# Aqua Security

**Canonical:** https://apis.io/providers/aqua-security/  
**Website:** https://www.aquasec.com/  
**APIs profiled:** 8

Aqua Security provides cloud-native security for the full application lifecycle, protecting containers, serverless functions, and cloud workloads with vulnerability scanning, runtime protection, and compliance enforcement.

## Kin Score — 36.3 / 100 (thin)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 36.3).

| Facet | Score |
|---|---|
| Discoverability | 64.8 |
| Contract Quality | 27.0 |
| Governance | 25.0 |
| Contract Governance | 25.0 |
| Operational Transparency | 50.0 |
| Developer Ergonomics | 31.0 |
| Commercial Clarity | 36.8 |
| Access Clarity | 36.8 |

## Agent readiness — 46.0 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | documented |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | verified |
| OpenAPI Examples | verified |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Enterprise · Self-serve signup — onboarding: self-serve, pricing: enterprise, trial: no (confidence: high).

## APIs (8)

- **Trivy** — Trivy is a comprehensive open source security scanner for containers, Kubernetes, code repositories, clouds, and more — finding vulnerabilities, misconfigurations, secrets, and ...
- **Tracee** — Tracee is a runtime security and forensics tool for Linux that uses eBPF technology to trace system events and detect suspicious behavioral patterns.
- **Aqua Security Authentication API** — User authentication and token management
- **Aqua Security Containers API** — Running container monitoring and enforcement
- **Aqua Security Images API** — Container image scanning and vulnerability management
- **Aqua Security Policies API** — Security policy management
- **Aqua Security Registries API** — Container registry configuration
- **Aqua Security Users API** — User and role management

## MCP servers (1)

- **MCP Server**

## Agentic access (1)

- **Aqua Security Agentic Access** — 10 operations · 4 acting

## Security (3)

- **Aqua Security Authentication** — http · 1 scheme
- **Aqua Security Domain Security** — TLSv1.3 · HSTS · DMARC
- **Aqua Security Vulnerability Disclosure** — Bugcrowd

## Plans (1)

- **Aqua Security Plans Pricing**

## Use cases (6)

- **Container Security** — Secure Docker and OCI containers throughout the build-to-runtime lifecycle.
- **Kubernetes Security** — Enforce security policies, runtime protection, and compliance for Kubernetes clusters.
- **Serverless Security** — Protect AWS Lambda, Azure Functions, and Google Cloud Functions from vulnerabilities and runtime attacks.
- **DevSecOps** — Integrate security scanning into CI/CD pipelines to shift security left and prevent vulnerabilities from reaching production.
- **Cloud Workload Protection** — Protect VMs and cloud workloads across multi-cloud environments from threats and misconfigurations.
- **SBOM Generation** — Generate Software Bill of Materials (SBOM) for container images and code repositories to understand component risk.

## Tags

Cloud-Native, Containers, Kubernetes, Runtime Protection, Security, Vulnerability Scanning

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/aqua-security/). Scores are computed from the provider's own public artifacts under a published rubric.
