Listing Thumbnail

    Orca Security CNAPP Cloud Security Platform

     Info
    Deployed on AWS
    Free Trial
    Vendor Insights
    Quick Launch
    Agentless Cloud Security in a Single, Complete Platform with 100% Coverage
    4.7

    Overview

    Play video

    Orca Security is the true Cloud Native Application Protection Platform (CNAPP) that identifies, prioritizes, and remediates risks and compliance issues across all of your workloads, configurations, and identities on AWS. Orca offers the industrys most comprehensive cloud security solution in a single platform, eliminating the need to deploy and maintain multiple point solutions.

    FAST TIME TO VALUE: The Orca CNAPP Platform is agentless first, and connects to your environment in minutes using patented SideScanning™ technology that provides deep and wide visibility into your cloud environment, without requiring agents. In addition, Orca offers a lightweight agent for organizations that require real-time protection for critical workloads.

    RISK PRIORITIZATION: Orca effectively prioritizes risks by applying a granular risk score to each alert, and recognizes when seemingly unrelated issues can be combined to create dangerous attack paths straight to your crown jewels.

    FULL SDLC SECURITY: The Orca platform shifts security left by seamlessly integrating into the CI/CD process so that applications can be secured from code to cloud and back.

    AI-POWERED: Orca is at the forefront of leveraging Generative AI for simplified investigations and accelerated remediation, reducing required skill levels and saving cloud security, DevOps, and development teams time and effort, while significantly improving security outcomes.

    PURPOSE-BUILT CNAPP: Orca unifies many different point solutions in one platform, including CSPM, CWPP, CIEM, DSPM, Container security, API security, AI-SPM, and much more.

    Sign up for a demo to uplevel your cloud security and get the fastest time to value available in the industry: https://orca.security/demo/ 

    Additional platform licensing options are not shown in this listing but are available via Private Offer. Please email aws@orca.security .

    Highlights

    • Visibility to all your IAAS and PAAS assets including EC2, Containers, S3 buckets using account level read only permissions
    • Detect compromises, vulnerabilities and risky configuration within minutes
    • No impact on your assets, grows automatically with your cloud account

    Get personalized pricing in minutes - New

    If qualified, an express private offer gets you custom pricing and terms. Finalize your purchase in the AWS Marketplace console.

    Details

    Delivery method

    Deployed on AWS

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Quick Launch

    Leverage AWS CloudFormation templates to reduce the time and resources required to configure, deploy, and launch your software.

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (2)

    Pricing

    Free trial

    Try this product free according to the free trial terms set by the vendor.

    Orca Security CNAPP Cloud Security Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    1-month contract (4)

     Info
    Dimension
    Description
    Cost/month
    Small
    Small starter pack of concurrent workloads (EC2) per month
    $7,000.00
    Small-Medium
    Small-Medium starter pack of concurrent workloads (EC2) per month
    $12,000.00
    Medium
    Medium starter pack of concurrent workloads (EC2) per month
    $17,000.00
    Large
    large starter pack of concurrent workloads (EC2) per month
    $30,000.00

    Vendor refund policy

    Contact us

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Monitoring, Application Development
    Top
    25
    In Observability, Software Development
    Top
    10
    In Container Workloads

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Agentless Cloud Security Architecture
    Agentless-first approach using patented SideScanning technology that provides deep visibility into cloud environments without requiring agent deployment
    Risk Prioritization and Attack Path Analysis
    Granular risk scoring applied to each alert with capability to identify and correlate seemingly unrelated issues into dangerous attack paths
    Unified Cloud Security Platform
    Single platform consolidating multiple security functions including CSPM, CWPP, CIEM, DSPM, Container security, and API security
    CI/CD Integration for Application Security
    Seamless integration into CI/CD process to secure applications from code to cloud deployment
    AI-Powered Investigation and Remediation
    Generative AI capabilities for simplified security investigations and accelerated remediation workflows
    Offensive Security Engine
    Simulates external exploits to produce Verified Exploit Paths for prioritizing exposures that are reachable by outside attackers and reducing cloud attack surface.
    Cloud Security Posture Management
    Continuously monitors and manages security of AWS configurations to prevent public exposure and ensure compliance.
    Secrets Scanning
    Identifies more than 750 types of secrets across public and private repositories.
    Cloud Infrastructure Entitlements Management
    Detects and manages excessive or unused permissions to mitigate the risk of privilege escalation.
    Real-Time Malware Detection
    Detects malware including zero-days in milliseconds with scanning performed directly in cloud environment for object storage services like Amazon S3 and file storage services.
    Multi-Workload Security Coverage
    Unified platform securing containers, serverless, Kubernetes, and AI workloads across AWS, on-premises, and multi-cloud environments
    Runtime Threat Detection and Enforcement
    Runtime protection to detect threats, block malicious activity, and enforce compliance in production across all cloud native workloads
    AI and LLM Security Governance
    Purpose-built AI workload security to govern large language models and generative AI applications with model abuse detection and policy enforcement
    Full Lifecycle Security
    Security coverage across the entire software development lifecycle from code development through production deployment
    Compliance and Authorization Standards
    FedRAMP High authorization enabling compliance with rigorous security and regulatory standards

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    -
    -
    -
    -
    -
    No security profile
    -
    -
    -

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.7
    327 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    77%
    22%
    1%
    0%
    0%
    24 AWS reviews
    |
    303 external reviews
    External reviews are from G2  and PeerSpot .
    Rafael Bueno

    Cloud security has gained full visibility and real-time remediation for our small team

    Reviewed on Jul 16, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I use Orca Security  to have a complete view of our cloud environment at the company.

    I needed to know what assets were vulnerable and how to fix them, and it was very helpful to have Orca Security  because it has some AI features that helped our developers fix the vulnerabilities while coding and understand which vulnerabilities require more attention and resources.

    OrcA Security automates remediation because we could install a plugin in the developer's IDE , so while they were coding, it actually helped them fix vulnerabilities in real time, which was very helpful.

    What is most valuable?

    The AI fix for vulnerabilities that we found is the best feature because it gives us more time to focus on other things.

    The dashboards were very helpful, and I could personalize them for our case, which helped me show my leadership where the main points were and how to address them, allowing us to focus on what was really important. It was very easy to change the dashboards and personalize everything.

    OrcA Security improved our collaboration because we could explain better to everyone at the company what we were doing and how it positively impacts our security posture. We could also measure our risks and vulnerabilities better, enabling us to think more strategically about improving our cybersecurity posture.

    We have faster fixing of vulnerabilities with our DevOps team, and we could have fewer attacks.

    It was really good because we could see threats coming before they materialize, which I think is a really good way to protect ourselves, our resources at the company, and all our assets.

    We are a small team, and I did not feel any difficulty in the work using Orca Security, so I believe it saved us more employees and other costs, helping us save in different ways.

    What needs improvement?

    Some dashboards could be a little more personalized for each company and have more options to show the real data we need for our leadership.

    For how long have I used the solution?

    I have been using Orca Security for a year.

    What do I think about the stability of the solution?

    I believe it is stable, and we did not have any availability problems with them.

    What do I think about the scalability of the solution?

    It is very scalable. We have a small environment, but it was very scalable when the Orca Security engineers were explaining the tool to us.

    How are customer service and support?

    It was really good. We had direct access to some commercial people and also the engineers, and they helped us every time we needed.

    Which solution did I use previously and why did I switch?

    It was Prisma Cloud, and we stopped using it because of the costs, and the results were not that organized or easy to use as Orca Security.

    We jumped directly to Orca Security without comparing it with any other platform.

    How was the initial setup?

    We installed the Orca Security plugin in the developers' machines, and when they were coding, they could see the vulnerabilities with the Orca Security plugin and fix them in the code before it was put into the production environment. This allowed us to fix vulnerabilities before they reached our productive systems, which was very helpful.

    What about the implementation team?

    We are not working with a partner or reseller.

    What was our ROI?

    Eight out of ten.

    What's my experience with pricing, setup cost, and licensing?

    I believe it can be improved, but it is also a really good platform to use.

    Which other solutions did I evaluate?

    Someone asked me on LinkedIn to talk about Orca Security.

    What other advice do I have?

    It was really accurate and gave us the right answers.

    The advice I give is to talk with the support team. They help us and listen to us about features and things that made sense for our environment and our specific case, and they consider applying them to the final product.

    I rate this product a 10 out of 10.

    Jack J.

    Orca Delivers Clear Visibility Into Agent Data Access and Compliance Boundaries

    Reviewed on Jul 14, 2026
    Review provided by G2
    What do you like best about the product?
    As our agents reason over regulated data—customer records and financial datasets—we needed confidence that they weren’t crossing residency or compliance boundaries. Orca shows where each agent runs, which data stores it can reach, and how those access paths align with our regulatory and policy constraints. That level of visibility lets us quickly spot an agent that could read out-of-region data or touch a store that should be locked down to specific roles.
    What do you dislike about the product?
    We updated a few of our compliance dashboards to incorporate Orcas agent views, which has made our conversations with risk and legal far more concrete.
    What problems is the product solving and how is that benefiting you?
    It made AI agent behavior part of our compliance story, so agents can keep helping the teams without accidentally violating rules that would be easy to miss without that context.
    AvrahamGoldwasser

    Cloud security has become unified with agentless visibility, faster remediation, and better compliance

    Reviewed on Jul 14, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Orca Security  is cloud security, and we integrated AppSec in the last year.

    What is most valuable?

    Orca Security  offers good security as a CSPM, runtime security with the real-time security agent on Kubernetes , and excellent visual representation to see what is really going on. The visual representation helps me understand where our gaps are and what needs to be fixed through remediations. In terms of AppSec, it provides entire connectivity with some missing parts, but mainly the Git  parts with the repos allow me to see everything, how it is integrated, and to assess its risks. The SCA  with the SAST  is also crucial.

    The feature that stands out the most for me is that it is agentless, so I have simple connectivity where I can see everything in one place. If there are misconfigurations, security risks, or misconfiguration gaps, I can be alerted and set up custom alerts and non-custom alerts, allowing our security team to observe these alerts and take action.

    Orca Security has positively impacted my organization mainly through use by the security team, but we also use it for compliance reports. We can set the compliance standards we want to adhere to in Orca Security, and then I can check in which areas of each resource or organization-wide efforts comply with those standards. This is really useful to know where our compliance gaps are.

    Risk detection and identification capabilities of Orca Security are great and really useful. They had too many false positives in the past, but over time, with their improvements, probably due to UBA  or something similar, it has really improved.

    What needs improvement?

    Orca Security can be improved by adding more connectivity and more integrations because the world is moving so fast that having integrations is really poor compared to other vendors.

    What is also missing with Orca Security is more robust AI security. Even though they have something, it is still really immature. We need better observability, and not only for cloud-based issues but also for any AI LLMs to ensure real security over AI.

    Regarding Orca Security's AI capabilities, I think it is still immature and we are missing some introduction to it. In terms of Orca Security's accuracy and reliability of output, I find that it is still immature, so I have a gap over there.

    For how long have I used the solution?

    I have been using Orca Security for the last four years.

    What do I think about the stability of the solution?

    I find Orca Security stable.

    What do I think about the scalability of the solution?

    Orca Security's scalability is great and I have not seen any faults.

    How are customer service and support?

    The customer support from Orca Security is the best and it is really good. I would rate the customer support a ten.

    Which solution did I use previously and why did I switch?

    We did not previously use a different solution. We conducted a POC with other solutions, and at the end of the day, after checking everything, it was my choice to go with Orca Security.

    How was the initial setup?

    I purchased Orca Security through the AWS Marketplace .

    What was our ROI?

    Orca Security has helped my organization reduce the time it takes to address cloud security alerts, and it does so very fast. Its visualization of the alerts, including custom alerts, makes it really efficient. Today, it is integrated with our SOC team.

    I have utilized Orca  Sensor for Cloud Detection and Response, CDR, and it has been effective in providing runtime visibility and security. This was the main part because we started with CDR straight at the beginning before doing anything else, and it was good.

    Orca Security has helped in preventing risks and attacks across my application lifecycle if it is about secrets, exposed secrets, or vulnerable packages within the CI/CD pipeline, which were detected through the pipeline. It has full integration with GitHub  or other tools such as Azure DevOps .

    Which other solutions did I evaluate?

    Before choosing Orca Security, we evaluated other options, including Prisma Cloud, which is now in Cortex , Wiz , and Uptime.

    What other advice do I have?

    I rate Orca Security a ten out of ten. I chose this rating because we started with Orca Security when it was a new kind of competition to Wiz . We went with Orca Security because of its support, which is one of the best third-party supports we have. They made a really big jump over the last two years, especially in the last year where they changed almost everything, from visualization to reducing false positives, and now they categorize alerts separately compared to what it was earlier, making this really useful. My advice for others looking into using Orca Security is to really consider them. I have given this advice before, and I know that some have taken my advice and moved forward with Orca Security. My overall rating for Orca Security is ten.

    Samuel J.

    Orca Unifies AppSec, Cloud, and Agent Context in One Clear View

    Reviewed on Jul 13, 2026
    Review provided by G2
    What do you like best about the product?
    We used to split our view of risk: AppSec tools looked at the code, cloud tools looked at the infrastructure, and nobody owned the full picture for the agents that sit on top of both. In reality, the marketer was writing the Python, the analyst was shipping the agents, and those agents call the APIs, touch the containers, and invoke serverless functions across clouds. Orca ties the application, cloud, and agent context together in one unified model. When there’s an issue, we can see the agent, the vulnerable code it relies on, the service it runs on, and the data it touches—all in a single view.
    What do you dislike about the product?
    Our appsec engineers broadened their focus to include agent behaviour and the cloud context, and that shift has helped them collaborate more closely with the rest of the security team.
    What problems is the product solving and how is that benefiting you?
    It brings application cloud and AI agent security into a single story we can actually act on, aligned with how our teams build and deploy agents.
    Shubhankar T.

    Orca Keeps AI Agent Compliance Continuously Aligned With Our Cloud Workloads

    Reviewed on Jul 13, 2026
    Review provided by G2
    What do you like best about the product?
    We are constantly creating with AI agents, and compliance used to feel completely disconnected from that reality. Teams ship agents to production, analysts wire agents into workflows, PMs push agent-backed features, and then audit season arrives with the spreadsheet. Orca continuously maps our cloud workload and agent posture to the frameworks we care about, tied directly to the resources and agents that power what we build.
    What do you dislike about the product?
    We fine-tuned how Orca’s controls map to the way our auditors phrase agent and AI governance requirements, which helped align its evidence directly with our own review style.
    What problems is the product solving and how is that benefiting you?
    This Sift AI agent compliance takes what used to slow down our normal security posture work and turns it into part of the process, so we can keep shipping agents while still proving we’re safe enough to keep going.
    View all reviews