Orca Security CNAPP Cloud Security Platform - GovCloud logo

    Orca Security CNAPP Cloud Security Platform - GovCloud

    Agentless Cloud Security in a Single, Complete Platform with 100% Coverage

    Ratings and reviews

    4.3
    31 ratings
    3 star
    2 star
    1 star
    52%
    48%
    0%
    0%
    0%
    24 AWS reviews
    |
    7 external reviews
    External reviews are from PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (31)
    Guilherme Ferreira Mury

    Integrated devsecops practices have prevented vulnerabilities across the application lifecycle

    Reviewed on Jul 29, 2026
    Review provided by PeerSpot

    What is our primary use case?

    In my previous experience with Orca Security, I was working on the DevSecOps model, mainly using it for CI/CD pipelines, scanning our repositories for identifying vulnerabilities and breaking the build of the project if there are any high or critical vulnerabilities.

    Prioritizing risks using Orca Security is straightforward; it has many tools for assessing and prioritizing risk, including CVSS for all vulnerabilities and the Orca Score that considers the whole context of each vulnerability, helping me understand the true risk and impact.

    We had experience with the Orca Sensor, but we did not think it brings too much value to our current environment, so we decided to remove it.

    I have used the Cloud to Dev feature in Orca Security before, but not as much as other features such as the DevSecOps model.

    How has it helped my organization?

    Orca Security has helped me in preventing risks and attacks across my application life cycle by being the base of the whole secure development life cycle I implemented in my previous experience, which was crucial for detecting vulnerabilities both in development and runtime.

    What is most valuable?

    What I appreciate the most about Orca Security are the AI features for solving false positives and tackling some cases that are not entirely clear for my team, which helped greatly for investigating and dealing with those situations and proved to be highly accurate.

    What needs improvement?

    Some visualizations and dashboards in Orca Security were not as clear to me; even though I can edit and modify them as much as I prefer, the dashboards that came with the application were not ideal.

    There are not many negative aspects about Orca Security; I think it is a solid solution and the issue with the dashboards is more of a design preference of mine, so I am not certain if it qualifies as a downside.

    For how long have I used the solution?

    I have been working with Orca Security for around one to one and a half years.

    What do I think about the stability of the solution?

    I have not experienced any lagging, crashing, downtime, or any sort of instability with Orca Security.

    What do I think about the scalability of the solution?

    Orca Security is quite scalable; we had more than 500 projects on the platform, and adding more projects is a natural progression.

    How are customer service and support?

    I have contacted the technical support of Orca Security and had positive experiences; I always received quick answers and was able to resolve my problems.

    I would rate the support of Orca Security an eight on a scale from one to ten.

    How was the initial setup?

    The initial deployment of Orca Security was straightforward, but the configuration as a whole and integrating all of our tools and repositories was challenging, requiring significant work to configure it and put it into production.

    It took approximately two months to fully deploy Orca Security.

    What about the implementation team?

    Deploying Orca Security probably requires a team; a single person can deploy it, but not to its fullest potential, so you probably need more people and workforce to integrate everything effectively.

    Which other solutions did I evaluate?

    I have used Snyk as an alternative security coding solution, and while it does not have as many functions and models as Orca Security, it works as a security coding solution as well. I am also currently evaluating Wiz, which is quite similar to Orca Security.

    I am not the person that interacts with the pricing of Orca Security, but the solutions have standard pricing; I do not think Orca Security is higher or cheaper than Wiz or similar solutions. I know Snyk is cheaper, but it does not have many of the models and functions that Orca Security has.

    What other advice do I have?

    I was a regular customer of Orca Security, responsible for operating it daily, and I do not have any current relation with them, but I remain impressed with the application as a whole. I would rate this review a nine out of ten.

    reviewer2879382

    Cloud security has improved posture and simplifies risk remediation and alert response

    Reviewed on Jul 23, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Orca Security is to secure infrastructure, course, and service. A specific example of how I use Orca Security to secure my infrastructure or services is for vulnerability management on VMs or other resources in Azure or AWS.

    I have more to add about my main use case with Orca Security, including security posture frameworks such as ISO 27007 and 9001.

    What is most valuable?

    The best feature Orca Security offers is a remediation solution. What I appreciate most about the remediation solution is that it provides a fast fix for the vulnerabilities in my day.

    Orca Security has positively impacted my organization by improving our security posture and hardening our services and resources.

    What needs improvement?

    Regarding how Orca Security can be improved, I think there is not much; it is fully completed and it is great.

    For how long have I used the solution?

    I have been using Orca Security for around two years.

    What do I think about the stability of the solution?

    Orca Security is stable.

    What do I think about the scalability of the solution?

    The scalability of Orca Security is great.

    How are customer service and support?

    I find the customer support to be excellent. I would rate the customer support a ten.

    Which solution did I use previously and why did I switch?

    I did not use a different solution before Orca Security; it is the one and only for me.

    What was our ROI?

    I do not know if I have seen a return on investment with Orca Security; I cannot share any relevant metrics.

    What's my experience with pricing, setup cost, and licensing?

    Regarding my experience with pricing, setup cost, and licensing, I think that is not my place in the company.

    Which other solutions did I evaluate?

    Before choosing Orca Security, I evaluated other options, such as Wiz or Google, perhaps.

    What other advice do I have?

    My advice to others looking into using Orca Security is to practice and study the platform in test scenarios. My impressions of the risk detection and identification capabilities of Orca Security are fascinating because they are clear and serve as a guide. Orca Security has helped my organization reduce the time it takes to address cloud security alerts because we can automate alerts.

    To the extent that Orca Security has helped in preventing risks and attacks across our application lifecycle, it has allowed me to understand the security status of our resources before they go into production. My experience prioritizing risks using Orca is easy. In my experience, Orca Security's ability to analyze risks contextually and holistically is excellent. I have not utilized Orca Security's sensor for cloud detection and response, so I cannot speak to its effectiveness.

    I would rate this review a ten out of ten. Orca Security is a great platform, and I am very happy with it.

    Logan Gray

    Cloud risk context has improved and prioritization now streamlines patching decisions

    Reviewed on Jul 20, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Orca Security is to protect our cloud infrastructure. Specifically, I scan our cloud workloads with Orca Security to detect vulnerabilities and help determine what to prioritize for patching and upgrading.

    What is most valuable?

    Orca Security helps me decide what to prioritize for patching and upgrading with its workload protection features that work really well and help contextualize and prioritize the issues it finds.

    The best features Orca Security offers are cloud security and its shift-left features. The shift-left features of Orca Security help detect issues earlier in the software development lifecycle, benefiting my team day-to-day.

    Orca Security has positively impacted my organization by helping us become more secure by flagging and prioritizing issues.

    My impressions of the risk detection and identification capabilities of Orca Security are that they are very good because it helps contextualize and prioritize the issues for us to work on.

    Orca Security has helped in preventing risks and attacks across my application lifecycle by highlighting insecure configurations or vulnerabilities that do not yet have an exploit so that we can resolve those issues before they become more critical.

    My impression of Orca Security's ability to analyze risks contextually and holistically is that it seems quite good because it has visibility of our entire cloud infrastructure and can gather additional context to help prioritize and inform on issues.

    What needs improvement?

    Sometimes with Orca Security, it is a little bit hard for me to differentiate between different ephemeral cloud workloads and what the actual root cause of a particular issue is. I rate it a nine because of the issues with ephemeral workloads that I mentioned, which kept it from being a perfect ten.

    For how long have I used the solution?

    I have been using Orca Security for four years.

    What do I think about the stability of the solution?

    Orca Security is stable.

    What do I think about the scalability of the solution?

    The scalability of Orca Security is very good.

    How are customer service and support?

    I find the customer support for Orca Security to be good.

    Which solution did I use previously and why did I switch?

    I did not previously use a different solution.

    How was the initial setup?

    My experience with pricing, setup cost, and licensing is that the pricing was about on par with other options, the setup was very easy, and licensing is quite straightforward.

    What was our ROI?

    Although I do not have well-defined ROI with Orca Security, it has prevented us from needing additional employees, and it has certainly saved time.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing is that the pricing was about on par with other options, the setup was very easy, and licensing is quite straightforward.

    Which other solutions did I evaluate?

    Before choosing Orca Security, I evaluated other options, which included Google Security Command Center, Prisma Cloud, and Qualys.

    What other advice do I have?

    Orca Security has helped my organization reduce the time it takes to address cloud security alerts; since bringing Orca Security in, it has improved our time to resolve by about fifty percent.

    I find it very easy to prioritize risks using Orca Security.

    Regarding Orca Security's AI capabilities, I think their governance and security are pretty good because I use those capabilities as well.

    I have not seen any issues with the accuracy and reliability of Orca Security's AI output; it seems accurate.

    My advice to others looking into using Orca Security is to try to consider organizing assets by business units just to help organize and prioritize findings relevant to different teams. I rate Orca Security a nine overall.

    Rafael Bueno

    Cloud security has gained full visibility and real-time remediation for our small team

    Reviewed on Jul 16, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I use Orca Security to have a complete view of our cloud environment at the company.

    I needed to know what assets were vulnerable and how to fix them, and it was very helpful to have Orca Security because it has some AI features that helped our developers fix the vulnerabilities while coding and understand which vulnerabilities require more attention and resources.

    OrcA Security automates remediation because we could install a plugin in the developer's IDE, so while they were coding, it actually helped them fix vulnerabilities in real time, which was very helpful.

    What is most valuable?

    The AI fix for vulnerabilities that we found is the best feature because it gives us more time to focus on other things.

    The dashboards were very helpful, and I could personalize them for our case, which helped me show my leadership where the main points were and how to address them, allowing us to focus on what was really important. It was very easy to change the dashboards and personalize everything.

    OrcA Security improved our collaboration because we could explain better to everyone at the company what we were doing and how it positively impacts our security posture. We could also measure our risks and vulnerabilities better, enabling us to think more strategically about improving our cybersecurity posture.

    We have faster fixing of vulnerabilities with our DevOps team, and we could have fewer attacks.

    It was really good because we could see threats coming before they materialize, which I think is a really good way to protect ourselves, our resources at the company, and all our assets.

    We are a small team, and I did not feel any difficulty in the work using Orca Security, so I believe it saved us more employees and other costs, helping us save in different ways.

    What needs improvement?

    Some dashboards could be a little more personalized for each company and have more options to show the real data we need for our leadership.

    For how long have I used the solution?

    I have been using Orca Security for a year.

    What do I think about the stability of the solution?

    I believe it is stable, and we did not have any availability problems with them.

    What do I think about the scalability of the solution?

    It is very scalable. We have a small environment, but it was very scalable when the Orca Security engineers were explaining the tool to us.

    How are customer service and support?

    It was really good. We had direct access to some commercial people and also the engineers, and they helped us every time we needed.

    Which solution did I use previously and why did I switch?

    It was Prisma Cloud, and we stopped using it because of the costs, and the results were not that organized or easy to use as Orca Security.

    We jumped directly to Orca Security without comparing it with any other platform.

    How was the initial setup?

    We installed the Orca Security plugin in the developers' machines, and when they were coding, they could see the vulnerabilities with the Orca Security plugin and fix them in the code before it was put into the production environment. This allowed us to fix vulnerabilities before they reached our productive systems, which was very helpful.

    What about the implementation team?

    We are not working with a partner or reseller.

    What was our ROI?

    Eight out of ten.

    What's my experience with pricing, setup cost, and licensing?

    I believe it can be improved, but it is also a really good platform to use.

    Which other solutions did I evaluate?

    Someone asked me on LinkedIn to talk about Orca Security.

    What other advice do I have?

    It was really accurate and gave us the right answers.

    The advice I give is to talk with the support team. They help us and listen to us about features and things that made sense for our environment and our specific case, and they consider applying them to the final product.

    I rate this product a 10 out of 10.

    AvrahamGoldwasser

    Cloud security has become unified with agentless visibility, faster remediation, and better compliance

    Reviewed on Jul 14, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Orca Security is cloud security, and we integrated AppSec in the last year.

    What is most valuable?

    Orca Security offers good security as a CSPM, runtime security with the real-time security agent on Kubernetes, and excellent visual representation to see what is really going on. The visual representation helps me understand where our gaps are and what needs to be fixed through remediations. In terms of AppSec, it provides entire connectivity with some missing parts, but mainly the Git parts with the repos allow me to see everything, how it is integrated, and to assess its risks. The SCA with the SAST is also crucial.

    The feature that stands out the most for me is that it is agentless, so I have simple connectivity where I can see everything in one place. If there are misconfigurations, security risks, or misconfiguration gaps, I can be alerted and set up custom alerts and non-custom alerts, allowing our security team to observe these alerts and take action.

    Orca Security has positively impacted my organization mainly through use by the security team, but we also use it for compliance reports. We can set the compliance standards we want to adhere to in Orca Security, and then I can check in which areas of each resource or organization-wide efforts comply with those standards. This is really useful to know where our compliance gaps are.

    Risk detection and identification capabilities of Orca Security are great and really useful. They had too many false positives in the past, but over time, with their improvements, probably due to UBA or something similar, it has really improved.

    What needs improvement?

    Orca Security can be improved by adding more connectivity and more integrations because the world is moving so fast that having integrations is really poor compared to other vendors.

    What is also missing with Orca Security is more robust AI security. Even though they have something, it is still really immature. We need better observability, and not only for cloud-based issues but also for any AI LLMs to ensure real security over AI.

    Regarding Orca Security's AI capabilities, I think it is still immature and we are missing some introduction to it. In terms of Orca Security's accuracy and reliability of output, I find that it is still immature, so I have a gap over there.

    For how long have I used the solution?

    I have been using Orca Security for the last four years.

    What do I think about the stability of the solution?

    I find Orca Security stable.

    What do I think about the scalability of the solution?

    Orca Security's scalability is great and I have not seen any faults.

    How are customer service and support?

    The customer support from Orca Security is the best and it is really good. I would rate the customer support a ten.

    Which solution did I use previously and why did I switch?

    We did not previously use a different solution. We conducted a POC with other solutions, and at the end of the day, after checking everything, it was my choice to go with Orca Security.

    How was the initial setup?

    I purchased Orca Security through the AWS Marketplace.

    What was our ROI?

    Orca Security has helped my organization reduce the time it takes to address cloud security alerts, and it does so very fast. Its visualization of the alerts, including custom alerts, makes it really efficient. Today, it is integrated with our SOC team.

    I have utilized Orca Sensor for Cloud Detection and Response, CDR, and it has been effective in providing runtime visibility and security. This was the main part because we started with CDR straight at the beginning before doing anything else, and it was good.

    Orca Security has helped in preventing risks and attacks across my application lifecycle if it is about secrets, exposed secrets, or vulnerable packages within the CI/CD pipeline, which were detected through the pipeline. It has full integration with GitHub or other tools such as Azure DevOps.

    Which other solutions did I evaluate?

    Before choosing Orca Security, we evaluated other options, including Prisma Cloud, which is now in Cortex, Wiz, and Uptime.

    What other advice do I have?

    I rate Orca Security a ten out of ten. I chose this rating because we started with Orca Security when it was a new kind of competition to Wiz. We went with Orca Security because of its support, which is one of the best third-party supports we have. They made a really big jump over the last two years, especially in the last year where they changed almost everything, from visualization to reducing false positives, and now they categorize alerts separately compared to what it was earlier, making this really useful. My advice for others looking into using Orca Security is to really consider them. I have given this advice before, and I know that some have taken my advice and moved forward with Orca Security. My overall rating for Orca Security is ten.

    Anurag Jat

    Holistic risk monitoring has improved cloud file integrity checks and reduced false positives

    Reviewed on Jul 08, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I was using Orca Security in my previous organization, and I have recently switched to a new organization, so my previous company domain and email ID are no longer active.

    I last used Orca Security approximately five months ago and worked with it for around two years.

    I used Orca Security for file monitoring of AWS EC2 instances and S3 buckets, with the focus primarily on EC2 instances. Orca Security was migrated with AWS, and we routinely monitored and checked file integrity. We received details about EC2 instances, including instance type, who created it, and when it was created.

    I am not currently using Orca Security, and none of my clients are using it. My previous client was using it.

    What is most valuable?

    I find the filters of Orca Security very beneficial, and the GUI is also very beneficial. The migration support provided by Orca Security across multiple clouds, including AWS, GCP, and Azure, gives a wide range for searching.

    All risks are timely identified in Orca Security and timely notified, with alerts triggering over the ticketing tool, providing good risk identification and incident handling.

    Orca Security provides a very holistic approach and holistic view of what has happened, with things categorized accordingly.

    Orca Security generally has a rating based on risk parameters. If the risk level is high, the rating is based on a zero to five star scale, and high-risk items generally have a rating of 4.5 or above, which is very beneficial for judging incidents based on their rating.

    Orca Security helps much in defense and gives notifications prior to the alert, providing a more detailed view for proper investigation.

    Orca Security provides a very holistic approach and a very user-friendly GUI while supporting multiple clouds, which is helpful for security personnel to identify and mitigate risks.

    Orca Security helped us reduce the false positive rate. When changes in instances are made by a historical user or the user to which the instance is assigned, I can set a query in Orca Security and the alert is not triggered. However, if changes have been made by a malicious person, the alert triggers. This means not every change triggers an alert, only malicious ones do, reducing the false positive rate by approximately 10 to 20 percent.

    What needs improvement?

    Orca Security could support its own ticketing tool, which would be helpful for security personnel so they would not need to integrate with any other ticketing tool. We could receive a ticket directly in Orca Security and work on it there since most of the information is available. Additionally, Orca Security should present raw logs, which would make it much easier to do the findings.

    For how long have I used the solution?

    I worked with Orca Security for around two years.

    What do I think about the stability of the solution?

    Orca Security was fully stable, and I did not experience any instability.

    Which solution did I use previously and why did I switch?

    I have worked a little bit with Qualys, but not extensively, just an overview of the tool.

    How was the initial setup?

    I have not set up the initial level of Orca Security, as it was handed over to me by someone already set up. I have not seen the initial setup or migration of Orca Security.

    What's my experience with pricing, setup cost, and licensing?

    I have no idea about the pricing of Orca Security. I do not have any information about the pricing or cost, as it was managed by my organization.

    What other advice do I have?

    There was no technical fault while I was using Orca Security, and I did not encounter any such technical faults, so I have not contacted any technical team. I have not explored many options in the VM field. At this time, nothing additional comes to mind. All matters regarding scalability and other technical details were managed by my organization, and I just had to work with the system. My overall review rating for Orca Security is 8 out of 10.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Nykole Denoo

    Cloud risk visibility has transformed how I prioritize threats and reduce unnecessary spend

    Reviewed on Jul 02, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I have used Orca Security for continuous cloud assessment visibility, identifying and prioritizing vulnerabilities and misconfigurations. I also monitor compliance against frameworks, whether it's NIST or SOC 2. Additionally, I use it for detecting cloud security risk and supporting incident response because it provides context around affected cloud resources.

    Risk detection in Orca Security is strong, mainly because it provides agentless visibility across the cloud environments I work in. My job involves identifying vulnerabilities, misconfigurations, identifying risk or exposed assets, and Orca Security does a great job helping to prioritize those risks on their potential business impact. It helps me align very well with the type of risk and the type of work I do in an AWS environment.

    I have used Orca Security's Cloud Cost Optimization feature in one of my recent projects to help identify underutilized cloud resources or cloud resources that have been idle for a long time. That feature allows me to identify those resources. My main focus is security, but I find it useful because if I'm able to see those resources that are not being used, I can adjust them. If I have to reduce their size, depending on what the case might be, or if I have to get it decommissioned, I can do so to help reduce unnecessary cloud spending while maintaining a secure environment. As much as my part of the job is security, I think overall, making sure that we are not just spending money on resources that we're not taking full advantage of is definitely a role that I would have to play. It also helps support conversations with the infrastructure team about balancing cost, performance, and security, to be able to get more data to have those conversations with those teams.

    Regarding the Cloud to Dev feature, I personally have not used that. However, I do know about it. Orca Security has the capability to help developers identify and remediate security issues early in software development life cycles by connecting cloud risk back to the code, repositories, or development responsibility. Although I have not used it personally, I have had a conversation with the software team where it helps to bridge the gap between security and development by mapping cloud security findings back to relative code repositories and development teams. It makes it easier to identify root causes and prioritize remediation early in the development cycle, which helps with collaboration between engineers and the security team.

    How has it helped my organization?

    Orca Security has helped significantly to reduce the time it took to identify or prioritize cloud security alerts because of the way it provides a centralized view of risk and correlated findings across the cloud environment. Instead of manually investigating every alert, I am able to focus on high-risk issues first based on factors such as exposure, exploitability, or business impact. This definitely significantly improves response time and makes the remediation process more efficient. Taking that manual factor out of it overall reduces the time for everything.

    Orca Security has been very helpful in preventing risks and attacks across my application life cycle by providing continuous visibility into the cloud workload. This also allows my team to prioritize and remediate issues before they could be exploited in production. It has also helped strengthen collaborations between security and development teams by providing actionable findings, which reduce the overall attack surface and improve security posture.

    What is most valuable?

    The features of Orca Security that stand out to me from my experience are that it allows agentless deployments. Since it is integrated into my AWS environment, it gives me comprehensive visibility across my whole AWS environment. With that kind of visibility, I am able to detect vulnerabilities or misconfigurations. I can do risk prioritizations and compliance monitoring through that. These capabilities of Orca Security align closely with the work I do when it comes to vulnerability management or security, cloud security assessments, or even regulatory compliance. Those features help with my day-to-day activities.

    Orca Security goes beyond just basic vulnerability detection when analyzing risks contextually and holistically. I think it adds a strong contextual understanding. Instead of treating each finding in isolation, it correlates risk across cloud assets, identities, network exposures, or workload configurations. That really helps provide a more holistic view of the attack path and potential business impact.

    What needs improvement?

    From my perspective, Orca Security is a really good tool. I would say one area I would like to see CNAPP platforms get is more intelligence when it comes to risk prioritization, which correlates with vulnerability, exposing assets, identities, and active threats to help the security team focus on risks that are more likely to be exploited. I am a huge advocate for automation. I also think deeper automation for remediation or stronger integration with ticketing and CI/CD pipelines or more customization would help. Executive reporting would help the security team respond significantly faster and communicate risk more effectively if those kinds of improvements are made.

    For how long have I used the solution?

    I have relatively hands-on experience with Orca Security for about three to four years. I have worked more hands-on with cloud security projects, and some of them are integrated with Orca Security.

    What do I think about the stability of the solution?

    I think the state of stability with Orca Security is impressive. It generally provides strong availability and scalability compared to a traditional on-premises security tool. I think the agentless part of it and the fact that it integrates directly with a cloud provider such as AWS helps to reduce operational overhead and potential points of failure that come with managing agents across multiple systems. From what I have seen, the architecture can support consistent visibility and create a very good, reliable risk detection across environments, even as a cloud workload scales.

    What do I think about the scalability of the solution?

    Before Orca Security, I used different solutions for the same use cases because of my expertise in those areas. I have used Amazon Web Services Security Hub, IAM, native logging and monitoring tools, Nessus, and a lot of SIEM platforms such as Splunk or QRadar. Overall, those tools together helped with vulnerability detection. They also helped with incident response or compliance monitoring and security alert triage. However, when it comes to more correlated data across multiple systems, Orca Security streamlines that by centralizing and correlating the risk all in one place.

    With my previous agent-based solutions, I have encountered performance issues when identifying risks. The challenges came more with the scalability of risk analysis across the multiple tools. Each solution provided a valuable insight on its own. For example, Nessus for vulnerability scanning and Splunk or QRadar for log analysis. However, the main limitation was that the findings were often siloed because they are different platforms. That meant I had to do the manual correlation of the data across the different platforms to understand the full context of the risk, which could slow down triage or investigation overall, especially if I was working with a larger environment with higher volume alerts.

    Which solution did I use previously and why did I switch?

    Before Orca Security, I used different solutions for the same use cases because of my expertise in those areas. I have used Amazon Web Services Security Hub, IAM, native logging and monitoring tools, Nessus, and a lot of SIEM platforms such as Splunk or QRadar. Overall, those tools together helped with vulnerability detection. They also helped with incident response or compliance monitoring and security alert triage. However, when it comes to more correlated data across multiple systems, Orca Security streamlines that by centralizing and correlating the risk all in one place.

    With my previous agent-based solutions, I have encountered performance issues when identifying risks. The challenges came more with the scalability of risk analysis across the multiple tools. Each solution provided a valuable insight on its own. For example, Nessus for vulnerability scanning and Splunk or QRadar for log analysis. However, the main limitation was that the findings were often siloed because they are different platforms. That meant I had to do the manual correlation of the data across the different platforms to understand the full context of the risk, which could slow down triage or investigation overall, especially if I was working with a larger environment with higher volume alerts.

    How was the initial setup?

    I did not participate in the initial setup and installation process of Orca Security personally. When I joined the team, it was already set up. I was not directly involved in the initial installation or setup. However, in my previous role, I did support some onboarding of other tools. I have a good understanding of how certain platforms are implemented or operationalized in an enterprise environment, but I did not set up Orca Security that I work with now.

    What's my experience with pricing, setup cost, and licensing?

    This is somewhat out of my scope because I do not see the exact pricing structure of Orca Security. However, from what I know through research, I think it is good. I think it is fair pricing in my opinion. I have that in place of multiple tools. Orca Security kind of replaces multiple tools that help improve efficiency. So when it comes down to it, if it is cost-effective in terms of overall security operation, I think the price point is reasonable. However, I do not know the exact amount or the exact pricing.

    Which other solutions did I evaluate?

    That personally would not be a decision I made before choosing Orca Security. However, I have been collaborating with a bunch of other people in my team, and I think they have considered other options. Depending on what the environment is being used for and the use case in general, they like to look for something that will mix with cloud-native tools. Any third-party solution, whether it is Prism Cloud or Wiz, is something that I have heard of. However, the decision usually comes down to factors such as coverage across the multi-cloud environment or how easily it is to deploy or signal-to-noise ratio. Many factors come in before selecting what CNAPP they want to get. I feel that across everything, Orca Security stands out. The main thing that many people appreciate is the agentless visibility and the contextual risk prioritization, which is a good benefit that it has over competitors.

    What other advice do I have?

    Regarding Orca Sensor, I personally have not used it, but I do know of it. I have not used it directly, but my experience has been more about how it collaborates with the AWS environment, which is my strong field. However, I know it has been useful when deploying sensors and agents. I do not know how in-depth that goes because I have never done that personally, but I still feel that overall, it does what it needs to do. It still provides visibility into workloads and vulnerabilities, whether it is misconfigurations or exposed assets, in whatever environment they are running it in.

    I have used the official documentation offered by Orca Security a few times. I have used the documentation and guidelines in the context of IAM management workflows, particularly around single sign-on, multi-factor authentication, and user provisioning. The documentation from Orca Security is structured really properly. It got all the points across really great. It made it easy for me to read and understand. It was very straightforward. I was able to understand what was put across in the documentation without having to do multiple research or over-explanation. I appreciate that.

    I would rate this review as an eight out of ten.

    Harsh Goenka

    Cloud security has improved as we identify vulnerabilities and address risks proactively

    Reviewed on Jun 04, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I have used Orca Security for one year while working for a client where we set up Orca Security to scan our environment and identify vulnerabilities.

    The main use case for using Orca Security is to identify vulnerabilities in our environment so that we can address them before any issues occur.

    In one of our projects in GCP, we purchased Orca Security from the marketplace, which was enabled in our account at the organization level.

    What is most valuable?

    The main feature that I appreciated about Orca Security is that it is 100% agentless and context-aware, meaning it understands what it is doing.

    The primary benefit is that it provides us with CVEs, through which I can identify the vulnerabilities in our security posture.

    In the long run, as a security tool, it has helped us improve our security posture.

    What needs improvement?

    There is one issue that I encountered: when Orca Security provides CVEs and we attempt to implement its solutions, sometimes those solutions are not available on the cloud and cannot be implemented.

    My main concern is the integration of Orca Security with generative AI for remediation inquiry.

    Another concern I have is around the guardrails.

    The primary improvement that Orca Security needs is to enhance its remediation steps based on the cloud platform being used.

    For how long have I used the solution?

    I have been working in my current field for the past five or more years.

    What do I think about the stability of the solution?

    Orca Security has been stable in my experience.

    What do I think about the scalability of the solution?

    Orca Security is internally based on cloud infrastructure and is 100% agentless, so it does not require significant scalability considerations.

    How are customer service and support?

    Customer support is also good. I would rate it a 10 because they respond properly and communicate effectively.

    Which solution did I use previously and why did I switch?

    Previously, I used to install an open-source tool to understand my security posture, which required some additional infrastructure investment.

    I was using the native GCP Security Command Center.

    How was the initial setup?

    We purchased Orca Security from the AWS Marketplace.

    What's my experience with pricing, setup cost, and licensing?

    I am aligned with the pricing, as it is not that costly.

    Which other solutions did I evaluate?

    I did evaluate open-source tools, Orca Security, native open-source tools, and cloud-native tools as well.

    What other advice do I have?

    When Orca Security provides CVEs, clicking on them gives suggestions about what can be done to resolve the issue.

    I would advise others to use Orca Security because of the rich features that it offers.

    I would rate this review a 9.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Krishnakumar Mahadevan

    Integrated cloud risks have been managed centrally and security posture improves continuously

    Reviewed on Jun 04, 2026
    Review from a verified AWS customer

    What is our primary use case?

    Of my three customers, one is using Orca Security, and two are not using it. There are plenty of use cases available for Orca Security, and I can provide more details.

    Orca Security is very good for faster management due to their CNAP, which stands for Cloud Native Application Protection Platform. It consolidates CSPM, CWPM, CWPP, and CAEM, which includes entitlement management and vulnerability scanning. Orca Security consolidates these solutions into a single platform. If I buy Orca Security, I can check data-related security posture management across various domains, including security and multi-cloud compliance. We put security at the forefront rather than waiting until project completion to engage security. It is important to place security in the field, and Orca Security is a very good tool for that.

    Orca Security is an agentless vulnerability scanner, meaning we do not need to run any agents. The first use case is for consolidating various solutions into one. The second use case is agentless vulnerability scanning, and the third use case is for multi-cloud security. Some customers might have different cloud environments that can lead to vulnerabilities if not carefully managed, especially in stringent scenarios like FedRAMP. Orca Security is quite effective in these aspects, particularly for government and semi-government scenarios.

    Orca Security serves to analyze configurations against what is optimally used and identify gaps. It identifies when servers are underutilized. For example, if a server is supposed to be at least eighty-eight percent utilized and is running below one percent, that results in unnecessary costs. This gap analysis is something every synaptic tool, including Orca Security, supports for cost optimization.

    How has it helped my organization?

    Orca Security has improved our cloud security visibility, streamlined vulnerability management, reduced alert fatigue through risk-based prioritization, and helped us remediate critical issues faster while maintaining compliance across our cloud environments.

    What is most valuable?

    Orca Security excels in identifying risks. If posture management is configured well, the tool performs effectively in identifying risks. I appreciate the tool as it finds various issues. In today's AI era, we see many new challenges, including tool poisoning and broken paths, which Orca Security identifies effectively. The tool captures all the risks related to entitlement management as well, focusing on the segregation of duties to minimize risks.

    We use AI across the cloud environment, which helps in automating and remediating issues while enabling organizations to connect fragmented data for faster investigations and prioritizing measurable risks. Orca Security has seven distinct positive risks, including token theft and command injections, which are vital for security posture management.

    What needs improvement?

    I think Orca Security should be more SMB friendly since I mostly work with enterprise customers who have more budget. Orca Security could include options for smaller businesses and improve on areas like agentless functionalities and cost efficiency for small-scale deployments.

    I work in an SMB organization and find Orca Security quite expensive. They typically offer some credit periods to conduct proofs of value for various products.

    For enterprises, I find Orca Security to be fairly priced, whereas it is a bit more expensive for SMBs.

    For how long have I used the solution?

    Everything is around five years, and I have been using it for the whole thing because I have been in this field since nineteen ninety-five. All these tools are five years old, maximum of five to six years old. In fact, they were born during my tenure.

    What do I think about the stability of the solution?

    Yes, Orca Security is generally considered a stable and mature enterprise-grade CNAPP (Cloud-Native Application Protection Platform) rather than an emerging startup product. However, stability can be viewed from three perspectives in my personal opinion, they are

    1. Product Stability

    2. Company Stability

    3. Operational Stability

    What do I think about the scalability of the solution?

    Yes. Scalability is actually one of the strongest differentiators of Orca Security compared to traditional agent-based cloud security platforms.

    1. Agentless Architecture Eliminates Deployment Bottlenecks

    Traditional CWPP and EDR-style cloud security solutions require agents on every VM, Kubernetes node, or workload. As organizations grow from hundreds to tens of thousands of cloud assets, agent deployment, upgrades, troubleshooting, and performance management become significant operational challenges.

    Orca uses its patented Side Scanning™ technology to scan cloud workloads directly from cloud-provider storage snapshots and APIs without deploying agents. This means:

    • No agent rollout projects
    • No agent lifecycle management
    • No performance impact on workloads
    • New assets are automatically discovered and assessed

    This architecture allows organizations to onboard large multi-cloud environments much faster than agent-centric solutions.


    2. Designed for Large Multi-Cloud Estates

    Orca supports:

    • AWS
    • Azure
    • Google Cloud
    • Oracle Cloud
    • Alibaba Cloud
    • Kubernetes environments

    A large enterprise running thousands of subscriptions, accounts, projects, containers, and serverless workloads can manage them from a single platform and unified data model.

    For organizations like:

    • Global banks
    • Telecom providers
    • Retail giants
    • SaaS companies

    this becomes important because security teams do not need separate tools for CSPM, CWPP, CIEM, DSPM, vulnerability management, and container security.


    3. Automatic Discovery of New Resources

    One common scaling problem in cloud environments is asset churn:

    • New VMs
    • New Kubernetes clusters
    • Auto-scaling groups
    • Temporary containers
    • Serverless functions

    Orca automatically discovers and monitors newly created cloud assets without requiring manual updates or security onboarding processes. This is particularly valuable in DevOps-heavy environments where infrastructure changes continuously.


    4. Unified Data Model Reduces Operational Complexity

    Many enterprises end up with:

    • Prisma Cloud
    • Tenable
    • Wiz
    • CrowdStrike
    • Native CSPM tools

    all generating separate alerts.

    Orca's Unified Data Model correlates:

    • Vulnerabilities
    • Misconfigurations
    • IAM risks
    • Sensitive data exposure
    • Attack paths

    into a single risk graph. This helps maintain operational scalability because the security team is not overwhelmed as cloud assets increase.

    How are customer service and support?

    Orca Security's technical support is very good, aligning with my consulting operations, and I have not received any escalations.

    Which solution did I use previously and why did I switch?

    In identifying risks with previous products, there are notable pros and cons between agent-based and agentless solutions. Agentless tools eliminate orchestration concerns, while agent-based tools allow more granular control and calculations.

    How was the initial setup?

    The initial setup is straightforward, but I find it a bit complex due to the learning curve involved, which requires thorough guidance during the first configuration.

    What about the implementation team?

    Yes, many organizations use either Orca Security Professional Services or partners such as Accenture, Deloitte, or Optiv for deployment. The feedback is generally positive, with customers highlighting fast onboarding, minimal operational overhead due to the agentless architecture, and strong implementation support. Orca Professional Services is often preferred for quicker deployments and product-specific expertise.

    What was our ROI?

    Regarding the time to value from Orca Security, if it is a SaaS setup, it is immediate. For larger solutions like ERP or MSSP setups, it can take more than six months. But for security scanning, it is shorter since we pay only for what we use.

    What's my experience with pricing, setup cost, and licensing?

    Pricing was competitive for an enterprise-grade CNAPP platform, and the agentless architecture helped minimize deployment and maintenance costs. Licensing was straightforward, and the time-to-value was relatively fast compared to other cloud security solutions.

    Which other solutions did I evaluate?

    Among competitors like Trend Micro and Cisco, I compare Orca Security with offerings from those vendors based on features and costs.

    In terms of objectives, I need functionality without paying a luxury price. The features offered by some competitors may be attractive, but what counts most is that Orca Security provides essential functions with lower costs.

    What other advice do I have?

    I cannot provide a straightforward answer about the time it takes to address cloud security alerts because different levels of alerts exist, and fixing each alert can vary depending on how alerts are configured. Policies play a crucial role in alert management.

    If SaaS is available, customers prefer it due to low engagement compared to hybrid models. The cost savings on SaaS are quite attractive.

    Orca Security's ability to combine functionalities of multiple tools into one platform is indeed one of its strongest points.

    I would rate support at eight plus points. My personal rating for Orca Security as a service provider would be nine.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    RiteshWalia

    Centralized cloud scanning has improved compliance and simplifies cross-account reporting

    Reviewed on May 16, 2026
    Review from a verified AWS customer

    What is our primary use case?

    Orca Security serves as a centralized solution within our organization that offers scanning of all issues found in our cloud accounts. We have AWS, Azure, and GCP, and Orca Security identifies best practices we are not following or configurations that are not optimal. Orca Security automatically finds these issues and generates reports for us.

    For example, if we have any EBS volumes or file systems which are not encrypted, Orca Security scans all cloud resources and detects such misconfigurations. These issues are then flagged in the report and we act on them accordingly.

    What is most valuable?

    The best feature I appreciate about Orca Security is its reporting functionality. The dashboard is very clear and concise, and it helps filter multiple accounts by issue type. Exporting the dashboard into an Excel sheet provides a good user experience.

    To ensure we remain compliant, Orca Security's dashboard is really helpful in tracking the issues we have, with the end goal of always being compliant with our compliance standards and organizational requirements. It helps significantly with that.

    Orca Security has helped our organization become compliant and maintain high standards because any organization with multiple products needs to be compliant, especially when it comes to underlying infrastructure and cloud resources. Orca Security helps tremendously in that regard.

    What needs improvement?

    Orca Security could benefit from more agentic workflows, where agentic workflows could be integrated with Orca Security to provide a quick view of large reports and issues we have. Additionally, data analytics capabilities could be improved.

    For how long have I used the solution?

    I have been using Orca Security for the last five years.

    What do I think about the stability of the solution?

    Orca Security is quite stable.

    What do I think about the scalability of the solution?

    Scalability is good. So far, we have not faced any issues related to scalability when using it or the underlying infrastructure on AWS. It is quite responsive and we have not encountered any issues. Orca Security provides a highly scalable architecture for us.

    Which solution did I use previously and why did I switch?

    We have used only Orca Security.

    What was our ROI?

    We save a lot of time now. We have also implemented automations from our side so that people receive reports automatically, whether they are Orca Security IVM issues or Orca Security issues related to any resource. This has been really helpful.

    Which other solutions did I evaluate?

    We did not evaluate alternate solutions because this organization initiated Orca Security centrally. We do not have much control over it as I am just a user.

    What other advice do I have?

    The advice I would give is that you can make good use of the issues depending on different organizational use cases. Try your best to have all Orca Security issues into one dashboard and then export them. Additionally, making it more AI-enabled would be beneficial because when you have multiple Excel sheets exported with all the data, that data can be visualized in a better way. I would rate this review a 9.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)