Kivera
Kivera built a preventive cloud security platform, using a Golang cloud proxy and Rego/OPA policy engine, that enforced security guardrails at build and run time across AWS, GCP, Azure, and select SaaS services for regulated enterprises. It was acquired by Cloudflare in 2024.
- Company typePrivate
- Founded2023
- HeadquartersNew York, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Kivera does
Kivera is a cloud security company that built a preventive cloud security platform designed to enforce security controls at build and run time across AWS, Google Cloud, and Azure environments. Its core technology is a modern cloud proxy written in Golang that inspects Cloud APIs, paired with a Rego/OPA-based policy engine that supports every service and parameter across the three major hyperscalers, plus SaaS providers including GitHub, Elastic, OpenAI, Google Workspaces, and Microsoft Graph. The company published a public library of over 300,000 preventive policies and offered five capability modules — Cloud Protection (customizable guardrails), Securing Cloud Data (exfiltration prevention), Simple Compliance (NIST 800-53, CSA CCM, FedRAMP, HIPAA, PCI DSS), Cloud Agility (zero-lag new service support), and Granular Visibility (audit logging and dashboards) — alongside a policy-as-code configuration layer called Kivera Konfig.
The company monetized through SaaS subscriptions to enterprises in regulated industries, sold via a direct enterprise field-sales motion with a demo-request mechanism and supported by AWS, Google Cloud, and Microsoft Partner marketplace channels. Founded with an origin in Sydney, Australia and relocated to New York City following a $3.5 million seed round in August 2023 (with an earlier ~$1.9 million round in October 2020), Kivera operated with 11-50 employees across the United States, United Kingdom, Canada, and Australia. In October 2024, Kivera was acquired by Cloudflare (NYSE: NET) and integrated into Cloudflare's preventive cloud security portfolio.
Kivera firmographics
Firmographics- Name
- Kivera
- Legal name
- Kivera Corporation
- Website
- https://kivera.io
- Company type
- Private
- Founded year
- 2023
- Operating status
- Acquired
- Headcount range
- 11–50 employees
- Short description
- Kivera built a preventive cloud security platform, using a Golang cloud proxy and Rego/OPA policy engine, that enforced security guardrails at build and run time across AWS, GCP, Azure, and select SaaS services for regulated enterprises. It was acquired by Cloudflare in 2024.
- Ownership category
- akta.pro rank
Kivera industry classification
Industry- Product category
- Cloud Security Software
- NAICS
- Computer Systems Design and Related Services (5415), Computer Systems Design and Related Services (54151), Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (5182)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370), Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Cloud Compliance, Audit & Continuous Controls Monitoring (CCM/GRC) (HDABAHAI)
- akta.pro secondary industries
- Cloud Network Security (Microsegmentation, Cloud Firewall, WAF, DDoS) (HDABAHAJ), Cloud Security & Compliance Services (BPAEACAG)
Keywords
Where Kivera is headquartered
LocationHeadquarters
- HQ city
- New York
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
Kivera business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- SaaS Subscription: Cloud-based security platform delivered as a service, providing preventive cloud security controls on a subscription basis. The platform's API-first design and policy-as-code capabilities suggest enterprise licensing models.
Go-to-market motion1 record
Distribution channels4 records
Marketing channels5 records
Kivera product offering
Product offeringCore offering
Kivera provides a preventive cloud security platform built as a modern cloud proxy in Golang that inspects and controls cloud API interactions across AWS, Google Cloud, and Azure. The platform enforces security policies at build and run time using a Rego (OPA) policy engine, supports policy-as-code configuration via Kivera Konfig in YAML or JSON, and delivers capabilities including customizable guardrails, data exfiltration prevention, compliance framework enforcement, granular visibility, and rapid adoption of new cloud services.
Product overview
Kivera is a cloud security company offering the Cloud Security Protection Platform — a unified, API-first preventive cloud security solution. The core platform provides deep visibility and control over cloud configurations through a modern cloud proxy built in Golang, with flexible deployment options (Kubernetes, containers, VMs, Docker, Helm, CloudFormation, Bicep, Terraform) and support for any CI/CD tool and SDK. The platform is complemented by five capability modules: Cloud Protection (customizable guardrails and baseline non-negotiables), Securing Cloud Data (data exfiltration prevention via secure data boundaries), Simple Compliance (framework-based compliance assessment against NIST, CSA CCM, FedRAMP, HIPAA, PCI DSS), Cloud Agility (rapid secure enablement of new cloud services with 100% coverage), and Granular Visibility (actionable insights, dashboards, and audit logging). Policy management is handled through Kivera Konfig, a policy-as-code module supporting YAML and JSON configuration. The company also publishes a public policy reference documentation site covering over 300,000 policies across AWS, Azure, and GCP services. Kivera was acquired by Cloudflare in 2024.
Differentiator
Problem solved
Functional benefit
Products and services
- Cloud Security Protection Platform
Quantifiable outcome
- 100% coverage of every cloud service down to individual parameters
- +2 more outcomes
Companies that use Kivera
Customer profileSegments1 record
Ideal customer profiles1 record
Kivera technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration9 records
Feature10 records
Kivera partnerships and signals
Strategic signalPartnerships
Five partnerships are on record, tiered core.
- CloudflarecoreAcquired by Cloudflare in 2024 as part of Cloudflare's strategy to deliver simple preventive cloud security. The acquisition integrates Kivera's technology into Cloudflare's security portfolio, with Kivera now part of Cloudflare with announcement on cloudflare.com.
- AWScoreAWS Partner and Qualified Software certification. Kivera's policy engine supports all AWS services and parameters with zero-lag coverage for new releases. Deployment via CloudFormation, Terraform, and other IaC tools supported.
- Google CloudcoreGoogle Cloud Partner status with full support for all GCP services and parameters. Integration with Google Workspaces and other GCP services.
- Microsoft AzurecoreMicrosoft Partner certification with comprehensive Azure service support. Integration with Microsoft Graph and Azure-native deployment options.
- KubernetescoreContainer orchestration platform supported for Kivera deployment via Helm, Docker, and Kubernetes-native configurations.
Scale indicators3 records
Recent moves7 records
Expansion highlights6 records
Kivera competitors and assessment
Company assessmentDirect peers
- Wiz: Wiz is a leading CNAPP that provides agentless cloud security posture management, vulnerability scanning, and identity analysis across AWS, Azure, and GCP — directly comparable to Kivera's preventive cloud controls across the same hyperscaler estate.
- Lacework: Lacework delivers cloud security posture management and workload protection across AWS, Azure, and GCP, with compliance framework coverage and policy-driven controls similar to Kivera's preventive approach.
- Orca Security: Orca Security provides agentless cloud security and compliance posture management with broad multi-cloud coverage, competing head-to-head with Kivera in CSPM and compliance-driven preventive controls.
- Aqua Security: Aqua Security provides cloud-native application protection including CSPM and container/Kubernetes security across AWS, Azure, and GCP — overlapping with Kivera's compliance and policy enforcement scope, particularly in regulated environments.
- Sysdig: Sysdig offers cloud security posture management and runtime threat detection with strong Kubernetes and container focus; comparable to Kivera in policy-driven preventive controls and compliance framework enforcement.
Broad incumbents
- Palo Alto Networks Prisma Cloud: Prisma Cloud is a broad cloud security platform offering CSPM, CIEM, CWPP, and compliance capabilities across AWS, Azure, and GCP, overlapping significantly with Kivera's preventive policy enforcement and compliance framework support.
- Microsoft Defender for Cloud: Defender for Cloud is Microsoft's native CSPM/CWPP offering tightly integrated with Azure and increasingly multi-cloud; it competes with Kivera's preventive controls and compliance frameworks via a bundled, hyperscaler-native go-to-market.
- AWS Security Hub: AWS Security Hub is AWS's native CSPM-style aggregator with preventive Config rules and compliance checks; it competes with Kivera's AWS-focused preventive controls via a bundled, hyperscaler-native offering.
Emerging players
- Sonrai Security: Sonrai Security delivers cloud security posture and identity governance for AWS, Azure, and GCP — overlapping with Kivera's preventive controls and identity-aware policy enforcement in mid-market and enterprise segments.
- Tenable Cloud Security (formerly Accurics): Tenable Cloud Security provides CSPM and infrastructure-as-code security with policy-as-code enforcement, directly comparable to Kivera's preventive controls and Rego-based policy engine approach.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks5 records
Key highlights6 records
Customer concentration
Kivera social profiles
Digital presenceKivera financial estimates
Financial estimateRevenue estimate
Valuation estimate
Kivera leadership team
Management profileNumber of profiles
Profiles6 records
Kivera funding detail
Funding detailFunding overview
Funding rounds2 records
Investors2 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Kivera M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Kivera
What does Kivera do?
Kivera provides a preventive cloud security platform built as a modern cloud proxy in Golang that inspects and controls cloud API interactions across AWS, Google Cloud, and Azure. The platform enforces security policies at build and run time using a Rego (OPA) policy engine, supports policy-as-code configuration via Kivera Konfig in YAML or JSON, and delivers capabilities including customizable guardrails, data exfiltration prevention, compliance framework enforcement, granular visibility, and rapid adoption of new cloud services.
Is Kivera a public or private company?
Kivera is a private company. It is classified as corporate owned and is currently acquired.
When was Kivera founded?
Kivera was founded in 2023. It employs 11 to 50 people.
Where is Kivera based?
Kivera is headquartered in New York, United States, in the North America region.
How does Kivera make money?
One revenue line is on record: saaS Subscription.
Who are Kivera's main competitors?
Direct peers on record are Wiz, Lacework, Orca Security, Aqua Security and Sysdig. Broad incumbents are Palo Alto Networks Prisma Cloud, Microsoft Defender for Cloud and AWS Security Hub. Emerging players are Sonrai Security and Tenable Cloud Security (formerly Accurics).
Does Kivera have an API?
Yes. Kivera is an API-first platform enabling programmatic configuration updates. Users can manage Kivera policy as code in YAML or JSON through Kivera Konfig. The policy engine supports every service and parameter in AWS, Google Cloud, and Azure, as well as SaaS providers including GitHub, Elastic, OpenAI, Google Workspaces, and Microsoft Graph.
What industry is Kivera in?
Kivera's product category is Cloud Security Software. Its primary akta.pro industry code is HDABAHAI, Cloud Compliance, Audit & Continuous Controls Monitoring (CCM/GRC), with a secondary code of HDABAHAJ, Cloud Network Security (Microsegmentation, Cloud Firewall, WAF, DDoS). Its NAICS code is 5415 and its SIC code is 7370.