
Overview
AlgoSec Horizon is an application-centric security management platform built for the hybrid enterprise, enabling organizations to secure application connectivity across data centers and multi-cloud environments, including AWS. Private Offering only. It automatically discovers and visualizes business applications and their dependencies, providing a unified view of traffic flows, security policies, misconfigurations, and risk exposure. Horizon enables intelligent automation of security policy changes, reduces manual effort, and prioritizes risks based on business context. By enforcing consistent security controls across cloud and on-premises environments, it ensures continuous compliance and operational efficiency at scale.
Highlights
- Application Connectivity & Visibility: Automatically discover business applications, map dependencies, and visualize traffic flows across hybrid and multi-cloud environments for complete visibility into connectivity and risk.
- Intelligent Automation & Policy Orchestration: Automate security policy changes and connectivity processes to reduce manual effort, minimize errors, and accelerate secure application deployment.
- Risk-Based Prioritization & Continuous Compliance: Link risks to business-critical applications, prioritize remediation, and continuously identify and resolve policy and compliance gaps across cloud and data center environments..
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
ALGOSEC_ACE_SB2 | AlgoSec Cloud Enterprise 100 Workloads package, Monthly Subscription Preferred | $27,000.00 |
Vendor refund policy
For cancellation and refund details please refer to: https://www.algosec.com/money-back/
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
AlgoSec offers 9am-5pm and 24x7 support. Please refer to the AlgoSec website for additional information
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

FedRAMP
GDPR
HIPAA
ISO/IEC 27001
PCI DSS
SOC 2 Type 2
Standard contract
Customer reviews
Unified firewall audits have improved efficiency and simplified compliance reporting
What is our primary use case?
My main use case for AlgoSec is for firewall management, auditing, and managing firewalls. A quick specific example of how I have used AlgoSec for firewall management and auditing is when we had multiple firewalls that we wanted to get a unified view, and there we used AlgoSec. That was the main reason for what we used.
What is most valuable?
The best feature AlgoSec offers is the ability to create a unified view for auditing. What I find most helpful about the unified view is that it saves time and simplifies audits because it reduces false positives and brings a smoother auditing process.
I would add that the reporting is also very advanced, and regarding automation, I was not very involved in that part, but I heard that it is also a very mature feature from AlgoSec.
AlgoSec has impacted my organization positively as it has brought noticeable improvements, including having multiple firewalls and vendors while getting a unified view, automated processes, and very good reporting.
What needs improvement?
AlgoSec could be improved by extending their products for security because they are very focused at the moment. They could have broader product lists, which would be a good idea.
Regarding needed improvements, we did not have any issues with integration as it was very smooth and not very complex. However, for usability, I suggest a better UI, as compared to Palo Alto, which I find is more friendly and attractive compared to AlgoSec.
For how long have I used the solution?
I work in my current field for around one year.
What do I think about the stability of the solution?
AlgoSec is stable, which is why it was suggested, and I have no experience with other products.
What do I think about the scalability of the solution?
AlgoSec's scalability is absolutely good.
How are customer service and support?
I have not needed to reach out to customer support, as we did not contact them.
What was our ROI?
I have not seen a return on investment, and I cannot share any relevant metrics such as fewer employees needed or money saved.
What's my experience with pricing, setup cost, and licensing?
I was not involved in the process of pricing, setup cost, and licensing. Our manager was dealing with the licenses while we focused on the technical side.
Which other solutions did I evaluate?
I did not previously use a different solution. I think for this matter, AlgoSec is the best product in the market that can unify all firewalls for auditing.
What other advice do I have?
On a scale of one to ten, I would rate AlgoSec between eight and nine. I chose the number eight because I believe that the functionality is very good. While the functionality is very good, as I mentioned, the UI can be improved, and the products can be more varied. AlgoSec could explore more topics such as Zero Trust or other security standards.
AlgoSec's AI capabilities is something that I did not work with, to be honest. I have not used AlgoSec's AI capabilities regarding accuracy and reliability of output, so I cannot provide any insight there.
I do not have any improvements needed for AlgoSec that I have not already mentioned. It was just my personal experience. My advice to others looking into using AlgoSec is that if they want to have a unified view, it is a very good product. They can have a proof of concept, test it, and see the benefits. This is how I would suggest others go with AlgoSec. I would rate AlgoSec a score of eight out of ten.
Automation has transformed firewall policy management and now unifies compliance and audits
What is our primary use case?
My main use of AlgoSec in my organization is for firewall security policy management and automation.
A concrete example of how I use automation with this tool in my daily work is that the FireFlow module is a real time saver. What used to take us hours for impact analyses, rule change or implementation requests, and verification is now automated in a few minutes, all without introducing human error.
What is most valuable?
I would like to add that we have incredible end-to-end visibility, and in fact, the network mapping is surgically precise. AlgoSec allows us to visualize traffic flow across our entire on-premises, hybrid cloud, and multicloud infrastructure in a single, intuitive interface.
In my opinion, the best features that AlgoSec offers include continuous compliance, as AlgoSec checks our firewall rules in real time against regulations, such as ISO 27001, PCI DSS, or NIST, and against our internal policy. Audit reports are generated with one click, and our auditors absolutely love that.
Regarding continuous compliance and audit report generation, this has simplified our audits and the management of regulatory controls in our organization because we don't use several applications; we only use AlgoSec.
I would also like to add that there is multi-vendor compatibility that we manage. We can manage our Palo Alto, Check Point, or Fortinet devices at the same time, and as a result, AlgoSec integrates perfectly with our entire ecosystem without any friction.
What needs improvement?
In my opinion, AlgoSec could be improved in the future, as we had some small issues with it at the level of overload. There was a lot of overhead, and we increased the disk space. Afterward, I think it was more the development part on our internal side than the tool itself, but the tool was really good; it was complete, and I had nothing to add.
For how long have I used the solution?
I have been using this solution for a year and a half.
What do I think about the stability of the solution?
In my opinion, AlgoSec is stable in my current environment.
How are customer service and support?
I find AlgoSec's customer support generally positive based on user feedback in my experience so far.
Which solution did I use previously and why did I switch?
I have never used another solution before for network security management before using AlgoSec.
What was our ROI?
I have seen a return on investment with AlgoSec in that our network and security teams spend sixty to seventy percent less time on manual tasks for managing flow openings and documenting rules.
Which other solutions did I evaluate?
Before choosing AlgoSec, I did not evaluate other solutions because when I arrived at the company, they already had it.
What other advice do I have?
AlgoSec has had a positive impact on my organization in that we no longer have to connect directly to the firewalls one by one. We can directly have AlgoSec manage the entire firewall group, so it is perfect.
I can explain in more detail that this frictionless integration has improved productivity and collaboration within my team. I would say that there is perfect alignment between security and the business. With the application-oriented view AppChange, we no longer speak only in IP addresses and ports, but in business applications, which has significantly improved collaboration between our security infrastructure teams and the developers.
My advice to other professionals who are considering using AlgoSec is to clean up your rule bases beforehand. AlgoSec is excellent for cleaning up your firewalls. You can deploy solutions step-by-step, and there is visibility provided by AlgoSec. Then, there is automation, and there are business applications rather than IP addresses. I rate this solution a ten out of ten.
Policy management has unified multi-vendor firewalls and has increased margins for managed services
What is our primary use case?
My main use case for AlgoSec is the policy management for plus 10,000 firewalls and security equipment in multi-vendor situations. Since my customers have legacy security equipment, it is necessary to apply policy to all security equipment in general, and this also extends to identity access management. I have migrated from Tufin to AlgoSec and from AlgoSec to Tufin based on my customer's requirements.
What is most valuable?
In my experience, the best features that AlgoSec offers include policy management, which is very open to multi-vendor situations, especially for firewalls and companies that have legacy firewalls. This functionality allows us to reduce the attack surface while applying policies globally and homogeneously across our IT and ITS infrastructures. As a CISO and also managing the network and security operations center, it has proven very helpful, especially in an MSSP situation where I deal with multiple clients across finance, defense, and medical sectors. I find myself very comfortable with AlgoSec to apply security and network application delivery.
AlgoSec positively impacts my organization by commanding higher margins. Given that I am an MSSP serving multiple clients, having one tool for all my customers is fantastic.
What needs improvement?
Currently, from my experience with AlgoSec, I believe it needs improvements, particularly with custom or open-source software integration. Some of my customers cannot purchase commercial software due to strict opposition for security reasons. For instance, I had a customer who required an entirely BSD-based firewall, which necessitated coding to facilitate integration with AlgoSec. Furthermore, AlgoSec could excel by helping us as MSSPs integrate with CTI teams. Being involved with cyber threat intelligence would allow us to be proactive, applying data-driven policies rather than just implementing policies for the sake of compliance. I also collaborate with OT and IT departments, and it is important to note that OT systems have long lifespans, sometimes dating back 20 years. I have encountered situations where policies had to be applied manually since certain legacy systems date back to the 1970s and 1980s and remain unchanged.
What do I think about the stability of the solution?
From what I have heard, the solutions I have built around AlgoSec continue to work well.
What do I think about the scalability of the solution?
AlgoSec's scalability appears to be pretty good for a multinational company and fares well.
How are customer service and support?
Regarding customer support, I have not had to engage with it directly, so I cannot provide an assessment. However, I can state that the integration support I received was very kind.
Which solution did I use previously and why did I switch?
Before choosing AlgoSec, I did not switch from another solution. Before selecting AlgoSec, my evaluations were limited as there were no other options considered since it was mostly the de facto decision due to budgetary considerations.
What was our ROI?
I have seen a return on investment with AlgoSec, including money saved, time saved, and more efficient operations. However, specific metrics cannot be disclosed due to a non-disclosure agreement.
Which other solutions did I evaluate?
I have used AlgoSec on and off, and I have used Tufin, the competitor of AlgoSec, with AlgoSec intertwined both.
What other advice do I have?
I find that AlgoSec's holistic approach allows me to present at the C-suite level without needing to dive too deep into technical details, advocating for budget justification on a business process level. Furthermore, BOT automation has significantly bolstered my business-driven approach and security policy management across the whole spectrum of our security equipment overview. Overall, even as a managed MSSP, I can effectively manage multiple clients and create policies that can be applied to all or specific customers within my MSSP. I appreciate the fact that it is business-driven.
Regarding those higher margins, I have seen a growth from 45 percent to 70 percent in security policy management while providing network security policy management services. I work closely with the customer to build a policy tailored to their needs, which alleviates the necessity for one-on-one interactions. I can apply security policy templates that are already functional, thus not requiring me to rewrite security policies repeatedly. This reusability leads to gains in productivity, making processes much more agile and compliant.
In my experience, the best features that AlgoSec offers include policy management, which is very open to multi-vendor situations, especially for firewalls and companies that have legacy firewalls. This functionality allows us to reduce the attack surface while applying policies globally and homogeneously across our IT and ITS infrastructures. As a CISO and also managing the network and security operations center, it has proven very helpful, especially in an MSSP situation where I deal with multiple clients across finance, defense, and medical sectors. I find myself very comfortable with AlgoSec to apply security and network application delivery. I give this review a rating of 8.
Automated reports have simplified firewall audits and now support faster security decisions
What is our primary use case?
My main use case for AlgoSec is AFA, which stands for AlgoSec Firewall Analyst.
What is most valuable?
The best feature AlgoSec offers is the report. I say the report is very helpful because we get consulting about the firewall, and they want to know the current condition of this firewall. We have around 10 Cisco firewalls, so it is very hard to collect all this information about these firewalls. AlgoSec provides the tool to connect to 10 firewalls and gather everything from them, making it very helpful to optimize or improve the firewall rules.
AlgoSec's AI capabilities refer to any AI-related features in AlgoSec such as automation, governance controls, or security aspects. I did not remember any automation at first, but automation, yes, I recall some. I was shocked by the report created automatically by the system, providing clarity on rules usage. Our consultant requires reports now and three months later to compare everything about the firewalls. I think those AI or automation capabilities are really helpful.
The accuracy and reliability of AlgoSec's output are really good. The reports, whether weekly or monthly, are very accurate and reliable, allowing me to check everything.
AlgoSec has positively impacted my organization as we focus on cybersecurity and always put it first. The firewall is a key point because threat actors have all kinds of tools for cyber invasion, but the firewall is crucial. Our consultants want to know the report about the current firewall status weekly or monthly, and that is the only way to get this report from all these 10 firewalls. Without that, we could not manage anything about this firewall.
What needs improvement?
AlgoSec can be improved as we use AlgoSec AFA version 30 or higher. AlgoSec has a lot of product lines, but we only have AFA. If possible, we could buy other products as a bundle with AFA, providing all the tools to manage firewalls and security issues. It would be very helpful if AlgoSec provided a whole picture of their product lines, not only AFA.
When initially installed, there were confusing moments as we encountered two bugs, requiring help from the support team. The tech support from AlgoSec was very helpful, but we still spent approximately one or two months on the whole process. If possible, providing more immediate support in one or two weeks to solve these simple bugs would be beneficial since AlgoSec is a very good system.
For how long have I used the solution?
I have been using AlgoSec for two years.
What do I think about the stability of the solution?
AlgoSec is stable and works fine as long as we install it properly.
What do I think about the scalability of the solution?
AlgoSec's scalability appears to be good. We have eight licenses for eight firewalls, but I do not know the exact number of firewalls one AFA can connect. Connecting a firewall to the system is easy with two connections: a syslog connection and an SSH connection.
How are customer service and support?
The customer support from AlgoSec is very good. During installation, I reached out to tech support, and they responded immediately.
Which solution did I use previously and why did I switch?
I did not previously use a different solution.
How was the initial setup?
Connecting to multiple firewalls and optimizing rules with AlgoSec was initially time-consuming as we spent time on the connection between AlgoSec and the firewalls. We encountered two bugs and spent approximately one or two months figuring it out, but after that, everything works very smoothly. We do daily checking, produce reports, and check every feature of our firewalls, which are working just as expected.
I remember doing several upgrades, which are a little challenging, but if you are familiar with the process, it is very easy to handle.
What was our ROI?
I could not remember every detail about the outcomes from using AlgoSec, but we save a lot of money on consultants since we built this system. We were not buying another system to do this kind of work, which helped us a lot, not only in money but also in time. I worked in the infrastructure team while the consulting worked in another team, the cybersecurity team, so I always provided tools in advance, just ahead of when they asked.
Using AlgoSec has saved us a lot of time. Our consultant needs detailed reports about firewalls, which AlgoSec provides very efficiently. Doing this manually is unimaginable, so it saves a lot of time and money.
What's my experience with pricing, setup cost, and licensing?
Regarding pricing, setup cost, and licensing, we started with eight licenses for eight firewalls, if I remember correctly, but I do not know the price or exact setup costs.
Which other solutions did I evaluate?
Before choosing AlgoSec, I personally did not evaluate other options, but our consultant mentioned something similar to AlgoSec. I cannot remember the details.
What other advice do I have?
My advice for others looking into using AlgoSec is that it is a very helpful system. If you have firewalls and need to generate reports or conduct research on them, AlgoSec is a great tool to connect to those systems and collect everything. I would rate my overall experience with AlgoSec as a 9 out of 10.
Rule Analysis and App Mapping That Make Firewall Migrations Faster
FireFlow is where the change management side clicks. Every request has a state, an owner, and a paper trail, so nobody's asking "wait, who approved this NAT rule" three months later.
AppViz is the one that changes how you talk to other teams. Instead of a spreadsheet of IPs and ports, you can show someone the actual application flow and point at exactly which policy is blocking it. Cuts the back and forth with dev teams down to nothing.
A few other things that stood out:
Clean UI - doesn't bury you in menus, you can get to compliance status or a specific rule fast.
Change automation - pushing a firewall or cloud security group change through FireFlow instead of doing it by hand cuts down on the "wrong object-group" mistakes.
Compliance reports - PCI-DSS and similar are basically ready to export, which matters during audit season.
Handles scale - ran it against a fairly large hybrid estate and it didn't choke.
Don't treat it as just a firewall dashboard. The application mapping is genuinely useful when you need to explain a security decision to someone who doesn't care about ports and protocols.
The custom reporting side could use work too. The out-of-the-box compliance templates are fine, but building something custom branded for an exec presentation takes longer than it should. A proper drag-and-drop report builder would help.
It's also cut down the back and forth with app owners a lot. Before, a "why is my app broken" ticket meant pulling logs from three devices and guessing. Now we can point at the AppViz map and say exactly which rule or path is the problem, so tickets close in minutes instead of days.
On the compliance side, it's saved a ton of manual prep before audits. Reports that used to take a day to assemble by hand now export in a few clicks.
Integration wise, it plays well with the Cisco ASA/FTD and Palo Alto stacks we deal with most, and the API access has made it straightforward to pull data into our own tracking without living inside the Horizon UI all day.
On pricing, it's not cheap, and licensing scales with the number of devices, so for a smaller shop it can be a hard sell up front. For anything running a genuinely hybrid, multi vendor estate though, the time saved on rule cleanup and audit prep tends to justify it within a few migrations.