Overview

Product video
Orca Security is the true Cloud Native Application Protection Platform (CNAPP) that identifies, prioritizes, and remediates risks and compliance issues across all of your workloads, configurations, and identities on AWS. Orca offers the industrys most comprehensive cloud security solution in a single platform, eliminating the need to deploy and maintain multiple point solutions.
FAST TIME TO VALUE: The Orca CNAPP Platform is agentless first, and connects to your environment in minutes using patented SideScanning™ technology that provides deep and wide visibility into your cloud environment, without requiring agents. In addition, Orca offers a lightweight agent for organizations that require real-time protection for critical workloads.
RISK PRIORITIZATION: Orca effectively prioritizes risks by applying a granular risk score to each alert, and recognizes when seemingly unrelated issues can be combined to create dangerous attack paths straight to your crown jewels.
FULL SDLC SECURITY: The Orca platform shifts security left by seamlessly integrating into the CI/CD process so that applications can be secured from code to cloud and back.
AI-POWERED: Orca is at the forefront of leveraging Generative AI for simplified investigations and accelerated remediation, reducing required skill levels and saving cloud security, DevOps, and development teams time and effort, while significantly improving security outcomes.
PURPOSE-BUILT CNAPP: Orca unifies many different point solutions in one platform, including CSPM, CWPP, CIEM, DSPM, Container security, API security, AI-SPM, and much more.
Sign up for a demo to uplevel your cloud security and get the fastest time to value available in the industry: https://orca.security/demo/
Additional platform licensing options are not shown in this listing but are available via Private Offer. Please email aws@orca.security .
Highlights
- Visibility to all your IAAS and PAAS assets including EC2, Containers, S3 buckets using account level read only permissions
- Detect compromises, vulnerabilities and risky configuration within minutes
- No impact on your assets, grows automatically with your cloud account
Get personalized pricing in minutes - New
Details
Features and programs
Trust Center
Buyer guide

Financing for AWS Marketplace purchases
Quick Launch
Security credentials achieved
(2)


Pricing
Free trial
Dimension | Description | Cost/month |
|---|---|---|
Small | Small starter pack of concurrent workloads (EC2) per month | $7,000.00 |
Small-Medium | Small-Medium starter pack of concurrent workloads (EC2) per month | $12,000.00 |
Medium | Medium starter pack of concurrent workloads (EC2) per month | $17,000.00 |
Large | large starter pack of concurrent workloads (EC2) per month | $30,000.00 |
Vendor refund policy
Contact us
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

FedRAMP
GDPR
HIPAA
ISO/IEC 27001
PCI DSS
SOC 2 Type 2
Standard contract
Customer reviews
Cloud security has improved as we identify vulnerabilities and address risks proactively
What is our primary use case?
I have used Orca Security for one year while working for a client where we set up Orca Security to scan our environment and identify vulnerabilities.
The main use case for using Orca Security is to identify vulnerabilities in our environment so that we can address them before any issues occur.
In one of our projects in GCP , we purchased Orca Security from the marketplace, which was enabled in our account at the organization level.
What is most valuable?
The main feature that I appreciated about Orca Security is that it is 100% agentless and context-aware, meaning it understands what it is doing.
The primary benefit is that it provides us with CVEs, through which I can identify the vulnerabilities in our security posture.
In the long run, as a security tool, it has helped us improve our security posture.
What needs improvement?
There is one issue that I encountered: when Orca Security provides CVEs and we attempt to implement its solutions, sometimes those solutions are not available on the cloud and cannot be implemented.
My main concern is the integration of Orca Security with generative AI for remediation inquiry.
Another concern I have is around the guardrails.
The primary improvement that Orca Security needs is to enhance its remediation steps based on the cloud platform being used.
For how long have I used the solution?
I have been working in my current field for the past five or more years.
What do I think about the stability of the solution?
Orca Security has been stable in my experience.
What do I think about the scalability of the solution?
Orca Security is internally based on cloud infrastructure and is 100% agentless, so it does not require significant scalability considerations.
How are customer service and support?
Customer support is also good. I would rate it a 10 because they respond properly and communicate effectively.
Which solution did I use previously and why did I switch?
Previously, I used to install an open-source tool to understand my security posture, which required some additional infrastructure investment.
I was using the native GCP Security Command Center.
How was the initial setup?
We purchased Orca Security from the AWS Marketplace .
What's my experience with pricing, setup cost, and licensing?
I am aligned with the pricing, as it is not that costly.
Which other solutions did I evaluate?
I did evaluate open-source tools, Orca Security, native open-source tools, and cloud-native tools as well.
What other advice do I have?
When Orca Security provides CVEs, clicking on them gives suggestions about what can be done to resolve the issue.
I would advise others to use Orca Security because of the rich features that it offers.
I would rate this review a 9.