Tigera
Creator and commercial steward of Project Calico, the most widely adopted Kubernetes networking and network-policy engine, extended into a commercial platform for container and cloud-native security and observability.
Visit Website ↗ + Add to CompareOverview
Tigera created and maintains Project Calico, an open-source networking and network-policy engine for containers, Kubernetes, and bare-metal workloads that has become the default or optional CNI (container network interface) across every major managed Kubernetes service, including those from AWS, Microsoft, and Google. On top of that open-source base, Tigera sells a commercial platform, Calico Cloud and Calico Enterprise, that adds network security policy enforcement, intrusion detection, and observability purpose-built for containerized and cloud-native workloads, using an eBPF-based data plane rather than traditional perimeter network security tooling retrofitted onto Kubernetes.
Founded in 2016 and headquartered in San Francisco, Tigera has grown to roughly 130 employees and raised a $30 million Series B in December 2018 led by Insight Partners. The scale of open-source Calico adoption — reportedly powering more than a million clusters globally — gives Tigera a distribution advantage most cloud-native security vendors don’t have: enterprises already running Calico for basic networking are a natural upgrade path to the paid security and observability tier. Tigera has continued extending Calico’s scope, including recent work applying its network-policy model to securing AI and machine-learning workloads running on Kubernetes.
For CISOs, Tigera is relevant wherever Kubernetes is a meaningful part of the infrastructure footprint: it addresses the specific problem that traditional network security tools generally cannot see or enforce policy inside a Kubernetes cluster at the pod level, a gap that grows as more workloads move to containers.
Innovation Matrix Assessment
Tigera continues to actively extend Calico's scope, including 2026 work applying its policy model to securing AI/ML workloads on Kubernetes, on top of ongoing open-source project development, indicating a healthy iteration pace for the category.
Stewardship of an open-source project reportedly running in more than a million clusters, combined with a commercial team of roughly 130 people supporting enterprise customers, reflects real operational reach relative to headcount.
Recent product extensions (AI workload security) show continued platform relevance, but the company's last publicly disclosed funding round was in 2018, making financial momentum harder to verify from current public information.
An eBPF-based data plane purpose-built for container and Kubernetes-native network security is a meaningfully different technical approach than legacy network security tools adapted after the fact for containerized environments.
Calico's status as a default or supported CNI across AWS, Microsoft, and Google managed Kubernetes offerings is an independently observable adoption signal that is difficult to fabricate, distinct from self-reported vendor customer counts.
As Kubernetes becomes the default deployment substrate for enterprise workloads, pod-level network visibility and policy enforcement is an increasingly necessary and previously underserved cloud security control.
Why CISOs Should Care
Tigera closes a specific, growing gap: traditional network security tooling generally cannot see or enforce policy inside a Kubernetes cluster, and Tigera's Calico-based platform is purpose-built for that layer with a distribution advantage from mass open-source adoption.
What Makes It Different
Unlike security vendors that bolt Kubernetes support onto existing network security products, Tigera's commercial platform is a direct extension of Calico, the open-source project it created and that already underpins networking in a large share of production Kubernetes clusters.
The Matrix Verdict
70/100 — MEANINGFUL INNOVATOR
A technically credible cloud-native network security vendor with an unusually strong, independently verifiable distribution channel through open-source Calico adoption, tempered by limited visibility into recent financial momentum.
Editorial Note: Claims vs. Verified Findings
Calico's adoption as a default/supported CNI in major managed Kubernetes services and the 1M+ cluster figure are corroborated by cloud provider documentation and third-party cloud-native coverage. Specific named enterprise customers (Discover, Chipotle, NBCUniversal, RBC, NVIDIA, Bloomberg, and others) are drawn from Tigera's own marketing materials and should be treated as vendor-sourced unless confirmed directly by those companies.
Sources
Alternatives to Tigera
Wiz
Agentless, graph-based cloud security platform that maps multi-cloud risk end-to-end, now owned by Google after a record $32B…
Chainguard
Provides hardened, minimal, continuously-rebuilt container images and software packages to eliminate vulnerabilities before they reach production.
Microsoft Defender for Cloud
Microsoft's built-in cloud-native application protection platform, unifying CSPM, workload protection, and DevOps security natively across Azure, AWS, and…
Obsidian Security
Obsidian Security provides a SaaS security posture management (SSPM) platform that detects identity-centric threats and misconfigurations across enterprise…
Sysdig
The company behind Falco, the CNCF's runtime security standard, offering an eBPF/kernel-level CNAPP built on live syscall-based threat…
Upwind Security
Fast-growing, venture-backed CNAPP startup combining agentless scanning with eBPF runtime sensors for real-time cloud and AI workload risk…