Edera offers a hardened runtime for Kubernetes that runs each container inside a lightweight Xen‑based microVM, providing hardware‑level isolation and reducing the attack surface by up to 95%. The platform delivers near‑native performance—within 5% of standard containers—without requiring specialized hardware or workflow changes, and includes built‑in observability and policy enforcement for multi‑tenant, GPU‑accelerated, and edge workloads.
Funding
$15M raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.






+3Founders
Product
Problem
Containers and Kubernetes workloads are vulnerable to privilege escalation, lateral movement, and kernel-level exploits, especially when running untrusted code, GPU drivers, or edge applications. Traditional security tools rely on detection and generate high alert volumes, leading to alert fatigue and limited isolation for multi‑tenant environments.
Solution
Edera provides a hardened runtime built on the Xen hypervisor that runs each container inside an efficient microVM, delivering true isolation and reducing the attack surface by up to 95%. By stripping away unnecessary kernel code and enabling per‑zone kernel versions, the platform prevents privilege escalation, lateral movement, and data exfiltration without sacrificing performance—running within 5% of native containers. The solution integrates seamlessly with any Kubernetes deployment (cloud, on‑prem, or edge) via a few lines of YAML, requiring no specialized hardware or workflow changes. It also offers enhanced observability and enforcement capabilities, allowing teams to enforce security policies and gain deep insights into guest workloads while maintaining fast development cycles.
Target Audience
Primary customers are cloud‑native engineering teams, platform operators, and AI/ML infrastructure providers that run multi‑tenant, GPU‑accelerated, or edge workloads on Kubernetes and need strong isolation without performance trade‑offs.
Features
- MicroVM‑based container isolation that provides hardware‑level security for multi‑tenant workloads
- Attack surface reduction of ~95% by removing unnecessary kernel paths and using a minimal Xen hypervisor layer
- Per‑zone kernel flexibility enabling different kernel versions and GPU driver configurations without conflicts
- Near‑native performance (within 5% of standard containers) on any Kubernetes platform, including edge nodes
- Built‑in observability and policy enforcement that surface guest‑level metrics and allow real‑time security actions
- Simple deployment via a few YAML statements, compatible with private, public, and on‑prem Kubernetes clusters
- Support for confidential computing and secure execution of untrusted code without dedicated hardware