For neoclouds and GPU cloud operators

Security for Neoclouds

Lava secures neoclouds from external and cross-tenant threats by verifying isolation, and providing an end-to-end context graph.

THE PROBLEM

Speed and Shared Infrastructure Create Security Blind Spots

Rapid buildouts leave security gaps across compute, networks, and storage, while multi-tenancy turns every gap into a potential cross-tenant exposure. Fragmented tools lack the context to show which risks really matter.

WHAT LAVA DOES

Lava Protects Neoclouds

Agentless discovery gives full inventory and posture on day one, across every layer and vendor.

Baseline coverageOne standard per layer, applied to the vendors that actually serve itLast scan · 12m agoLayerBaselineVendors in this layerAppliedBMCCIS BMC hardening404/412HostHost OS baseline1,018/1,024NetworkSwitch mgmt plane92/96FabricPartition enforcement1/2StorageExport policy6/6A layer is scored only against the vendors present in it — no vendor is marked short for a layer it does not serve.

Harden every layer

Apply security baselines across every vendor and layer, and reduce your attack surface before attackers find it.

Management PlaneHandover ResidueHost & ContainerTenant ATenant BFabric PartitioningCriticalShared ServicesNetwork Segmentation

Verify tenant isolation

Confirm that tenants are truly separated, can’t reach each other, and leave nothing behind by checking every layer and shared infrastructure according to industry standards: Forge framework & SemiAnalysis.

Firmware integrityBMCLast scan · 12m agoiDRAC 9 · 412 devicesEvery BMC measured by its own hardware root of trustATTESTATION RECORDbmc-gpu-node-114Last measured12m agoProtocolSPDM 1.2SigningECDSA P-384HashingSHA-384Cert issuerDell iDRAC CAAuthentic · measurement validVERSIONS IN THIS LAYER2.4.1318Current2.3.983Outdated2.2.411CVE-2024-38482One CVE, and it reaches 11 of 412 BMCs.

Firmware integrity and attestation

Firmware attested, with versions and CVEs ranked by real exploitability. You’ll have an up-to-date view of what’s running on every node and appliance, and that it’s what was signed.

Tenant security reportWhat you hand a customer who asks how you keep them apartQ3 202694/100Tenant isolation verified across compute, network and storageNodes attested clean before handover, and after releaseNo cross-tenant path found in this periodShare with customerEvidence attachedRegenerated every month

Win by proving security

Build trust by sharing security reports on tenant isolation, node cleanup, and overall security with your customers. Turn verified integrity into something you can sell.

Scan historyEvery scan, what it found and what it confirmed fixed18 cleared this week12m agoscan 2,4183,558 components swept2 new1 fixedCipher suite 0 enabled318 BMCsCriticalGPU memory still holds data from before handover24 hostsMediumIPMI over LAN enabled412 BMCsFixed6h agoscan 2,4173,558 components swept1 newPrior tenant data may survive on the local scratch RAID11 hostsHigh1d agoscan 2,4163,552 components sweptnothing new

Check configuration continuously and before you deploy

Make sure configurations are continuously checked, and validate new changes before deployment so they don’t expose your infrastructure to new risks.

Attack pathsWhere an attacker is standing, and what the chain reaches from thereLast analysis · 9m agoInternet2 pathsTenant User2 pathsFirewall exposure chains BMC compromise to Weka theft6 stages · 412 BMCs · 2 Weka clustersCriticalStolen instance credentials reach the control plane5 stages · 1 secret · 74 infra hostsCriticalStorage exfiltration via an over-privileged account4 stages · 2 Weka clusters · no audit trailHighManagement fabric takeover via exposed SSH5 stages · 96 switches · 2 fabricsHigh

Find gaps before customers do

Detect misconfigurations and exposures across your data center - from reachable management interfaces to shared resources.

Control your neocloud security