Listing Thumbnail

    Aqua Cloud Native Application Protection Platform

     Info
    Deployed on AWS
    Vendor Insights
    Aqua secures every cloud native application on AWS across the entire lifecycle. Protect containers, serverless, Kubernetes, and AI workloads to accelerate innovation and scale securely. Prevent attacks and reduce risk with security enforced from code to cloud to prompt
    4.2

    Overview

    Play video

    Aqua secures every cloud native application everywhere, including AI. The Aqua Platform (CNAPP) delivers full lifecycle security from development to production, enabling organizations to build faster and innovate with confidence. FedRAMP High Authorized, Aqua helps enterprises meet the most rigorous security and compliance standards. By embedding security across the software development lifecycle, Aqua reduces risk and accelerates digital transformation on AWS. Get a Demo: https://www.aquasec.com/demo/ 

    Highlights

    • Unified platform to secure every cloud native application, including containers, serverless, Kubernetes, and AI workloads across AWS, on-premises, and multi-cloud environments
    • Runtime protection to detect threats, block malicious activity, and enforce compliance in production across all cloud native workloads
    • Purpose-built AI workload security to govern LLMs and generative AI applications, detect model abuse, and enforce policy

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (4)

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Aqua Cloud Native Application Protection Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (3)

     Info
    Dimension
    Description
    Cost/12 months
    Aqua Platform Shift Left
    Standard Plan
    $50,000.00
    Aqua Platform Protect
    Advanced Plan
    $100,000.00
    Aqua Platform Ultimate
    Ultimate Plan
    $150,000.00

    AI Insights

     Info

    Dimensions summary

    You buy this platform through a contract with three plan levels, each priced per unit. The Aqua Platform Shift Left (Standard Plan) covers early-stage development security. The Aqua Platform Protect (Advanced Plan) adds runtime and workload protection. The Aqua Platform Ultimate (Ultimate Plan) is the broadest tier. The plans build on each other, so higher tiers add more security coverage across the application lifecycle. You pick one plan and set the number of units you need. Pricing scales with the plan level you choose and the unit quantity you commit to.

    Top-of-mind questions for buyers

    A unit is the metered quantity you commit to under the contract. You set the number of units to match the scope of workloads you want to protect. The plan you select and the unit count together determine your price. Contact the vendor to confirm how units map to your specific workloads.
    The Shift Left (Standard Plan) focuses on early development security like scanning and supply chain checks. The Protect (Advanced Plan) adds runtime and workload protection in production. The Ultimate Plan is the broadest tier. Each higher plan builds on the coverage below it across the application lifecycle.
    You commit to a set number of units when you buy. Cost scales with the plan level and unit quantity you choose. Adding coverage means adjusting your committed units rather than an automatic increase. Contact the vendor to add units or change plans during your contract.
    www.aquasec.com
    Helpful?

    Vendor refund policy

    All software, maintenance and support are provided subject to the terms and conditions of the Aqua Security Inc. License Agreement.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Container Workloads
    Top
    10
    In Monitoring, Application Development
    Top
    25
    In Observability, Software Development

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Multi-Workload Security Coverage
    Unified platform securing containers, serverless, Kubernetes, and AI workloads across AWS, on-premises, and multi-cloud environments
    Runtime Threat Detection and Enforcement
    Runtime protection to detect threats, block malicious activity, and enforce compliance in production across all cloud native workloads
    AI and LLM Security Governance
    Purpose-built AI workload security to govern large language models and generative AI applications with model abuse detection and policy enforcement
    Full Lifecycle Security
    Security coverage across the entire software development lifecycle from code development through production deployment
    Compliance and Authorization Standards
    FedRAMP High authorization enabling compliance with rigorous security and regulatory standards
    Agentless Cloud Security Architecture
    Agentless-first approach using patented SideScanning technology that provides deep visibility into cloud environments without requiring agent deployment
    Risk Prioritization and Attack Path Analysis
    Granular risk scoring applied to each alert with capability to identify and correlate seemingly unrelated issues into dangerous attack paths
    Unified Cloud Security Platform
    Single platform consolidating multiple security functions including CSPM, CWPP, CIEM, DSPM, Container security, and API security
    CI/CD Integration for Application Security
    Seamless integration into CI/CD process to secure applications from code to cloud deployment
    AI-Powered Investigation and Remediation
    Generative AI capabilities for simplified security investigations and accelerated remediation workflows
    Offensive Security Engine
    Simulates external exploits to produce Verified Exploit Paths for prioritizing exposures that are reachable by outside attackers and reducing cloud attack surface.
    Cloud Security Posture Management
    Continuously monitors and manages security of AWS configurations to prevent public exposure and ensure compliance.
    Secrets Scanning
    Identifies more than 750 types of secrets across public and private repositories.
    Cloud Infrastructure Entitlements Management
    Detects and manages excessive or unused permissions to mitigate the risk of privilege escalation.
    Real-Time Malware Detection
    Detects malware including zero-days in milliseconds with scanning performed directly in cloud environment for object storage services like Amazon S3 and file storage services.

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    -
    -
    -
    -
    -
    -
    -
    -
    No security profile

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.2
    67 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    52%
    37%
    8%
    3%
    0%
    8 AWS reviews
    |
    59 external reviews
    External reviews are from G2  and PeerSpot .
    Dmytro Volobuev

    Lightweight container security has improved startup scans and supports automated AWS microservices

    Reviewed on Aug 31, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I wrote a setup process for Aqua Cloud Security Platform during a short-term contract with the company, and I probably used it for around one month after installation.

    Aqua Cloud Security Platform was a piece of microservices on AWS Elastic Container Service with a few microservices, something around maybe 100 or 150 containers representing different parts of services of the company. It was really different because it was a few different services. I was writing implementation as a DevOps engineer and developer of infrastructure rather than as a user.

    It was easy only on the test stage with Aqua Cloud Security Platform where I could run manual tests and verify it was working. However, we were too optimistic about how much time the implementation should take. I had to rewrite a lot of Terraform modules because every container needed to be updated. The most difficult things compared to our expectation were that the last simple step of updating the entry point proved extremely complex. Every module, every build, and every container was reviewed and rewritten. I had to rewrite builds and deployments because it was a pretty big system that was highly automated and had been done by different people at different times with different scripts in Bash, Python, and Terraform. Some things were updated manually in Terraform, so the entry point was probably the most tricky part because it involved Java microservices with some entry points that were scripts and some entry points that were huge terrible lines with everything related to Java starts that sometimes looked a poem. I had to move all this content to the command line, which was tricky as a syntax and as a part of the build process. Some entry points were already patched in the entry point at container startup in the module, which made it pretty tricky.

    It was not only ECS; my part was ECS while someone was working in EKS and we had discussions and testing on how to move it better with a lot of experiments because different entry points were patched, updated, scripted, or endless lines. It took pretty much time, and it was also complicated by company processes because different departments had different procedures for implementation. It took, with all these experiments, probably about four months to push it through all processes because some departments had up to four environments with procedures, QAs, testing, and all this. It was definitely more than one month that I estimated at the very beginning, but that was mostly due to company processes. If I had worked there a couple of years before, I would not have estimated one month, and if I had full knowledge of processes and experience with implementation, I would have approached it differently.

    It was more tricky because I was new to the company and had to learn not only Aqua Cloud Security Platform but much more. I had to learn all modules, procedures, and processes, which was good. I jumped into infrastructure in a way that was a pretty good learning experience because I learned everything: build, deploy, infrastructure, and procedures. I pushed all this up to production and started in production, which is a pretty good line in my resume.

    What is most valuable?

    What I like the most about Aqua Cloud Security Platform is that as I understand it, it is a pretty lightweight service and the sidecar container cannot fail because it is actually doing nothing other than bringing a binary. From my point of view, it is not a bottleneck and it is not a wrapper that can fail. As I understand it, it just scans the container on start and then does nothing. There is no extra load and no extra resources. I think it is pretty light. From my point of view as DevOps, it is a pretty good thing. It is not something that works all the time as a microservice addition, it does not increase costs or resources, and that is good.

    What needs improvement?

    What I dislike about Aqua Cloud Security Platform is that we did not find an option to turn off logging or split logs to avoid putting Aqua Cloud Security Platform logs into a logging system because there was a lot of information about logs. We would have preferred to turn logs off after full installation just for production. It would be nice to have a log parameter for starting in production. These logs are definitely not useful because on start, there is a pretty big piece of logs and any kind of automated analysis of process start required us to rewrite the analysis of all these patterns that were making a decision if the process was started properly. A logging system parameter to turn off Aqua Cloud Security Platform logs completely would be helpful. The other thing was rather technical because implementation processes were pretty tricky due to a high level of automation with all infrastructure and builds, and I had to rewrite a lot of things, which was just a technical difficulty.

    For how long have I used the solution?

    I probably used Aqua Cloud Security Platform for around one month after the installation was complete.

    What do I think about the stability of the solution?

    Regarding stability with Aqua Cloud Security Platform, I did not experience any problems. I do not know how this binary is working, but I guess it is not working as a service. It probably does its job just at the very beginning when the container starts and then it sleeps. We did not experience any problems with access to Aqua Cloud Security Platform repository, but theoretically, it could be an issue if there were any problems with the container repository or with the image repository. I do not know how Aqua Cloud Security Platform binary will act if Aqua Cloud Security Platform fails on the installation step because it is installed on every container start.

    What do I think about the scalability of the solution?

    Regarding scalability, I do not know how it works inside, so I cannot predict how it will work. However, if it is simple and works for a few seconds on the startup of the container, it does not matter. The only thing that can make things go wrong is if it makes a delay on the container startup. It can break some things, such as checks. For example, we had Java services where, after 15 seconds, there were checks started that run every 5 seconds while waiting for the service to get up. This delay can hit these checks and make them less precise in timings. Sometimes this can be crucial.

    How are customer service and support?

    For support related to Aqua Cloud Security Platform, I would rate it a 10 because I did not have a support request that was not handled. If I got an answer in a couple of days, it was probably even faster.

    Which solution did I use previously and why did I switch?

    I have never used any alternatives to Aqua Cloud Security Platform that I can compare it with. I did not use it before. However, I was thinking about how it would work with a container that is already wrapped with some monitoring system or system that also scans containers. I did not meet one, but there is sometimes a pretty popular thing that also scans containers for counting system and load monitoring.

    What other advice do I have?

    Overall, I would give Aqua Cloud Security Platform a score of 7 to 8 because I do not know how it will behave in all situations. For example, a network problem with connectivity to an image or if Aqua Cloud Security Platform binary will not be able to connect to somewhere could be an issue. Some environments are highly hidden under VPCs, so some security changes can cut off a route to Aqua Cloud Security Platform repository or something similar. Someday it can be a surprise. I cannot predict how Aqua Cloud Security Platform is going to work and how long it can handle this. Regardless, there will be a delay and it can break any kind of post-start checks or something else. There are a lot of things I can imagine breaking. My overall rating for this review is 8 out of 10.
    Francisco Pulido

    Comprehensive container security has strengthened our Kubernetes lifecycle protection and productivity

    Reviewed on Aug 15, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Aqua Cloud Security Platform is container and Kubernetes security across the full life cycle, including image scanning for vulnerabilities, malware, and secrets in CI.

    For example, I use Aqua Cloud Security Platform for scanning container images through my registries, specifically Docker Hub, and I scan them before deployment. I have policies that are set to fail a build or a PR when any critical or high CVEs appear.

    What is most valuable?

    The best features Aqua Cloud Security Platform offers are the depth at which container and Kubernetes security is covered, including image assurance and scanning, along with very strong runtime protection with drift detection and prevention.

    Regarding how runtime protection and drift detection have helped my team, as any drift detection mechanism does, it helps identify if anything has been changed in production that is not reflected in code, and when that happens, an alarm is triggered.

    Aqua Cloud Security Platform has positively impacted my organization by significantly increasing productivity and helping identify the security posture of my environments, which releases a lot of pressure from the security team.

    My productivity increased mainly because time to production has been reduced, thanks to the drift detection and malware analysis at runtime, allowing my team to react faster before reaching production.

    What needs improvement?

    Aqua Cloud Security Platform could be improved as the UI can feel rough to navigate, and sometimes finding the data I need has a really high learning curve.

    I think Aqua Cloud Security Platform could work on its SOAR integration for needed improvements.

    I chose a rating of eight because it is technically really good for what it is built for, but the UI complexity and the need for improved remediation guidance on findings affect my rating.

    For how long have I used the solution?

    I have been using Aqua Cloud Security Platform for three years.

    What other advice do I have?

    Regarding Aqua Cloud Security Platform's AI capabilities, I think its governance is lifecycle oriented, and although it has been implemented relatively recently, I have not had a huge opportunity to test it yet.

    Concerning the accuracy and reliability of its AI capabilities, I can say that the scanning accuracy of the AI in Aqua Cloud Security Platform is quite good for catching CVEs that other tools have otherwise missed.

    My advice for others looking into using Aqua Cloud Security Platform is that it requires a big and mature security team or at least someone with enough experience in Aqua security in order to get the most out of it. I gave this product a rating of eight.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Sudheer Kumar

    Unified cloud-native security has improved compliance and now needs simpler deployment and AI insight

    Reviewed on Jul 04, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I used Aqua Cloud Security Platform for container image scanning, runtime threat detection, infrastructure as code scanning, and software supply chain security.

    I used it for container image scanning registries for our Azure cloud environment and AWS ECR as well. So it was for Azure Container Registry scanning and Amazon ECR scanning.

    For Kubernetes security, I think it is a good feature, including RBAC analysis, privileged containers, host path detection, and pod security. And on the CSPM side as well.

    Mostly, I used it for container scanning and our CI/CD pipeline scanning. So mostly, on the CSPM side.

    We deployed it in a hybrid environment. We also have both AWS cloud and Azure cloud. So it is a hybrid deployment.

    What is most valuable?

    The best features I can identify are container image scanning, Kubernetes security, runtime protection, CSPM, infrastructure as code security, and supply chain security as well.

    Not specifically cost saving, but from the security side, we completed our compliance standards, and in our CI/CD pipeline, we set up our security gates between the planning, build, and code phases.

    What needs improvement?

    I think Aqua Cloud Security Platform has a good, strong platform, but there are still other areas. For example, if we compare it with Prisma Cloud or Wiz, I can see that with the initial deployment, in the deployment phase, they need to create a more user-friendly interface. Also, the cloud context visualization is an area for improvement. Aqua Cloud Security Platform is focusing heavily on workloads and runtime security, but it offers less intuitive visualization of cloud relationships compared to Wiz and Prisma Cloud.

    I think for the licensing part and AI-driven prioritization, this needs improvement. While Aqua Cloud Security Platform prioritizes findings using CVSS and policy context, if we compare it with Wiz and Prisma Cloud, they are increasingly using AI-driven risk scoring that incorporates exploitability, identity exposure, internet reachability, and business context.

    Regarding AI-driven activities, I think there is still a need for them to think about, or implement, or enhance their LLM models so they can prioritize the CVSS or policy context scoring based on AI-driven methodologies.

    I think the licensing complexity and agent dependency are areas for improvement. Many runtime protection capabilities rely on deploying Aqua enforcers and Aqua agents. So, organizations that prefer completely agentless security for operational simplicity may find this less attractive than platforms like Wiz or Orca Security, which emphasize agentless assessment for many use cases. Also, the licensing can become difficult to estimate for large environments with many clusters, workloads, and cloud accounts, making cost forecasting less straightforward than for some competitors.

    For how long have I used the solution?

    I used Aqua Cloud Security Platform in my previous job for around three years.

    What do I think about the stability of the solution?

    Aqua Cloud Security Platform is stable as of now.

    What do I think about the scalability of the solution?

    Platform scalability is fantastic and its enterprise solution is really amazing.

    How are customer service and support?

    Customer support is acceptable. Sometimes we receive a complaint from our L3 or L2 engineers that they are not getting proper on-time support, but overall, it is acceptable.

    Which solution did I use previously and why did I switch?

    Previously, we were using multiple tools for scanning: container image scanning, Kubernetes security, runtime security, CSPM and on the IAC side. We were using multiple scanning tools for that. Then we found one single solution, which is Aqua Cloud Security Platform. So it really added value for our organization.

    We were previously using a lot of open-source tools. Open-source tools have their limitations and there is no vendor support. Then we did a lot of analysis with multiple paid solutions and came to know that Aqua Cloud Security Platform is the best from our environment's perspective.

    How was the initial setup?

    The main trend is for deployment complexity, so we still have to use multiple resources for that. But after deploying it in the CI/CD pipeline, it enhances our CI/CD or automation capability for the organization. So the DevSecOps capacity or DevSecOps integration is good. And the supply chain security is also fantastic. Container security, Kubernetes security, runtime protection, everything is fantastic.

    What's my experience with pricing, setup cost, and licensing?

    I think the licensing part and the cost part are as per the market standard, but it again depends on your budget and what services you are looking for. So, overall, it is good. Not too high, not too low. It is easy for organizations.

    Which other solutions did I evaluate?

    We went through Wiz, Prisma, and Orca as well.

    What other advice do I have?

    My advice would be that if someone is looking for runtime protection, Kubernetes security, container security, IAC security, and supply chain security for their organization, then I think Aqua Cloud Security Platform is fantastic. But if they are looking for agentless assessment, attack path analysis, and ease of deployment, then they can look at other vendors. I would rate this product seven out of ten.

    DeepakReddy

    Cloud-native security has unified container protection and now automates vulnerability checks

    Reviewed on Jun 27, 2026
    Review from a verified AWS customer

    What is our primary use case?

    Aqua Cloud Security Platform secures our containers, Kubernetes clusters, and container images. We regularly run container image scanning, SAST scans, and vulnerability management and software supply chain security scans. We also use it for secret detection, rotation of secret keys, and compliance monitoring.

    Aqua helps with secret detection by scanning our GitHub or GitLab repositories to check whether there are any passwords or sensitive data present. If it detects them, we remove them or take action around them.

    How has it helped my organization?

    Aqua Cloud Security Platform has positively impacted our organization by improving our tooling usage.

    It has positively impacted us by reducing twenty to thirty percent of our manual vulnerability checks.

    We see a return on investment in terms of time saved, with around twenty-five to thirty percent of our time saved as we no longer need to search for vulnerabilities manually. We can now see all vulnerabilities on one dashboard.

    What is most valuable?

    Aqua Cloud Security Platform is perfect for us because it has container image scanning, real-time protection, Kubernetes security, and inbuilt cloud security. It is an all-in-one tool.

    The best feature of Aqua Cloud Security Platform is the Kubernetes security, which secures admission controllers, runtime policies, namespace protection, and RBAC and pod security. It helps manage all these aspects effectively with this cloud-native security tool.

    We use admission controllers, and this Aqua cloud-native solution has inbuilt admission controllers and Kubernetes operators that help secure our Kubernetes pods, deployments, and services. This is particularly beneficial for us, especially because other solutions operating in the same space do not match the accuracy and operational capability. The scans and benchmarking are also very good.

    Other notable features I found in Aqua Cloud Security Platform include multiple integrations with tools such as Docker, AWS, Azure, Google Cloud, GitHub, GitLab, Jenkins, Azure DevOps, Bitbucket, Terraform, and Jfrog. There are hundreds of integrations available. It also has multiple deployment options such as hybrid cloud, multi-cloud, or on-premise, and includes SAST with all security tooling inbuilt, making it a comprehensive tool.

    The dashboard shows all the important information we were missing in our previous tool.

    What needs improvement?

    Improvements could be made to Aqua Cloud Security Platform.

    I am considering some specific features that Aqua could include for better functionality.

    The UI needs some improvement as it is somewhat overwhelming, and the licensing can be expensive at scale. The AI output of Aqua Cloud Security Platform is good, but I believe it can be improved. We received alerts about vulnerabilities in our dashboard, particularly related to a database call issue. The AI identified a problem with a Postgres snapshot, which turned out to be accurate, but it could be enhanced by including specific details about what has gone wrong.

    For how long have I used the solution?

    I have been using Aqua Cloud Security Platform for around a year.

    What do I think about the stability of the solution?

    Aqua Cloud Security Platform is stable based on my experience.

    What do I think about the scalability of the solution?

    It can handle increasing workloads easily.

    How are customer service and support?

    The customer support has been responsive and knowledgeable, especially regarding deployment questions and policy tuning.

    Which solution did I use previously and why did I switch?

    We previously used a security tool built into our company, which had many issues, mainly only supporting AWS and Docker, without Kubernetes or other cloud providers. That is why we switched to Aqua Cloud Security Platform, an all-in-one solution.

    How was the initial setup?

    We purchased Aqua Cloud Security Platform from the AWS Marketplace.

    What's my experience with pricing, setup cost, and licensing?

    My experience with Aqua Cloud Security Platform's pricing, setup cost, and licensing has been good.

    The license and setup costs have been reasonable, though a challenge arises when deploying the entire application in our own cloud, as we must manage everything from scratch. The customer support has also been very cooperative.

    Which other solutions did I evaluate?

    We evaluated various options, including Snyk and Splunk, as well as other tools such as Trivy. We found Aqua Cloud Security Platform to be the best choice among all alternatives.

    What other advice do I have?

    The AI output of Aqua Cloud Security Platform is good, but I believe it can be improved. We received alerts about vulnerabilities in our dashboard, particularly related to a database call issue. The AI identified a problem with a Postgres snapshot, which turned out to be accurate, but it could be enhanced by including specific details about what has gone wrong.

    Aqua Cloud Security Platform needs some improvement in the UI, which is somewhat overwhelming, and the licensing can be expensive at scale. I gave this product a rating of eight.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Sudheer Kumar

    Cloud-native security has strengthened our pipeline and now needs better dashboards and AI risk views

    Reviewed on Jun 20, 2026
    Review from a verified AWS customer

    What is our primary use case?

    Aqua Cloud Security Platform is primarily used for cloud-native applications, focusing on cloud identity and entitlement management and vulnerability management for containers, Kubernetes, and ISC, along with secret detection and DevSecOps.

    A recent project with Aqua Cloud Security Platform addressed a security challenge related to container and Kubernetes security using runtime protection. Examples include container escape attempts, privilege escalations, reverse shell executions, malicious process wrapping, and crypto mining, which involved using Aqua runtime controls to scan the entire CNAPP.

    Kubernetes security is a key focus, where Aqua provides capabilities for network segmentation, pod security controls, and service account monitoring, often stronger than Microsoft Defender for Cloud and more mature than Orca.

    What is most valuable?

    The best features found in Aqua Cloud Security Platform include capabilities at the domain-wise level, which include CWPP, secret detection, runtime protection, Kubernetes security, vulnerability management, and CSPM.

    Aqua Cloud Security Platform positively impacted my organization by allowing deployment from code to cloud in the entire CI/CD pipeline, with excellent capabilities and recent AI application security that is useful in the DevSecOps platform.

    Multi-cloud support with AWS, Azure, GCP, and software supply chain security with SBOM generation and CI/CD pipeline scanning are unique aspects that set Aqua Cloud Security Platform apart.

    What needs improvement?

    When compared to modern platforms like Wiz and CrowdStrike, the user interface of Aqua Cloud Security Platform feels more engineer-focused than executive-friendly, requiring improvement in user interfaces for CISO preferences.

    Currently, there is a move towards agent-based solutions, and Aqua Cloud Security Platform lacks visibility on the agent side. Wiz and Orca have changed the market with agentless scanning, while Aqua Cloud Security Platform still relies on deeper runtime agents, inviting operational overhead compared to other vendors.

    Risk prioritization in security graphs is a point where Aqua Cloud Security Platform is less mature than Wiz, which excels at identifying critical vulnerabilities as a single attack path.

    For how long have I used the solution?

    I have been using Aqua Cloud Security Platform for around four years.

    What do I think about the stability of the solution?

    Aqua Cloud Security Platform is stable, providing good capabilities and service.

    What do I think about the scalability of the solution?

    Aqua Cloud Security Platform's scalability is good, providing better services compared to DevSecOps when compared to CrowdStrike and Orca.

    How are customer service and support?

    The customer support for Aqua Cloud Security Platform is excellent, available 24/7, and provides better solutions for any issues raised through tickets.

    Which solution did I use previously and why did I switch?

    I did not previously use a different solution; we were using earlier open-source solutions only. We wanted to go with a paid solution to provide good capability that we can rely on.

    What was our ROI?

    I have seen a return on investment with Aqua Cloud Security Platform as it provides good capabilities. It is generally used for the DevSecOps pipeline to scan the entire SAST, DAST, or ISC, performing excellently in that area.

    What's my experience with pricing, setup cost, and licensing?

    Compared to other vendors, Aqua Cloud Security Platform's pricing is good or lesser. The pricing part is acceptable, and ease of use, as well as DevSecOps integration, is excellent.

    Which other solutions did I evaluate?

    Before choosing Aqua Cloud Security Platform, I evaluated other options including CrowdStrike and Orca.

    What other advice do I have?

    My advice for others looking into using Aqua Cloud Security Platform is that for container security, Kubernetes security, runtime protection, supply chain, or overall CNAPP, if someone wants to use it at a lesser price, this product provides good capabilities. They can proceed with this product; however, for dashboard and executive reporting, if that is specifically what you are looking for, you may want to consider other products.

    Aqua Cloud Security Platform's AI capabilities provide good governance and security primarily through risk prioritization, although compared to Wiz, Prisma Cloud, and Orca, it is less competitive at the moment. In terms of supply chain securities, Aqua Cloud Security Platform is paramount in comparison to other vendors.

    When it comes to the accuracy and reliability of Aqua Cloud Security Platform's AI capabilities, more work on the AI security side is required. A responsible AI part is missing, making it less valuable.

    I rated this product a seven out of ten.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    View all reviews