Sysdig today announced plans to acquire Apolicy, a company offering security and compliance for cloud-native applications based in the U.S. and Israel. The deal will allow Sysdig to shift security further left by integrating Apolicy’s infrastructure as code (IaC) technology into its platform to better secure DevOps workflows.

As part of the acquisition deal, which is expected to close in about four weeks, Apolicy’s founders Maor Goldberg, Eran Leib, and Shlomi Wexler will join the Sysdig team. Sysdig did not disclose the acquisition price.

Apolicy has raised $3.5 million in seed funding, mainly from StageOne Ventures.

Founded in 2019, Apolicy offers a cloud-native policy orchestration platform that automates policy management, risk identification, and remediation across the development process at scale. Its IaC security technology is designed to automate cloud and Kubernetes security controls.

According to Sysdig CEO Suresh Vasudevan, the two companies have been in communication for almost a year.

“When we started looking at IaC security, one of the things that really appealed to us about Apolicy is that they took the latest open-source standard, which is called OPA [open policy agent],” he told SDxCentral in an interview. “OPA is evolving into the default standard, and so we basically created our compliance and security policies using OPA to make sure we're able to keep up with standards.” 

Apolicy Offers Auto-Remediation

Sysdig expects the acquisition to strengthen existing cloud and Kubernetes security in its Secure DevOps platform with OPA. Apolicy complements these capabilities by enforcing compliance and governance via policy as code, closing the loop from production to source with auto-remediate drift, and fixing issues faster with risk-based prioritization.

IaC allows security teams to define policies, keep these policies in an independent repository, and then apply the policies across the whole infrastructure. “The big benefit is consistent policy applied with automation, so that you're not depending on individual teams to enforce it,” Vasudevan explained. “Ultimately, it's about developer productivity.”

Secondly, “instead of just telling a developer or an application team: You have these five risks, now go figure out how to change the configuration, it goes all the way towards pointing out what change you need to make in what file that created that risk,” he added.

Sysdig competitor Aqua Security recently made a similar move and acquired tfsec to add IaC security scanning capabilities to its platform.

However, Vasudevan said that Sysdig’s Apolicy buy goes beyond just scanning IaC files. Apolicy can also remediate and fix the detected issues, he explained.  “More and more of a security concern is to reduce the amount of alert noise and ideally just remediate it,” he said. “So, auto-remediation and policy as code are unique.”

Sysdig Aims for IPO

In April, Sysdig announced it raised $188 million funding in its Series F round, which pushed its valuation to $1.19 billion. The company has raised $394 million since it was founded in 2014.

Sysdig grew extremely rapidly in the second half of last year, and Vasudevan attributes this to companies’ increasing container adoption, and the need to secure those containers. He also see an initial public offering (IPO) in Sysdig's future.

“IPO is absolutely sort of what we're aiming for,” he added. “At this point, our entire focus is on growth, and really addressing the customer problem on the container cloud security."