Listing Thumbnail

    Orca Security CNAPP Cloud Security Platform

     Info
    Deployed on AWS
    Free Trial
    Vendor Insights
    Quick Launch
    Agentless Cloud Security in a Single, Complete Platform with 100% Coverage
    4.7

    Overview

    Play video

    Orca Security is the true Cloud Native Application Protection Platform (CNAPP) that identifies, prioritizes, and remediates risks and compliance issues across all of your workloads, configurations, and identities on AWS. Orca offers the industrys most comprehensive cloud security solution in a single platform, eliminating the need to deploy and maintain multiple point solutions.

    FAST TIME TO VALUE: The Orca CNAPP Platform is agentless first, and connects to your environment in minutes using patented SideScanning™ technology that provides deep and wide visibility into your cloud environment, without requiring agents. In addition, Orca offers a lightweight agent for organizations that require real-time protection for critical workloads.

    RISK PRIORITIZATION: Orca effectively prioritizes risks by applying a granular risk score to each alert, and recognizes when seemingly unrelated issues can be combined to create dangerous attack paths straight to your crown jewels.

    FULL SDLC SECURITY: The Orca platform shifts security left by seamlessly integrating into the CI/CD process so that applications can be secured from code to cloud and back.

    AI-POWERED: Orca is at the forefront of leveraging Generative AI for simplified investigations and accelerated remediation, reducing required skill levels and saving cloud security, DevOps, and development teams time and effort, while significantly improving security outcomes.

    PURPOSE-BUILT CNAPP: Orca unifies many different point solutions in one platform, including CSPM, CWPP, CIEM, DSPM, Container security, API security, AI-SPM, and much more.

    Sign up for a demo to uplevel your cloud security and get the fastest time to value available in the industry: https://orca.security/demo/ 

    Additional platform licensing options are not shown in this listing but are available via Private Offer. Please email aws@orca.security .

    Highlights

    • Visibility to all your IAAS and PAAS assets including EC2, Containers, S3 buckets using account level read only permissions
    • Detect compromises, vulnerabilities and risky configuration within minutes
    • No impact on your assets, grows automatically with your cloud account

    Get personalized pricing in minutes - New

    If qualified, an express private offer gets you custom pricing and terms. Finalize your purchase in the AWS Marketplace console.

    Details

    Delivery method

    Deployed on AWS

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Quick Launch

    Leverage AWS CloudFormation templates to reduce the time and resources required to configure, deploy, and launch your software.

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (2)

    Pricing

    Free trial

    Try this product free according to the free trial terms set by the vendor.

    Orca Security CNAPP Cloud Security Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    1-month contract (4)

     Info
    Dimension
    Description
    Cost/month
    Small
    Small starter pack of concurrent workloads (EC2) per month
    $7,000.00
    Small-Medium
    Small-Medium starter pack of concurrent workloads (EC2) per month
    $12,000.00
    Medium
    Medium starter pack of concurrent workloads (EC2) per month
    $17,000.00
    Large
    large starter pack of concurrent workloads (EC2) per month
    $30,000.00

    Vendor refund policy

    Contact us

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Monitoring, Application Development
    Top
    25
    In Observability, Software Development
    Top
    10
    In Container Workloads

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Agentless Cloud Security Architecture
    Agentless-first approach using patented SideScanning technology that provides deep visibility into cloud environments without requiring agent deployment
    Risk Prioritization and Attack Path Analysis
    Granular risk scoring applied to each alert with capability to identify and correlate seemingly unrelated issues into dangerous attack paths
    Unified Cloud Security Platform
    Single platform consolidating multiple security functions including CSPM, CWPP, CIEM, DSPM, Container security, and API security
    CI/CD Integration for Application Security
    Seamless integration into CI/CD process to secure applications from code to cloud deployment
    AI-Powered Investigation and Remediation
    Generative AI capabilities for simplified security investigations and accelerated remediation workflows
    Offensive Security Engine
    Simulates external exploits to produce Verified Exploit Paths for prioritizing exposures that are reachable by outside attackers and reducing cloud attack surface.
    Cloud Security Posture Management
    Continuously monitors and manages security of AWS configurations to prevent public exposure and ensure compliance.
    Secrets Scanning
    Identifies more than 750 types of secrets across public and private repositories.
    Cloud Infrastructure Entitlements Management
    Detects and manages excessive or unused permissions to mitigate the risk of privilege escalation.
    Real-Time Malware Detection
    Detects malware including zero-days in milliseconds with scanning performed directly in cloud environment for object storage services like Amazon S3 and file storage services.
    Multi-Workload Security Coverage
    Unified platform securing containers, serverless, Kubernetes, and AI workloads across AWS, on-premises, and multi-cloud environments
    Runtime Threat Detection and Enforcement
    Runtime protection to detect threats, block malicious activity, and enforce compliance in production across all cloud native workloads
    AI and LLM Security Governance
    Purpose-built AI workload security to govern large language models and generative AI applications with model abuse detection and policy enforcement
    Full Lifecycle Security
    Security coverage across the entire software development lifecycle from code development through production deployment
    Compliance and Authorization Standards
    FedRAMP High authorization enabling compliance with rigorous security and regulatory standards

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    -
    -
    -
    -
    -
    No security profile
    -
    -
    -

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.7
    334 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    77%
    22%
    1%
    0%
    0%
    24 AWS reviews
    |
    310 external reviews
    External reviews are from G2  and PeerSpot .
    reviewer2879382

    Cloud security has improved posture and simplifies risk remediation and alert response

    Reviewed on Jul 23, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Orca Security  is to secure infrastructure, course, and service. A specific example of how I use Orca Security  to secure my infrastructure or services is for vulnerability management on VMs or other resources in Azure  or AWS .

    I have more to add about my main use case with Orca Security, including security posture frameworks such as ISO 27007 and 9001.

    What is most valuable?

    The best feature Orca Security offers is a remediation solution. What I appreciate most about the remediation solution is that it provides a fast fix for the vulnerabilities in my day.

    Orca Security has positively impacted my organization by improving our security posture and hardening our services and resources.

    What needs improvement?

    Regarding how Orca Security can be improved, I think there is not much; it is fully completed and it is great.

    For how long have I used the solution?

    I have been using Orca Security for around two years.

    What do I think about the stability of the solution?

    Orca Security is stable.

    What do I think about the scalability of the solution?

    The scalability of Orca Security is great.

    How are customer service and support?

    I find the customer support to be excellent. I would rate the customer support a ten.

    Which solution did I use previously and why did I switch?

    I did not use a different solution before Orca Security; it is the one and only for me.

    What was our ROI?

    I do not know if I have seen a return on investment with Orca Security; I cannot share any relevant metrics.

    What's my experience with pricing, setup cost, and licensing?

    Regarding my experience with pricing, setup cost, and licensing, I think that is not my place in the company.

    Which other solutions did I evaluate?

    Before choosing Orca Security, I evaluated other options, such as Wiz  or Google, perhaps.

    What other advice do I have?

    My advice to others looking into using Orca Security is to practice and study the platform in test scenarios. My impressions of the risk detection and identification capabilities of Orca Security are fascinating because they are clear and serve as a guide. Orca Security has helped my organization reduce the time it takes to address cloud security alerts because we can automate alerts.

    To the extent that Orca Security has helped in preventing risks and attacks across our application lifecycle, it has allowed me to understand the security status of our resources before they go into production. My experience prioritizing risks using Orca  is easy. In my experience, Orca Security's ability to analyze risks contextually and holistically is excellent. I have not utilized Orca Security's sensor for cloud detection and response, so I cannot speak to its effectiveness.

    I would rate this review a ten out of ten. Orca Security is a great platform, and I am very happy with it.

    Sara J.

    Rapid Visibility into Inherited AI Agents and Their Risk Paths

    Reviewed on Jul 21, 2026
    Review provided by G2
    What do you like best about the product?
    When we acquire a new business or bring a new cloud environment into the fold, we’re not just inheriting infrastructure; we’re inheriting their agents, their workflows, and their data paths. Orca lets us connect the new accounts quickly and immediately see which AI agents exist there, what identities they use, and which systems and data stores they can reach. Instead of months of manual discovery, we get a clear picture of inherited AI agent risk within days.
    What do you dislike about the product?
    We chose to standardize some basic tagging and ownership conventions for newly onboarded agents, and that upfront work has already made cross-business-unit reviews much smoother.
    What problems is the product solving and how is that benefiting you?
    This turns onboarding from a slow discovery process into a quick, agent-aware integration. The CISO can clearly see which AI agents in a new environment carry meaningful risk and bring them under the same governance as our existing estate.
    Logan Gray

    Cloud risk context has improved and prioritization now streamlines patching decisions

    Reviewed on Jul 20, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Orca Security  is to protect our cloud infrastructure. Specifically, I scan our cloud workloads with Orca Security  to detect vulnerabilities and help determine what to prioritize for patching and upgrading.

    What is most valuable?

    Orca Security helps me decide what to prioritize for patching and upgrading with its workload protection features that work really well and help contextualize and prioritize the issues it finds.

    The best features Orca Security offers are cloud security and its shift-left features. The shift-left features of Orca Security help detect issues earlier in the software development lifecycle, benefiting my team day-to-day.

    Orca Security has positively impacted my organization by helping us become more secure by flagging and prioritizing issues.

    My impressions of the risk detection and identification capabilities of Orca Security are that they are very good because it helps contextualize and prioritize the issues for us to work on.

    Orca Security has helped in preventing risks and attacks across my application lifecycle by highlighting insecure configurations or vulnerabilities that do not yet have an exploit so that we can resolve those issues before they become more critical.

    My impression of Orca Security's ability to analyze risks contextually and holistically is that it seems quite good because it has visibility of our entire cloud infrastructure and can gather additional context to help prioritize and inform on issues.

    What needs improvement?

    Sometimes with Orca Security, it is a little bit hard for me to differentiate between different ephemeral cloud workloads and what the actual root cause of a particular issue is. I rate it a nine because of the issues with ephemeral workloads that I mentioned, which kept it from being a perfect ten.

    For how long have I used the solution?

    I have been using Orca Security for four years.

    What do I think about the stability of the solution?

    Orca Security is stable.

    What do I think about the scalability of the solution?

    The scalability of Orca Security is very good.

    How are customer service and support?

    I find the customer support for Orca Security to be good.

    Which solution did I use previously and why did I switch?

    I did not previously use a different solution.

    How was the initial setup?

    My experience with pricing, setup cost, and licensing is that the pricing was about on par with other options, the setup was very easy, and licensing is quite straightforward.

    What was our ROI?

    Although I do not have well-defined ROI with Orca Security, it has prevented us from needing additional employees, and it has certainly saved time.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing is that the pricing was about on par with other options, the setup was very easy, and licensing is quite straightforward.

    Which other solutions did I evaluate?

    Before choosing Orca Security, I evaluated other options, which included Google Security Command Center, Prisma Cloud, and Qualys.

    What other advice do I have?

    Orca Security has helped my organization reduce the time it takes to address cloud security alerts; since bringing Orca Security in, it has improved our time to resolve by about fifty percent.

    I find it very easy to prioritize risks using Orca Security.

    Regarding Orca Security's AI capabilities, I think their governance and security are pretty good because I use those capabilities as well.

    I have not seen any issues with the accuracy and reliability of Orca Security's AI output; it seems accurate.

    My advice to others looking into using Orca Security is to try to consider organizing assets by business units just to help organize and prioritize findings relevant to different teams. I rate Orca Security a nine overall.

    Manohar K.

    Orca Brings AI Agents Into Focus With Prioritized, Business-Relevant Risk Views

    Reviewed on Jul 20, 2026
    Review provided by G2
    What do you like best about the product?
    Our teams are drowning in alerts, and the dashboards barely mention AI agents, even though those agents are quietly involved in many of the riskiest paths. Orca changes that by presenting a prioritized view where AI agents, their permissions, and the data they can touch show up alongside traditional services. As a result, we spend less time flipping between tools and more time focused on the short list of agent-driven attack paths that actually matter to the business.
    What do you dislike about the product?
    We took some time to align the Orcas risk views with how our teams talk about the agents and services, including a few naming and tagging conventions. That small investment made it much easier for engineers and analysts to immediately recognize the agents and the paths tied to their work.
    What problems is the product solving and how is that benefiting you?
    It reduced alert fatigue by helping us focus on the AI agents and services with a real blast radius, rather than getting stuck in the long tail of low-impact findings. As a result, more of what we fix measurably reduces agent-related exposure, and we spend less effort on issues that never touch meaningful data.
    Alvaro V.

    Orca Makes Least Privilege Practical with Clear Permission and Usage Visibility

    Reviewed on Jul 17, 2026
    Review provided by G2
    What do you like best about the product?
    Least privilege is always the goal, but in a world where the marketer writes the Python and the analyst ships the agents, it was hard to know where to start. Orca shows the effective permissions and the actual usage across agents and identities tied to the systems our team builds, so the effort can go first to the agents and roles with the largest blast radius around the assets that drive the business. That makes the CISO’s least-privilege goal something the team can realistically chip away at each sprint—for agents and humans—instead of leaving it as a theoretical aspiration.
    What do you dislike about the product?
    We took care to test the changes around some legacy applications and the older agents before tightening access based on the Orcas findings, which helped us roll out least privilege safely.
    What problems is the product solving and how is that benefiting you?
    It turns least privilege for AI agents into a practical, incremental approach that fits how builders actually work, instead of treating it like a blanket rule that would slow everything down. Over time, that means agents and their identities steadily become safer, without putting a brake on creation.
    View all reviews