Overview
Sweet Security delivers a runtime-powered detection and response platform that provides real-time visibility into applications, workloads, AI workloads and cloud environments.
Powered by deep runtime context and AI-driven analysis, Sweet detects sophisticated threats as they happen, cutting through noise and surfacing only what truly matters. Security teams gain the ability to investigate incidents quickly, understand attacker behavior in context, and respond decisively.
By focusing on real runtime activity rather than static signals, Sweet helps organizations move from reactive alert chasing to proactive threat detection and rapid response, enabling teams to stop real attacks in real time.
Highlights
- Widest coverage and unparalleled protection across the entire cloud stack within a single runtime solution.
- Lean sensor technology that requires minimal resources and takes only minutes to deploy.
- 30+ out-of-the-box integrations with SIEM, SOAR, notification and ticketing systems, and more.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
Sweet Primary | Secure 100 workloads with log-based cloud runtime protection | $50,000.00 |
Sweet Advanced | Secure 100 workloads with comprehensive cloud runtime protection | $60,000.00 |
Vendor refund policy
For more information about refunds, please contact support@sweet.security .
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
Personalized onboarding and on-demand training, 1:1 slack channel for fast communication with our technical teams, access to our docs for guides/how-to articles/best practices, support email available 24/7: support@sweet.security .
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

![Tenable Cloud Security [Private Offer Only]](https://d7umqicpi7263.cloudfront.net/img/product/f8dd5bda-e5d4-4005-a6de-de1c70986a74.png)
FedRAMP
GDPR
HIPAA
ISO/IEC 27001
PCI DSS
SOC 2 Type 2
Standard contract
Customer reviews
Cloud threat detection has transformed incident response and streamlined identity risk investigation
What is our primary use case?
My main use case for Sweet Security is that it helps my organization detect and respond to threats in the cloud environment such as AWS and Azure , and it is also used in runtime security to identify threat detection, attack path analysis, incident investigation, and threat response.
A specific example of how I have been using Sweet Security in my organization involved detecting unusual IAM activity in our AWS environment, where Sweet Security identified a service account that had begun accessing resources it normally would not, triggering an anomaly alert. The platform correlated identity activity, workload behavior, and cloud events to show a potential attack path where the compromised credentials would have been used to move laterally and access sensitive resources.
Once Sweet Security generated the alert for the unusual IAM activity, our SOC team first validated whether the activity was legitimate or potentially malicious by reviewing the correlated cloud events and identity context provided by the platform. Since the activity was deemed suspicious, we immediately disabled the affected credentials, notified the access keys, and revoked any unnecessary permissions. We then reviewed the attack path identified by Sweet Security to determine which resources could have been impacted and verified that no lateral movement or unauthorized access had occurred. Based on the findings, we updated our IAM policies to enforce least privilege access and strengthened monitoring rules to detect similar behavior in the future.
Regarding my main use case, Sweet Security has been helpful because it correlates identity workload and cloud activity into a single investigation, which has reduced the time required to understand the scope of the incident and prioritized remediation, enabling the team to respond much faster than if we had relied on manual log analysis alone.
What is most valuable?
In my opinion, the best features that Sweet Security offers include attack path analysis, which visualizes how an attacker could move through the cloud environment, making it easier to prioritize high-risk issues. The real-time visibility provides continuous monitoring of the cloud environments with actionable insights into security risks. Risk prioritization focuses on exploitable attack paths and high-impact risks instead of overwhelming teams with low-priority alerts. Identity threat detection detects suspicious IAM activity, privilege escalation, credential misuse, and anomalous access, and I personally appreciate the identity threat detection for its capability to detect suspicious IAM activity in the cloud environment.
The identity threat detection feature stands out the most for me, as it detects suspicious IAM activities related to roles and everything, making it useful if misused.
Sweet Security has positively impacted my organization by allowing us to identify and prioritize risks much more effectively in cloud security operations.
What needs improvement?
Sweet Security can be improved in many ways; it is a strong cloud security platform but has a few areas for improvement, such as a more customizable dashboard to allow teams to prioritize relevant metrics and alerts for their environment, and enhanced alert tuning to reduce noise and provide more granular control over detection policies. Despite these areas for improvement, the platform has been reliable and has significantly strengthened our threat detection and incident response capabilities.
I would appreciate seeing more dashboard customization, additional integrations with security and DevOps tools, and more detailed documentation, as these improvements can make the platform even more effective for day-to-day cloud security operations.
The points I have mentioned can be improved and then it will be fine.
For how long have I used the solution?
I have been using Sweet Security for the past four years.
What do I think about the stability of the solution?
In my experience, Sweet Security is completely stable.
What do I think about the scalability of the solution?
Sweet Security has scaled well as our cloud environment has grown, allowing us to expand coverage across additional cloud accounts, workloads, containers, and identities without significant operational overhead or noticeable performance issues. A key advantage is that it maintains centralized visibility across the environment while continuing to provide real-time threat detection and runtime monitoring.
How are customer service and support?
The customer support has been quite good; they are knowledgeable and helpful, and we have had a good experience with them.
Which solution did I use previously and why did I switch?
Before adopting Sweet Security, we primarily relied on a combination of native cloud security services and traditional SIEM-based monitoring for threat detection and investigations. While these tools provided good visibility, they required significant manual effort to correlate events across cloud identities, workloads, and network activity. We switched to Sweet Security because we wanted a more unified cloud detection and response platform with real-time visibility, attack path analysis, and contextual threat detection, as the platform's ability to automatically correlate cloud telemetry and prioritize exploitable risks significantly reduced investigation time and improved the efficiency of our SOC team.
How was the initial setup?
We were not involved in the initial setup as it was handled by our procurement and licensing teams. Despite being a premium security platform, we found the cost to be justified by the visibility, runtime threat detection, and operational efficiencies it provides.
What was our ROI?
We have seen a positive return on investment from Sweet Security, with the biggest gains coming from improved operational efficiency and faster incident response. The automated correlation of telemetry has significantly reduced investigation time. While it is difficult to assign an exact figure value, the combination of reduced resource and investigation work, faster response times, improved visibility, and stronger overall security posture has delivered a clear return on investment.
Which other solutions did I evaluate?
Before selecting Sweet Security, we evaluated several cloud security and cloud detection and response solutions, including Wiz , Palo Alto, Prisma Cloud, CrowdStrike Falcon , Lacework , and Microsoft Defender for Cloud .
What other advice do I have?
My advice for others looking into using Sweet Security is to clearly define your cloud security goals and involve both security and cloud engineering teams early in the evaluation and deployment process, as Sweet Security delivers the most value when it is integrated into existing cloud security and incident response workflows rather than used as a standalone tool. Sweet Security is a good security tool that every organization should use. I would rate this review a 9.
Runtime visibility has improved cloud security learning and prioritizes real attack paths
What is our primary use case?
My main use case for Sweet Security is evaluating cloud-native runtime security for Kubernetes-based applications. Given my background in backend development, API testing, Docker, and Kubernetes, I sought to understand how the platform provides runtime visibility and threat detection for containerized workloads. Although I haven't deployed it in a production environment yet, I have been exploring its capabilities as part of my learning in cloud security.
What is most valuable?
During my exploration of Sweet Security, the runtime visibility for cloud-native environments stood out to me. The platform focuses on application behavior and relationships between workloads rather than merely scanning for known vulnerabilities. The attack path visualization also caught my attention because it could help security teams prioritize actual risk exploitation rather than investigating every alert. Furthermore, the ability of Sweet Security to enhance collaboration between developers and security teams by providing better visibility into cloud applications could reduce manual investigations and increase security workflow efficiency.
What needs improvement?
I think the documentation could include more step-by-step examples for new users. It would also be helpful to have more integration guides for popular DevOps and CI/CD tools. Although the user interface is clean, adding more customization options for dashboards and reports could improve usability. Enhancements in these areas could help new users get started more quickly.
For how long have I used the solution?
I have been in this field for about two years through internships, academic projects, and hands-on software development.
What do I think about the stability of the solution?
I haven't used Sweet Security in production, so I cannot comment on stability from first-hand experience. However, based on what I have learned, it appears to be designed for reliable cloud-native development.
What do I think about the scalability of the solution?
From what I have learned, Sweet Security looks highly scalable, especially for organizations running Kubernetes and cloud workloads. It seems well-suited for growing environments.
Which solution did I use previously and why did I switch?
I wasn't replacing an existing solution, so I didn't switch from any other product. My interest in Sweet Security came from learning more about cloud-native runtime security. I was aware of other cloud security platforms such as Wiz, Orca Security, Prisma Cloud, and Lacework, but my evaluation focused on understanding Sweet Security's approach.
How was the initial setup?
The setup appears to be straightforward for cloud-native environments, based on what I have learned.
What about the implementation team?
Regarding the deployment in my organization, I focused on a public cloud setup because it is the most common environment for cloud-native applications.
What was our ROI?
My evaluation indicates that Sweet Security could provide a strong return on investments by reducing the time security teams spend investigating alerts, helping them prioritize critical threats more effectively, and improving incident response. Over time, these benefits could save operational effort and reduce the cost of responding to security incidents.
What's my experience with pricing, setup cost, and licensing?
I personally handle the pricing on licensing, so I cannot comment on the actual cost. However, the licensing seems appropriate for organizations looking for advanced cloud security, with value derived from improved visibility and faster threat detection.
Which other solutions did I evaluate?
I was aware of other cloud security platforms such as Wiz, Orca Security, Prisma Cloud, and Lacework during my evaluation of Sweet Security.
What other advice do I have?
Imagining the use of Sweet Security in a real-world team setting, I think it could save time by helping security engineers focus on the most important risks instead of checking every alert. Real-time detection and response features could replace manual investigation and improve collaboration between developers and security teams. AI-generated insights should always be reviewed by security professionals to ensure accuracy and avoid false positives. I have given this review a rating of eight out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Cloud runtime monitoring has transformed how our team detects threats and investigates incidents
What is our primary use case?
Sweet Security is evolved for the cloud native application protection platform. It focuses specifically on protecting cloud workloads by combining runtime telemetry with cloud security postures, identity, and data deployed in AWS , Azure , Kubernetes , or any cloud environment. Sweet Security plays a crucial role in providing runtime visibility and helping security teams prioritize real-time threats that are actively occurring in production. It provides dynamic runtime information for application security rather than just static analysis.
Sweet Security gives runtime visibility into cloud workloads and Kubernetes environments, correlates cloud infrastructure, workloads, identities, and application activity into a single investigation. It combines all activities related to a single identity and correlates all those alerts to make one incident, which helps SOC teams get all alerts related to that entity in one place. For organizations moving towards cloud environments, Sweet Security provides a reliable solution to protect cloud resources and supports major cloud platforms including AWS , Azure , and Kubernetes environments.
Before implementing Sweet Security, we did not have a solution specifically for cloud resources. We had a SIEM integrated Microsoft Azure and Defender. After incorporating Sweet Security, we observed a significantly higher number of alerts and more reliable alerts with greater visibility into what was happening at the cloud level in the runtime dynamic timeframe. We were able to get in-depth details about cloud resource sharing, uploads, and downloads, and our SOC team utilized it across a broad range of applications.
Sweet Security reduced most of the false positive alerts that we were getting through our SIEM . It provided more real-time interaction data, allowing us to identify threats more effectively. The alert logics available in the platform are very helpful for conducting in-depth investigations.
What is most valuable?
Sweet Security is a good tool for governance and security. It is a very reliable and secure tool because most cloud infrastructure has been integrated into it, and it has all the security plugins and policies in place to prevent data leaks. It is a reliable solution for cloud native application security.
Sweet Security is a next-generation application security tool with AI capabilities. The alerting functionality is continuously integrating and evolving. Whenever we found something needed in the tool, we contacted customer support and they implemented it. They are very helpful and ready to take feedback and make changes to the tool. Sweet Security is well-scalable throughout multi-cloud environments and Kubernetes clusters because it relies on lightweight runtime telemetry and cloud native architecture, allowing it to support growing cloud infrastructure of any size.
Sweet Security reduced most false positives and combines all alerts and events into a single alert or incident, which is helpful for the security team to review everything together. Initially, we had Defender for Cloud integrated with Sentinel , which did not provide complete visibility into SharePoint and all other cloud resources. After implementing Sweet Security, we were able to integrate all logs configured with our SIEM and Defender XDR , which was very helpful for fine-tuning incidents and creating organization-specific analytical tools.
Sweet Security combines all alerts into one single incident, which majorly addresses most of the problems that SOC environments face. We experienced an incident where a user was sharing multiple resources with third-party vendors. We received an alert about someone outside the organization sharing confidential data and project details with a vendor we had no prior communication with. Through the security team's investigation using Sweet Security, we discovered there was a new deployment plan happening with that vendor involving major confidential data sharing. Sweet Security is a value for money solution that helped us track cloud transactions and activities that we were previously unable to monitor.
What needs improvement?
Additional integration with third-party SIEM solutions and ITSM ticketing tools could be made easier. During the initial integration part, the platform sometimes flags anomalous problems when integrating with SIEM or SOAR solutions. Some of the reporting aspects could be fine-tuned, particularly dashboards and executive reports that could be summarized in a better way so that high-level personnel can understand them more quickly.
The reporting part could use more focus and improvement. Regarding AI capabilities, Sweet Security is already advancing into next-generation AI capabilities, which is moving in a better direction.
What do I think about the stability of the solution?
The platform has been stable during day-to-day operations with no noticeable downtimes. Runtime monitoring, alert generation, and cloud resource visibility have been very reliable without noticeable impact on any workload performance. Sweet Security delivers cloud-native service updates seamlessly and requires very minimal operational effort.
What do I think about the scalability of the solution?
Sweet Security scales well across all multi-cloud environments. Because it relies on lightweight runtime telemetry and cloud native architecture, it can support growing cloud infrastructure without any significant operational overheads. It appears very well-suited for organizations adopting modern DevSecOps and cloud native architectures.
How are customer service and support?
Whenever we faced any issue during the integration phase, we received very good direction to resolve the issues. The customer support is very helpful and knowledgeable. They have documentation that is very well organized and presented in a simple way.
Which solution did I use previously and why did I switch?
Sweet Security is the first application security solution that we implemented. Previously, security was totally managed by Defender for Cloud, but we later moved to Sweet Security based on client specifications.
How was the initial setup?
The integration process is very easy. In our environment, we integrated through AWS, so it was quite user-friendly.
What about the implementation team?
We directly contacted the customer through a middle-tier license provider to obtain the solution.
Which other solutions did I evaluate?
There are related security monitoring tools. Sweet Security is a better tool and provides layer-by-layer protected environments. It is a key competitor compared to others including Palo Alto, Wiz , and Microsoft Defender for Cloud . With Sweet Security for cloud, security is totally under control.
What other advice do I have?
When it comes to user experience, more time is needed to understand the tool, and then everything will fall into place. While integrating with some other SIEM or SOAR solutions such as Netskope , we encountered problems and had to repeatedly reach out to the support team, which was somewhat cumbersome. Licensing and cost have been handled by the higher organization, so we do not get involved with those aspects. My review rating for this solution is nine.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Runtime-first security has transformed real-time threat detection and reduced alert fatigue
What is our primary use case?
My main use case for Sweet Security as a distributor is to distribute to our partners within the UK channel, and they then take it to their customers who are looking for a cloud-native platform that offers advanced threat detection and incident response capabilities to provide deep runtime context to security teams, enabling them to quickly extract actual attack narratives. Sweet Security is designed to protect sensitive data in cloud environments, understand the environment, and respond to any threats as they occur. The platform leverages runtime insights to deliver comprehensive protection across all layers of the security stack.
I can provide a specific example of how one of my partners' customers has used Sweet Security in practice. Organizations primarily utilize Sweet Security for VM vulnerability management on cloud assets, particularly with AWS , which enhances runtime visibility and enables effective threat detection. Sweet Security is integrated for runtime protection and has evolved to support broader security ranges. It allows users to visualize cloud relationships, understand dependencies, and manage vulnerabilities from a code perspective. Sweet Security provides real-time security event response for security teams.
What is most valuable?
What stands out about my main use case and how my partners use Sweet Security is the deep runtime visibility and application layer security, particularly for APIs and microservices. This is where most traditional CNAPP solutions are weakest, and this is where Sweet Security performs exceptionally well. Additionally, in production environments, Sweet Security is focused on detecting and responding to real-life effects in live production environments. It correlates signals across cloud, apps, identity, and data into a single attack story. The way it contextualizes information in story form is another real positive, which I found mentioned by other reviewers as well.
Before Sweet Security, partners and customers needed to conduct extensive investigations when they found detection of activity across all different platforms and security logs until they could identify what was actually wrong in the bigger picture. Sweet Security enabled teams to see each detection of activity upon every request made from the application level towards the infrastructure, making it much easier and reducing the time for an analyst to understand what is really happening. It provides real-time visibility in the cloud environment, which is a massive differentiator because teams are seeing events as they happen, live in real time.
Sweet Security's capabilities in runtime coverage impact my overall security strategy and the strategies of my partners by allowing us to capture threats as they occur in the live production environment in real time. We are capturing code-level events because we have shifted right in our approach. This is a key point to add: we are not traditional tools on the left side of the shift. We shift right, which means we operate in production and in real time. We are not pre-code or pre-cloud. We have shifted right, and this is a massive positive for time efficiency, workload efficiency, and more importantly, being proactive rather than reactive across the cyber landscape.
What needs improvement?
Sweet Security can be improved in terms of product maturity and ecosystem. It has a smaller market presence, so we do not have as many large enterprise deployments. Sweet Security is less mature than competitors such as Wiz or Palo Alto Networks. Some competitors provide better integrations and workflow tooling. Additionally, as a new vendor, there is a new market perception and higher perceived risk, which relates to trust of the product. Some competitors are seen as safer and more established choices. Since Sweet Security operates in the production live environment, there have been a couple of problems reported where issues occurred in production environments. However, these have been resolved within about an hour or two. Having that risk is always going to be a negative.
As a cloud-native platform solution, Sweet Security is really good overall. There are only a couple of areas for improvement, such as not being fully 100% production safe, and the reality that its competitors are global, well-known companies such as Palo Alto and Wiz .
For how long have I used the solution?
I have been working in my current field for about 18 months. I have been using Sweet Security for about 18 months, as long as I have been working within cyber. Sweet Security, as a cloud-native platform, has been part of my experience for approximately 18 months.
What do I think about the stability of the solution?
From my observations, Sweet Security is stable, as I find that user experience does not tend to reveal many production problems, and when they do occur, they are resolved quickly. Users have reported that they are very satisfied and Sweet Security garners praise while maintaining a stable environment across diverse scenarios. It is extremely stable, and I would give it a nine out of ten because if a problem does occur, it is resolved quickly.
What do I think about the scalability of the solution?
Regarding scalability, I find that deployment is quite straightforward across multiple different infrastructures. However, regarding performance with large-scale infrastructures, particularly those of enterprises across cloud assets, it sometimes struggles. Smaller to medium-sized enterprises or organizations represent the sweet spot for Sweet Security. There may be a couple of issues with scalability at the top level of enterprise and large organizations. While many find the scalability is good, it could be rated a bit lower if it was trying to cater exclusively to enterprise organizations. The best sweet spot is small to medium organizations, and there have been some issues with scalability across large enterprise organizations.
How are customer service and support?
Sweet Security excels in customer support, as they provide on-hand, prompt, hands-on assistance. Their customer service and CSM team address issues, and users get a line to a specialist who are the right experts and are involved in technical support. They are quick to resolve any issues that are encountered. This is why, even if the price is a bit higher, users get ROI from the price they pay because of the constant user help provided by customer service and support.
I would rate customer support a nine out of ten because they maintain a competitive price, offer trial periods, provide follow-up, are very responsive, and are effectively hands-on in assisting and offering prompt service and support.
How was the initial setup?
Sweet Security is deployed in my organization in a straightforward manner for multiple users across our partners and customers. While some experienced a few challenges, including a couple of bug log connections, the process was mostly easy and quick to implement. Generally, across variant sizes of teams, the setup was effective and took a couple of days depending on the approach from the security teams.
What was our ROI?
Sweet Security has positively impacted my organization by providing faster incident response in minutes versus hours, reducing alert fatigue through significant noise reduction because of the prioritization feature, giving better prioritization of exploitable risk, and providing better coverage for both traditional and AI-based apps. Sweet Security also improves visibility across multi-cloud environments and provides a unified visible platform. Most of the cyber landscape is moving toward platform plays, so Sweet Security is well-positioned in this direction. Most importantly, it moves from finding misconfigurations to detecting and stopping threats in real time in the environment.
Alert fatigue is always happening because at the end of the day, what we look for is not swimming through noise. Therefore, time is saved by the analyst or security team. The ROI is that we are not waiting for a breach but being proactive rather than reactive. Most people in that proactive phase find that it gives them the ability to find their infrastructure's breach attack paths and understand where they are most vulnerable to exposure. Sweet Security really does provide that proactive rather than reactive mentality within the cyber landscape.
Sweet Security has helped my team and my partners prioritize risks and threats more effectively because everything that comes out represents real-life detects and threats. Every time we see a threat, we push it through to our first-line support team so they can action it. Everything we see on Sweet Security then gets pushed and actioned because it represents real-time threats, and we are getting ahead of the curve. We can then over time as an ROI see where we are best suited and where we are finding most risks. From there, in our security stack or platform, we can assess whether we need to invest in a new tool, giving us ROI to take through the board to explain that this is where we are getting breached most and that having a tool like X will help with Y.
I have seen a return on investment where time saved is the best benefit because we are not working through hundreds of vulnerabilities. Sweet Security condenses it down, contextualizes it, and allows us to identify what is really going to breach us in real time. That is the best ROI. Additionally, we can spend less time worrying about where we will not get breached with vulnerabilities that might not be anywhere near breachable. However, if we find that certain cloud vulnerabilities come up time and time again, we can look into a tool that will help that as well. We can invest in that tool and go to the board or executive level explaining that we need this tool because Sweet Security has pinpointed specific issues, and we need to have this to prevent that from happening because we are seeing that as an ongoing problem we keep finding using Sweet Security.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing has been that Sweet Security's pricing is quite fair and cost-effective by many users. It is not the cheapest option, but it offers competitive rates compared to its competitors. It shows better value through ROIs by reducing reliance on other tools because you can have Sweet Security as a platform across many different cloud tools. Obviously, the pricing depends on the specific company and what they are actually using it for, but overall, it highlights great value. Sweet Security works well for enterprise-level businesses, which many startups or newer companies struggle with. Overall, it is a fair and cost-effective solution because of the platform play and how it integrates and works.
Which other solutions did I evaluate?
I evaluated other options before choosing Sweet Security, including Wiz and Palo Alto. I also work with Tenable as a CNAPP platform, as they have released a new cloud component as part of their Tenable One platform.
What other advice do I have?
I would describe the effectiveness of Sweet Security's Layer-7 network traffic inspection in understanding application requests and responses as very important. Sweet Security monitors real-time API and service-to-service traffic in production while building context around normal versus abnormal application behavior. What Layer 7 detects in Sweet Security is essential because many modern attacks do not break infrastructure; they abuse applications. Traditional CNAPP tools often just look at misconfigurations and CVEs, whereas Sweet Security adds depth by focusing on runtime behavior. Sweet Security's Layer 7 capability means real-time visibility into API and application behavior to detect attacks that bypass infrastructure-level defenses.
I would assess the integration of LLMs in Sweet Security's vulnerability management as beneficial because they can summarize complex runtime security events in plain English. This gives faster alert triage and investigation and reduces alert noise. CNAPP tools can normally generate many alerts, but LLMs filter duplicates, group related issues, and prioritize real threats. This is why we are experiencing better time efficiency because we are prioritizing real threats and taking away alert fatigue. LLMs help interpret API and application layer behavior, which is useful for understanding normal API flows and authentication abuse, providing strong Layer 7 contextual analysis. Additionally, LLMs enable executive-ready reporting by converting technical incidents into summaries, impact analysis, and business risk explanations, making it much easier to communicate with leadership. The LLM integration with Sweet Security improves detection, reduces noise, and turns complex runtime cloud security data into clear, actionable intelligence.
My advice to others looking into Sweet Security is to examine whatever cloud-native platform they have, run a free trial, and attempt a proof of value or proof of concept. Learn about it, use it, and compare it to what you currently have. Although it may not be as well-known as Wiz, Palo Alto, or Tenable CNAPP, Sweet Security definitely stands the test of time and is a great product. Everything I have mentioned is truly excellent. Sweet Security represents the next generation of CNAPP that differentiates through a runtime-first approach and focuses on detecting and responding to real attacks in environments. For me, that provides correlating signals across cloud, app, and identity. What stands out against traditional tools is that we are shifting right in our approach. If you want to be proactive rather than reactive, Sweet Security is a strong CNAPP enterprise vendor that any organization should consider.
As a shifting-right technology in the production environment responding to real-time threats with Layer 7 integration and LLMs to help contextualize risk and show where breaches will occur rather than providing a long list of vulnerabilities, Sweet Security offers competitive pricing and great customer service. I would highly recommend that people research Sweet Security, trial it, and definitely compare it to their current CNAPP platform. I would rate this review an eight out of ten overall.
Continuous runtime security has improved visibility while the interface still needs refinement
What is our primary use case?
I'm mostly using Sweet Security for real-time infrastructure security. If there is any threat, I want to detect it in real time. That's the main use case. Vulnerability management is one other benefit I am getting from Sweet Security as well.
What is most valuable?
In terms of the best features of Sweet Security, I haven't had any threat detected in the sense that there hasn't been any incident so far while Sweet Security is in place. In terms of vulnerabilities, I got some good findings and some good vulnerabilities were detected. Software that was on my infrastructure had known vulnerabilities and I was able to patch it timely. These things I was unaware of before installing Sweet Security on my infrastructure. So it was pretty good.
The Layer 7 network traffic inspection in Sweet Security has been pretty good. It can understand the traffic that's coming and can find potential credentials from users in this traffic, for example. Overall, it can detect sensitive data in this traffic very well.
Having runtime coverage with Sweet Security is also one of my audit requirements toward getting a certification. So having this in place will help me toward getting a certification in the future.
Having real-time visibility into my cloud environment with Sweet Security has changed the way my team detects and responds to threats. I didn't have a tool in place before. I have established a process for potential real-time threat findings, but I haven't had any yet, so I was not able to test this process yet.
Sweet Security helps unify various aspects of security detection into a single platform. It provides real-time infrastructure security and vulnerability management. It also monitors Layer 7 traffic for credential leaks and helps with vulnerability management on cloud accounts to detect if something is not configured properly. It's a lot of different functionality.
For the time I have been using Sweet Security, I feel a bit more safe in the sense that there is something that continuously scans my infrastructure for issues. I didn't have a solution in place for that before. So it has provided me peace of mind. In terms of actual findings, it found several vulnerabilities in my software. This has been definitely a benefit toward operating more secure software on infrastructure.
What needs improvement?
One thing I think Sweet Security can definitely improve is that they have a lot of features, but the UI right now is not so well designed in my opinion. It's a bit difficult to navigate and get to the signal. There is a lot of signal there, but it's a bit difficult to get to the correct place and understand what I am seeing. It has a small learning curve that I don't think such a product should have. It should be very straightforward.
Sweet Security has a mechanism where they initially show all the vulnerabilities that are in my infrastructure, which they show as a huge number, maybe around ten thousand, and they narrow it down to which of these could actually be exploited and are actually severe. It's nice that they are able to narrow it down to a few incidents. However, they don't really need to show this in the UI. Maybe they can just show the actual signal and not show that there is a lot of vulnerabilities, but indicate which are important. That's good that they can do it, but it's not so important to see it every time in the platform.
For how long have I used the solution?
I have been using Sweet Security for one to two months.
What do I think about the stability of the solution?
There were some issues during the proof of concept with Sweet Security. I would rate the stability at nine out of ten.
What do I think about the scalability of the solution?
I have a feeling that Sweet Security is better for small to medium-sized companies. I cannot give a one hundred percent answer here because I haven't tried to scale it. My infrastructure is not very big and my team is not very big, so these are just assumptions. However, the user interface that I see doesn't make me very confident that I will be able to extract information in case I had hundreds or thousands of Kubernetes clusters or hundreds or thousands of hosts. In terms of scalability, I would rate Sweet Security at five out of ten.
How are customer service and support?
If I take into account everything and all the support I received during the onboarding of Sweet Security, I would score it at nine out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have previously used Wiz .
How was the initial setup?
I wouldn't say the deployment of Sweet Security is too complex. There was some bug in the Sweet Security UI at first that didn't allow me to fully connect the sensor to AWS logs or something. However, apart from that, once they resolved this issue, the installation itself is not very difficult. It's straightforward. It took days to get Sweet Security implemented.
What was our ROI?
With Sweet Security, it's something around ten to twenty percent resources saved.
What's my experience with pricing, setup cost, and licensing?
One very strong point of Sweet Security is their pricing. It's really good. Also, their team is very good, very responsive, and motivated. They gave me a trial period, did multiple follow-ups, and were reviewing themselves the findings to actually understand how their product is performing. I got a very hands-on team compared to other solutions I evaluated where I didn't see such an attitude.
Which other solutions did I evaluate?
We didn't evaluate other tools as we were moving from a purely manual process. Implementing Sweet Security automated our monitoring and alerts, saving us approximately 20% in time compared to our previous manual methods.
What other advice do I have?
I am using the eBPF sensor in Sweet Security. The usage of the eBPF-based sensor has been pretty low. I was concerned about this initially because these sensors typically are pretty resource-intensive. However, this specific one is below one gigabyte of RAM and has very low CPU usage. The RAM consumption is around three hundred megabytes and the CPU usage is around three percent of one core. It's super low.
I haven't tried the LLM-based reply scanning feature in Sweet Security yet. I recently received a message that they are also doing LLM reply scanning now, but I haven't tested this one yet.
It hasn't really saved me time, I would say. It actually creates more work because it makes me aware of things that I was not aware of before. I would probably receive a different answer from a company that had another tool before and now has Sweet Security, but for me, I didn't have any tool before, so Sweet Security creates more work now. However, it's good to have.
Babylon is a pretty small company, so the number I'll give for Sweet Security usage is up to ten users. That's a small number.
I am a global company with Sweet Security and operate remotely.
I have integrated Sweet Security with AWS and have integrated it with my own on-premises infrastructure as well. I have tried a few more integrations. I requested an integration with PagerDuty and an integration with GitHub audit logs, which they both don't have. They haven't implemented this and it's been almost half a year now. So they have some things, but they could have more.
I would definitely recommend Sweet Security to companies like mine, to small companies, small to medium-sized companies, or startups that need somewhere to start, need to get a lot of things from a single tool, don't want to pay a lot of money, and want to build the initial security. My overall review rating for Sweet Security is seven out of ten.