Listing Thumbnail

    Orca Security CNAPP Cloud Security Platform

     Info
    Deployed on AWS
    Free Trial
    Vendor Insights
    Quick Launch
    Agentless Cloud Security in a Single, Complete Platform with 100% Coverage
    4.7

    Overview

    Play video

    Orca Security is the true Cloud Native Application Protection Platform (CNAPP) that identifies, prioritizes, and remediates risks and compliance issues across all of your workloads, configurations, and identities on AWS. Orca offers the industrys most comprehensive cloud security solution in a single platform, eliminating the need to deploy and maintain multiple point solutions.

    FAST TIME TO VALUE: The Orca CNAPP Platform is agentless first, and connects to your environment in minutes using patented SideScanning™ technology that provides deep and wide visibility into your cloud environment, without requiring agents. In addition, Orca offers a lightweight agent for organizations that require real-time protection for critical workloads.

    RISK PRIORITIZATION: Orca effectively prioritizes risks by applying a granular risk score to each alert, and recognizes when seemingly unrelated issues can be combined to create dangerous attack paths straight to your crown jewels.

    FULL SDLC SECURITY: The Orca platform shifts security left by seamlessly integrating into the CI/CD process so that applications can be secured from code to cloud and back.

    AI-POWERED: Orca is at the forefront of leveraging Generative AI for simplified investigations and accelerated remediation, reducing required skill levels and saving cloud security, DevOps, and development teams time and effort, while significantly improving security outcomes.

    PURPOSE-BUILT CNAPP: Orca unifies many different point solutions in one platform, including CSPM, CWPP, CIEM, DSPM, Container security, API security, AI-SPM, and much more.

    Sign up for a demo to uplevel your cloud security and get the fastest time to value available in the industry: https://orca.security/demo/ 

    Additional platform licensing options are not shown in this listing but are available via Private Offer. Please email aws@orca.security .

    Highlights

    • Visibility to all your IAAS and PAAS assets including EC2, Containers, S3 buckets using account level read only permissions
    • Detect compromises, vulnerabilities and risky configuration within minutes
    • No impact on your assets, grows automatically with your cloud account

    Get personalized pricing in minutes - New

    If qualified, an express private offer gets you custom pricing and terms. Finalize your purchase in the AWS Marketplace console.

    Details

    Delivery method

    Deployed on AWS

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Quick Launch

    Leverage AWS CloudFormation templates to reduce the time and resources required to configure, deploy, and launch your software.

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (2)

    Pricing

    Free trial

    Try this product free according to the free trial terms set by the vendor.

    Orca Security CNAPP Cloud Security Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    1-month contract (4)

     Info
    Dimension
    Description
    Cost/month
    Small
    Small starter pack of concurrent workloads (EC2) per month
    $7,000.00
    Small-Medium
    Small-Medium starter pack of concurrent workloads (EC2) per month
    $12,000.00
    Medium
    Medium starter pack of concurrent workloads (EC2) per month
    $17,000.00
    Large
    large starter pack of concurrent workloads (EC2) per month
    $30,000.00

    Vendor refund policy

    Contact us

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Monitoring, Application Development
    Top
    25
    In Observability, Software Development
    Top
    10
    In Container Workloads

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Agentless Cloud Security Architecture
    Agentless-first approach using patented SideScanning technology that provides deep visibility into cloud environments without requiring agent deployment
    Risk Prioritization and Attack Path Analysis
    Granular risk scoring applied to each alert with capability to identify and correlate seemingly unrelated issues into dangerous attack paths
    Unified Cloud Security Platform
    Single platform consolidating multiple security functions including CSPM, CWPP, CIEM, DSPM, Container security, and API security
    CI/CD Integration for Application Security
    Seamless integration into CI/CD process to secure applications from code to cloud deployment
    AI-Powered Investigation and Remediation
    Generative AI capabilities for simplified security investigations and accelerated remediation workflows
    Offensive Security Engine
    Simulates external exploits to produce Verified Exploit Paths for prioritizing exposures that are reachable by outside attackers and reducing cloud attack surface.
    Cloud Security Posture Management
    Continuously monitors and manages security of AWS configurations to prevent public exposure and ensure compliance.
    Secrets Scanning
    Identifies more than 750 types of secrets across public and private repositories.
    Cloud Infrastructure Entitlements Management
    Detects and manages excessive or unused permissions to mitigate the risk of privilege escalation.
    Real-Time Malware Detection
    Detects malware including zero-days in milliseconds with scanning performed directly in cloud environment for object storage services like Amazon S3 and file storage services.
    Multi-Workload Security Coverage
    Unified platform securing containers, serverless, Kubernetes, and AI workloads across AWS, on-premises, and multi-cloud environments
    Runtime Threat Detection and Enforcement
    Runtime protection to detect threats, block malicious activity, and enforce compliance in production across all cloud native workloads
    AI and LLM Security Governance
    Purpose-built AI workload security to govern large language models and generative AI applications with model abuse detection and policy enforcement
    Full Lifecycle Security
    Security coverage across the entire software development lifecycle from code development through production deployment
    Compliance and Authorization Standards
    FedRAMP High authorization enabling compliance with rigorous security and regulatory standards

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    -
    -
    -
    -
    -
    No security profile
    -
    -
    -

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.7
    341 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    78%
    21%
    1%
    0%
    0%
    24 AWS reviews
    |
    317 external reviews
    External reviews are from G2  and PeerSpot .
    Guilherme Ferreira Mury

    Integrated devsecops practices have prevented vulnerabilities across the application lifecycle

    Reviewed on Jul 29, 2026
    Review provided by PeerSpot

    What is our primary use case?

    In my previous experience with Orca Security , I was working on the DevSecOps  model, mainly using it for CI/CD pipelines, scanning our repositories for identifying vulnerabilities and breaking the build of the project if there are any high or critical vulnerabilities.

    Prioritizing risks using Orca Security  is straightforward; it has many tools for assessing and prioritizing risk, including CVSS for all vulnerabilities and the Orca  Score that considers the whole context of each vulnerability, helping me understand the true risk and impact.

    We had experience with the Orca  Sensor, but we did not think it brings too much value to our current environment, so we decided to remove it.

    I have used the Cloud to Dev feature in Orca Security before, but not as much as other features such as the DevSecOps  model.

    How has it helped my organization?

    Orca Security has helped me in preventing risks and attacks across my application life cycle by being the base of the whole secure development life cycle I implemented in my previous experience, which was crucial for detecting vulnerabilities both in development and runtime.

    What is most valuable?

    What I appreciate the most about Orca Security are the AI features for solving false positives and tackling some cases that are not entirely clear for my team, which helped greatly for investigating and dealing with those situations and proved to be highly accurate.

    What needs improvement?

    Some visualizations and dashboards in Orca Security were not as clear to me; even though I can edit and modify them as much as I prefer, the dashboards that came with the application were not ideal.

    There are not many negative aspects about Orca Security; I think it is a solid solution and the issue with the dashboards is more of a design preference of mine, so I am not certain if it qualifies as a downside.

    For how long have I used the solution?

    I have been working with Orca Security for around one to one and a half years.

    What do I think about the stability of the solution?

    I have not experienced any lagging, crashing, downtime, or any sort of instability with Orca Security.

    What do I think about the scalability of the solution?

    Orca Security is quite scalable; we had more than 500 projects on the platform, and adding more projects is a natural progression.

    How are customer service and support?

    I have contacted the technical support of Orca Security and had positive experiences; I always received quick answers and was able to resolve my problems.

    I would rate the support of Orca Security an eight on a scale from one to ten.

    How was the initial setup?

    The initial deployment of Orca Security was straightforward, but the configuration as a whole and integrating all of our tools and repositories was challenging, requiring significant work to configure it and put it into production.

    It took approximately two months to fully deploy Orca Security.

    What about the implementation team?

    Deploying Orca Security probably requires a team; a single person can deploy it, but not to its fullest potential, so you probably need more people and workforce to integrate everything effectively.

    Which other solutions did I evaluate?

    I have used Snyk  as an alternative security coding solution, and while it does not have as many functions and models as Orca Security, it works as a security coding solution as well. I am also currently evaluating Wiz , which is quite similar to Orca Security.

    I am not the person that interacts with the pricing of Orca Security, but the solutions have standard pricing; I do not think Orca Security is higher or cheaper than Wiz  or similar solutions. I know Snyk  is cheaper, but it does not have many of the models and functions that Orca Security has.

    What other advice do I have?

    I was a regular customer of Orca Security, responsible for operating it daily, and I do not have any current relation with them, but I remain impressed with the application as a whole. I would rate this review a nine out of ten.

    Fernando S.

    Orca Uncovered Agent-Reachable Secrets Fast, with Clear Context and Low Noise

    Reviewed on Jul 27, 2026
    Review provided by G2
    What do you like best about the product?
    We had a vague sense that credentials and secrets were scattered across our environment, but we didn’t have a clear map of which ones agents could actually see. Orca surfaced hardcoded API keys, SSH private keys, and database credentials in places agents or their tools might read—config files, storage buckets, and logs. It doesn’t just pattern-match; it uses entropy and the surrounding context to decide whether a string is truly a secret, which keeps the noise down. Seeing each secret in the context of agent reachability made it clear which exposures could be triggered by agents and needed immediate cleanup.
    What do you dislike about the product?
    We spent some time defining suppression rules for the test credentials in our sandboxes, so that agent-relevant secrets stayed front and center in the findings.
    What problems is the product solving and how is that benefiting you?
    It turned secret sprawl from an abstract worry into a concrete, prioritized cleanup list, with a special focus on the secrets that AI agents could stumble over. Exposed credentials have become a tracked, agent-aware risk rather than something we had to get to eventually.
    Jonathan X.

    Orca Delivers a True Shift-Left Win for IaC and Pipeline Security

    Reviewed on Jul 27, 2026
    Review provided by G2
    What do you like best about the product?
    Having Orca scan our infrastructure as code and our pipelines has been a genuine shift-left win for the AI agents. We started catching templates and configuration snippets that would have granted agents broad, long-lived permissions or exposed new agent endpoints before any of those changes ever deployed. Because Orca ties these IaC findings back to the same risk model it uses for the running environment, we can clearly see that a misconfiguration flagged in code is the same kind of agent exposure we’d otherwise be chasing down in production later.
    What do you dislike about the product?
    We worked closely with our platform team to integrate agent-focused checks cleanly into our build steps, and to decide which misconfigurations should trigger a warning versus block a deployment.
    What problems is the product solving and how is that benefiting you?
    It shifts cloud and agent security left in a way that actually sticks. We’re catching reachable, exploitable agent misconfigurations during code review instead of after agents are already live and exposed, which has made the whole pipeline safer without adding friction.
    Markose J.

    Orca Clarified Sensitive Data Exposure and AI Agent Access Paths

    Reviewed on Jul 26, 2026
    Review provided by G2
    What do you like best about the product?
    Orca gave us a much clearer picture of where sensitive data actually lives in relation to our AI agents. It surfaced PII in storage, secrets in places agents might read, and old database snapshots sitting in accounts that newly created agents were able to reach. The real value is the context: each finding shows what the data is, whether it’s exposed, and which agents and identities can access it. That turned what could have been an overwhelming inventory into a clear, prioritized list of data our agents should never be able to touch, along with the paths we needed to close.
    What do you dislike about the product?
    We spent a bit of time upfront tuning the data classification and agent reachability settings to align with our own definitions of sensitive information, as well as the agent access paths we consider unacceptable.
    What problems is the product solving and how is that benefiting you?
    It folds data security into the same agent-aware risk picture as misconfigurations and identities, so “where is our sensitive data, and which agents can reach it?” is finally a question we can answer continuously.
    Rio T.

    Orca Brings AI Agent Risk Into Clear Business Context

    Reviewed on Jul 26, 2026
    Review provided by G2
    What do you like best about the product?
    Our finance and enterprise risk teams wanted to understand AI agent risk in business terms, not just issue counts or an abstract idea of "agent exposure." Orca’s context—what data an agent can touch, whether it can reach internet-facing services, and which identities and systems sit behind its paths—lets us group agent-driven risks around business-critical assets and regulated workflows. It’s not a full quantitative risk engine, but it has given us a structured way to discuss which agent behaviors matter most to revenue, compliance, and our contractual obligations.
    What do you dislike about the product?
    We still add some business mapping on our side for certain agent-centric technical risks, so they line up neatly with the revenue streams and the contractual exposure.
    What problems is the product solving and how is that benefiting you?
    It has moved our security discussions with Finance and Enterprise Risk from “here is a pile of agent findings” to “here are the top agent-driven threats to the system” that actually drive cost and compliance exposure.
    View all reviews