How Does Soluble Secure Kubernetes at Scale?

TL;DR
Soluble uses Kubernetes itself to distribute security capabilities consistently across multi-cloud and multi-cluster environments. Its SaaS control plane lets DevOps and SRE teams onboard clusters, deploy open-source-based security microproducts, collect telemetry, and automate operations, with a low-cost, usage-based subscription intended to preserve cloud-native development speed.
Transcript
All right, thanks. Our next contestant, dropping security into DevOps so engineers can move faster. Please welcome from Soluble, founder and CEO, Richard Searson. Wow. Wow, nice entry music, man. All right. Okay, your five minutes begins now. Can you guys hear me? No. No. Try again. Speak. Uh-oh. Hot mic swap? Wait, no. I don't know. Don't do the s... Read More
Key Insights
- Cloud-native development can overwhelm traditional security teams because its release velocity, sprawling clusters, and multi-cloud deployments require more human and engineering resources than security organizations may possess.
- Traditional CI/CD security integration can face developer resistance because tools such as SAST and DAST may slow delivery. In Seiersen's experience, DevOps rejected such attempts as worse than doing nothing.
- Soluble is a SaaS control plane that delivers security microproducts into Kubernetes clusters. These microproducts are assembled from accepted open-source components and include capabilities such as privileged access management, identity and access management, and role-based access control.
- Kubernetes is both the environment being secured and Soluble's delivery mechanism. The company uses the Kubernetes API and ecosystem to distribute security capabilities across clusters and clouds instead of focusing only on securing containers.
- Soluble's operational workflow includes onboarding clusters, deploying microproducts, collecting control-plane telemetry, and performing automation. The platform is presented as capable of serving one cluster or 1,000 clusters within minutes.
- DevOps and SRE teams are Soluble's primary prospective buyers because they increasingly own operational security responsibilities. The product aims to speak their language, minimize disruption, and help them complete security work before returning to engineering priorities.
- Soluble's commercial model is a bottom-up, usage-based subscription designed around how technical teams acquire software. The initial approach emphasizes trying and buying without budget ceremonies, permissions, approvals, or salespeople, although top-down sales may come later.
- Soluble's central differentiation requires sharper communication because investors wanted two or three concrete outcomes unavailable elsewhere. Seiersen emphasized usability, Kubernetes-native deployment, and consistent delivery across multi-cloud and multi-cluster environments as the distinguishing elements.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: How does Soluble secure Kubernetes environments?
Soluble provides a SaaS control plane that delivers security microproducts into Kubernetes clusters. Teams onboard their clusters, deploy selected capabilities, receive telemetry through the control plane, and automate related operations. The company uses Kubernetes itself, including its API and ecosystem, as the means of distributing security consistently across multi-cloud and multi-cluster environments.
Q: Why did traditional security tools struggle with cloud-native development?
Traditional approaches struggled because cloud-native teams operated with rapid releases, sprawling clusters, and multi-cloud deployments, while security teams lacked comparable human and engineering resources. Attempts to add SAST and DAST to CI/CD were rejected as too slow. The resulting mismatch made established security processes poorly suited to the speed and working style of DevOps organizations.
Q: What are Soluble security microproducts?
Soluble's microproducts are security capabilities made from accepted open-source components and delivered into Kubernetes clusters through a SaaS control plane. The pitch names privileged access management, identity and access management, and role-based access control as examples. Scanning and alerting microproducts were described as available, while privileged access management was in beta.
Q: Who is the target user for Soluble?
Soluble primarily targets DevOps and site reliability engineering teams, with developers and the DevSecOps persona also included in its intended audience. Seiersen argued that DevOps and SRE practitioners increasingly own security responsibilities and want tools that are easy to acquire, deploy, and operate without obstructing their central goal of delivering reliable software quickly.
Q: What is Soluble's value proposition for DevOps and SRE teams?
Soluble promises to make security deployment easy and compatible with existing cloud-native practices. DevOps and SRE teams receive a control plane that can manage security across one or 1,000 clusters, including multi-cloud environments. The intended benefit is completing required security work efficiently, using familiar Kubernetes mechanisms, and then returning to broader engineering responsibilities.
Q: How is Soluble different from container security vendors?
Seiersen described Soluble's distinguishing approach as using Kubernetes itself as an ecosystem and delivery mechanism for security software. He contrasted this with vendors that primarily secure containers and may also cover Kubernetes. Soluble instead uses the Kubernetes API and its control plane to distribute security capabilities consistently across clusters, clouds, and organizational environments.
Q: How does Soluble plan to sell its platform?
Soluble initially follows a bottom-up, try-and-buy subscription strategy modeled on how DevOps, SRE, and developer teams acquire software. The pitch emphasizes low-cost, usage-based purchasing without salespeople, budget ceremonies, permissions, or approvals. Seiersen later clarified that the no-salesperson position applied for the moment and that top-down sales could become part of the longer-term approach.
Q: What investor feedback did Soluble receive at RSAC Launch Pad?
The investors recognized microservices and Kubernetes adoption as significant market shifts and supported the bottom-up purchasing model. Their central concern was differentiation. They repeatedly asked Seiersen to identify the specific capabilities that Soluble enables, explain why a practitioner would choose it over alternatives, and reduce the value proposition to two or three unmistakable customer outcomes.
Summary & Key Takeaways
-
Traditional security tools struggled to fit cloud-native development because attempts to insert SAST and DAST into CI/CD were considered too slow. Soluble was created to give security teams software-like velocity by placing security delivery inside the Kubernetes ecosystem and making deployment compatible with DevOps and SRE working practices.
-
Soluble offers a SaaS control plane that delivers security microproducts made from accepted open-source components into Kubernetes clusters. The pitch identifies PAM, IAM, and RBAC as examples. Users can onboard clusters, deploy microproducts, receive telemetry, and automate security operations across multi-cloud and multi-cluster environments.
-
The company targets DevOps and SRE teams through a bottom-up, try-and-buy subscription model with low-cost, usage-based pricing. Investors liked the market created by microservices and Kubernetes adoption but repeatedly pressed Richard Seiersen to state the specific capabilities and differentiation that would make practitioners choose Soluble over competing security products.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator