Today, we're introducing Sweet’s enhanced response capabilities, bringing together native response actions, reusable playbooks, webhooks, and response history into a unified experience that helps security teams contain threats directly from the Sweet platform.
Organizations are adopting cloud-native applications and AI at an unprecedented pace. Understanding what's happening in production is only part of the challenge. Security teams also need the ability to act quickly and consistently using the same runtime intelligence that identified the threat in the first place.
Beyond Observability: Operationalizing Runtime Data
Runtime capabilities via eBPF have fundamentally changed cloud security.. They provide visibility into workload activity, identities, API communication, and application behavior that simply isn't available through configuration data alone. Security teams use that context to determine which risks are actually exploitable and where they should focus first. The next step is turning those insights into action.
Too often, analysts validate a threat only to leave the platform and pivot into other tools to begin containment. They manually execute response steps, notify the appropriate teams, or stitch together automation across multiple products. Every handoff adds time, increases complexity, and slows response when every minute matters. Runtime data should do more than improve security observability - runtime data should help organizations quickly reduce risk, reducing mean time to containment (MTTC) and resolution (MTTR). That's the philosophy behind the Sweet Learning Loop and our Attack, Fix, Defend approach.
- Attack continuously and proactively proves real attack paths using runtime intelligence on both cloud and AI applications, highlighting the most acute risks..
- Fix helps security and engineering teams eliminate those risks through runtime-based remediation, guardrails, and permission changes before they become incidents.
- Defend focuses on responding quickly to an active threat and preventing the next one.
Sweets response capabilities strengthen that final phase by giving security teams more ways to act on the runtime intelligence they're already using every day.
Meet Response
Sweet brings response capabilities into a single experience that's accessible directly from findings, incidents, and workloads. This means analysts can investigate a threat and immediately take containment actions while staying in the same workflow.
With this enhancement, teams take actions, including:
- Terminating malicious processes running on compromised workloads.
- Killing compromised containers directly from Kubernetes investigations.
- Preventing pod scheduling to stop affected workloads from being redeployed.

Organizations can also create Custom Playbooks that combine multiple response actions and webhook integrations into reusable workflows. Rather than executing the same containment steps manually every time, analysts can launch an entire response sequence with a single action while maintaining control over execution order and failure handling.

Every response is recorded, providing a complete audit trail of what was executed, who initiated it, when it occurred, and whether it succeeded. This gives security and platform teams the visibility needed to review previous response actions, troubleshoot failures, and demonstrate operational accountability.

The result is a faster path from investigation to containment without forcing analysts to leave the Sweet platform.
Response Isn't Only for Active Threats
Response is usually framed as a reaction: a threat is detected, an analyst validates it, and containment follows. But some of the most valuable actions a security team can take don't wait for a finding at all. That's why Sweet Response lets teams act on a workload directly, not just on the threat attached to it.
From any workload in the Sweet platform, analysts can run response actions, whether or not that workload currently has an active finding or incident. A container that's running a version with a known exploitable vulnerability, a pod that shouldn't be reachable from the internet, a workload behaving outside its usual baseline - none of these need to escalate into a confirmed threat before a team decides to act.
This turns response from a purely reactive tool into a proactive one. Teams can harden their environment based on what runtime intelligence tells them about a workload's exposure and behavior, closing gaps before an attacker finds them. It also gives platform and security teams a consistent, audited way to enforce decisions about how workloads are allowed to run, using the same actions, playbooks, and response history they rely on during an incident.
Completing the Runtime Security Workflow
Runtime visibility has become a foundational part of modern cloud and AI security. Organizations seeing the greatest value from runtime use it to validate risk, drive remediation, and respond to threats from the same source of truth. Sweets response capabilities build on that by making response a more integrated part of the Sweet platform and strengthening the Defend phase of our Sweet Learning Loop’s Attack. Fix. Defend. Approach.
Ready to see Sweet’s response capabilities in action? Schedule a demo to see how Sweet helps organizations proactively prove risk, accelerate response, and operationalize runtime security across cloud and AI environments.




