---
title: "Kubernetes Security: CVEs in Running Images, Access and Control | Lens — Lens"
description: "Security Center scans every image your clusters run for CVEs with Trivy, Teamwork shares cluster access with no inbound port, and Hardened Lens controls features with SSO, SCIM and audit logs."
url: https://lenshq.io/use-cases/security-center/
---

Security Center

# Keep your organization's Kubernetes secure.

Lens Security Center visualizes all vulnerabilities in a single pane.

[Start your free trial](https://lenshq.io/download/)

![Boundary diagram. Engineers, SREs and new hires reach a Lens Teamwork space through SSO with seats assigned by email, and space roles start read-only. A dashed vertical line marks the cluster firewall, crossed by exactly one arrow: the cluster's own agent dialling outward over TLS, so no inbound port is opened. Inside the cluster, requests arrive through native Kubernetes impersonation as the real user. A Hardened Lens band spans the top, marked Enterprise: feature control that turns GitOps, Ask AI, the MCP Server, the editor and Security Center on or off for every install](https://lenshq.io/images/use-cases/cluster-connect.svg)

How Lens resolves it

## Access, exposure, and control in one place

Security Center scans the clusters your team shares, and the same console that assigns their seats decides which features exist at all.

![The Lens Security Center Images view: donut charts for scan status, results, vulnerabilities and exposed secrets, above a table listing each cluster image with its platform, how many pods run it, its vulnerability counts by severity and its scan status](https://lenshq.io/blog/best-kubernetes-security-tools/img-13.webp)

### Shared access, unexposed cluster

The agent dials out over TLS. No inbound port, no VPN, and your own RBAC still decides.

![Trivy](https://lenshq.io/images/brands/trivy.svg)

### Know what is running with a CVE

Images, Resources and Roles, scanned by the Trivy Operator. Exports to CSV.

![Microsoft Entra ID](https://lenshq.io/images/brands/microsoft.svg)

![Okta](https://lenshq.io/images/brands/okta.svg)

### Feature control, on Enterprise

SSO and SCIM from your IdP. Hardened Lens switches features on or off org-wide.

Vulnerability scanning across the clusters you share

## Which running image carries a critical CVE

A registry scan tells you about images. Security Center tells you which ones are running right now, in which namespace, and in how many pods.

![Lens Security Center with an image selected: donut charts for vulnerabilities and exposed secrets, the scan result source reported as Trivy, and a table of findings listing CVE IDs with their severity, affected package, installed version and the version that fixes them](https://lenshq.io/images/use-cases/security-center-cves.webp)

![Trivy](https://lenshq.io/images/brands/trivy.svg)

### Every image the cluster runs

Platform, pods per image, severity counts and exposed secrets, scanned by the Trivy Operator inside your cluster.

### Findings follow the pod

The same results appear on the pod and on the image details, so a severity count leads to the workload running it.

### Misconfiguration and over-broad roles

The Resources and Roles views cover misconfigured objects and permissions that reach further than they should.

Access control

## Who gets in, what they can open

Lens Business ID holds the user list and the subscription seats. Feature Management decides which Lens features exist on every install in your organization.

### Add, promote, revoke

Invite users by email as Member or Administrator, assign or un-assign a seat, and promote an admin. Automatic Seat Assignment gives new joiners a seat.

![Microsoft Entra ID](https://lenshq.io/images/brands/microsoft.svg)

![Okta](https://lenshq.io/images/brands/okta.svg)

### Or hand it to your IdP

With SCIM, provisioning and de-provisioning happen in your IdP console and synchronize to Lens Business ID. Manual invites are switched off.

### Restrict features org-wide

Turn Lens Teamwork, Security Center, Ask AI, Live Support Chat, Air-Gapped Mode and Offline Activation on or off for every user at once.

For the administrator

## Identity from your IdP, exposure and features under your control

SAML + OIDC

SSO with Microsoft Entra ID, Okta or JumpCloud

[Lens documentation, Authentication](https://docs.lenshq.io/k8slens/lens-id/lens-business-id/integration-guides/)

Three views

Images, Resources and Roles, each exporting to CSV

[Lens documentation, Security Center](https://docs.lenshq.io/k8slens/security-center/)

Six

Feature control by admin

[Lens documentation, Hardened Lens](https://docs.lenshq.io/k8slens/lens-id/lens-business-id/security/feature-management/)

Free. No payment details needed.

## Evaluate every premium feature in the Lens 14-day trial

Every premium feature, unlocked for 14 days.

![Amazon Web Services](https://lenshq.io/images/brands/aws.svg)

### AWS EKS

Discover EKS clusters across your AWS accounts.

[Read the docs](https://docs.lenshq.io/k8slens/getting-started/add-clusters/add-aws-eks/)

![Microsoft Azure](https://lenshq.io/images/brands/azure.svg)

### Azure AKS

Discover AKS clusters across your Azure subscriptions.

[Read the docs](https://docs.lenshq.io/k8slens/getting-started/add-clusters/add-azure-aks/)

### Ask AI

Connect your own AI CLI to any Kubernetes object, with live cluster context.

[Read the docs](https://docs.lenshq.io/k8slens/ask-ai/)

### Lens MCP Server

Reach every cluster Lens knows from Claude, Codex or any MCP client.

[Read the docs](https://docs.lenshq.io/k8slens/mcp-server/)

![Argo CD](https://lenshq.io/images/brands/argo.svg)

### Argo CD

Sync and health for every Application, next to its pods.

[Read the docs](https://docs.lenshq.io/k8slens/argo-cd/)

![Flux](https://lenshq.io/images/brands/flux.svg)

### Flux CD

Reconciliation, drift and failures across every Flux resource.

[Read the docs](https://docs.lenshq.io/k8slens/flux-cd/)

### Security Center

Scan the images your cluster runs for CVEs and exposed secrets.

[Read the docs](https://docs.lenshq.io/k8slens/security-center/)

### Hotbar

Quick access to the clusters you open most.

[Read the docs](https://docs.lenshq.io/k8slens/using-lens/hotbar/)

### Advanced editor

Edit a live resource in diff mode, and revert in one click.

[Read the docs](https://docs.lenshq.io/k8slens/using-lens/advanced-editor/)

Download Lens Desktop and create your Lens ID from the app. Your 14 days start there. When the trial ends, your configuration is kept and the features lock until you upgrade.

[Contact Sales](https://lenshq.io/contact/) [Start your free trial](https://lenshq.io/download/)
