Q Advisors' Cloud Native/DevOps Private Vendors Matrix By Dmitry Netis & Jordan Rupar / 4.7.2020 Q Advisors assembled over 100 startups in the cloud native Kubernetes ecosystems, peddling various offerings across the following six distinct cloud native / Kubernetes market sub-segments:

Continuous Integration / Development Tools Testing & Monitoring (“Dev”) (“Mon”) (“CI/CD”)

Product Deployment, Service Mesh Security Management & Orchestration (“Run”) (“Sec”) (“Ops”)

Sector Company Description

Buildkite is a platform for running fast, secure, and scalable pipelines. Buildkite is a CI and build CI/CD automation tool that combines build infrastructure with the convenience of a managed, centralized web UI.

CircleCI provides online automated testing and continuous CI/CD integration tools for developers worldwide.

CloudBees developed Jenkins, a tool for continuous delivery both on-premises and in the cloud. In 2018, CloudBees acquired CI/CD Codeship, a provider of CI/CD as a cloud-based service, a move that broadened its portfolio for organizations of all sizes.

Codefresh provides powerful, fast, and simple CI/CD pipelines. Each CI/CD step in a Codefresh CI/CD pipeline is its own container, enabling speed, modularity, and flexibility.

GitLab is a continuous integration and deployment tool for the entire DevOps lifecycle. The company also offers Git repository and CI/CD GitLab Serverless that enables enterprises to run serverless workloads on any cloud using Google’s Knative.

Harness uses machine learning to simplify the process of delivering code from artifact into production. Its platform includes various CI/CD features, such as pipeline builder, workflow wizard, continuous verification, automated rollback, secrets management, audit trails, real-time delivery analytics, and GitOps.

1 Q Advisors Cloud Native Vendor Matrix

Sector Company Description

Puppet is an infrastructure automation and delivery platform that CI/CD spans across hybrid environments to automate infrastructure and application workflows and ongoing management.

Travis CI is a continuous integration platform that helps developers CI/CD build, test and deploy open source and private projects.

Agile Stacks is a DevOps automation platform for cloud infrastructure and machine learning. The Agile Stacks Machine Dev Learning Stack allows teams to automate the entire data science workflow, from data ingestion and preparation to deployment and ongoing operations.

Canonical offers Ubuntu, a standard secure enterprise Linux for servers, desktops, cloud and developers. Ubuntu is the reference Dev platform for Kubernetes on all major public clouds, including Google’s GKE, Microsoft’s AKS and Amazon’s EKS CAAS offerings.

Cloud 66 offers a full DevOps toolchain for containerized apps in production, automates much of the heavy-lifting for Devs through Dev specialized Ops tools. The end-to-end infrastructure management platform currently runs 4,000 customer workloads on Kubernetes and manages 2,500 lines of configuration.

A hybrid and multicloud database built by Apache Cassandra Dev experts, Datastax offers distributed data management products and cloud services.

2 Q Advisors Cloud Native Vendor Matrix

Sector Company Description

Frog offers DevOps automation, providing universal artifact Dev management for DevOps acceleration.

Kong, previously known as Kong Community (CE), is an API platform Dev for microservices.

Replex is a governance and management platform designed for working in Kubernetes environments. The tool solves the challenges Dev surrounding Kubernetes’ dynamic nature by unifying cost and governance management for deployments in the cloud.

Sonatype is an integrated open source governance platform that Dev helps more than 1,000 organizations and 10 million software developers accelerate innovation and improve application security.

XeviaLabs’ XL Platform offers automation products for deployment, environment provisioning, test management, and enterprise release Dev management. XebiaLabs’ DevOps Platform is an end-to-end DevOps toolchain orchestration and reporting platform.

xMatters offers an operational visibility and IT alerting platform providing toolchain integrations with hundreds of IT management, Dev security, and DevOps apps. The xMatters platform allows organizations to automate key processes and streamline workflows.

Chronosphere provides an open source metric data platform called M3, created by the founders of Chronosphere while at Uber. The Mon data platform, proven at petabyte scale in production, stores over tens of billions of metric time series and ingests and serves billions of data points per second.

3 Q Advisors Cloud Native Vendor Matrix

Sector Company Description

Cribl, a log data and metrics tool, gives full access to the data in Mon motion to lookup, enrich, redact, encrypt, transform, or sample data before indexing.

Datatron is a machine learning / AI tool that provides automation of Mon standardized deployment, monitoring, governance, and validation of models to be developed in any environment.

Built for security and IT operations teams, Devo’s data analytics Mon platform addresses both the explosion in volume of machine data and the new demands of algorithms and automation.

The ELK stack comprises Fluentd, Elasticsearch, and Kibana. These Mon tools fully integrate and represent a reliable solution used for Kubernetes monitoring and log aggregation.

Epsagon offers automated tracing for cloud microservice, whether containers and serverless, or in cloud-based environments. It's the Mon only agentless solution that provides distributed, automated tracing of every request in a transaction including payload visibility.

Grafana is an open source analytics and monitoring solution for Mon databases, enabling users to take control of their unified monitoring and avoid vendor lock in and the spiraling costs of closed solutions.

Graphite is an enterprise-ready monitoring tool that runs equally well on cheap hardware or cloud infrastructure. Graphite tracks the Mon performance of websites, applications, business services, and networked servers.

4 Q Advisors Cloud Native Vendor Matrix

Sector Company Description

Humio provides log management with streaming observability through a purpose-built platform to enable fast, scalable and Mon efficient log data management. Humio is an alternative solution to Splunk, Elasticsearch, Sumo Logic, and Datadog.

LogicMonitor is a SaaS-based performance monitoring platform that empowers DevOps teams and web-commerce companies to Mon monitor the availability and performance of their critical IT infrastructure.

Nagios provides monitoring of all mission-critical infrastructure Mon components, including applications, services, operating systems, network protocols, systems metrics, and network infrastructure.

Scalyr is a log management and operational visibility platform for Mon high-speed log management and server monitoring.

ScienceLogic is an AIOps platform that sees everything across cloud and distributed architectures, contextualizes data through Mon relationship mapping, and acts on this insight through integration and automation.

Sensu is a full-stack monitoring platform for dynamic operating environments. It offers Telemetry and service health checking Mon solutions for multi-cloud monitoring at scale, enabling deep visibility into servers, containers, services, applications, functions, and connected devices across public or private cloud.

Sumo Logic develops and provides cloud log management and metrics monitoring solutions including visibility into nodes within Mon Kubernetes clusters, as well as application logs. Solutions include monitoring and troubleshooting container health, replication, load balancing, pod state and hardware resource allocation.

5 Q Advisors Cloud Native Vendor Matrix

Sector Company Description

Sysdig offers container production by solving complex issues of monitoring and managing the performance of cloud-based Mon application delivery infrastructures. It offers cloud monitoring at scale, with full Prometheus compatibility.

Weaveworks offers weave scope, a zero-configuration monitoring Mon tool that generates a map of processes, containers, and hosts in a Kubernetes cluster to help monitor Docker containers in real time.

Zenoss develops intelligent application and service monitoring software and builds comprehensive real-time models of hybrid IT Mon environments, providing unparalleled holistic health and performance insights.

Alluxio offers data orchestration for analytics and machine learning in the cloud. Alluxio moves data closer to big data and machine Ops learning compute frameworks in any cloud across clusters, regions, clouds and countries, providing memory-speed data access to files and objects.

Arrikto provides decentralized storage for the cloud native world. It allows containers to run over super-fast local storage, while Ops providing instant clones and snapshots, readily available to any other node, which can be shared over a decentralized network.

Banzai Cloud is an operating system for containers and cloud that Ops allows enterprises to develop, deploy and scale container-based applications.

Chef offers teams that ability to secure, configure and deploy Ops containers with applications in a cloud-native or bare metal environment.

6 Q Advisors Cloud Native Vendor Matrix

Sector Company Description

Cockroach Labs is a distributed SQL for cloud native environments that enables developers to build applications that survive Ops datacenter-scale outages. The solution scales horizontally; survives disk, machine, rack, and datacenter failures with minimal latency disruption and no manual intervention.

Datrium is a disaster recovery and disaggregated HCI for hybrid cloud, private cloud, and on-premises data centers. Datrium’s Ops platform, Automatrix, natively converges DR, backup, primary storage, mobility, and encryption in a single platform.

DeployHub provides a microservices configuration management Ops solution through a microservices hub that catalogs, versions, tracks and deploys microservices to the applications that consume them.

Diamanti is a purpose-built, enterprise-grade Kubernetes platform, spanning on-premises and public cloud environments. It is a highly Ops available and scalable database providing turnkey solution for deploying modern, cloud native containerized databases and associated applications for DBaaS environments.

Drivesale is an elastic bare metal cloud that turns industry standard Ops compute nodes, GPU nodes and storage into elastic resource instances.

Fossa is an open source management tool designed to support development and legal teams alike. Fossa provides component Ops intelligence, continuous compliance, and cross-team collaboration solutions.

Gravitational offers open-core products Teleport and Gravity for running cloud-native applications securely. Gravitational bridges the Ops gap between software vendors and enterprise customers. It helps deploy, remotely manage and run SaaS on private clouds and allows applications delivered as a service on any infrastructure.

7 Q Advisors Cloud Native Vendor Matrix

Sector Company Description

HashiCorp provides open-source tools that provision, secure, run and connect cloud-computing infrastructure including: Terraform, a cloud infrastructure automation tool; Vault, a platform for managing Secrets and protecting data; Consul, a multi-cloud service Ops networking platform to connect and secure services across any runtime platform and public or private cloud; and Nomad, a flexible workload orchestrator that enables organizations to deploy applications on any infrastructure at scale.

Kasten provides cloud-native data management for Kubernetes, Ops offering data protection and portability across hybrid clouds and container clusters.

Kontena is a management dashboard for Kubernetes that specializes in creating fully integrated solutions for software Ops development teams to deploy, run, monitor and operate containers on the cloud. The underlying Kontena Platform technology is open source and available under Apache 2.0 license.

Kublr is an enterprise-grade Kubernetes management platform that Ops automates the deployment and management of production-ready, secured Kubernetes clusters and environments.

Mirantis delivers Kubernetes on-premises for enterprise-grade container orchestration. Mirantis offers Murano, a tool that enables Ops IT administrators to publish cloud-ready applications in an online catalog; OpenStack Drivers and Plugins; turnkey OpenStack rack- based appliances; and Containers-as-a-Service.

NuoDB is a distributed SQL database that offers peer-to-peer Ops architecture to ensure that database services can be natively distributed across multiple nodes, data centers, and clouds.

Platform9 is a fully managed hybrid cloud platform for Kubernetes and OpenStack that enables enterprises to manage VMs, containers Ops and serverless functions on any infrastructure- on-premises, in public clouds, or at the edge.

8 Q Advisors Cloud Native Vendor Matrix

Sector Company Description

Rafay provides multi-cluster management and application operations at scale. The platform enables DevOps and site reliability Ops engineering teams to govern, manage and monitor multiple Kubernetes clusters and distros, and operating applications running on-premise, in the cloud or at the edge.

Rancher Labs develops an open source container management software platform. The platform allows users to manage various Ops aspects of running containers in development and production environments.

Stackery is a tool to deploy and operate the entire stack. It is used to design stack by dragging in components, such as Docker Ops clusters, virtual networks, and load balancers; and connect and configure these services for an error-proof deployment.

StorageOS provides cloud native storage that enables clients to run Ops containerized databases, CI/CD workloads, and enterprise public cloud.

Turbonomic offers Kubernetes-as-a-service (KaaS) management capabilities that include Amazon Elastic Container Service for Ops Kubernetes (EKS), Microsoft Azure Kubernetes Service (AKS), Google Kubernetes Engine (GKE), and Pivotal Container Service (PKS).

Tyk is an open source API and service management platform with Ops an API Gateway, API Analytics, and Dev Portal.

Upbound manages workflows for multiple cloud services from a Ops single interface in GitLab. It provides multi-cloud flexibility, enabling applications to move freely.

Buoyant provides a service mesh tool that helps deploy and run Run Linkerd, the fully open source, ultralight service mesh.

9 Q Advisors Cloud Native Vendor Matrix

Sector Company Description

Istio is an open platform to connect, manage, and secure Run microservices.

Moogsoft develops and provides AIOps solutions to help automate Run service assurance, avoid outages, and accelerate digital transformation initiatives.

Opsani provides continuous optimization AI and machine learning- driven automation to enable autonomous operations for DevOps Run teams. The company was founded as Datagrid Systems and became Opsani in 2017.

Planetscale is a NewSQL, cloud native database-as-a-service (DbaaS) for mission critical applications. It is built on Vitess Run distribution, an open source massively scalable database and MySQL.

Portworx is a storage platform for Kubernetes that provides production grade data availability, data security, backup, DR, and Run automation of persistent storage for container-based applications running on-premise and across clouds.

Reduxio, formerly a developer of hybrid flash storage arrays, provides a cloud data platform for Kubernetes that pairs software- Run defined container-native storage and data management with data mobility to enable customers to build a single data cloud for their applications across all their infrastructure, anywhere.

Solo.io provides a next-gen API gateway and service mesh management solution. Solo.io’s suite of tools allows enterprises to Run connect the old world of stable, well-tested applications that are hard to change with the newer, flexible world of microservices, serverless and service mesh.

Tetrate provides service mesh for any workload on any environment. Tetrate's service mesh platform allows DevOps, Run security, and network administrators to manage the complexity of modern hybrid cloud application infrastructure.

10 Q Advisors Cloud Native Vendor Matrix Sector Company Description

Alcide is a Kubernetes-native, AI-driven security platform for Sec configuration risks, visibility, runtime security events, and a single policy framework across Kubernetes clusters.

Aporeto provides security for containers, microservices, cloud and legacy applications based on workload identity, encryption, and Sec distributed policies. Aporeto policies function independently of the underlying infrastructure and across hybrid environments that include Kubernetes and non-Kubernetes deployments.

Aqua offers cloud native security and container protection for cloud Sec native apps & infrastructure including containers, serverless and VMs, across all platforms and clouds.

CloudPassage provides cloud security visibility, offering an automation platform, delivered via software-as-a-service, that Sec improves security for private, public, and hybrid cloud computing environments.

Conjur offers directory services and cloud native authorization Sec platform for developers and security teams to monitor, adopt, manage, secure, and audit modern infrastructure environments.

DivvyCloud offers container security that protects cloud and Sec container environments from misconfigurations, policy violations, threats and other security challenges.

Gremlin is a platform that provides the framework to safely, securely, and easily simulate real outages with an ever-growing Sec library of attacks. The platform detects resource exhaustion, bad behavior, and unreliable network.

Lacework provides cloud workload protection, offering security Sec visibility, compliance & audit control, and automatic threat defense.

11 Q Advisors Cloud Native Vendor Matrix

Sector Company Description

NeuVector is a container security platform that delivers security Sec from DevOps vulnerability protection to complete run-time security and container firewall.

Nuweba provides serverless application security. It is an ultra-fast and highly-secure serverless (FaaS) platform enabling organizations Sec to use serverless for core functionalities, mission-critical tasks, and user-facing applications.

Odo provides secure and scalable zero-trust network access. Odo’s architecture moves access control decisions from the network Sec perimeter to individual devices, users, and applications, where business-driven security policies and access controls are best enforced.

Portshift is a data protection platform that provides an identity- Sec based cloud workload protection platform that secures applications from CI/CD to runtime.

Protego offers cloud workload protection (CWPP) and security Sec posture management (CSPM), delivering continuous serverless security. Checkpoint acquired Protego Labs in December 2019.

ShieldX is the first containerized, microservices platform for Sec agentless, multi-cloud security.

StackRox is a Kubernetes-native container security platform that Sec helps cloud-native companies, Global 2000 enterprises, and government agencies protect their Kubernetes applications.

Styra, a cloud-native authorization company, supports open-source community centered around Open Policy Agent (OPA) enhancing Sec turnkey enterprise security and compliance solutions for Kubernetes environments.

12 Q Advisors Cloud Native Vendor Matrix

Sector Company Description

Snyk is an open source code security software that finds and fixes Sec known vulnerabilities in open source, built by the developers and security researchers in the open source space.

Tigera is an enterprise network security platform for Kubernetes Sec offering open source software that provides networking and network policy for Kubernetes.

Trilio provides data protection and app resiliency. TrilioVault for Kubernetes natively integrates with Red Hat OpenShift to ease Sec backing up and restoring workloads orchestrated across Kubernetes clusters.

Twistlock continually monitors applications deployed on Kubernetes for vulnerability and compliance issues, including the underlying host as well as containers and images. It provides both layer 3 Sec micro-segmentation as well as a layer 7 firewall that can protect frontend microservices from common attacks. Twistlock was acquired by Palo Alto in July 2019 for $410 million.

Virsec provides runtime application memory protection using patented, non-signature-based technology. Virsec detects and Sec remediates previously “indefensible” advanced memory-based attacks on critical applications and server endpoints.

Wallarm provides an AI-powered app security platform, which Sec includes adaptive WAF, vulnerability scanner, incident verification and dev time testing modules.

WhiteSource offers open source security for containers, a cloud- based platform for managing the OSS lifecycle and an open source Sec security developer tool for GitHub and Microsoft Azure DevOps users.

13