Apache Sentry
Apache Sentry™ is a system for enforcing fine grained role based authorization to data and metadata stored on a Hadoop cluster. Apache Sentry has successfully graduated from the Incubator in March of 2016 and is now a Top-Level Apache project. Apache Sentry is a granular, role-based authorization module for Hadoop. Sentry provides the ability to control and enforce precise levels of privileges on data for authenticated users and applications on a Hadoop cluster. Sentry currently works out of the box with Apache Hive, Hive Metastore/HCatalog, Apache Solr, Impala and HDFS (limited to Hive table data). Sentry is designed to be a pluggable authorization engine for Hadoop components. It allows you to define authorization rules to validate a user or application’s access requests for Hadoop resources. Sentry is highly modular and can support authorization for a wide variety of data models in Hadoop.
Learn more
KnoxCall
Every app, build pipeline and AI agent that calls Stripe, OpenAI or another third-party API needs its key, so copies of live keys pile up in .env files, CI settings, laptops and agent environments. Each copy can leak through a poisoned package, a prompt-injected agent or a compromised build, and a stolen key keeps working until it is replaced everywhere.
KnoxCall keeps the real key in one place and adds it to each call on its way out. Your apps, pipelines and agents hold only a KnoxCall token. If one leaks, one click revokes it everywhere, without rotating the provider key. Every call is logged with the app or agent that made it.
AI agents get spend limits, prompt checks, and redaction of the personal data KnoxCall detects. CI can use workload identity instead of a stored secret, and Enterprise adds a master key held in your own cloud account, SSO and SCIM.
SDKs for Node, Python, Go, PHP, Ruby, React and the browser. Free plan, no card; paid plans from $19 a month.
Learn more
AccuKnox
AccuKnox provides a zero trust Cloud Native Application Security (CNAPP) platform. AccuKnox is built in partnership with SRI (Stanford Research Institute) and is anchored on seminal inventions in the areas of container security, anomaly detection, and data provenance. AccuKnox can be deployed in public and private cloud environments. AccuKnox runtime Security helps you discover the application Behavior of the workloads running in a public cloud, private cloud, or on-prem in VM/BareMetal or local Kubernetes orchestrated cluster or unorchestrated pure-containerized cluster. If any ransomware attacker tries to compromise the security of the pod and gets access to the vault pod, they can do a command injection and encrypt the secrets stored in the volume mount points. Then the organizations have to pay millions of dollars to get back their secrets decrypted.
Learn more
Samsung Knox Suite
Knox Suite is an all-in-one enterprise mobility solution designed to secure, deploy, manage, and analyze work devices across their entire lifecycle. Built on the Samsung Knox platform, it enables organizations to safeguard device fleets and corporate data by detecting vulnerabilities, enforcing security patches, verifying device integrity remotely, and locking or wiping devices when needed. Deployment is streamlined with automated enrollment options, such as QR-code setup or bulk provisioning by certified resellers, and devices seamlessly integrate into the Knox ecosystem with a unified single-sign-on admin experience. Device and app management is handled centrally: IT teams can define granular policies by location, time, network status, or device state; control OS versions and updates; distribute, configure, or remove apps; and lock down lost or stolen devices.
Learn more