Security Center

Keep your organization's Kubernetes secure.

Lens Security Center visualizes all vulnerabilities in a single pane.

Boundary diagram. Engineers, SREs and new hires reach a Lens Teamwork space through SSO with seats assigned by email, and space roles start read-only. A dashed vertical line marks the cluster firewall, crossed by exactly one arrow: the cluster's own agent dialling outward over TLS, so no inbound port is opened. Inside the cluster, requests arrive through native Kubernetes impersonation as the real user. A Hardened Lens band spans the top, marked Enterprise: feature control that turns GitOps, Ask AI, the MCP Server, the editor and Security Center on or off for every install

How Lens resolves it

Access, exposure, and control in one place

Security Center scans the clusters your team shares, and the same console that assigns their seats decides which features exist at all.

The Lens Security Center Images view: donut charts for scan status, results, vulnerabilities and exposed secrets, above a table listing each cluster image with its platform, how many pods run it, its vulnerability counts by severity and its scan status

Shared access, unexposed cluster

The agent dials out over TLS. No inbound port, no VPN, and your own RBAC still decides.

Trivy

Know what is running with a CVE

Images, Resources and Roles, scanned by the Trivy Operator. Exports to CSV.

Microsoft Entra IDOkta

Feature control, on Enterprise

SSO and SCIM from your IdP. Hardened Lens switches features on or off org-wide.

Vulnerability scanning across the clusters you share

Which running image carries a critical CVE

A registry scan tells you about images. Security Center tells you which ones are running right now, in which namespace, and in how many pods.

Lens Security Center with an image selected: donut charts for vulnerabilities and exposed secrets, the scan result source reported as Trivy, and a table of findings listing CVE IDs with their severity, affected package, installed version and the version that fixes them
Trivy

Every image the cluster runs

Platform, pods per image, severity counts and exposed secrets, scanned by the Trivy Operator inside your cluster.

Findings follow the pod

The same results appear on the pod and on the image details, so a severity count leads to the workload running it.

Misconfiguration and over-broad roles

The Resources and Roles views cover misconfigured objects and permissions that reach further than they should.

Access control

Who gets in, what they can open

Lens Business ID holds the user list and the subscription seats. Feature Management decides which Lens features exist on every install in your organization.

Add, promote, revoke

Invite users by email as Member or Administrator, assign or un-assign a seat, and promote an admin. Automatic Seat Assignment gives new joiners a seat.

Microsoft Entra IDOkta

Or hand it to your IdP

With SCIM, provisioning and de-provisioning happen in your IdP console and synchronize to Lens Business ID. Manual invites are switched off.

Restrict features org-wide

Turn Lens Teamwork, Security Center, Ask AI, Live Support Chat, Air-Gapped Mode and Offline Activation on or off for every user at once.

For the administrator

Identity from your IdP, exposure and features under your control

SAML + OIDC
SSO with Microsoft Entra ID, Okta or JumpCloud

Lens documentation, Authentication

Three views
Images, Resources and Roles, each exporting to CSV

Lens documentation, Security Center

Six
Feature control by admin

Lens documentation, Hardened Lens

Free. No payment details needed.

Evaluate every premium feature in the Lens 14-day trial

Every premium feature, unlocked for 14 days.

Amazon Web Services

AWS EKS

Discover EKS clusters across your AWS accounts.

Read the docs

Microsoft Azure

Azure AKS

Discover AKS clusters across your Azure subscriptions.

Read the docs

Ask AI

Connect your own AI CLI to any Kubernetes object, with live cluster context.

Read the docs

Lens MCP Server

Reach every cluster Lens knows from Claude, Codex or any MCP client.

Read the docs

Argo CD

Argo CD

Sync and health for every Application, next to its pods.

Read the docs

Flux

Flux CD

Reconciliation, drift and failures across every Flux resource.

Read the docs

Security Center

Scan the images your cluster runs for CVEs and exposed secrets.

Read the docs

Hotbar

Quick access to the clusters you open most.

Read the docs

Advanced editor

Edit a live resource in diff mode, and revert in one click.

Read the docs

Download Lens Desktop and create your Lens ID from the app. Your 14 days start there. When the trial ends, your configuration is kept and the features lock until you upgrade.