Project Information
About Smartvid
Smartvid.io uses machine learning to improve safety, productivity, and quality in the AEC industry. Its SmartTag Engine analyzes video and photo content, tags it, and syncs it with BIM 360™—saving time and reducing risk.
The Challenge
From Managing Vulnerabilities to Managing Risks
Upon integrating with xantra, smartvid further improved its ability to manage vulnerabilities by focusing on exploitable runtime risks. Jaffe emphasizes “xantra provides awareness of package vulnerabilities that are exploitable in a much more useful way than a lot of other products do. It narrows down exploits to what can actually be exploitable.” Identifying and prioritizing exploitable—and fixable—vulnerabilities helps smartvid avoid bombardment by irrelevant alerts. This precision enhances security effectiveness, and strengthens collaboration with the development team, by presenting actionable insights rather than overwhelming team members with non-critical issues.
100% Visibility into smartvid’s Cloud Applications
In addition to leveraging runtime insights to manage vulnerabilities, xantra addressed gaps in Kubernetes security, offering important capabilities in detection and response generally not available in standard Kubernetes deployments. Jonathan Jaffe notes “xantra fills typical Kubernetes security gaps. Few, if any products out there, provide reliable Kubernetes detection and response.” xantra extends its functionality beyond detection and response to include other areas such as non-human identities management and providing a comprehensive graphical views of smartvid s environment topology. This visibility is helpful to smartvids DevOps team, offering insights into resource relationships and aiding in task prioritization. “It’s the first time we’ve been able to point to graphs that show where resources are in relation to other resources. That helps us understand the context of a problem and how to prioritize what to work on.” Detection & response for kubernetes Non human identities management Topology view of entire environment
smartvid is able to maintain robust protection against advanced threats that could circumvent other defensive layers. “Having something at runtime is yet another layer of defense above other standard defenses such as network defenses and protocol defense.” An example of an advanced threat is code injection. This occurs when malicious code is inserted into a dependency or a component of the application. Despite best efforts in securing coding and vulnerability management, dependencies can be compromised or inadvertently introduce vulnerabilities. xantra Security monitors the execution of code at runtime and can detect whether theres an attempt to inject malicious code into the application s codebase.
