Runtime security · production reality

Stop patching
risks that
never execute.

Primod maps what your systems actually run in production, so your team patches exploitable code instead of theoretical CVEs.

91%

backlog removed

<10 min

blast-radius scoping

<20 min

to first evidence

Interactive demo

See Primod
in action.

Preparing Interactive Demo

The demo loads automatically when this section enters view to keep initial page load lighter.

Works with your stack

Plugs into everything
you already run.

One eBPF sensor per node. No sidecars, no code changes, no restarts. Findings flow to the tools your teams live in, with 40+ integrations across cloud, CI, and on-call.

Reference cluster · last 30 days

From thousands of findings, the handful that matter emerge.

0

CVEs reported by static scanners

0

actually executed in production

0%

of the backlog removed in one sprint

app.primod.io / runtime / detections / CVE-2024-21907
ACTION REQUIRED

Upgrade Newtonsoft.Json to remediate the vulnerable code that executed in production.

INSTALLED (VULNERABLE)
12.0.3
RECOMMENDED (SECURE)
13.0.1+

The vulnerable function Newtonsoft.Json.JsonConvert.DeserializeObject was observed executing in a live request.

Where it ran

Nodelima-default
Poddotnet-vuln-api-6bb7d4b879-drh5x
Containerdotnet-vuln-api
Import pathNewtonsoft.Json
BinaryN/A
Namespacedotnet-vuln-ns

When Primod says it is critical, it actually is. No theoretical CVEs. No guesswork. Only code that ran in production.

Platform capabilities

Everything you need
to move from
noise to signal.

Runtime Visibility

See every executed code path — live.

Primod's eBPF sensor traces syscalls, network calls, and library invocations continuously. You get a living process-tree of exactly what code runs in each workload — no instrumentation, no rebuilds.

Process lineagePackage call-graphContainer scope
app.primod.io / runtime / detections / call-stack

Call stack

STACK TRACE (9 OF 24)
1Newtonsoft.Json.JsonTextReader.ParseValue
Newtonsoft.Json.dll:0
2Newtonsoft.Json.JsonTextReader.ParseObject
Newtonsoft.Json.dll:0
3Newtonsoft.Json.Linq.JTokenWriter.WriteToken
Newtonsoft.Json.dll:0
4Newtonsoft.Json.Serialization.JsonSerializerInternalReader.CreateJToken
Newtonsoft.Json.dll:0
5Newtonsoft.Json.Serialization.JsonSerializerInternalReader.CreateValueIn…
Newtonsoft.Json.dll:0
6Newtonsoft.Json.Serialization.JsonSerializerInternalReader.Deserialize
Newtonsoft.Json.dll:0
7Newtonsoft.Json.JsonSerializer.DeserializeInternal
Newtonsoft.Json.dll:0
8Newtonsoft.Json.JsonConvert.DeserializeObjectTRIGGER
Newtonsoft.Json.dll:0
9Program/<>c.<<Main>$>b__0_3
DotnetVulnApp.dll:0
View full 24-frame call stack
CVE Prioritisation

Close the gap between theory and exploit.

Static scanners report thousands of CVEs. Primod correlates each finding with live execution data. If the vulnerable function never runs, it drops off your queue — automatically.

CVSS vs. reachability scoreOne-click suppressionCI gate integration
app.primod.io / runtime / detections
CRITICAL CVSS 7.5CVE-2024-219078/10/2026, 9:55:09 PM

Vulnerable Newtonsoft.Json code executed

Upgrade Newtonsoft.Json to 13.0.1 or later to remediate CVE-2024-21907

Present

Executed

Exploited

Impacted

Contained

Nodelima-default
Poddotnet-vuln-api-6bb7d4b879-drh5x
Containerdotnet-vuln-api
Namespacedotnet-vuln-ns

Call stack · Newtonsoft.Json.JsonConvert.DeserializeObject

6Newtonsoft.Json.Serialization.JsonSerializerInternalReader.DeserializeNewtonsoft.Json.dll:0
7Newtonsoft.Json.JsonSerializer.DeserializeInternalNewtonsoft.Json.dll:0
8Newtonsoft.Json.JsonConvert.DeserializeObjectTRIGGER
9Program/<>c.<<Main>$>b__0_3DotnetVulnApp.dll:0
Blast Radius

Know the real impact before you page anyone.

When a new 0-day lands, Primod immediately shows which services call the affected package, which environments are active, and what data stores are reachable — so you triage in minutes, not days.

Service dependency graphEnvironment cross-checkData-path exposure
app.primod.io / kubernetes / workload-map
lima-default192.168.5.1514 Executed178 Misconfig
vuln-demo3 Exec38 Misc
demo-cve-dvwa
demo-cve-dvwa
13 Misconfig
go-sessions-api-76949fd76d…
go-sessions-api
Executed (1)
jline-cve-api-78dc8bc95d-8j…
java
Executed (2)
trafficloop
trafficloop
13 Misconfig
Compliance Evidence

Evidence your auditors can actually verify.

Every time a vulnerability is detected, Primod records the exact execution context — timestamped, traceable, and tied to the specific function that ran. When your SOC 2 or ISO 27001 audit comes around, you export a complete evidence chain instead of manually assembling logs from five different tools.

Runtime reachability proofExecution-linked evidenceImmutable audit trail
app.primod.io / workloads / demo-springboot

Activity Timeline

Every detection, version change and remediation for this workload, in the selected period.

Aug 10, 2026 09:58:19 PMRemediated · CVE-2024-21733 · 9.0.99 (patched-1)
Aug 10, 2026 09:58:19 PMRemediated · CVE-2023-45648 · 9.0.99 (patched-1)
Aug 10, 2026 09:58:19 PMRemediated · CVE-2021-33037 · 9.0.99 (patched-1)
Aug 10, 2026 09:58:19 PMRemediated · CVE-2021-43980 · 9.0.99 (patched-1)
Aug 10, 2026 09:58:19 PMVersion changed · CVE-2025-66614 · cve-2022-42889 → patched-1

Version History

Every image version this workload has run, and how long each was live.

Aug 10, 2026 09:57:19 PMdocker.io/library/demo-springboot-vuln:patched-1Still runningsha256:36b0d9560f7f93ec8c1532ebe8f7cb6a8936f8e2dd26073eb74adcfb133e8d6b
Aug 10, 2026 09:37:19 PMdocker.io/library/demo-springboot-vuln:cve-2022-42889Ran until Aug 10, 2026 09:57:19 PMsha256:d85a0a2ea3bfb6eb472fa976dc7bd6a06a928100d64934631471786968 6b0f11
Aug 10, 2026 09:33:19 PMdocker.io/library/demo-springboot-vuln:patched-1Ran until Aug 10, 2026 09:37:19 PMsha256:36b0d9560f7f93ec8c1532ebe8f7cb6a8936f8e2dd26073eb74adcfb133e8d6b
How it works

From deploy to defensible in three steps.

01

Deploy in minutes.

One lightweight eBPF agent. No source-code access. No app restarts. Live in your cluster in under 20 minutes.

02

See what actually runs.

Capture executed code paths, reachable packages, process lineage and service interactions — as they happen.

03

Fix only what matters.

Correlate CVEs with runtime reachability and blast radius into a single confidence score. Stop guessing, start shipping.

What teams say

Less noise.
Real evidence.

91%

backlog removed

We had 4,200 open CVEs. Primod showed us 38 actually execute in production. Our backlog dropped by 91% in one sprint.

DS

Daniel S.

Director of Security Engineering · Series B Cloud Infrastructure Co.

<10 min

to scope blast radius

Incident response used to mean hours of guesswork. Now we scope blast radius in under 10 minutes with execution traces.

PA

Priya A.

Principal Security Architect · Fintech Platform (Regulated)

80%

cut in two weeks

We cut our CVE backlog by 80% in two weeks. Primod showed us which vulnerabilities actually ran in production — the rest just disappeared from our queue.

VP

Viktor P.

VP Engineering · Enterprise SaaS · 10M+ users

For security & platform teams

If it didn't execute,
it doesn't lead your queue.

Bring runtime evidence into every remediation decision. Reduce operational drag. Make every engineering hour defensible.

No source-code access requiredeBPF — low production overheadWorks with Kubernetes & containers
Secure Now