Listing Thumbnail

    TrendAI™ Enterprise Security Solutions

     Info
    Sold by: Trend Micro 
    Deployed on AWS
    Enterprise security solutions powered by TrendAI™ (a business unit of Trend Micro) to help protect users, data, and workloads. Contact us today to tailor a solution for your needs!
    4.3

    Overview

    Play video

    TrendAI™, a business unit of Trend Micro and a global AI security leader, makes the world safer for digital information exchange across enterprises, governments, and organizations. Powered by security expertise and innovation, TrendAI™ leverages artificial intelligence to protect over 500,000 enterprises and millions of individuals across AI, cloud, networks, endpoints, and devices. AI Fearlessly.

    TrendAI™ delivers adaptable enterprise security designed to enhance visibility, strengthen protection, and streamline response across complex environments. With deep threat intelligence and AI-driven analytics, TrendAI™ helps organizations reduce risk and confidently defend their digital operations.

    Looking for advanced detection and response capabilities across workloads, identities, endpoints, networks, and more? Check out TrendAI Vision One™, which also offers a flexible pay-as-you-go option.

    If you'd like support exploring the right security approach for your organization, please contact us at aws.marketplace@trendmicro.com .

    Highlights

    • Enterprise security solutions- including managed XDR. See more, respond faster.
    • Increase risk visibility while decreasing response times.
    • Greater Security Team Efficiency: one platform to respond faster with less resources and one source of truth

    Details

    Categories

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    TrendAI™ Enterprise Security Solutions

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    1-month contract (1)

     Info
    Dimension
    Description
    Cost/month
    Enterprise Solution
    Custom Security solutions - contact for more info and pricing
    $10,000.00

    AI Insights

     Info

    Dimensions summary

    This listing offers a single pricing option: a custom Enterprise Solution priced in units. Rather than fixed tiers or instance sizes, you work with the vendor to scope a security solution for your needs. Pricing is set through a contract and depends on what you configure, so you contact the vendor for details and a quote. The solution covers cloud security for your AWS environment, including workload, container, and file protection. Because pricing is tailored, there is no published per-unit rate to compare here.

    Top-of-mind questions for buyers

    A unit is not a fixed item like a server or user. This is a custom solution scoped with the vendor. The number of units depends on what you configure for your environment. Because the solution is tailored, you contact the vendor to learn how units map to your specific setup and quote.
    The solution secures your AWS environment across several areas. You get server and cloud workload protection, container security with image scanning and runtime protection, and file scanning for cloud objects in applications. It also centralizes visibility across multiple AWS accounts and helps detect misconfigurations against compliance frameworks.
    This is a contract-based pricing model, not usage metering. You do not pay per hour of running time. Instead, you agree on a scoped solution and quantity of units through a contract with the vendor. Because pricing is custom, you contact the vendor to define scope and terms.
    trendmicro.com
    Helpful?

    Vendor refund policy

    Refunds are not available at this time.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Your purchase also includes 24x7 support from Trend Micro. If you experience any issues or have questions, please contact our AWS Cloud Security experts by email at aws.marketplace@trendmicro.com . aws.marketplace@trendmicro.com 

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Security
    Top
    10
    In Managed Services
    Top
    10
    In Education & Research

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    5 reviews
    Insufficient data
    Insufficient data
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Managed Extended Detection and Response
    Managed XDR capabilities for detecting and responding to threats across enterprise environments
    AI-Driven Threat Analytics
    Artificial intelligence-powered analytics for threat detection and analysis across workloads, identities, endpoints, and networks
    Unified Security Platform
    Centralized platform providing single source of truth for security operations and incident response across complex environments
    Deep Threat Intelligence Integration
    Integration of deep threat intelligence to enhance detection capabilities and reduce organizational risk
    Multi-Layer Protection Coverage
    Security protection spanning AI, cloud, networks, endpoints, and devices across enterprise infrastructure
    Extended Detection and Response (XDR)
    XDR technology with full coverage across endpoints, network, users, and cloud environments powered by proprietary Threat Intelligence and Detection Engine
    Unlimited Data Ingestion and Retention
    Unlimited data ingestion capability with 13 months of data storage for comprehensive investigation and forensic analysis
    24/7 Threat Monitoring and Hunting
    Round-the-clock monitoring, triage, investigation, and threat hunting services delivered by security experts
    Integrated Vulnerability and Exposure Management
    Vulnerability management and exposure management capabilities integrated with threat detection and response to strengthen security posture
    Unlimited Incident Response and Forensics
    End-to-end digital forensics and incident response services without limits on investigation hours, complexity, or scope
    Endpoint Detection and Response
    EDR capabilities enabling detection, investigation, and response to multi-stage threats across all key attack vectors
    Extended Detection and Response
    Unified XDR platform detecting and responding to threats across network, cloud, endpoint, identity, and email data sources
    Managed Detection and Response
    24/7 ransomware and breach prevention services with breach warranty and integration capabilities for existing security tools
    Threat Prevention Technology
    Prevention-first approach using sophisticated technologies to block a broad range of attacks
    Security Posture Assessment
    Deployment capabilities with drift identification in security posture and default-enabled strong protection

    Contract

     Info
    Standard contract
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.3
    131 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    57%
    40%
    2%
    0%
    1%
    28 AWS reviews
    |
    103 external reviews
    External reviews are from G2  and PeerSpot .
    Mayankt Tripathi

    Centralized visibility has streamlined threat investigations and improves daily security monitoring

    Reviewed on Sep 25, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case of TrendAI Vision One is security monitoring and threat detection. On a day-to-day basis, I use it to monitor endpoint and server activity, investigate security alerts, and understand suspicious behavior. I also find the XDR capabilities useful because they correlate events from different security layers, giving the SOC team better context during incident investigation and response.

    TrendAI Vision One's XDR capabilities help by correlating endpoint, email, and network events into a single incident view. For example, when a user received a suspicious email and their endpoint subsequently showed unusual activity, we could connect those events instead of investigating them separately. This gave the SOC better context around the timeline, reducing manual investigation and helping us determine the appropriate response more quickly.

    What is most valuable?

    TrendAI Vision One has helped improve our overall security visibility and made incident investigations more structured. The centralized view of security events gives the team better context and reduces the need to manually correlate information from different tools. We have also seen improvements in handling repetitive alerts through automation. Overall, it has helped the SOC team handle incidents more effectively and streamline day-to-day security operations.

    What needs improvement?

    One area I would like to see improved is the overall user experience and customization options, usually for dashboards and reporting and integrations. Some configurations can also require additional effort when working with a complex enterprise environment. I would also like more flexibility around automation and investigation workflows. Improvement in these areas could make the platform easier to tailor to different SOC teams and operational requirements.

    I think the documentation could be more detailed for advanced configuration and integration, particularly for a larger enterprise environment. More practical examples and troubleshooting guides would make implementation easier for security teams. On the support side, faster resolution for complex technical issues would be helpful. As the environment scales, continued improvements in performance, reporting, and integration flexibility would also add value.

    For how long have I used the solution?

    I have been using TrendAI Vision One for around six months.

    What do I think about the stability of the solution?

    Overall, TrendAI Vision One has been stable in our experience. We have not faced any major reliability issues during normal security monitoring and investigation activities. Performance has generally been consistent, although any enterprise security platform's resource requirements can become more noticeable as the number of protected endpoints and servers increases. Proper sizing and capacity planning are therefore important for maintaining smooth performance at scale.

    What do I think about the scalability of the solution?

    TrendAI Vision One has scaled well with our environment so far. As we have increased the number of protected endpoints and servers, it has continued to provide centralized monitoring and security visibility without major operational issues. The main consideration is proper capacity planning and infrastructure sizing as the environment grows. Overall, it provides a practical foundation for expanding endpoint and server coverage in a timely manner.

    How are customer service and support?

    We have had to contact support for configuration and troubleshooting-related questions. Overall, the support experience has been positive, especially when dealing with product-specific technical issues. The support team was helpful in understanding the problem and providing guidance, although the response times can vary depending on the complexity and priority of the issue. More detailed self-service documentation would also make solving common issues faster.

    Which solution did I use previously and why did I switch?

    We previously used separate security solutions for endpoint protection and monitoring, which meant analysts had to work across multiple consoles during investigations. We moved toward TrendAI Vision One mainly to consolidate visibility and reduce those silos. Having XDR capabilities and centralized incident context in one platform made it easier to correlate events, investigate threats, and streamline the overall security operational workflows.

    How was the initial setup?

    Our experience with pricing and licensing has been reasonable overall, although the total cost depends on the number of endpoints, servers, and security capabilities required. The initial setup also requires some planning, particularly when integrating it with an existing enterprise environment. I would recommend clearly mapping the required modules and expecting deployment scale beforehand to avoid unexpected licensing or infrastructure costs.

    What was our ROI?

    We have seen a practical return on investment, mainly through analyst time saved rather than direct headcount reduction. Centralized visibility and XDR correlation reduce the time spent collecting and correlating information across different tools. Automation also helps with repetitive investigation and response tasks. Although we cannot calculate an exact monetary saving, the reduction in manual effort and faster incident handling have provided clear operational value.

    Which other solutions did I evaluate?

    We have evaluated a few established endpoint and XDR solutions before choosing TrendAI Vision One. The comparison mainly focused on detection capabilities, XDR correlation, endpoint and server coverage, integration with our existing environment, ease of investigation, and overall licensing. TrendAI Vision One stood out because it provided broader centralized visibility and allowed us to bring multiple security capabilities within a single platform.

    What other advice do I have?

    TrendAI Vision One is useful when you need centralized visibility across a diverse environment. It helps reduce the need to switch between multiple security consoles and gives the team more context during investigations. I also find the automated response and risk visibility capabilities useful for prioritizing incidents and reducing repetitive manual work from the SOC team.

    The biggest improvement has been reducing the time spent switching between different security consoles during investigations. With correlated events and a centralized incident view, analysts can understand the timeline and context faster. Automated response and playbooks also help with repetitive tasks. Overall, it has made our investigation process more streamlined and helped the team respond to relevant alerts more efficiently.

    The features that stand out most to me are the XDR correlation, centralized incident visibility, and endpoint protection. XDR helps connect activity across endpoints, email, networks, and other security layers, which makes the investigation easier. I also find the workbench useful for getting a consolidated view of incidents, while the automated response and playbook capabilities can help reduce repetitive manual tasks for the SOC team.

    One of the main challenges is dealing with phishing, malware, and endpoint compromise while managing increasingly sophisticated attacks and a larger number of security events. TrendAI Vision One helps by providing centralized visibility across endpoints and servers, correlating related security events, and supporting faster investigations. Detection and response capabilities help the SOC prioritize higher-risk incidents and reduce manual investigation effort.

    I would rate this review a ten out of ten.

    Which deployment model are you using for this solution?

    On-premises

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Dev Ramtoolah

    Automated remediation has transformed incident triage and now streamlines threat hunting

    Reviewed on Sep 25, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for TrendAI Vision One is for incident triage and response management.

    A specific example of how I use it for incident triage and response management is the elimination of collateral display and low log management from emails. This is how it helped.

    The automated remediation triggers automated commitment actions, isolating infection of the endpoint. This is beneficial and helps significantly.

    What is most valuable?

    The best features TrendAI Vision One offers include the powerful threat hunting and AI security capabilities, among the top features mentioned. The AI security analysis allows input of plain language requests for effective endpoint command analysis. Threat hunting assists in identifying alerts. Additionally, real-time inspection of LLM interactions helps secure operations within private and public environments. The centralized Vision One console hosted in a cloud-native environment also contributes greatly by ensuring robust security coverage.

    What needs improvement?

    TrendAI Vision One can improve in control responsiveness, particularly in navigating through heavy analytics interfaces like workbench, where execution graphs can experience noticeable latency. This occurs during multi-complex layers correlation and high volume of queries load. Secondly, I suggest improving license and credit allocation transparency.

    A deep ecosystem integration with deeper non-Trend native telemetry ingestion would help significantly.

    For how long have I used the solution?

    I have used TrendAI Vision One for almost two years.

    What do I think about the stability of the solution?

    TrendAI Vision One is stable.

    What do I think about the scalability of the solution?

    TrendAI Vision One's scalability is quite good; it benefits from cloud-native elasticity, which I use most often. The centralized Vision One console runs in the cloud-native environment, hosted on a public backbone like AWS and Azure. It is very easy for me to automatically scale based on log flow.

    How are customer service and support?

    The customer support has been acceptable.

    Which solution did I use previously and why did I switch?

    I previously used a different solution, Sophos, but it was too costly and very limited compared to TrendAI Vision One.

    What was our ROI?

    I have seen a return on investment financially, with up to a 79% reduction in security costs and a 70% faster incident investigation and response time.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing has been quite acceptable, especially with the flexibility of having a credit-based licensing architecture by using TrendFlex.

    Which other solutions did I evaluate?

    Before choosing TrendAI Vision One, I did not evaluate other options.

    What other advice do I have?

    My advice to others looking into using TrendAI Vision One is to utilize the powered API connectors, link your SaaS with Office 365 and endpoint security, and evaluate it thoroughly before proceeding. I would rate this product a 10.

    Mujahid Ali.

    Centralized threat visibility has streamlined daily investigations and improved incident response

    Reviewed on Sep 25, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for TrendAI Vision One is security monitoring and threat detection. On a daily basis, I check alerts, investigate suspicious activities, and look into endpoint or network-related incidents. For example, if TrendAI Vision One detects unusual behavior on any endpoint, I review the alert's details, check the related process and activities, and we take the required action or escalate if it is needed.

    What is most valuable?

    The best features in TrendAI Vision One that stand out to me are endpoint detections and response, centralized visibility, and detailed alert investigation. I also appreciate the correlations of security events, which makes it easier and simpler to understand the full context of an incident, and it gives better ability to investigate endpoint activity and respond from one platform. This is very useful for our SOC environment.

    TrendAI Vision One has positively impacted our organization by making our investigation workflow more efficient and providing better visibility into endpoint activity. We also have related alerts from one platform, which reduces the time spent switching between different tools, allowing me to investigate suspicious activity faster and easier while giving the team more context when deciding whether an incident needs escalation or not.

    What needs improvement?

    One area of TrendAI Vision One that could be improved is the alert investigation experience. Some alerts contain a lot of information, so having a simpler way to prioritize the most important details would make the investigation faster. I would also like to see more customization options for dashboards and alert filtering based on our SOC environment.

    Better integration with other security tools, especially for teams using multiple SIEM and security platforms such as Wazuh and Splunk, would be useful for TrendAI Vision One. Reporting could also be more flexible, with customizable templates and options to create reports based on specific incidents, alert types, or time periods, making it easier to share investigation results with the wider team.

    One smaller improvement I think would be beneficial for TrendAI Vision One is better notification and alert customization, providing more control over which alerts are prioritized or notified to the SOC team based on severity.

    For how long have I used the solution?

    I have been using TrendAI Vision One for around one and a half years, utilizing it for security monitoring, investigating alerts, threat detections, and analyzing suspicious activity.

    What do I think about the stability of the solution?

    In my experience, TrendAI Vision One has been generally stable for day-to-day SOC operations. I have not personally seen any major or prolonged downtime that affected our organization. There can be occasional delays or minor issues with alert data or console performance, but overall, it has been reliable enough for regular monitoring and incident investigation.

    What do I think about the scalability of the solution?

    TrendAI Vision One has scaled well with our environment so far. As the number of endpoints and servers increases, we are able to extend coverage without major changes to the SOC workflow. The centralized console also makes it easier to manage and investigate alerts across a large environment, and configuration and tuning become more important as the volume of alerts grows.

    How are customer service and support?

    I have had limited direct interactions with TrendAI Vision One support since our internal team handles most day-to-day issues. When we needed assistance, the support team was responsive and helped with troubleshooting and product-related questions. Having clear documentation and timely technical guidance is very useful when we face an issue requiring vendor-level support.

    Which solution did I use previously and why did I switch?

    Before TrendAI Vision One, we used a combination of endpoint security SIEM tools for monitoring and investigation. We switched to TrendAI Vision One because we wanted more centralized endpoint visibility and better correlation of security events while reducing the need to switch between multiple consoles during investigations. The different solutions we had to use in our environment are Wazuh and SentinelOne Singularity.

    What was our ROI?

    From my perspective, the biggest benefit of TrendAI Vision One has been time savings rather than directly reducing headcount or licensing costs. Having centralized visibility and better alert context makes triage and investigation quicker, allowing analysts to spend more time on genuine incidents instead of manually collecting information from different tools. The workflow efficiency has been noticeable, though I do not have a formal ROI figure.

    What's my experience with pricing, setup cost, and licensing?

    I am not directly involved in commercial negotiations, so I do not have the exact pricing or setup cost for TrendAI Vision One. The licensing is managed by our organization, and from the operational side, deployment and access have been fairly straightforward. For a detailed cost comparison, I would need to rely on our procurement or management team.

    Which other solutions did I evaluate?

    Our organization evaluated a few endpoint security and XDR options before selecting TrendAI Vision One. The options included Microsoft Defender for Endpoint, CrowdStrike Falcon, and SentinelOne. The evaluation focused mainly on detection capabilities, endpoint visibility, integrations, investigation workflow, and how well the solution would fit with our existing SOC environment.

    What other advice do I have?

    I rate TrendAI Vision One an eight out of ten.

    I chose eight out of ten for TrendAI Vision One because it provides good visibility and makes alert investigation easier for our SOC environment. To make it a ten, I would want to see a more streamlined investigation experience, better customizations for dashboards and reporting, and strong integration with other security tools we use.

    In my experience, the AI capabilities of TrendAI Vision One are useful for improving detections and investigation while security and access controls are important for keeping the environment protected. We also value having visibility into why an alert is being raised rather than relying only on AI-generated results. For our SOC workflow, keeping human review as part of the investigation is important.

    From my experience, the AI output of TrendAI Vision One has been fairly consistent and useful for the initial investigation. It helps provide context about suspicious activities and prioritize alerts. However, we still validate the findings with available events and logs to the endpoints' details before taking action, since AI results should not be treated as the only source of truth.

    We use TrendAI Vision One in a hybrid cloud setup, which gives us centralized visibility through the cloud platform while still allowing us to monitor and protect endpoints and infrastructure in our organization. This works well with our existing SOC environment and security tools.

    The cloud provider we primarily use in our hybrid setup for TrendAI Vision One is Microsoft Azure, which is utilized alongside our existing cloud and on-premises security infrastructure, helping us maintain centralized visibility across both environments.

    We have mainly used TrendAI Vision One sensors across endpoints and servers. They are deployed on employee workstations and critical servers to provide endpoint visibility and detect suspicious activity, while there is also some coverage for cloud workloads depending on our security environment requirements.

    The coverage from TrendAI Vision One is quite critical for our organization because it provides visibility across endpoints and servers, helping us detect suspicious activity earlier and investigate incidents with more context. Without this visibility, some endpoint-level activity could be harder to identify and correlate with other security alerts.

    Some of the top security challenges in our industry include phishing, malware, credential-based attacks, endpoint compromise, and the increasing number of security alerts our team needs to investigate. TrendAI Vision One helps us address these by providing endpoint visibility, detecting suspicious behavior, and correlating related activities, making it easier to identify real threats and investigate incidents with useful evidence.

    My impression is that TrendAI Vision One provides good centralized visibility across different protection layers, especially endpoints, servers, and related security events. From a SOC perspective, it is very useful to have endpoint telemetry and detection information available in one platform instead of investigating everything separately, which helps us correlate events and understand the wider context of an incident to decide what needs escalation.

    TrendAI Vision One has helped reduce silos to some extent by bringing endpoint detection, investigation data, and related security events into a more centralized view. From the SOC side, this means we do not always have to switch between multiple consoles to understand the same incident. We still use other security tools, but TrendAI Vision One helps us connect the information and provide a more complete scenario.

    AI capabilities in TrendAI Vision One are quite important for our organization because the SOC team deals with a high volume of alerts every day. It helps us detect, correlate, and prioritize suspicious activity while providing additional context during investigations. It does not replace analyst validation but helps us focus our time on the alerts that need deeper investigation and faster response.

    TrendAI Vision One has helped reduce the time spent on initial detection and investigation. I do not have a formally measured percentage, but in daily SOC work, having the alert context, endpoint activity, and related events in one place makes the initial triage noticeably faster, helping us validate suspicious activity and escalate genuine threats without spending much time gathering information from various consoles.

    AbdulAbdul

    Centralized XDR has improved investigations and now simplifies endpoint and email threat response

    Reviewed on Sep 25, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for TrendAI Vision One is endpoint security, server security, or network security.

    For endpoint server security, we have been using it as an essential endpoint security module where we deploy an agent on the client machines and maintain or monitor application control, firewall, anti-malware, spam, web reputation, spam reputation, and other similar capabilities, which is the same for servers including intrusion prevention and detection and response.

    Furthermore, for the servers, we use it on-prem and on-cloud, specifically on-prem deep security, which we can migrate and integrate to TrendAI Vision One cloud.

    What is most valuable?

    In my experience, one of the best features of TrendAI Vision One is the XDR capability, which involves a centralized console collecting logs from multiple sources, correlating them, and telling us a story.

    TrendAI Vision One positively impacts my organization because it is the tool we utilize more than any other cybersecurity-providing tool, as it has a very user-friendly console that I can easily explain to clients, allowing them to understand and carry forward investigations.

    For specific outcomes or metrics showcasing how TrendAI Vision One has benefited my organization, it includes playbooks that run on the workbench's correlations, correlating all log sets, pinpointing exact alerts so that the SOC team cannot waste more time and can simply investigate and address them.

    What needs improvement?

    An area for improvement for TrendAI Vision One that I notice is on the support side; if any support issues arise or bugs I report can be remediated or addressed more promptly.

    Additionally, regarding needed improvements, I pointed out to Trend Micro an issue related to email security, where an inbound protection policy I created, aimed at handling email attachments above a certain size, resulted in all emails being quarantined, and I reported that TrendAI Vision One lacked the capability to adequately manage this.

    For how long have I used the solution?

    I have been using TrendAI Vision One for more than five years.

    What do I think about the stability of the solution?

    TrendAI Vision One is stable in my experience, but some clients using data centers hosted in the Gulf region, mainly Dubai, face downtime issues.

    What do I think about the scalability of the solution?

    In terms of scalability, it performs well for endpoints, servers, email, network level, and sandboxing.

    How are customer service and support?

    I would rate customer support as average, about four out of five. On a scale of one to ten, I would rate customer support an eight.

    Which solution did I use previously and why did I switch?

    I have not switched from a different solution since my company provides multiple solutions as per client needs, leveraging various security vendors while finding TrendAI Vision One's features user-friendly and easy to understand.

    How was the initial setup?

    My advice to others looking into using TrendAI Vision One is that it is very user-friendly and easy to deploy, requiring some firewall rules, and you can deploy an agent to easily access control and investigate.

    What about the implementation team?

    We are using TrendAI Vision One sensors on endpoints and at the network level as well.

    This coverage is critical for my organization's network because the sensors collect XDR telemetry and forward it to the main console, TrendAI Vision One.

    What was our ROI?

    I have seen a return on investment, as I can affirm that employees save time dealing with complexities from other products due to TrendAI Vision One's ability to address many issues at the investigation, deployment, and analysis levels.

    What's my experience with pricing, setup cost, and licensing?

    Regarding my experience with pricing, setup cost, and licensing, I am uncertain about the exact price but note that TrendAI Vision One has shifted to a credit-based license model allowing flexible use across solutions.

    Which other solutions did I evaluate?

    Before choosing TrendAI Vision One, we evaluated other options including Kaspersky for endpoint security and FortiGate EDR.

    What other advice do I have?

    The governance and security of TrendAI Vision One's AI capabilities are actually good; I notice it provides alerts regarding exposure management and threats, along with compliance scores, overall scores, and risk scores to help mitigate and address concerns.

    In our industry, the top security challenges include securing endpoints against ransomware and malware attacks, which TrendAI Vision One covers well, along with email security.

    My impressions of TrendAI Vision One's ability to provide centralized visibility and management across protection layers are very good, as it collects data from all products and resources, correlating it to tell a cohesive story.

    TrendAI Vision One helps consolidate our use of security vendors and reduces silos, covering key areas such as endpoint encryption, compliance, and vulnerabilities, which I validate and remediate.

    The importance of TrendAI Vision One having AI built into its platform is high, as it helps explain alerts, attack phases, and process chains with ease. I would rate this review as eight out of ten.

    Lahiru Somasiri

    Unified security platform has reduced risk exposure and simplified threat detection and response

    Reviewed on Sep 24, 2026
    Review from a verified AWS customer

    What is our primary use case?

    TrendAI Vision One provides multiple security solutions including email security, endpoint security, XDR, and identity security, as well as cyber risk exposure management.

    For a Sri Lanka organization requesting a tender related to endpoint detection and response (EDR) solutions for their workstations and servers, I proposed TrendAI Vision One Standard Endpoint Protection.

    I also use TrendAI Vision One email security for customer requirements, such as securing their email traffic from attackers, and I have proposed an email security solution as well.

    What is most valuable?

    The best feature that is trending is cyber risk exposure management, which can be used to identify the risk score of the whole organization's security threat landscape.

    In customer environments where separate solutions exist to secure the environment, I integrate those third-party solutions with TrendAI Vision One, which analyzes the whole logs and shows a detailed view of the risk related to misconfigurations, vulnerabilities, and incidents captured from those third-party logs.

    When a customer comes with security solutions for their security landscape, including endpoint security, email security, and network security, I can propose a single solution to cater to all those requirements.

    The single solution approach allows me to avoid a siloed architecture. When I log into the solutions, I can use a single dashboard to navigate all security solutions, including endpoint security, email security, and cyber risk exposure management. Customers can identify their organization's risk and minimize that risk by following the remediation actions shown in TrendAI Vision One platform.

    What needs improvement?

    When it comes to challenges, I am using the Singapore region tenant, and I suggest adding more regions that come with the solution in the future.

    Regarding improvements, I believe they need to develop some dashboards with correlations; that would be better.

    For how long have I used the solution?

    I have been using TrendAI Vision One for nearly three-plus years.

    What do I think about the stability of the solution?

    TrendAI Vision One is stable.

    What do I think about the scalability of the solution?

    TrendAI Vision One now uses credits to manage the licensing part, so if I have free credits, I can utilize them for additional security requirements in TrendAI Vision One.

    How are customer service and support?

    Customer support is reliable. I have access to a support portal where I can raise support tickets according to severity levels, which are responded to quickly based on that severity.

    Which solution did I use previously and why did I switch?

    I started with TrendAI Vision One solution and have exclusively used that.

    What was our ROI?

    After deploying our solutions for customers, I find that there is no need for multiple admins to configure and monitor, as everything works independently from the configuration policies.

    Which other solutions did I evaluate?

    In the market, there are solutions such as Microsoft clouds or SentinelOne. As we are distributors for Trend Micro, I considered Trend Micro for our company domain.

    What other advice do I have?

    They are looking for new solutions with AI involvement while improving their policy levels and dashboards. They are also integrating their AI Chat companion into TrendAI Vision One console.

    Coverage is very critical for my organization's network because the threat landscape is increasing today, and attackers are using new techniques to compromise organizations. This is very critical for security solutions, and TrendAI provides security solutions to minimize the threat landscape.

    When it comes to remote code executions, I can use endpoint detection and response solutions. For spam and phishing mails, I can utilize TrendAI Vision One email security solution.

    These solutions are fully cloud-based, allowing access to the console from anywhere in the world using secure communications through the HTTPS protocol. If deployed as on-premise, I can use secure web gateways to communicate with that cloud console.

    TrendAI Vision One helps consolidate my use of security vendors and reduces silos since it provides multiple security solutions through one single dashboard, including email security, endpoint security, network security, and identity security.

    In today's threat landscape, it is important that TrendAI Vision One has AI built into its platform because I cannot rely solely on signatures, especially with attacks such as fileless attacks. I need AI and ML techniques to identify the behavior of these attacks.

    I use TrendAI Vision One in my hybrid environments to address security requirements, including Azure VMs where I have deployed TrendAI Vision One Server security agents, as well as on-premise deployments such as fingerprint and file servers to secure critical assets.

    TrendAI Vision One helps reduce my time to detect and respond to threats significantly due to its massive threat intelligence and the Zero-Day Initiatives team focusing on zero-day attacks and providing the best possible mitigation actions.

    When it comes to attacks, the solution carries out response actions quickly. I have not heard of any breaches from TrendAI Vision One platform.

    After analyzing logs from third-party solutions, TrendAI Vision One maps the risks and provides mitigation actions to reduce those risks. By following those steps, I can minimize risks.

    I use the cyber risk exposure management capabilities, which show me, for instance, what vulnerable software is installed on endpoints, helping me to identify versions, vulnerabilities, and risk scores. From there, I can determine necessary actions such as patching or protecting with endpoint security solutions.

    I rate this product nine out of ten based on my overall experience.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    View all reviews