Nirmata
Nirmata builds an AI-assisted Kubernetes governance and security platform on top of Kyverno, the Kubernetes-native policy engine its team created and maintains as a CNCF project, enforcing policy-as-code across clusters and CI/CD pipelines at scale.
Visit Website ↗ + Add to CompareOverview
Nirmata’s Control Hub gives platform and security teams a command center for enforcing Kubernetes governance policies across clusters and CI/CD pipelines, built on Kyverno — the Kubernetes-native policy engine originally created by Nirmata’s own engineering team and now a widely used CNCF open-source project. The platform layers AI-assisted policy authoring and drift detection on top of that open-source foundation.
Founded by CEO Jim Bugwadia along with co-founders Ritesh Patel and Damien Toledo, Nirmata is headquartered in Santa Clara, California, and has built its commercial business on the credibility and adoption of its open-source Kyverno project within the Kubernetes ecosystem.
Innovation Matrix Assessment
Maintaining and growing Kyverno as an actively developed CNCF project alongside a commercial AI-assisted governance layer reflects sustained technical investment over multiple years.
Policy-as-code enforcement integrated into CI/CD reduces the manual review burden of catching Kubernetes misconfigurations before they reach production.
Kyverno's broad open-source adoption across the Kubernetes community gives Nirmata a credible top-of-funnel, though specific commercial customer or revenue figures are not disclosed.
Policy-as-code for Kubernetes is now a well-established practice; Nirmata's differentiation is depth of open-source alignment rather than a fundamentally new security model.
Kyverno's wide community adoption and active CNCF maintenance is a meaningful indirect efficacy signal, though no independent benchmark of the commercial AI-assisted layer specifically was found.
As Kubernetes remains the dominant container orchestration standard, native policy governance for it stays strategically relevant regardless of broader CNAPP market shifts.
Why CISOs Should Care
Kubernetes misconfiguration remains a leading cause of container security incidents; Nirmata gives CISOs policy-as-code enforcement built on an open-source engine already trusted and adopted broadly across the Kubernetes community, reducing vendor lock-in risk.
What Makes It Different
Unlike CNAPP vendors that bolted on Kubernetes policy support after the fact, Nirmata's team originated Kyverno itself, giving it deep, native alignment with how the Kubernetes ecosystem actually implements policy enforcement.
The Matrix Verdict
53/100 — INCREMENTAL INNOVATOR
A credible, open-source-native Kubernetes governance vendor whose commercial value rests on the widespread adoption of Kyverno; disruption and momentum scores are constrained by limited independently verifiable funding and customer data.
Editorial Note: Claims vs. Verified Findings
Kyverno's origin at Nirmata and CNCF project status are independently verifiable through the open-source project's own governance records; specific funding amount, founding year, and employee count are not confirmed via a primary source and are treated with appropriate caution.
Sources
Alternatives to Nirmata
Wiz
Agentless, graph-based cloud security platform that maps multi-cloud risk end-to-end, now owned by Google after a record $32B…
Chainguard
Provides hardened, minimal, continuously-rebuilt container images and software packages to eliminate vulnerabilities before they reach production.
Microsoft Defender for Cloud
Microsoft's built-in cloud-native application protection platform, unifying CSPM, workload protection, and DevOps security natively across Azure, AWS, and…
Sysdig
The company behind Falco, the CNCF's runtime security standard, offering an eBPF/kernel-level CNAPP built on live syscall-based threat…
Obsidian Security
Obsidian Security provides a SaaS security posture management (SSPM) platform that detects identity-centric threats and misconfigurations across enterprise…
Upwind Security
Fast-growing, venture-backed CNAPP startup combining agentless scanning with eBPF runtime sensors for real-time cloud and AI workload risk…