Overview

Product video
TrendAI Vision One™ gives enterprises and security leaders the power to see, secure, and control their entire multi-cloud and hybrid environments from a single, unified platform. Gain complete visibility with real-time risk scoring, threat exposure mapping, and centralized monitoring all from one intuitive dashboard.
Backed by AI, machine learning, and predictive analytics, TrendAI Vision One™ empowers proactive cloud security by automating threat detection, risk mitigation, and response. Streamline operations, reduce security complexity, and offload the pressure on your teams with modern CNAPP capabilities so you can stay ahead of every attack.
Trusted by industry leaders and recognized as a 2024 Gartner Peer Insights™ Customers' Choice for CNAPP, Trend Vision One is proven to reduce operational costs by up to 79% and accelerate detection and response times by 70%. It's also a Leader in the 2025 Gartner® Magic Quadrant for Endpoint Protection Platforms, delivered a 100% detection rate in MITRE evaluations, and was named a Leader in the IDC MarketScape for Cloud-Native Application Protection Platforms 2025, solidifying its position as the most trusted platform for securing the cloud.
Confidently secure your cloud transformation with a platform built for the modern enterprise. From hybrid to multi-cloud, TrendAI Vision One™ delivers unmatched protection, visibility, and control - wherever your workloads live.
Trend provides custom pricing via Private Offer. Please contact us if you're interested in personalized pricing options.
Highlights
- Identify and eliminate hidden cloud risks with unified Cyber Risk Exposure Management - discover assets, prioritize vulnerabilities, and manage posture and attack surface all from one place.
- Stay steps ahead of threats with XDR for Cloud, which extends visibility into cloud environments and streamlines SOC investigations through powerful correlation and alerting.
- Secure every application and workflow - from containers and code to S3 files and cloud workloads - with holistic protection via the integrated stack: Container Security, File Security, Workload Security, and Code Security.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Security credentials achieved
(4)




Buyer guide

Financing for AWS Marketplace purchases
Pricing
Free trial
Dimension | Description | Cost/12 months |
|---|---|---|
TrendAI™ Flex (credits) | A credit-based licensing model that offers flexibility, simplifying purchasing, deployment, and management of Trend Vision One solutions. | $1.00 |
The following dimensions are not included in the contract terms, which will be charged based on your usage.
Dimension | Description | Cost/unit |
|---|---|---|
Cyber Risk Exposure Management - Cloud Risk Management | Per 500 resources per cloud account per hour | $0.12 |
Container Security | Per Amazon ECS instance or Kubernetes node per hour | $0.168 |
Container Security | Per serverless container pod or task per hour | $0.017 |
File Security SDK | Per file scan | $0.013 |
File Security Storage | Per cloud storage per hour | $1.155 |
Endpoint Security - Essentials | Per workload (Anti-Malware, Web Reputation, and XDR only) per hour | $0.007 |
Endpoint Security - Small | Per EC2 instance (micro to medium), WorkSpace, or other cloud (1 vCPU) per hour | $0.011 |
Endpoint Security - Medium | Per EC2 instance (large), WorkSpace, or other cloud (2 vCPU) per hour | $0.032 |
Endpoint Security - Large | Per EC2 instance (XL), WorkSpace, or other cloud (4 vCPU) per hour | $0.047 |
Endpoint Security - Non-Cloud | Per data center or non-cloud instance per hour | $0.047 |
Dimensions summary
Top-of-mind questions for buyers like you
Vendor refund policy
No refunds
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Support
Vendor support
Your purchase also includes 24x7 support from Trend Micro. You can log a support ticket for any issues directly from your TrendAI Vision One™ console. If you experience any issues or have questions, please contact our AWS Security experts by email at aws.marketplace@trendmicro.com .
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
FedRAMP
GDPR
HIPAA
ISO/IEC 27001
PCI DSS
SOC 2 Type 2
Standard contract
Customer reviews
Centralized visibility has improved threat detection and has reduced response time significantly
What is our primary use case?
Trend Vision One serves as my use case starting simply with its sensor agent as a basic Endpoint Detection and Response solution. After that, we started using its endpoint protection, and now we are integrated with its NDR solution, which is Network Detection and Response . We are moving forward towards its complete suite.
What is most valuable?
The best features of Trend Vision One that I prefer most are two main ones. One of them is its Attack Surface Discovery, which gives us the overall security posture of our network. The second is its Observed Attack Techniques section, which is mapped on MITRE ATT&CK and gives us an overall view of what is happening in our system and provides us with automatic detections based on the telemetry data.
What needs improvement?
One area that has room for improvement is the interface of Trend Vision One, which is very slow due to its data center being based in America. If the data center were in a nearby location, its response would be very quick. I think just the interface because everything else we can find in Trend Vision One such as endpoint protection, D-SIM security, DLP solution, and FIM , so there is nothing left behind.
For how long have I used the solution?
I have been using Trend Vision One for almost two years.
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
Trend Vision One is very scalable. We can integrate different solutions with it and perform some type of automation with this solution, so it is very scalable. I would rate it nine.
How are customer service and support?
I would rate the technical support that Trend Micro provides as seven point five. It depends on the functionality we are using. In most cases, the support quickly resolves the issue, and in some cases, they take some time.
How would you rate customer service and support?
Positive
How was the initial setup?
The deployment of Trend Vision One is very handy. There are not any complex issues I faced during the deployment, and it is a very quick deployment. The different guides they provide during deployment and for other configurations help us a lot in the overall deployment of the solution. The deployment process took approximately one point five to two months overall. We are working on an enterprise solution, so for each step, we have to do some testing on the configuration and then we do a full deployment. We are still testing its new features and enhancing it, so it is an ongoing process for us.
What other advice do I have?
We are using the sensors of Trend Vision One to cover almost seven thousand endpoints. It is covering our enterprise endpoints, and it is very critical to get overall telemetry data from all of the endpoints. It gives us better visibility into what is actually happening on these systems.
The top security challenges I faced in my industry before using Trend Vision One were about getting the whole telemetry data, meaning what is actually happening on the system. SIEM solutions only get limited logs, and secondly, we could not calculate our attack surface, which means what is our proper security posture and where we are standing according to our security level.
My impressions of Trend Vision One's ability to provide centralized visibility and management across protection layers is that it provides overall very good visibility in the network. It gets integrated with other security solutions, and we can centrally manage it. It can be integrated with our Active Directory, our firewalls, and security solutions for automatic IOCs blocking. In that respect, it is very much better.
Regarding the Cyber Risk Exposure Management , it helps my organization identify blind spots by calculating based on the vulnerabilities identified on our endpoints, the configuration settings on different endpoints, and on the Active Directory level, the number of alerts we are getting from different points. By calculating all of these, it gives us an overall percentage. Based on that, we assess how we are actually standing in terms of our security posture.
The solution has helped consolidate the use of security vendors because we are also using its MDR service for critical and high-level alerts, and it is cloud-based, so we do not usually need any type of vendor support to solve daily issues. If we get anyone, we can directly open a case with Trend Vision One, and the issue can be solved within one or two days.
Almost fifty people use the solution. They are all in Pakistan and working on-site.
The Service Gateway Management machine we use in our network requires maintenance on a monthly basis or every one to two months when we get a new update from them. To manage the different types of functionalities it provides, its license is credit-based, so we have to carefully use all of the functionalities provided by Trend Vision One. So it requires some type of maintenance as well.
Maintaining Trend Vision One is very easy and very handy.
I do not know the exact pricing of Trend Vision One, but the type of structure licenses they provide is very useful for us. We purchase overall credits and can use these credits according to our needs. So the structure of licensing is very much better than other vendors.
I chose Trend Vision One here in Pakistan because we have their principal support here in Pakistan, and we can directly connect with them and reach out to them. So the main purpose of purchasing Trend Vision One was its principal support.
Trend Vision One has reduced our time to detect and respond to threats almost sixty-five to seventy percent. We get alerts in real-time on the Observed Attack Techniques section, and for the higher critical alerts, our MDR service from Trend Micro sends us an email alert within approximately thirty minutes, and they also give us a call reminder to respond to that alert. Then it depends on us how we respond to that alert with different teams and come to the solution.
I cannot quantify by how much Trend Vision One has reduced our false positives, as we get false positive alerts on a daily basis. But in the high and critical section, we only get the most relevant alerts. In the medium and low sections, there are very false positive alerts and we are working with Trend Micro and our vendor to reduce these observed attack techniques.
I would recommend Trend Vision One because it provides many services in a single console, such as Attack Surface Discovery, awareness session, vulnerability, attack simulation, DLP , and many other EDR services, NDR services, and email security gateway. I would recommend this suite as one console can be used for many solutions.
It is very important for us that Trend Vision One has AI built into the platform as we are doing a proof of concept for its new technology, which is called ZTSA. The industry is evolving with respect to artificial intelligence, and we have to secure that area from both data leakage and data protection. So it is very important, and we are doing a proof of concept of ZTSA, which is its new feature of Trend Vision One.
I rate this review nine overall.
Centralized protection has improved threat response and simplified endpoint security management
What is our primary use case?
My use case for Trend Vision One is deploying it for an entity within a company. I deployed Trend Vision One to protect all kinds of endpoints, including mobiles, machines, mailboxes, and servers.
What is most valuable?
The best features of Trend Vision One that I appreciate include its centralized nature, the Copilot AI agent, its simplicity of use, and the quality of their API.
Trend Vision One has helped reduce my time to detect and time to respond to threats by approximately 10%.
What needs improvement?
To improve Trend Vision One to a perfect score, I believe better pricing and more support would be ideal.
For how long have I used the solution?
I have been using Trend Vision One for one year.
What do I think about the stability of the solution?
I would rate the stability of Trend Vision One highly, as there were no bugs. I would give it a 10.
What do I think about the scalability of the solution?
Regarding scalability, Trend Vision One is scalable. I would give it an eight.
How are customer service and support?
I rate the technical support an eight.
The coverage for my organization's network is critical. When we have questions, we return to them. When we need something, we return to them, and they were always available.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
The risk reduced by switching to Trend Vision One is similar to other EDR or XDR solutions. It can detect malicious operations and threats, but the exact percentage is difficult to quantify. For the company I was deploying it for, we detected many threats. I would rate the risk reduction as a 10 because the company in question did not have an XDR or EDR solution in place before.
How was the initial setup?
The deployment of Trend Vision One is easy; it is just an executable.
It takes almost one day for Trend Vision One to appear in the console.
What about the implementation team?
In my organization, we had four specialists working with Trend Vision One: myself and three security engineers. I was the project manager.
What was our ROI?
I can estimate the ROI seen from Trend Vision One to be approximately 15%.
What's my experience with pricing, setup cost, and licensing?
When it comes to pricing, I find Trend Vision One not expensive compared to other products.
Which other solutions did I evaluate?
I compare Trend Vision One with other solutions and vendors on the market, and we can see that it is well-placed in Gartner, so it is one of the best products.
What other advice do I have?
Trend Vision One helps with centralized visibility and protection across multiple layers.
The visibility and protection provided by Trend Vision One allow us to see all the assets in one console, which is beneficial. We can also see all the features in one console, which is equally advantageous.
I did not use the cyber risk exposure management capabilities with Trend Vision One, nor did my clients use that for identifying blind spots.
The top security challenges in the industry include handling the decommissioning of old products, specifically a Microsoft product. Additionally, not all features are centralized in one console, which is not ideal for the correlation of investigations.
Trend Vision One is deployed as a cloud solution and a SaaS solution.
I used Trend Vision One sensors.
I would recommend Trend Vision One to other users because it is easy to use and easy to deploy, as these are the most important factors. The importance of having AI built into Trend Vision One is significant; I use the AI aspects. When I want to look for a feature, I go to AI. When I want to create, for example, an IOC, I go to AI, and it assists with this.
Robust Security Tool with Centralized Management, Needs Improved License Control
Unified Security Dashboard and Effortless Integration
I've been using Trend Vision One for [1-2 Years] in our company, Amagi Media Labs Ltd, and wanted to share what I like best.
1. Unified Dashboard - The single pane of glass for threat detection across endpoints and cloud workloads. Real-time correlation of alerts reduces noise and speeds up investigation.
2. Easy Deployment & Integration - Third-party integrations and flexible licensing make onboarding simple, even for smaller teams.
3. Advanced Detection - Signatureless anomaly detection, user behavior analysis, and proactive risk assessment catch threats.
4. Reliable Performance - Minimal resource impact and strong endpoint protection provide peace of mind for our infrastructure.
I've been using Trend Vision One for [1-2 Years] in our company, Amagi Media Labs Ltd, and appreciate its unified detection capabilities. Here's the honest feedback on pain points to help prioritize roadmap items.
1. Frequent UI changes/UI Navigation - The interface is feature-rich but sometimes overwhelming - streamlined workflows for common tasks would improve usability. Navigation feels unstable and disrupts workflows.
2. False Positives and Alert Noise - low-quality alerts require excessive investigation time.
3. Support response times - Tier 1 support is slow to escalate
Problems solved:
Complex Threat Hunting - Manual investigations took hours/days. XDR now provides attack path visualization, MITRE ATT&CK mapping, and automated playbooks for rapid response.
Scaling Security Operations: Growing threats overwhelmed our small team. Unified console and automation handles multi‑cloud, OT, and hybrid environments efficiently.
Vision One correlates events across layers with AI, reducing noise by 99.6% and dwell time by 65%.
Benefits:
Proactive Defense: AI‑powered anomaly detection catches zero‑days and advanced persistent threats (APTs) early.
Team Efficiency: 92% cyber risk reduction lets our SOC focus on high‑value tasks instead of false positives.
Vision One has transformed our security posture from reactive to proactive. It’s now our central platform for endpoint, cloud, and email protection.
Maximized Efficiency and Cost Savings for SOC Teams
Alert Fatigue Reduction: Advanced filtering and correlation can reduce daily alert noise by over 90%, allowing SOC teams to focus on real threats.
Cost Efficiency: By consolidating multiple tools (SIEM, SOAR, EDR) into one platform, many companies report up to a 70% reduction in overall cybersecurity costs
The Solution: It provides Unified Visibility across all layers (Endpoint, Email, Network, Cloud, and Identity). It even detects "unmanaged" devices that aren't officially on your network.
+1
The Benefit to You: It reduces "Dwell Time"—the time an attacker spends in your system before being caught—by an average of 65%. You see the attack the moment it moves from an email to a server