Frequently Asked Questions
Find answers to common questions about Guardimesh container malware scanning, pricing, deployment, and compliance.
Getting Started
- What is Guardimesh?
- Guardimesh is an automated container malware scanner for Kubernetes and OpenShift clusters. It deploys as a DaemonSet on every node, scanning running containers for malware, fileless payloads, executable drift, and obfuscated binaries without modifying your application code. Guardimesh uses ClamAV with automatically updated signature databases and supports custom detection rules.
- How does Guardimesh scan containers for malware?
- Guardimesh scans containers at the point of entry, on the node where container images are pulled. It accesses container filesystem layers via the overlay filesystem, passing them to ClamAV for signature-based malware detection. Each new pod is scanned automatically at deployment time, and recurring scans can be scheduled for long-running workloads.
- What container runtimes does Guardimesh support?
- Guardimesh supports all OCI-compliant container runtimes that use the overlay filesystem, including Docker, Podman, CRI-O, and containerd. It runs on both AMD64 and ARM64 architectures.
- What types of threats does Guardimesh detect?
- Guardimesh detects 5 categories of threats: known malware via ClamAV signatures, fileless payloads injected into container writable layers, executable drift (new binaries appearing after container start), obfuscated or packed binaries, and custom threats defined through user-created ClamAV signature rules. The ClamAV signature database is updated automatically.
Pricing & Trial
- How much does Guardimesh cost?
- Guardimesh starts at $29 per month for the Individual plan (up to 3 nodes). The Startup plan is $99 per month (up to 5 nodes with real-time monitoring). The Team plan is $349 per month (up to 25 nodes with custom signatures and all integrations). Enterprise pricing is custom for unlimited nodes. All plans offer a 20% discount with annual billing: Individual at $278 per year, Startup at $950 per year, and Team at $3,350 per year.
- How does Guardimesh pricing compare to Sysdig, Aqua Security, and Prisma Cloud?
- Guardimesh is 10 to 50 times less expensive than enterprise container security platforms for equivalent node counts. Sysdig Secure typically costs $2,000 to $4,000 per host per year. Aqua Security ranges from $1,500 to $3,500 per host per year. Palo Alto Prisma Cloud costs $2,000 to $5,000 per year per 100 credits. Guardimesh Team tier covers 25 nodes for $3,350 per year ($134 per node per year), and the Individual plan covers 3 nodes for $278 per year ($93 per node per year). Guardimesh uses predictable per-tier bundled pricing rather than per-host billing.
- Is there a free trial?
- Yes, Guardimesh offers a 7-day free trial with up to 2 nodes. No credit card is required to start. The trial includes email notifications and 14-day log retention.
- What is the annual billing discount?
- Annual billing saves 20% compared to monthly billing. Individual drops from $29 per month to $278 per year ($23 per month equivalent). Startup drops from $99 per month to $950 per year ($79 per month equivalent). Team drops from $349 per month to $3,350 per year ($279 per month equivalent).
Compliance & Security
- Is Guardimesh FIPS 140-3 compliant?
- Yes, all Guardimesh client components are built with FIPS 140-3 certified cryptographic modules. FIPS 140-3 builds use Go’s native CMVP-certified Go Cryptographic Module (Certificate #5247) and are available on all tiers. The Enterprise tier additionally supports air-gapped deployments with FIPS-validated TLS for disconnected environments.
- Does Guardimesh support FedRAMP compliance?
- Yes, Guardimesh satisfies the NIST SI-3 malware protection control required by FedRAMP High authorization. It scans containers at the point of entry on each node, providing audit-ready compliance reports with timestamped logs. Guardimesh also addresses NIST 800-53 security controls and NIST 800-190 container security guidelines.
- What compliance frameworks does Guardimesh help with?
- Guardimesh helps organizations meet requirements for FedRAMP High (NIST SI-3), NIST 800-53, NIST 800-190, SOC 2, and ISO 27001. Scan logs are retained for up to 180 days on the Team plan (customizable on Enterprise), providing the audit trail required by these frameworks.
Deployment
- Does Guardimesh work in air-gapped environments?
- Yes, Guardimesh supports fully air-gapped (disconnected) deployment on the Enterprise tier. The on-premise edition runs entirely within the secure perimeter with no internet access required, using PostgreSQL for data storage instead of cloud services. ClamAV signature updates are transferred manually via secure media.
- How do I deploy Guardimesh on OpenShift?
- Guardimesh deploys on Red Hat OpenShift 4.12 and later via the Guardimesh Operator. The DaemonSet runs on every node in the cluster. No sidecars or service mesh modifications are required. The quickstart guide at docs.guardimesh.com/quickstart covers deployment from start to first scan result in under 5 minutes.
- Does Guardimesh require privileged containers?
- The Guardimesh scanner requires host filesystem access to read container storage layers. It mounts the host root filesystem as read-only for container inspection. On OpenShift, a SecurityContextConstraint is required. The specific RBAC permissions and security context configuration are documented at docs.guardimesh.com/architecture.
Features
- Does Guardimesh support real-time file monitoring?
- Yes, Guardimesh provides real-time file monitoring via Linux fanotify on the Startup plan ($99 per month) and above. Fanotify monitors container writable layers for new or modified files and triggers immediate scans, detecting threats as they appear rather than waiting for the next scheduled scan.
- Can I create custom malware signatures?
- Yes, the Team plan ($349 per month) and Enterprise plan support custom ClamAV signature databases. Team accounts can upload up to 10 custom signature databases (up to 2 MB each) in HSB, SFP, and DB formats. Enterprise accounts have unlimited custom signatures with additional LDB format support and a 5 MB file size limit.
- What integrations does Guardimesh support?
- Guardimesh integrates with Slack, PagerDuty, Jira, ServiceNow, and email for scan notifications. Slack and PagerDuty are available from the Startup plan ($99 per month). Jira, ServiceNow, and webhook integrations are available on the Team plan ($349 per month) and above.
- What is the difference between Guardimesh and Falco?
- Guardimesh and Falco address different aspects of container security. Guardimesh scans container filesystem layers for known malware, fileless payloads, and executable drift using ClamAV signature-based detection. Falco monitors kernel-level system calls for runtime behavioral anomalies. Guardimesh identifies malware artifacts; Falco detects suspicious runtime behavior. The two tools are complementary. Falco is open-source and free but requires self-management with no built-in UI, log retention, or compliance reporting.
- How long are scan logs retained?
- Scan log retention depends on your subscription tier. The Trial plan retains logs for 14 days. Individual and Startup plans retain logs for 90 days. The Team plan retains logs for 180 days. Enterprise plans offer customizable retention periods. All logs include timestamped entries for container creation events, scan results, and signature updates.