+Deterministic moving-target defense

The brain that decides what to move, and when.

Phorvex evicts attackers from Kubernetes and AI inference workloads in seconds, without breaking what is running. Every decision is mathematically proven, not hand-tuned.

00:00 / 00:24
NO LLM IN THE DECISION PATH PROVEN ON A REAL CLUSTER ZERO FALSE POSITIVES
EVICTION DWELL ~5.5S PREVENTION 100% STATEFUL JOBS PRESERVED 20/20 FALSE POSITIVES 0 ADAPTIVE ATTACKER NOT LEARNABLE DECISION PATH DETERMINISTIC AUDIT TRAIL IMMUTABLE
01Why now

Moving-target defense, finally with a brain.

Conventional MTD rotates on a clock or a rule table. It has no idea what a move costs, what is worth protecting, or what attacker knowledge it actually erases. Phorvex replaces the clock with a decision core that values every possible move and picks the best one under a hard safety budget.

~5.5s
Targeted eviction on zero-days
Blind timers need ~15s. Reactive tools never act.
100%
Prevention on zero-day scenarios
Reactive-only approaches scored 0%.
20/20
Stateful jobs preserved
The only approach that did no harm.
0
False positives
And not learnable by an adaptive attacker.

Measured on a real Kubernetes cluster, n=20, reproducible, controls clean.

02How it works

A decision loop that thinks like an economist.

Four stages, every tick, deterministically. The same inputs always produce the same decision, and every decision is recorded with its reasoning.

01 / DISCOVER

Scan

Phorvex reads your live fleet and derives its physics: reachability, scarcity, slack, exploitability. Measured, never assumed.

02 / ASSESS

Value

It works out what each workload is worth, how exposed it is, and where the attacker sits on the kill-chain.

03 / DECIDE

Select

The sealed, patent-pending core prices every feasible move and selects the optimal set under a hard safety budget.

04 / ACT

Move

Moves run through your unmodified policy controller, with a kill-switch, dry-run, and a complete audit record.

05The proof

Three outcomes, measured on a real cluster.

Head to head against a blind rotation timer and a reactive-only baseline, on zero-day scenarios that emit no alert. Time to evict the attacker, in seconds. Shorter is better.

Phorvexdecides, then moves
~5.5s100% prevention
Blind timerrotates on a clock
~15.2spartial prevention
Reactive onlywaits for an alert
~20.3snever acts, 0%
PhorvexBlind timerReactive only
Eviction dwell on a zero-day~5.5s~15.2s~20.3s, never acts
Prevention on a zero-day100%partial0%
Stateful work preserved20 / 200 / 200 / 20
Learnable by an adaptive attackerNoYesn/a
False positives000

Real Kubernetes cluster, n=20, reproducible, controls clean.

06How we build

Prove by running. Label everything unproven.

Every capability we claim traces to a real run on real infrastructure. Every figure we have not measured on hardware is marked pending. That discipline is the product.

See the decision brain in action.

A technical briefing, the full benchmark methodology, or a design-partner conversation. Your call.