Tier 1 → Tier 3 capability matrix

Compare All Three Tiers

EcheSky (Tier 1) is agentless and ships in minutes. EcheNet (Tier 2) adds a lightweight in-cluster agent. EcheDeep (Tier 3) runs an eBPF DaemonSet for runtime detection — without your data ever leaving the cluster in plaintext.

Tier 1
EcheSky

Agentless cloud scanner. Read-only IAM, hourly scans, 440+ misconfig rules.

Tier 2
EcheNet

Lightweight pod/sidecar. Continuous container scanning, runtime CVE correlation, SBOM.

Tier 3
EcheDeep

DaemonSet eBPF agent. Runtime anomalies, IOC matching, customer-KMS envelope encryption, on-cluster remediation.

FeatureTier 1
EcheSky
Tier 2
EcheNet
Tier 3
EcheDeep
Deployment & Operations
Deployment modelAgentless (API only)Lightweight agentContinuous on-cluster
Scan triggerManual / scheduledContinuous (real-time)Continuous + event-driven
Customer infra footprintRead-only IAM onlyPod / sidecarDaemonSet (1 per node)
Egress required
Air-gapped install
Asset Discovery
Cloud resources (compute, DB, storage)
Network topology (VPC, subnets, FW)
IAM & service accounts
Container images & registries
Runtime processes & syscalls
Shadow API discovery
Vulnerability Detection
Cloud misconfiguration (440+ rules)
CVE correlation (version → CVE)
CIS benchmark mapping
Runtime vulnerability detection
Container image scanning
SBOM generation
Zero-day correlation (threat intel)
Runtime & Detection
Process anomaly detection (eBPF)
Network anomaly + IOC matching
Lateral movement simulation
PII redaction at the bridge (zero-knowledge)n/an/a
Per-event KMS-wrapped envelope encryptionn/an/a
Customer-controlled KMS (AWS / GCP / Vault)
Compliance & Frameworks
CIS v2.0
SOC 2 Type II controls
HIPAA / PCI DSS v4.0
Custom Compliance Builder (Pro+)
Cross-framework score recompute
Daily score snapshots + 30-day trend
Scheduled compliance reports (HTML/CSV/PDF)
Remediation
Remediation suggestions
Approval-gated patches (dry-run by default)
Auto-PR via GitHub / GitLab connectors
Per-tenant remediation mode (dry-run / approval / pr / auto)
Apply patches in customer cluster
Observability & SLA
Prometheus /metrics endpointn/a
Cross-pod log correlation IDsn/a
99.9% ingester uptime target
Detection latency P95 ≤ 15s (process anomaly)
🚀

Need runtime detection + zero-knowledge?

Tier 3 (EcheDeep) ships eBPF process + network detection, IOC matching against URLhaus/Feodo/CISA KEV, customer-controlled envelope encryption (AWS KMS / GCP Cloud KMS / Vault), and on-cluster remediation — without data leaving your cluster in plaintext.