Listing Thumbnail

    Comply

     Info
    Zilla Security solves the #1 security problem organizations face today - preventing identity related data breaches. Zilla enables organizations to establish a security and compliance best practice to eliminate access risk. We've combined comprehensive identity and access governance, and cloud security in a single platform. Zilla monitors and gives you control over all your identity paths to data access. You get least-privilege security with total visibility, ongoing monitoring, and remediation for identity vulnerabilities. Zilla's fully automated, easy-to-use access reviews help you achieve compliance, demonstrate audit readiness, and provide robust evidence of your organization's security measures.

    Overview

    Zilla Security delivers an identity security solution focused on comprehensive security and compliance that is automated and easy to use. The platform combines identity governance with cloud security to deliver access visibility, compliance reviews, user lifecycle management, segregation of duties, and policy-based security remediation.

    Zilla's no-code integration with SaaS applications like Salesforce, cloud infrastructure like AWS, and cloud databases like Databricks, is unparalleled. Robotic automation enables the platform to monitor and configure all web-based applications, even those that don't have security APIs.

    Zilla's self-learning, intelligent automation easily handles cloud scale and dramatically reduces the cost of ownership via a simple user experience that enables collaboration between app owners, IT, security teams, and auditors.

    Zilla delivers:

    Extensive library of out-of-the-box app Integrations Fast onboarding of any app - no coding or scripting - including custom and legacy apps without APIs Fully automated access reviews campaigns and compliance assessments for multiple reviewer types Simple user experience for frictionless collaboration between stakeholders Continuous and audit-ready compliance with all the supporting evidence in one place Advanced search and reporting for the compliance audit purposes Complete visibility into who has access to what

    Highlights

    • Automated monitoring and remediation of access - who has access to what and any access risks. Zilla enables organizations to easily monitor all permissions, infrastructure entitlements, and security settings that give users, machines, and APIs access. We deliver insight into critical access risk and then remediate inappropriate access via integration with an organization's ITSM systems for ticketing workflows.
    • Comprehensive integrations with Zilla Universal Sync (ZUS) - we haven't met an app we can't support. Zilla makes it easy to integrate the tools, systems, and platforms organizations use every day. The platform includes robotic automation that enables customers to integrate with all applications, including legacy and homegrown apps, and ones that offer no security APIs or file exports for security data.
    • Simple, automated User Access Reviews (UAR) - go from months to days for reviews and audits. Zilla automates the entire UAR process and delivers an auditable system of record. The platform generates permissions relevant to a campaign, invites reviewers to complete work, and enables administrators to track reviewer progress. Reviewers can maintain, revoke, change, re-assign, or delegate permissions, while campaign administrators have complete control over the review process.

    Details

    Delivery method

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (3)

     Info
    Dimension
    Description
    Cost/12 months
    Comply 500/25
    Zilla Security - Comply for 500 Identities and 25 applications
    $45,000.00
    Comply 2500/100
    Zilla Security - Comply for 2500 identities and 100 applications
    $90,000.00
    Comply additional app
    Zilla Security - Comply Additional App
    $1,000.00

    Vendor refund policy

    No refunds are available

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Vendor resources

    Support

    Vendor support

    The Zilla Customer Support Team is dedicated to providing you with a best-in-class support experience. Our goal is to exceed your expectations and make you successful. Support@ZillaSecurity.com  address

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Hybrid Compute Remote Access, Centralized Identity Management
    Top
    25
    In Data Security and Governance

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    22 reviews
    Insufficient data
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Identity Governance
    Comprehensive platform combining identity and access governance with cloud security monitoring
    Access Control Automation
    Robotic automation for monitoring and configuring web-based applications without security APIs
    Multi-Application Integration
    No-code integration capabilities with SaaS applications, cloud infrastructure, and cloud databases
    Continuous Security Monitoring
    Intelligent self-learning system for tracking permissions, infrastructure entitlements, and security settings across user, machine, and API access
    Compliance Review Mechanism
    Fully automated access review campaigns with capabilities for generating permissions, inviting reviewers, and tracking review progress
    Access Control Mechanism
    "Implements Just-in-Time (JIT) and Break-Glass access provisioning with dynamic privilege management"
    Cloud Infrastructure Security
    "Supports Cloud Infrastructure Entitlement Management (CIEM) with granular access control across cloud environments"
    Identity Governance
    "Enables automated and delegated access workflows with scalable least privilege access management"
    Compliance Management
    "Facilitates comprehensive user access reviews supporting multiple compliance frameworks including SOX, SOC-2, ISO"
    Integration Capabilities
    "Provides seamless integration with collaboration and service management tools like Slack, Teams, Jira, ServiceNow"
    Identity Discovery
    Comprehensive discovery of identities and applications through multiple integration methods including SSO platforms, financial systems, direct integrations, and browser/desktop agents
    Access Management Automation
    Automated provisioning and deprovisioning of user access with bulk management capabilities for employee lifecycle transitions
    Compliance Control
    Automated access controls for meeting regulatory requirements including SOX, HIPAA, and SOC 2 standards
    Application Integration
    Multi-modal integration capabilities supporting direct, SSO, financial, browser, and desktop agent connection methods
    Security Governance
    Centralized platform for managing and reviewing user access rights across enterprise application ecosystem

    Contract

     Info
    Standard contract
    No

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 AWS reviews
    |
    24 external reviews
    Star ratings include only reviews from verified AWS customers. External reviews can also include a star rating, but star ratings from external reviews are not averaged in with the AWS customer star ratings.
    Information Technology and Services

    Access Reviews Made Simple

    Reviewed on Nov 08, 2024
    Review provided by G2
    What do you like best about the product?
    It's considerably sped up our user access review process and has a nice, modern UI. No more spreadsheets for us!
    What do you dislike about the product?
    Upkeep and data sanitation can be tedious.
    What problems is the product solving and how is that benefiting you?
    Primarily user access reviews. Zilla quickly allowed us to automate the process in a few key areas, such as data collection and automating portions of the review itself, significantly reducing the time our stakeholders require to complete reviews. The out-of-the-box integrations are simple and easy to configure, and Zilla offers excellent tools for data collection if API syncs are unavailable for a specific system.
    reviewer2517972

    The interface is highly intuitive and much easier for non-technical users than other tools

    Reviewed on Jul 24, 2024
    Review provided by PeerSpot
    ">

    What is our primary use case?

    We are a financial services company that's regulated by the FDIC, so we must complete a SOC 2 report showing evidence that we regularly review our high-risk applications. 

    How has it helped my organization?

    The solution has been a lifesaver. It has given us a unified platform that allows us to easily demonstrate what we need to do regarding user access reviews for compliance. 

    Before Zilla, we were using fairly complicated spreadsheets, and it took a long time for the information security team to update these and send them to the business lines every quarter. We wanted something that was automated and easier for the business lines to review. Ultimately, it ended up saving the InfoSec team 60 hours per quarterly review and the business lines well over 100 hours. 

    We had these spreadsheets all over the place, but now we have a library of evidence to consult when needed. Zilla keeps everything in one place. It's not scattered all over anymore. 

    Because we must adhere to the SOC 2 framework, we need to manage our user permissions to the least privileged level. Since the spreadsheets were so complicated, many people rubber-stamped permissions. They weren't going to dive into this rat's nest, so they would just say everything is fine. With Zilla, people were able to see more clearly into their permissions, and I feel confident that we're drilling down and adhering to the least privileged rule. 

    The manual work needed to track everything on spreadsheets was becoming unsustainable as we added applications. We can import permissions directly into Zilla instead of juggling the data and massaging it so it fits into the spreadsheets. It's probably saved my team about 40 hours per quarter.

    Zilla saves us money. We did some calculations during the first quarter and found that some people doing user access reviews were at the VP level, so their time is worth a ton of money. We also found that these folks were spending unnecessary time combing through these spreadsheets. Something that typically took an hour could be completed in 15 minutes with Zilla. 

    What is most valuable?

    The interface is highly intuitive, and that helps in many ways because we don't need to explain things to the business lines. It's much easier than other identity and management tools. We were looking for something clear-cut that makes sense to non-technical people. It has greatly improved the controls on our audit procedures by giving people something that's clean and makes sense.

    It's extremely important that Zilla provides us with a single pane of glass. When the FDIC asks us for a review, it's easier to have it in one portal than to go to all these spreadsheets scattered over SharePoint. Spreadsheets can also be manipulated, but Zilla has an audit trail that we can follow and show without a doubt that we've done what was required. 

    What needs improvement?

    Maybe this is coming with their AI module, but I would like to see a feature that performs baseline analysis of permissions that may not fit into a role, and it attempts to group them into a role. We've run into problems with applications where someone has not created a role but assigned ad hoc permissions to a user. We still need to do some manual work to identify the group that the user belongs to. It would be amazing to have Zilla streamline that. 

    For how long have I used the solution?

    I have used Zilla for a year and a half. 

    What do I think about the stability of the solution?

    Zilla is highly stable. We've had zero problems with it. 

    What do I think about the scalability of the solution?

    When we were using spreadsheets, we reviewed about eight applications, but since we added Zilla, we've scaled up to more than 40 and we continue to add to it quarterly.

    How are customer service and support?

    I haven't needed support since the initial setup, but we have a monthly meeting with our customer success rep. We discuss our needs and upcoming features on the roadmap.

    Which solution did I use previously and why did I switch?

    I have seven years of experience with SailPoint. It had the role-analysis feature and was a full-blown IAM solution, but we were looking for something we could use of the InfoSec team and GRC specifically that would enable us to do user access reviews. If I did an apples-to-apples comparison between Zilla and SailPoint regarding user access reviews, I would say Zilla comes out ahead for intuitiveness. It's easier to import permissions and it's simpler for non-technical people to use.

    We use a tool called Saviynt that's run in-house by our identity access and management department. That also has user access management, but they hope to move away from it because support hasn't been great. Rather than wait for the IAM team, we decided to go for our own solution. While doing a deep dive into Saviynt, we came across Zilla. Our IAM team told us that if we wanted to switch, it would take only a week or two to get it set up. 

    How was the initial setup?

    Deploying Zilla was easier than I expected, based on my experience with SailPoint and Saviynt. With those, it was an arduous process. The initial deployment was short, but it took us a quarter to get the solution up to usability. It doesn't require much maintenance aside from regularly updating permissions. It's more administration than maintenance. 

    What about the implementation team?

    We received support from Zilla's team, which was very helpful. 

    What's my experience with pricing, setup cost, and licensing?

    The Zilla license is what we expect to pay for a product like this. 

    What other advice do I have?

    I rate Zilla Security nine out of 10. I recommend that new users follow the advice of their solution engineer. They knew what they were doing and guided us through the installation. 

    Which deployment model are you using for this solution?

    Public Cloud
    Hubert Hopkins

    Reasonably priced, responsive support, and easy to implement access reviews

    Reviewed on Jul 17, 2024
    Review provided by PeerSpot
    ">

    What is our primary use case?

    We use the tool for access reviews. It is mainly for our regulatory SOX compliance. That was the main use case, and why we purchased Zilla back at the end of 2021.

    How has it helped my organization?

    The system is pretty self-explanatory and easy to use. It is menu-driven. You can certainly hide the menu and go with icons that describe the menu items. It is easy to locate the things or categories that you need.

    They are getting there in terms of the unified identity platform. We were one of the early adopters of Zilla, and I have seen it grow over the past couple of years. They are innovative and forward-thinking in their enhancements and development of the tool. They are adding things onto the tool to expand what it can do, whether it is additional application APIs or security findings and policies. 

    I don't know if it has helped to consolidate applications, but it has made it easy to implement access reviews for critical applications. Previously, there was no process at all for an access review. It was a manual process, and now we have been able to automate it. We have not utilized everything that Zilla can do now to its complete ability. We are still growing in terms of the opportunities in the system.

    We have looked at some of the policy-based information provided in Zilla but have not yet fully utilized it. I do look at some of the critical policies relevant to our environment that may pop up, and try to utilize them, such as if a terminated privileged user still has access to some systems. Whether that is true or false, it gives me that identification. I can then explore and validate if it is still true or not.

    There are prebuilt APIs for many well-known applications. We have a few applications for which they have prebuilt their APIs. Others in our environment require the use of a CSV file upload to import user lists, which Zilla makes easy to do.

    For our use case, when we initially purchased it, we did see the benefit right away or within the first few months of using it.

    Zilla Security  has helped improve controls when automating manual work. Some of these review processes were nonexistent or manual spreadsheet-based types of interactions. Being able to automate the process was a key factor.

    Zilla Security  has enabled me and one colleague to do more with less. It may have freed up some time for the business users, but it has enabled my smaller team to accomplish a lot more. 

    I am sure Zilla Security has helped us save costs. We have been able to use limited resources to do more. We have not had to increase the team to manage the access reviews we perform. I haven't put a quantitative number on savings, but it has streamlined processes.

    What is most valuable?

    I enjoy the ease of setup and creation of a review. Being a user of the tool or an admin of the tool, the ease of setup of an access review is valuable. End users find out, after they complain about having to do it, how simple and easy it was for them to complete their reviews. It's as simple for them to click on a link in an email, check a few boxes, and submit their review. I tell most reviewers that the process of review, depending on the number of items reviewed, can take you less than 5 minutes to complete. 

    The ability to sync applications via an API on a scheduled basis, if you choose, it also valuable in time savings because a admin doesn't have to remember to login and perform the function. 

    What needs improvement?

    There is still no automated way to de-provision access due to a review completion, but they are getting there in terms of making it unified.

    Right now it is just a one-way integration, importing user lists. I believe they working on it. I can pull a user list in, but when I do a review, the results get sent to a ticket which requires a person to execute. As a result of the review, there is no automation for the removal of access. They are going there, and the next step is to continue to streamline the process operationally and resource-wise. The review process is great. The scope for improvement is more at the results end. It would be great if it could systematically communicate with that end system and remove the requested access automatically.

    For how long have I used the solution?

    We first started using it in 2021.

    What do I think about the stability of the solution?

    We have had lagging-related issues on very rare occasions accessing the system pages, but I cannot say if it was on the Zilla side or our own network side. If there is a major issue, which over the past 2.5 years I can only think of 1, Zilla proactively communicates that they know about and are working on. 

    What do I think about the scalability of the solution?

    We have applications with 50 users in them, and we also have applications with 4,000 users that we review. It scales well across all of those applications. 

    How are customer service and support?

    I have contacted them a bunch of times. They react pretty quickly and they respond fast to take care of things or inquire for clarification of what the issue may be. I have had positive responses from the support team and I would rate them a nine out of ten.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    We have not used any other solution besides spreadsheets. I have seen other tools in my career and would say that Zilla still seems the simplest to use and setup when it comes to the review process. 

    How was the initial setup?

    Zilla is a cloud-based solution. It was fairly easy to set up. We had to pick a primary directory or source of truth for users. 

    If you have applications that they don't currently have APIs for, it is a manual input process. But once you have done a manual input file once or twice, it is fairly easy to use.

    We purchased Zilla at the end of October or November of 2021. I had it up and running our first access review within a month.

    One key is the need for collaboration with others who own applications. One or two people could manage the system, but you have to have that collaboration with others.

    In terms of maintenance, I would say that the system mostly can maintain itself. I would call myself the admin user of the system. I am in it every day. I keep an eye on certain things, especially scheduled APIs to ensure they execute.

    What about the implementation team?

    We implemented it in-house with our teams and Zilla. 

    What's my experience with pricing, setup cost, and licensing?

    It has been fair because we have been in from the beginning or close to the beginning. I know it is not truly an identity access management system yet, but its price was one of the appealing factors for us to purchase it at the time. It was reasonably priced.

    Which other solutions did I evaluate?

    We did not, mainly based on the size of our organization at the time. 

    What other advice do I have?

    I would advise knowing the source of truth that you are going to use upfront. If you need to change, that can be more complicated. Educating end users is always the biggest challenge with any process, but spending time to learn it is worth it.

    I would rate Zilla Security a nine out of ten. It has been very easy to use. I have liked working with their team on different things, and they are very responsive.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    SYED ZAFFAR M.

    Zilla Security- Enhanced automation of access control management.

    Reviewed on May 25, 2024
    Review provided by G2
    What do you like best about the product?
    We integrate Zilla security in our higher education institution to allow authorized students and subscribers access to academic resources, documents, projects and presentations. They frequently share their assignments and updates with group members remotely. This application helps us to monitor and control access management.
    What do you dislike about the product?
    So far, we have not faced any technical issues with this application.
    What problems is the product solving and how is that benefiting you?
    It provides the identity and details of all users who access our resources and automates the authorization management. Any misadventures will be detected and barred.
    Ahmad J.

    Great Product for Access Reviews

    Reviewed on Mar 22, 2024
    Review provided by G2
    What do you like best about the product?
    The easy connections to our core applications
    What do you dislike about the product?
    I wish there could be automated remediation
    What problems is the product solving and how is that benefiting you?
    Zilla has given us a better more streamlined approach to a previous manual process.
    View all reviews