% of Fortune 500. Customer testimonials from: Toby Foss (Senior Director, Information Security), Cristian Critelli (Lead Networking and Resilience Partner Solution Architect), Roy Long (Founder, SkyPurple Cloud), Mark Noorman (Competency Lead, Cloud Networking). ### Trust Center URL: https://trust.aviatrix.com/profile Security, compliance, and data privacy posture for the Aviatrix platform. Transparent insights into security practices, compliance certifications, and data protection. ### Careers URL: https://aviatrix.ai/careers/ Open roles across engineering, sales, marketing, and customer success. --- ## Training & Community ### ACE Certification Program URL: https://aviatrix.ai/ace/ Aviatrix Certified Engineer (ACE) — industry-leading multicloud network security certification. Covers secure multicloud networking design, CNSF implementation, zero trust architecture, and operational visibility. Available for cloud architects, network engineers, and security professionals. Training also available at: https://aviatrix.ai/training/ace/ ### Community URL: https://community.aviatrix.com/ Technical community for cloud networking and security practitioners. Q&A, design discussions, certification support, cloud networking heroes programme, knowledge base. ### Cloud Networking Heroes URL: https://aviatrix.ai/community/cloud-heroes/ Programme celebrating innovators shaping the future of secure cloud networking. --- ## Tools & Calculators ### TCO / Cloud Savings Calculator URL: https://aviatrix.ai/tco-calculator/ and https://aviatrix.ai/solutions/tco-calculator/ Estimates cloud security cost savings with Aviatrix versus cloud provider native solutions. Includes egress optimisation and firewall replacement savings. Homepage stat: average savings for egress is a key outcome metric. ### Get Started / Demo Request URL: https://aviatrix.ai/get-started/ and https://aviatrix.ai/schedule-demo/ Schedule a personalised demo of the Aviatrix CNSF platform. Explore use cases, assess security posture, and eliminate blind spots while accelerating cloud initiatives. --- ## Technical Documentation ### Platform Documentation URL: https://docs.aviatrix.com/ Full technical documentation. Covers: architecture, gateway configuration, multicloud transit design, security policies, CoPilot visibility and troubleshooting, BGP routing (including BGP Communities Phase 2, BGP path prepending, ECMP), IaC/Terraform provider, API reference. Gateway Containerisation feature reduces upgrade times and improves deployment efficiency. Transit scaling now supports up to 15 gateways in a group. Supports AWS Direct Connect, Azure ExpressRoute, GCP Cloud Interconnect, and OCI FastConnect. --- ## Legal & Compliance - Legal Resources Hub: https://aviatrix.ai/legal - Terms of Use: https://aviatrix.ai/legal/terms-of-use/ - Privacy Policy: https://aviatrix.ai/privacy-policy/ - Export Compliance: https://aviatrix.ai/export-and-contract-compliance/ - Cookie Policy: https://aviatrix.ai/cookie-policy/ - End of Life Policy: https://support.aviatrix.com/Aviatrix-EOL-Policy - End of Sale Notice: https://aviatrix.ai/aviatrix-end-of-sale-notice/ --- ## Contact URL: https://aviatrix.ai/contact/ Sales, support, and partnership enquiries. Email: info@aviatrix.com. Support portal: https://support.aviatrix.com/