# Harborbase

*/Startups/Harborbase*

## Startup Overview

This cloud security platform connects eBPF runtime events directly to known container vulnerabilities. Security and DevOps teams use the system to identify exactly which software flaws are actively exposed in live environments. By monitoring the behavior of containerized applications at the kernel level, the engine bridges the gap between static risk assessments and actual runtime execution.

Standard cloud security scanners generate thousands of unprioritized alerts, forcing engineers to chase false positives that never load into memory. By capturing eBPF telemetry without modifying the host or injecting sidecars, the platform filters out dormant vulnerabilities. It maps real system calls and network traffic back to vulnerable packages, isolating the specific flaws that active workloads interact with.

Unlike traditional protection platforms such as Wiz, Aqua Security, or Datadog Cloud Security, the system eliminates both operational drag and bloated licensing. It deploys with zero overhead, avoiding the performance penalties of heavy user-space agents. The platform also replaces arbitrary compute-based subscriptions with strict outcome pricing, charging exclusively for each remediated vulnerability.

## Startup Founding Hypothesis

**Approach**: that correlates eBPF runtime events to container vulnerabilities
**Competitors**:
- [Wiz](/Competitors/Wiz)
- [Aqua Security](/Competitors/Aqua_Security)
- [Datadog Cloud Security](/Competitors/Datadog_Cloud_Security)
**Differentiator2x2**: zero-overhead to deploy and outcome-priced per remediated vulnerability

## Startup Solution Coordinate

**Solution**: [Harborbase Runtime Security](/Services/Harborbase_Runtime_Security)

## Startup Position2x2

```mermaid
quadrantChart
    title Market Positioning
    x-axis "High Deployment Overhead" --> "Zero-Overhead Deployment"
    y-axis "Traditional Infra Pricing" --> "Outcome-Based Pricing"
    quadrant-1 "Frictionless & Aligned"
    quadrant-2 "Heavy & Aligned"
    quadrant-3 "Heavy & Fixed Cost"
    quadrant-4 "Frictionless & Fixed Cost"
    Wiz: [0.8, 0.2]
    Aqua Security: [0.3, 0.25]
    Datadog Cloud Security: [0.45, 0.3]
    Harborbase: [0.9, 0.85]
```

## Startup Offer

**Proof**:
- Aim to help mid-market SaaS teams eliminate 90% of critical container CVEs without manual developer intervention
- Targeting FinTech platforms to reduce container vulnerability time-to-remediate from 14 days to under 4 hours
- Designed to run the eBPF probe with less than 1% CPU overhead on standard production nodes
**Tiers**:
- Name: Pay Per Fix · Price: ~$40–$80 per verified remediation · Inclusions: Read-only eBPF daemonset deployment, runtime event correlation, and automated pull requests for container vulnerabilities. Billed only when the PR is merged and the CVE clears.
- Name: Volume Commitment · Price: ~$3,000–$6,000/mo · Inclusions: Pre-purchased block of up to 100 remediations per month at a discounted rate, plus intended webhook integrations for standard CI/CD pipelines.
- Name: Enterprise Site License · Price: ~$50k–$80k/yr · Inclusions: Unlimited automated remediations across all clusters, custom compliance reporting, and intended integration with existing CSPM platforms like Wiz or Aqua.
**Guarantee**: Harborbase guarantees you only pay for outcomes: if an automated pull request breaks the container build or fails to clear the runtime vulnerability flag, the fix is not billed and a fallback manual engineering review is provided.
**Business Function**: ProvideService
**Objection Handlers**:
- Objection: eBPF agents cause unacceptable kernel overhead or instability. Rebuttal: Harborbase is designed strictly as a read-only eBPF probe with hard-coded resource caps to ensure near-zero overhead.
- Objection: Automated PRs will break our production services. Rebuttal: We charge per verified remediation; PRs are designed to trigger your existing test suites to validate the patched image before merge.
- Objection: We already pay for Wiz or Datadog Cloud Security. Rebuttal: Those platforms generate alerts; Harborbase is designed to ingest those alerts and actually write the code to fix them.
**Pricing Architecture**: UsageMeter
**Agent Checkout Support**:
- agentic-commerce-protocol

## Startup Brand

**Voice**: Direct technical register distinguished by strict forensic precision
**Tagline**: Pay only for remediated container vulnerabilities with zero deployment overhead
**Icon Concept**: Container
**Palette Intent**: electric-signal
**Visual Identity**: The visual identity combines neon cyan and deep terminal black to reflect kernel-level visibility, using raw hex-code data textures instead of generic cybersecurity padlocks.
**Archetype Reference**: the-sage

## Startup Buyer Chain

**Chain**: Harborbase → DevSecOps Engineer → Platform Engineering Team
**Gtm Motion**: Acquisition drives bottoms-up adoption through frictionless, zero-overhead eBPF DaemonSet deployments on non-production Kubernetes clusters to instantly expose live runtime threats. Expansion scales revenue automatically as platform teams deploy the tool across production environments, triggering outcome-based billing solely upon the verified remediation of a vulnerability.
**Agent Channel**: Designed to publish a vulnerability correlation schema within the Model Context Protocol (MCP) registry, enabling autonomous AI DevSecOps agents to programmatically discover and query live exploitability states.
**Primary Channel**: Cloud security leads discover the tool via targeted technical searches for 'eBPF container runtime security' and through architectural tool evaluations on the CNCF Interactive Landscape and Kubernetes Artifact Hub.

## Startup Customer Journey

```mermaid
flowchart LR; A[CNCF Artifact Hub] --> B[eBPF DaemonSet]; B --> C[Development Kubernetes Cluster]; C --> D[Automated Pull Request]; D --> E[Continuous Integration Pipeline]; E --> F[Production Kubernetes Cluster]; F --> G[Model Context Protocol Registry];
```

## Startup Proof Points

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**Pilot Goals**:
- 14-day read-only staging pilot: Aiming to deploy the eBPF daemonset, monitor one cluster, and generate test-passing pull requests for 10 critical CVEs to prove the automated remediation workflow.
- 30-day bounded production pilot: Targeting the integration with existing CSPM platforms to automatically resolve up to 50 container vulnerabilities, validating the pay-per-fix ROI model.
**Target Metrics**:
- Target: 90% reduction in critical container CVEs requiring manual developer intervention
- Aim: Under 4 hours average time-to-remediate for runtime vulnerabilities
- Target: Less than 1% CPU overhead consumed by the read-only eBPF daemonset on production nodes
- Aim: 100% test-suite pass rate on Harborbase-generated pull requests before merge
**Target Case Studies**:
- A mid-market SaaS engineering team eliminating a backlog of unaddressed container CVEs via automated pull requests within a 30-day window.
- A high-growth FinTech platform reducing time-to-remediate for runtime container vulnerabilities from a 14-day average to under 4 hours without adding security headcount.
- An enterprise healthcare technology provider integrating automated remediation into existing CSPM deployments to close compliance gaps across multiple Kubernetes clusters.
**Testimonial Targets**:
- VP of Engineering: Expressing relief that developers no longer burn sprint capacity bumping container base images because Harborbase writes the fixes.
- Lead DevSecOps Engineer: Highlighting that Harborbase actually acts on cloud security alerts by opening pull requests, rather than just adding noise to a dashboard.
- Principal SRE: Confirming the eBPF probe deploys effortlessly and causes zero kernel instability or performance degradation.

## Startup Top Risks

**Risks**:
- Severity: existential · Description: Customers delay or refuse to patch vulnerabilities, starving Harborbase of revenue due to the outcome-based pricing model. · Mitigation Status: unmitigated
- Severity: high · Description: Managed Kubernetes providers restrict the kernel privileges required for eBPF, blocking deployment and nullifying the zero-overhead advantage. · Mitigation Status: in-progress
- Severity: high · Description: Incumbents like Wiz or Datadog replicate the eBPF-to-vulnerability correlation and bundle it for free within their widely deployed agents. · Mitigation Status: unmitigated
- Severity: moderate · Description: Customers dispute billing events because confirming exact vulnerability remediation across transient container lifecycles is technically ambiguous. · Mitigation Status: in-progress

## Startup Competitors

- [Wiz](/Competitors/Wiz) — Cloud Security Posture
- [Aqua Security](/Competitors/Aqua_Security) — Container Security
- [Datadog Cloud Security](/Competitors/Datadog_Cloud_Security) — Observability Platform
- [Falco](/Competitors/Falco) — Open Source eBPF
- [Sysdig](/Competitors/Sysdig) — Runtime Security
- [Prisma Cloud](/Competitors/Prisma_Cloud) — Incumbent CNAPP

## Startup Solution Stack

- [Vulnerability Remediation Service](/Services/Vulnerability_Remediation_Service) — Service-as-Software
- [Runtime Correlation Agent](/Agents/Runtime_Correlation_Agent) — Agent
- [Patch Generation Worker](/Agents/Patch_Generation_Worker) — Agent
- [Kernel Telemetry Engine](/Software/Kernel_Telemetry_Engine) — Software
- [Vulnerability Mapping API](/Software/Vulnerability_Mapping_API) — Software

## Startup Story Brand

**Hero**:
- **Need**: to be the strategic architect of a resilient infrastructure, not a ticket-pusher for library updates
- **Want**: to eliminate critical container CVEs without drowning their developers in security tickets
- **Identity**: the Platform Engineering Lead at a growing SaaS company
**Plan**:
- Step: Review · Detail: Browse the dashboard to see which runtime vulnerabilities are actually active in your production clusters.
- Step: Check · Detail: Inspect the automated pull requests generated for each identified vulnerability within your existing GitHub or GitLab flow.
- Step: Merge · Detail: Approve the patch to trigger your CI/CD suite and clear the security flag from your scanner.
**Guide**:
- **Empathy**: When your morning starts with a fresh Datadog Cloud Security alert for a production cluster, your planned sprint work vanishes into emergency patching.
**Problem**:
- **Villain**: alert fatigue
- **External**: Scanning tools like Wiz or Aqua generate thousands of vulnerability alerts in Jira, but leave DevOps teams to manually patch Dockerfiles and redeploy images one by one.
- **Internal**: You feel like a glorified janitor, spending your weekends chasing patch versions instead of building core features.
- **Philosophical**: Every engineering team deserves to focus on product innovation — not the endless drudgery of manual CVE remediation.
**Success**: Your container security backlog clears itself automatically, with remediation times dropping from weeks to hours without a single developer lifting a finger.
**One Liner**: What if your security scanner actually wrote the code to fix its own alerts? Harborbase correlates runtime events to container vulnerabilities and delivers verified pull requests, so you only pay for successful remediations.
**Positioning**:
- **So That**: automated patches are applied based on real runtime usage
- **Unlike**: Wiz and Datadog Cloud Security
- **For Whom**: Platform Engineering Leads at SaaS companies
- **Category**: Automated vulnerability remediation
**Call To Action**:
- **Direct**: Fix one CVE
- **Transitional**: View sample remediation PR
**Failure Stakes**:
- Critical vulnerabilities remain unpatched
- Developer burnout from security toil
- Slower product release cycles
**Transformation**:
- **To**: free to scale production infrastructure, no longer stuck doing the drudgery of manual image patching
- **From**: the lead buried in Jira security tickets
**Controlling Idea**: Remediation should be an automated outcome, not a manual engineering task.

## Startup Token Hero

**Genre**: founding-hypothesis
**Rendered**: What if your security scanner actually wrote the code to fix its own alerts? Harborbase correlates runtime events to container vulnerabilities and delivers verified pull requests, so you only pay for successful remediations.
**Mechanism**: spine-derived-v1
**Template Id**: spine-founding-hypothesis
**Vocab Fingerprint**: 6b4773c8f8dc42ba

## Startup Token Positioning

**Genre**: moore-positioning
**Rendered**: Automated vulnerability remediation for Platform Engineering Leads at SaaS companies. Unlike Wiz and Datadog Cloud Security — automated patches are applied based on real runtime usage.
**Mechanism**: spine-derived-v1
**Template Id**: spine-moore-positioning
**Vocab Fingerprint**: 402ed095dce9327c

## Startup Token Pitch Deck

**Genre**: pitch-deck
**Rendered**: Problem: Scanning tools like Wiz or Aqua generate thousands of vulnerability alerts in Jira, but leave DevOps teams to manually patch Dockerfiles and redeploy images one by one.
Solution: What if your security scanner actually wrote the code to fix its own alerts? Harborbase correlates runtime events to container vulnerabilities and delivers verified pull requests, so you only pay for successful remediations.
Customer: Platform Engineering Leads at SaaS companies
Unlike: Wiz and Datadog Cloud Security
**Mechanism**: spine-derived-v1
**Template Id**: spine-pitch-deck
**Vocab Fingerprint**: bbe4668e2ad64ebc

## Startup Token M E D D P I C C

**Pain**: Scanning tools like Wiz or Aqua generate thousands of vulnerability alerts in Jira, but leave DevOps teams to manually patch Dockerfiles and redeploy images one by one.
**Metrics**: Target: Your container security backlog clears itself automatically, with remediation times dropping from weeks to hours without a single developer lifting a finger.
**Rendered**: Pain: Scanning tools like Wiz or Aqua generate thousands of vulnerability alerts in Jira, but leave DevOps teams to manually patch Dockerfiles and redeploy images one by one.
Economic buyer: DevSecOps Engineer
Metrics: Target: Your container security backlog clears itself automatically, with remediation times dropping from weeks to hours without a single developer lifting a finger.
Competition: Wiz and Datadog Cloud Security
**Mechanism**: spine-derived-v1
**Competition**: Wiz and Datadog Cloud Security
**Economic Buyer**: DevSecOps Engineer
**Vocab Fingerprint**: f4c2a17333938156

## Startup Token Cold Email

**Genre**: cold-email
**Rendered**: Subject: Automated vulnerability remediation for Platform Engineering Leads at SaaS companies

Platform Engineering Leads at SaaS companies — Scanning tools like Wiz or Aqua generate thousands of vulnerability alerts in Jira, but leave DevOps teams to manually patch Dockerfiles and redeploy images one by one. What if your security scanner actually wrote the code to fix its own alerts? Harborbase correlates runtime events to container vulnerabilities and delivers verified pull requests, so you only pay for successful remediations.
**Mechanism**: spine-derived-v1
**Template Id**: spine-cold-email
**Vocab Fingerprint**: 7ec519048d21ef2e

## Startup Token Agent Spec

**Genre**: ai-agent-spec
**Rendered**: Automated vulnerability remediation. What if your security scanner actually wrote the code to fix its own alerts? Harborbase correlates runtime events to container vulnerabilities and delivers verified pull requests, so you only pay for successful remediations. Serves Platform Engineering Leads at SaaS companies.
**Mechanism**: spine-derived-v1
**Template Id**: spine-ai-agent-spec
**Vocab Fingerprint**: fcad8d67e241fcc3

## Neighborhood

### Candidate solutions

- [Source Heavy Plate Welders](/Problems/Source_Heavy_Plate_Welders) — candidate solution for · Problems

### Composed of

- [Runtime Correlation Agent](/Agents/Runtime_Correlation_Agent) — composes · Agents
- [Patch Generation Worker](/Agents/Patch_Generation_Worker) — composes · Agents
- [Vulnerability Mapping API](/Software/Vulnerability_Mapping_API) — composes · Software
- [Kernel Telemetry Engine](/Software/Kernel_Telemetry_Engine) — composes · Software
- [Vulnerability Remediation Service](/Services/Vulnerability_Remediation_Service) — composes · Services

### Embodies

- [Service-as-Software](/Theses/Service-as-Software) — embodies · Theses

### What it offers

- [Harborbase Runtime Security](/Services/Harborbase_Runtime_Security) — offers · Services

### Competitors

- [Prisma Cloud](/Competitors/Prisma_Cloud) — competes with · Competitors
- [Aqua Security](/Competitors/Aqua_Security) — competes with · Competitors
- [Datadog Cloud Security](/Competitors/Datadog_Cloud_Security) — competes with · Competitors
- [Falco](/Competitors/Falco) — competes with · Competitors
- [Sysdig](/Competitors/Sysdig) — competes with · Competitors
- [Wiz](/Competitors/Wiz) — competes with · Competitors

### Similar Startups

- [Sentinel](/Startups/Sentinel) — similar · Startups
- [Visibilitygrain](/Startups/Visibilitygrain) — similar · Startups
- [Activefire](/Startups/Activefire) — similar · Startups
- [Gorgetorch](/Startups/Gorgetorch) — similar · Startups
- [Mythenith](/Startups/Mythenith) — similar · Startups
- [Fenrir](/Startups/Fenrir) — similar · Startups
- [Abortedpoint](/Startups/Abortedpoint) — similar · Startups
- [Shielduffer](/Startups/Shielduffer) — similar · Startups
- [Probluard](/Startups/Probluard) — similar · Startups
- [Abimb](/Startups/Abimb) — similar · Startups
- [Hexharbor](/Startups/Hexharbor) — similar · Startups
- [Zerodaycrest](/Startups/Zerodaycrest) — similar · Startups
- [Awarestack](/Startups/Awarestack) — similar · Startups
- [Zenentinel](/Startups/Zenentinel) — similar · Startups
- [Mapleshape](/Startups/Mapleshape) — similar · Startups
- [Aurossom](/Startups/Aurossom) — similar · Startups
- [Weldedrock](/Startups/Weldedrock) — similar · Startups
- [Zenithember](/Startups/Zenithember) — similar · Startups
- [Accirm](/Startups/Accirm) — similar · Startups
- [Houndaga](/Startups/Houndaga) — similar · Startups
