
The runtime-based vulnerability prioritization has been the biggest improvement for us.
Instead of a flat CVE list per image, ARMO shows which vulnerable packages are actually
loaded and in use at runtime, which cut the list we have to act on down to something a
small team can realistically handle. The eBPF sensor gives that visibility without us
having to change our deployments or add sidecars.
We also get a lot of value out of the generated network policies and the way ARMO builds
them from observed traffic rather than asking us to write them from scratch — it turns
network segmentation from a project into a review step. Compliance reporting against
frameworks like NSA-CISA and CIS has been useful for demonstrating posture to customers
without maintaining our own spreadsheets.
Onboarding remains genuinely fast: a single Helm install per cluster, and the Slack
integration keeps new findings visible in the channels the team already works in. The
combination of posture, vulnerability and runtime data in one platform means we're not
stitching together three tools to answer one question. Review collected by and hosted on G2.com.
Multi-cluster reporting. Once you're running more than a handful of clusters, the
per-cluster views are strong but the roll-up across all of them is thinner. A single
trend view — "is our overall exposure going up or down this quarter" — would help a lot
when reporting to management.
Documentation for the less common paths. The happy-path setup is well documented; the
edges — custom control tuning, exceptions at scale, CI integration in less common
pipelines — take more trial and error than they should. Review collected by and hosted on G2.com.