Listing Thumbnail

    Orca Security CNAPP Cloud Security Platform

     Info
    Deployed on AWS
    Free Trial
    Vendor Insights
    Quick Launch
    Agentless Cloud Security in a Single, Complete Platform with 100% Coverage
    4.6

    Overview

    Play video

    Orca Security is the true Cloud Native Application Protection Platform (CNAPP) that identifies, prioritizes, and remediates risks and compliance issues across all of your workloads, configurations, and identities on AWS. Orca offers the industrys most comprehensive cloud security solution in a single platform, eliminating the need to deploy and maintain multiple point solutions.

    FAST TIME TO VALUE: The Orca CNAPP Platform is agentless first, and connects to your environment in minutes using patented SideScanning™ technology that provides deep and wide visibility into your cloud environment, without requiring agents. In addition, Orca offers a lightweight agent for organizations that require real-time protection for critical workloads.

    RISK PRIORITIZATION: Orca effectively prioritizes risks by applying a granular risk score to each alert, and recognizes when seemingly unrelated issues can be combined to create dangerous attack paths straight to your crown jewels.

    FULL SDLC SECURITY: The Orca platform shifts security left by seamlessly integrating into the CI/CD process so that applications can be secured from code to cloud and back.

    AI-POWERED: Orca is at the forefront of leveraging Generative AI for simplified investigations and accelerated remediation, reducing required skill levels and saving cloud security, DevOps, and development teams time and effort, while significantly improving security outcomes.

    PURPOSE-BUILT CNAPP: Orca unifies many different point solutions in one platform, including CSPM, CWPP, CIEM, DSPM, Container security, API security, AI-SPM, and much more.

    Sign up for a demo to uplevel your cloud security and get the fastest time to value available in the industry: https://orca.security/demo/ 

    Additional platform licensing options are not shown in this listing but are available via Private Offer. Please email aws@orca.security .

    Highlights

    • Visibility to all your IAAS and PAAS assets including EC2, Containers, S3 buckets using account level read only permissions
    • Detect compromises, vulnerabilities and risky configuration within minutes
    • No impact on your assets, grows automatically with your cloud account

    Get personalized pricing in minutes - New

    If qualified, an express private offer gets you custom pricing and terms. Finalize your purchase in the AWS Marketplace console.

    Details

    Delivery method

    Deployed on AWS

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Quick Launch

    Leverage AWS CloudFormation templates to reduce the time and resources required to configure, deploy, and launch your software.

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (2)

    Pricing

    Free trial

    Try this product free according to the free trial terms set by the vendor.

    Orca Security CNAPP Cloud Security Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    1-month contract (4)

     Info
    Dimension
    Description
    Cost/month
    Small
    Small starter pack of concurrent workloads (EC2) per month
    $7,000.00
    Small-Medium
    Small-Medium starter pack of concurrent workloads (EC2) per month
    $12,000.00
    Medium
    Medium starter pack of concurrent workloads (EC2) per month
    $17,000.00
    Large
    large starter pack of concurrent workloads (EC2) per month
    $30,000.00

    Vendor refund policy

    Contact us

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Monitoring, Application Development
    Top
    25
    In Observability, Software Development
    Top
    10
    In Container Workloads

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Agentless Cloud Security Architecture
    Agentless-first approach using patented SideScanning technology that provides deep visibility into cloud environments without requiring agent deployment
    Risk Prioritization and Attack Path Analysis
    Granular risk scoring applied to each alert with capability to identify and correlate seemingly unrelated issues into dangerous attack paths
    Unified Cloud Security Platform
    Single platform consolidating multiple security functions including CSPM, CWPP, CIEM, DSPM, Container security, and API security
    CI/CD Integration for Application Security
    Seamless integration into CI/CD process to secure applications from code to cloud deployment
    AI-Powered Investigation and Remediation
    Generative AI capabilities for simplified security investigations and accelerated remediation workflows
    Offensive Security Engine
    Simulates external exploits to produce Verified Exploit Paths for prioritizing exposures that are reachable by outside attackers and reducing cloud attack surface.
    Cloud Security Posture Management
    Continuously monitors and manages security of AWS configurations to prevent public exposure and ensure compliance.
    Secrets Scanning
    Identifies more than 750 types of secrets across public and private repositories.
    Cloud Infrastructure Entitlements Management
    Detects and manages excessive or unused permissions to mitigate the risk of privilege escalation.
    Real-Time Malware Detection
    Detects malware including zero-days in milliseconds with scanning performed directly in cloud environment for object storage services like Amazon S3 and file storage services.
    Multi-Workload Security Coverage
    Unified platform securing containers, serverless, Kubernetes, and AI workloads across AWS, on-premises, and multi-cloud environments
    Runtime Threat Detection and Enforcement
    Runtime protection to detect threats, block malicious activity, and enforce compliance in production across all cloud native workloads
    AI and LLM Security Governance
    Purpose-built AI workload security to govern large language models and generative AI applications with model abuse detection and policy enforcement
    Full Lifecycle Security
    Security coverage across the entire software development lifecycle from code development through production deployment
    Compliance and Authorization Standards
    FedRAMP High authorization enabling compliance with rigorous security and regulatory standards

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    -
    -
    -
    -
    -
    No security profile
    -
    -
    -

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.6
    291 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    75%
    24%
    1%
    0%
    0%
    20 AWS reviews
    |
    271 external reviews
    External reviews are from G2  and PeerSpot .
    Harsh Harsh

    Cloud security has improved as we identify vulnerabilities and address risks proactively

    Reviewed on Jun 04, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I have used Orca Security  for one year while working for a client where we set up Orca Security  to scan our environment and identify vulnerabilities.

    The main use case for using Orca Security is to identify vulnerabilities in our environment so that we can address them before any issues occur.

    In one of our projects in GCP , we purchased Orca Security from the marketplace, which was enabled in our account at the organization level.

    What is most valuable?

    The main feature that I appreciated about Orca Security is that it is 100% agentless and context-aware, meaning it understands what it is doing.

    The primary benefit is that it provides us with CVEs, through which I can identify the vulnerabilities in our security posture.

    In the long run, as a security tool, it has helped us improve our security posture.

    What needs improvement?

    There is one issue that I encountered: when Orca Security provides CVEs and we attempt to implement its solutions, sometimes those solutions are not available on the cloud and cannot be implemented.

    My main concern is the integration of Orca Security with generative AI for remediation inquiry.

    Another concern I have is around the guardrails.

    The primary improvement that Orca Security needs is to enhance its remediation steps based on the cloud platform being used.

    For how long have I used the solution?

    I have been working in my current field for the past five or more years.

    What do I think about the stability of the solution?

    Orca Security has been stable in my experience.

    What do I think about the scalability of the solution?

    Orca Security is internally based on cloud infrastructure and is 100% agentless, so it does not require significant scalability considerations.

    How are customer service and support?

    Customer support is also good. I would rate it a 10 because they respond properly and communicate effectively.

    Which solution did I use previously and why did I switch?

    Previously, I used to install an open-source tool to understand my security posture, which required some additional infrastructure investment.

    I was using the native GCP  Security Command Center.

    How was the initial setup?

    We purchased Orca Security from the AWS Marketplace .

    What's my experience with pricing, setup cost, and licensing?

    I am aligned with the pricing, as it is not that costly.

    Which other solutions did I evaluate?

    I did evaluate open-source tools, Orca Security, native open-source tools, and cloud-native tools as well.

    What other advice do I have?

    When Orca Security provides CVEs, clicking on them gives suggestions about what can be done to resolve the issue.

    I would advise others to use Orca Security because of the rich features that it offers.

    I would rate this review a 9.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Anil S.

    Clear, Agentless Cloud Risk Visibility with Smart Prioritization

    Reviewed on Jun 03, 2026
    Review provided by G2
    What do you like best about the product?
    Orca gives us a clear view of vulnerabilities, misconfigurations, and security risks across our cloud environment. Because it’s agentless, the setup was straightforward, and we were able to get it implemented and start monitoring resources quickly. I also appreciate the risk prioritization, which helps us focus on the most important findings rather than spending time chasing low-impact issues.
    What do you dislike about the product?
    The platform offers a wide range of capabilities, which can feel a bit overwhelming at first. A clearer starting point or guidance would help with the initial learning curve. Also, some reports could be more customizable to better match specific business requirements.
    What problems is the product solving and how is that benefiting you?
    It helps us centralize cloud security monitoring and reduces our reliance on multiple tools. Having everything in one platform improves visibility, and it’s easier to identify and address risks before they turn into bigger problems. Overall, it has saved us time and strengthened our security management process.
    Ryan F.

    Fast, Agentless Cloud Visibility with Practical Risk Prioritization

    Reviewed on Jun 02, 2026
    Review provided by G2
    What do you like best about the product?
    What I appreciate most is how quickly we gained clear visibility into our cloud environment. The agentless approach eliminated many of the usual deployment concerns, and the platform started surfacing meaningful findings right away. The risk prioritization feels practical and makes it easier to distinguish truly critical issues from lower-priority items. Having security, compliance, and vulnerability information consolidated in one place is also a major advantage.
    What do you dislike about the product?
    The interface is generally easy to use, although some of the more advanced features take a bit of extra exploration to figure out. I’d also appreciate more customization options for reporting, as that would make it easier to tailor reports to my needs.
    What problems is the product solving and how is that benefiting you?
    It helps us maintain a clearer understanding of cloud security risks without adding operational complexity. The centralized visibility makes it easier for teams to spot and resolve issues more quickly. As a result, we spend less time pulling information together and more time focusing on improving our security posture.
    Cassian T.

    Smooth Setup and Clear Dashboards for Prioritized Risk Visibility

    Reviewed on May 28, 2026
    Review provided by G2
    What do you like best about the product?
    The platform provides centralized visibility into vulnerabilities, misconfigurations, and exposed assets without requiring agents on our workloads. Setup was smooth, and the dashboards make it easier to see where the biggest risks are. I also find the contextual prioritization valuable because it cuts down on noise and helps the team stay focused on the most important findings.
    What do you dislike about the product?
    Some of the more advanced features take time to fully learn, especially for new users. I also think the reporting customization could be improved in a few areas to make it easier to tailor reports to specific needs.
    What problems is the product solving and how is that benefiting you?
    It helps us manage cloud security from a single platform instead of relying on multiple disconnected tools. We’re able to identify risks sooner and respond more quickly, while also cutting down on manual monitoring. Overall, it has improved our visibility and made our cloud operations more efficient.
    Barbara T.

    Orca Security’s Agentless Side-Scanning Delivers Zero-Latency Performance

    Reviewed on May 28, 2026
    Review provided by G2
    What do you like best about the product?
    We manage high-volume travel booking engines, hospitality data, and our corporate cloud infrastructure. Because we process thousands of international flight and hotel transactions every hour, zero-latency cloud performance is non-negotiable. Orca Security’s agentless side-scanning is good.
    What do you dislike about the product?
    The executive reporting can feel a bit rigid. When I need to present our security posture to the board of directors—who are focused on business risk rather than technical metrics—Orca’s native reports are too granular. I usually have to export the raw data and build my own presentations to translate CVSS scores into actual business risk.
    What problems is the product solving and how is that benefiting you?
    This provides absolute visibility into an infrastructure that changes by the minute. Orca ensures that our cloud environment can scale up and down to meet seasonal travel demand, and our security scales with it effortlessly.
    View all reviews