Why just detect when you can prevent? Aviatrix's in-line managed security platform stops breaches in real-time by embedding dynamic, policy-driven control directly into the data path of all workload communication designed to enforce a zero trust posture within modern cloud environments, effectively stopping the lateral movement of attackers, preventing accidental data exfiltration from human error or misconfigurations, securing the network complexities of Kubernetes, and allows you to see, segment, and secure communications from autonomous agents and AI-generated code, often referred to as "Shadow AI."
Modern cloud initiatives like Kubernetes and Generative AI have broken traditional security perimeters, distributing critical data across multiple clouds and regions. Legacy security tools can't keep up, resulting in inconsistent policies, blind spots, and a larger attack surface.
Cloud Native Security Fabric (CNSF) solutions are designed to offer a dynamic, policy-driven control directly into the data path of all workload communications. This approach provides the necessary visibility and control to secure applications and data as they move, enabling a true zero trust architecture that enforces policy on all traffic.
Aviatrix PaaS addresses the urgent risks introduced by innovations like Kubernetes and AI. It manages the network complexity of Kubernetes, providing unified visibility and security for traffic between ephemeral pods. It also allows you to see, segment, and secure communications from autonomous agents and AI-generated code, often referred to as "Shadow AI."
Designed to be an enabler for developers, Aviatrix's CNSF-based solution is IaC-native with deep Terraform integration, allowing security to be embedded directly into CI/CD pipelines. Rather than replacing your existing security stack, it acts as a connective tissue that enhances the effectiveness of your current firewalls and security tools.
Network security professionals operating in AWS and multicloud environments face challenges managing diverse tools and policies across clouds. An enterprise-grade secure networking platform extends native AWS capabilities, providing a unified architecture for networking and security. It enables and provides a consistent posture, AI-powered insights, and intelligent automation across your entire cloud footprint for simplified control.
Benefits & Capabilities
Comprehensive PaaS-based cloud network and security management: Benefit from a fully managed service that handles the complexities of cloud networking and security, significantly reducing your team's operational burden and eliminating the need for infrastructure maintenance, updates, and availability management. This allows your skilled engineers to focus on core business initiatives and innovation rather than routine upkeep. The PaaS offering includes a robust secure cloud egress solution with advanced NAT and AI-powered FQDN/URL filtering, enterprise-level cloud firewall capabilities with centralized policy control, comprehensive monitoring dashboards and dynamic topology views for real-time insights, a detailed cloud asset inventory (CAI), and granular role-based access control (RBAC) for secure administration.
Fast time to value with seamless integration and scalability: Accelerate your cloud journey and quickly realize security and networking benefits through rapid deployment and seamless integration with your AWS environments. Aviatrix PaaS provides clarity over your network by abstracting infrastructure complexity, offering a ready-to-use platform that boosts business agility and allows your network to scale effortlessly with evolving security and business demands.
AI-enhanced visibility and control tailored for complex cloud network environments: Leverage the power of AI and machine learning for proactive identification of potential issues, predictive analytics, and real-time operational intelligence through natural language queries with Aviatrix AI Assist. This allows for simplified troubleshooting and data-driven recommendations for security posture enhancement. Benefit from continuous risk scoring and AI-driven analysis for real-time security benchmarking and AI-assisted improvements to continuously strengthen your defenses across complex cloud networks.
Highlights
In-Line Zero Trust Enforcement & AI-Enhanced Visibility: Go beyond passive scanning with a fully managed PaaS solution that actively segments, encrypts, and controls traffic in real-time across virtual networks, regions, and clouds using enterprise-level firewalling. Tame cloud complexity with AI-powered insights, gaining comprehensive visibility and consistent policy enforcement for all traffic, including Kubernetes, as well as securing data paths from Generative AI and autonomous agents.
Unified Multi-Cloud Security & Simplified Operations: Define your security policies a single time and enforce them universally across AWS, Azure, and GCP. This unified platform eliminates the need for re-architecting and reduces management complexity. It simplifies network and security management through centralized policy, robust monitoring dashboards, a detailed cloud asset inventory, and granular role-based access control (RBAC), lessening the operational burden on your team.
Developer-Ready & IaC-Native Integration: Seamlessly embed security directly into your DevOps workflows. The platform offers deep, native integration with Terraform, allowing you to automate the deployment of both security and networking infrastructure. This makes secure cloud workload management an integral part of your development process from the very beginning.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
Entitlements: Fabrics: QTY 1 , Nodes: QTY 5 , Advanced Security Module: QTY 5 , Professional Services: Includes implementation of up to 5 nodes , Support : Includes 24x7 Support
$27,700.00
Aviatrix Cloud Firewall 10-Pack (PaaS)
Entitlements: Fabrics: QTY 1 , Nodes: QTY 10 , Advanced Security Module: QTY 10 , Professional Services: Includes implementation of up to 10 nodes , Support: Includes 24x7 Support
$46,800.00
Aviatrix Cloud Firewall 15-Pack (PaaS)
Entitlements: Fabrics: QTY 1 , Nodes: QTY 15 , Advanced Security Module: QTY 15 , Professional Services: Includes implementation of up to 10 nodes , Support: Includes 24x7 Support
$66,400.00
Workload Threat Visibility
Provides unified outbound visibility and Zero Trust proof across every cloud. Aviatrix Workload Threat Visibility gives security teams consistent, cross-cloud insight into where workloads connect and whether those destinations are safe, compliant, or malicious. It observes outbound traffic through the Aviatrix NAT Gateway layer to detect threats, validate Zero Trust controls, and provide audit-ready evidence across frameworks like CISA ZTMM 2.0, PCI DSS 4.0, DORA, and HIPAA 2025.
This listing sells four contract options. Three are Cloud Firewall packs sized by node count: 5, 10, or 15 nodes. Each pack includes one fabric, matching Advanced Security Module entitlements, professional services for implementation, and 24x7 support. You pick a pack based on how many firewall nodes you need, so pricing scales with node capacity. The fourth option, Workload Threat Visibility, is a separate add-on. It gives cross-cloud outbound traffic visibility through the NAT Gateway layer and is billed independently of the firewall packs.
Top-of-mind questions for buyers
What counts as one node for billing in the Cloud Firewall packs?
A node is a firewall enforcement point deployed in your cloud environment. The 5-Pack covers 5 nodes, the 10-Pack covers 10, and the 15-Pack covers 15. Each pack includes one fabric plus matching Advanced Security Module entitlements. You size the pack to how many enforcement points your workloads require.
What does the Workload Threat Visibility option cover, and are there deployment limits?
It provides outbound traffic visibility through the NAT Gateway layer for up to 50 VPCs or VNETs. Setup needs no agents or sensors. You enable flow logs and deploy the NAT Gateway. It includes threat and reputation data and basic support, and works in any cloud where the gateway runs.
If I buy a firewall pack, do I still need to buy Workload Threat Visibility separately?
Yes. The firewall packs and Workload Threat Visibility are separate contract options billed independently. The packs deliver inline enforcement across nodes. Workload Threat Visibility delivers outbound traffic visibility through the NAT Gateway layer. You buy each based on the capability you need; neither includes the other.
aviatrix.ai
Helpful?
Vendor refund policy
Contact us
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Aviatrix Cloud Network CoPilot provides a global view of your multicloud network. It helps IT teams maintain accurate topology maps, analyze network traffic flows, and troubleshoot anomalies. Aviatrix Cloud Network CoPilot offers operational features like packet capture, trace route, ping, and a metrics api. It leverages Aviatrix's advanced network and security services.
At Aviatrix, we simplify cloud networking so your business stays agile. Our cloud networking platform delivers the visibility, security, and control enterprises need to successfully manage and operate cloud networks at scale.
The Aviatrix Cloud Network Controller is a tool that manages gateways, coordinates the connectivity of cloud and hybrid networks, and automates routing on a large scale. The Aviatrix Terraform Provider works with the controller to automate the setup and configuration of network infrastructure wherever it is needed by the enterprise.
The Aviatrix Cloud Network License Service provides the customer IDs (licenses) that are needed to access the Aviatrix Cloud Network Controller and Aviatrix Cloud Network CoPilot. This service also calculates Aviatrix bills based on usage, which are then sent to AWS Marketplace for customer billing purposes. Customers can view their Aviatrix bill detail in the Aviatrix Cloud Network CoPilot. This service includes a free trial.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.