My main use case for DevOcean is that I use it on a day-to-day basis to get a unified view of the overall cloud security posture of my clients and help them with scanning their vulnerabilities in their accounts, code scanning, any misconfigurations they may have, and providing them an overall picture of how secure their account actually is, and taking necessary actions further.
A specific example of how I have used DevOcean for a client recently is that I worked with a client who had a cloud-native application in which he required a risk remediation drive, and DevOcean helped us consolidate all the alerts automatically and suggest the lowest cost remediation paths, which allowed us to cut down the noise and alert fatigue dramatically and focus on the key findings which otherwise would have been big threats for them in the longer run.
Overall, I think DevOcean is a really great tool as it visually connects vulnerabilities, codes, and runtime assets giving you a full bigger picture.
The best features DevOcean offers are how it is built on a unified platform of all the cloud assets and maps risks in context linking together coding, infrastructure, runtime, and dependencies, which gives you a bigger picture of the entire infrastructure and ensures issues get assigned to the right owners in the right way.
The workflow automation in DevOcean has been great as it has helped our overall automation reduce vulnerabilities and the need to repeatedly check for any faults or loopholes in security systems, thus aiding in automating our overall security procedures.
Overall, DevOcean gives a great overall picture of the environment and provides an executive summary of the overall status of the entire connected accounts.
DevOcean has positively impacted not only my organization but many clients as well, addressing the critical factor of security across the cloud industry since it solves day-to-day issues that companies face.
I have seen significant positive outcomes since using DevOcean such as a minimization of security vulnerabilities that would otherwise go unnoticed and a considerable amount of time saved, specifically, nearly 10 hours a week for a single person who would otherwise spend time integrating or checking for security findings.
One area where DevOcean could improve is by adding a prioritization logic, as sometimes it may suggest risks to tackle first that may vary per business and require some level of customization.
I do not have much else in mind regarding needed improvements; I think the prioritization logic is the only thing I would suggest.
The reason I did not give a perfect score is that the requirement of each client may differ, and while some level of customization is available, there may be a need for a more tailored prioritization of the type of risks.
I have been using DevOcean throughout my entire DevOps journey since it has been a critical part of my operations.
I have not experienced any downtime or major issues with DevOcean personally.
DevOcean has shown great scalability and can handle our growing needs effectively, allowing us to keep adding more tools and cloud resources.
I have never had to reach out to DevOcean's customer support.
I have not used any other solution before DevOcean as it has been a reliable tool used for quite a while.
We purchased DevOcean through the AWS Marketplace.
I think we are just a customer; I am unsure about the reseller aspect and I do not think we are partners.
We definitely see a return on investment with DevOcean as there has been substantial time and money saved; specifically, one client was saving around 10 hours a week for a single person troubleshooting.
My experience with pricing, setup cost, and licensing for DevOcean has been good, even though I am not usually the one responsible for that part, it is heavily used by our organization.
Before choosing DevOcean, I think some other tools were evaluated, specifically Orca Security, but they ultimately ended up selecting DevOcean.
I would rate DevOcean a solid nine out of ten, as it is extremely useful for security teams juggling multiple tools needing one place to see everything in context.
My advice for others looking into using DevOcean is that it is a really good tool and I highly recommend it, as it is not just another dashboard, it acts as a brain on top of your entire stack.
Overall, I have really good feedback and highly recommend DevOcean as a great tool.