Best Software for 2025 is now live!
Save to My Lists
Paid
Claimed
Optimized for quick response

Orca Security Reviews & Product Details

Maksym M.
MM
Security engineer
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
(Original )Information
What do you like best about Orca Security?

Agentless Approach and Deep Visibility. It doesn't require the installation of any agents or additional software, that’s why we need just minutes to onboard new accounts to Orca. After onboarding, Orca provides really comprehensive asset discovery, vulnerability scanning, and risk assessment. Also, I am impressed by Orca Security's continuous product development and its dedication to introducing new features. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

Usually, Orca performs scans every 24 hours, that's why alerts are not real-time. Also, it would be great if Orca expand its integration capabilities especially with Cloudflare Review collected by and hosted on G2.com.

What problems is Orca Security solving and how is that benefiting you?

Orca Security provides contextualized alerts and actionable insights to security teams. By correlating security incidents with context, it helps prioritize and address security issues effectively. Additionally, its agentless approach reduces the complexity of deployment and ongoing management, making it easier for us to integrate Orca Security into our existing security operations. Review collected by and hosted on G2.com.

Orca Security Overview

What is Orca Security?

The Orca Cloud Security Platform identifies, prioritizes, and remediates risks and compliance issues in workloads, configurations, and identities across your cloud estate spanning AWS, Azure, Google Cloud, Kubernetes, Alibaba Cloud, and Oracle Cloud. Orca offers the industry’s most comprehensive cloud security solution in a single platform — eliminating the need to deploy and maintain multiple point solutions. Orca is agentless-first, and connects to your environment in minutes using Orca’s patented SideScanning™ technology that provides deep and wide visibility into your cloud environment, without requiring agents. In addition, Orca can integrate with third-party agents for runtime visibility and protection for critical workloads. Orca is at the forefront of leveraging Generative AI for simplified investigations and accelerated remediation – reducing required skill levels and saving cloud security, DevOps, and development teams time and effort, while significantly improving security outcomes. As a Cloud Native Application Protection Platform (CNAPP), Orca consolidates many point solutions in one platform, including: CSPM, CWPP, CIEM, Vulnerability Management, Container and Kubernetes Security, DSPM, API Security, CDR, Multi-cloud Compliance, Shift Left Security, and AI-SPM.

Orca Security Details
Product Website
Languages Supported
English
Show LessShow More
Product Description

Get workload-level visibility into AWS, Azure, and GCP without the operational costs of agents. You could buy three tools instead… but why? Orca replaces legacy vulnerability assessment tools, CSPM, and CWPP. Deploys in minutes, not months.

How do you position yourself against your competitors?

t’s time to move on from using 5+ siloed tools to meet your cloud security needs and from deploying agent-based platforms designed for on-prem networks.

Orca’s agentless-first platform consolidates many point solutions in a single platform, deploys in minutes, and provides wide and deep visibility across all your clouds. There are no agents to install and keep updated, no overlooked assets, no DevOps headaches, and no performance hits on live environments.

Orca’s key differentiators include:

✓ Built as one unified platform
✓ Deploys in minutes
✓ Agentless-first, with option to deploy agent
✓ 100% continuous coverage
✓ AI-driven cloud security


Seller Details
Company Website
Year Founded
2019
HQ Location
Portland, Oregon
Twitter
@orcasec
4,847 Twitter followers
LinkedIn® Page
www.linkedin.com
442 employees on LinkedIn®
Description

Orca Security is the pioneer of agentless cloud security, and is trusted by hundreds of enterprises globally. We're the industry-leading Cloud Security Platform that identifies, prioritizes, and remediates security risks and compliance issues across your cloud estate spanning AWS, Azure, Google Cloud and Kubernetes.


CF
Overview Provided by:

Recent Orca Security Reviews

Virginie D.
VD
Virginie D.Enterprise (> 1000 emp.)
5.0 out of 5
"Orca Security implementation in our ecosystem"
Regular addition of new features Everything is accessible by API very intituive Plug and play, user friendly and ergonomic Partnership and rela...
Verified User
A
Verified UserMid-Market (51-1000 emp.)
5.0 out of 5
"Comprehensive tool at a very affordable price-point"
Orca security has basically anything we could think of interms of CNAPP and CSPM capabilities. It gives us valuable insight and is truly an all in ...
Jackson B.
JB
Jackson B.Mid-Market (51-1000 emp.)
5.0 out of 5
"Orca is a game changer with Observability"
Orca has really been a game changer helping accelerate our observably and security journey. The AI assisted search has increased our ability to qui...
Security Badge
Orca Security Security
Get security information from Orca Security to help you buy the right software. View Security Information

Orca Security Media

Orca Security Demo - The Agentless Cloud Security Pioneer
The Orca Cloud Security Platform is built on Orca’s patented SideScanning technology that scans your entire cloud estate to eliminate the gaps in coverage, organizational friction, performance hits, and high operational costs of agent-based solutions.
Orca Security Demo - Achieve 100% coverage
Orca provides full-stack visibility and coverage for all your cloud assets within minutes across VMs, containers, and serverless applications, as well as cloud infrastructure resources, so you can understand all of your cloud risks.
Orca Security Demo - Prioritize and understand your greatest risks
Orca's context-aware engine prioritizes the 1% of alerts that truly matter and surfaces the attack paths with the greatest impact to your business - providing you with a detailed understanding of your cloud risks and how to tackle them.
Orca Security Demo - A single platform with a Unified Data Model
As a purpose-built CNAPP Platform, Orca addresses all of your cloud security needs including CSPM, CWPP, CIEM, DSPM, Vulnerability Management, API Security, Compliance, and more - in a single, centralized platform, allowing you to easily query, investigate, and understand all your cloud risks and...
Orca Security Demo - Quickly trace and remediate risks from Cloud to Dev
Remediating cloud risks is a huge challenge for security teams, especially in a world where DevOps is the norm. Orca not only alerts on an issue, but if applicable, also shows the code origin, even down to the line of code that caused the risk, enabling developers to remediate issues at a lightni...
Play Orca Security Video
Play Orca Security Video
Play Orca Security Video
Play Orca Security Video
Play Orca Security Video

Official Downloads

Answer a few questions to help the Orca Security community
Have you used Orca Security before?
Yes

Video Reviews

208 out of 209 Total Reviews for Orca Security

4.6 out of 5
The next elements are filters and will change the displayed results once they are selected.
Search reviews
Popular Mentions
The next elements are radio elements and sort the displayed results by the item selected and will update the results displayed.
Hide FiltersMore Filters
The next elements are filters and will change the displayed results once they are selected.
The next elements are filters and will change the displayed results once they are selected.

Orca Security Pros and Cons

How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Cons

Overall Review Sentiment for Orca SecurityQuestion

Time to Implement
<1 day
>12 months
Return on Investment
<6 months
48+ months
Ease of Setup
0 (Difficult)
10 (Easy)
Log In
Want to see more insights from verified reviewers?
Log in to view review sentiment.
G2 reviews are authentic and verified.
JB
SecOps Administrator
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Orca Security?

The interface is very intuitive and there was not a learning curve at all. Being able to create reports on pretty much any dashboard has been very helpful. Vulnerabilities and misconfigurations found by Orca give us more than enough information to be handed to our development team for remediation without having to do any additional research. Overall, this is a very well thought out platform. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

I honestly have not found anything I dislike yet. Review collected by and hosted on G2.com.

What problems is Orca Security solving and how is that benefiting you?

It was a very painful process to search for misconfigurations with IAM and networking in our environment. Orca has given us a way to have all of the data we need without having to spend hours searching and it most cases gives the instructions needed to remediate. It has also helped us add more shift left into our development process. Review collected by and hosted on G2.com.

SB
Security Architect
Enterprise(> 1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Orca Security?

Orca provides top-tier dashboards and easy dashboard customization which quickly surfaces critical risks.

Orca support replies rapidly and consistently works to resolve issues.

Orca installation in 2/3 of our main cloud environments was a smooth process, and the last environment took just an extra hour of work. Overall, a very smooth onboarding process, and great training resources were provided.

Orca provides incredibly rich, useful data about the risks it detects, with very low/none false positives. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

The compliance modules currently load extremely slowly, lack CIS critical controls v8.1, and waiting for the promised module rewrite next year sucks.

Orca knowledgebase documentation is tied to your Orca login. To faciliate non-technical staff (or folks who don't need console access) working with the tool, it would be great if they were decoupled.

Exporting risk data to CSV from Orca often requires selecting which of 119-250+ columns I want, at least once, unless you like getting a 1 GB CSV file (wow!)

Exporting to CSV frequently hangs (probably due to the default enormous CSV size), requiring the usage of scheduled reports, which is less convenient. Review collected by and hosted on G2.com.

What problems is Orca Security solving and how is that benefiting you?

Orca is an incredibly powerful tool. We're using it to detect vulnerabilities in virtual machines, misconfigured serverless functions, excessive IAM policies, unhardened virtual machines, VMs missing critical protective software, VMs under attack, and so much more, and that's just the tip of what Orca can do. Review collected by and hosted on G2.com.

Sunny A.
SA
Sales Engineer
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Organic Review from User Profile
Incentivized Review
What do you like best about Orca Security?

Easy Onboarding, I don't need consider the agent implementation plan, or any rollback plan if any bad thing happens. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

lack of sandbox, or real-time protection Review collected by and hosted on G2.com.

What problems is Orca Security solving and how is that benefiting you?

Orca Security enhances cloud security by leveraging CNAPP benefits, offering comprehensive visibility and protection across environments. This approach enables organizations to identify vulnerabilities, prioritize risks, and ensure compliance, all while streamlining security operations and improving response times. Most important things are 1) no agent, I don't need to take care the installation and compatibility issues, 2) it helps me to prioritize the alerts and risks that I need deal with them immediately. Review collected by and hosted on G2.com.

Verified User in Computer Software
AC
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
(Original )Information
What do you like best about Orca Security?

I really appreciate that Orca brings together multiple aspects of cloud security in a single console. It covers everything we need, from vulnerability management to misconfigurations, compliance, entitlement management, IaC, and code security, all in one place. The integration options are also strong - especially the bi-directional integration with ServiceNow, which has been a huge help for us. Slack integration is another plus, making it easy for our team to discuss alerts across departments and coordinate remediation efforts without missing a beat.

One feature we’ve found especially valuable is Orca’s compliance management. The AWS CIS Benchmark tool has been a game changer for us. With Orca’s guidance and insights, we were able to identify compliance gaps we hadn’t even noticed and systematically address them. This took our compliance score from 58% all the way up to 100%. Now we’re not just meeting industry standards but have much more confidence in the security and compliance of our AWS setup. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

I wish Orca offered an endpoint agent for managing vulnerabilities on non-cloud devices. If this capability were added, we’d likely consider consolidating our vulnerability management into Orca, which would be more convenient than juggling multiple platforms. Currently, we’re running two overlapping solutions to cover vulnerabilities on our endpoints, which adds complexity.

Also, we found it necessary to adjust the default permissions assigned to the role used by Orca, as the out-of-the-box required permissions were too broad and didn’t align with our organization’s principle of least privilege. By tailoring the permissions more specifically to our needs, we were able to enhance security by limiting access only to what was essential for Orca’s operations in our environment. Review collected by and hosted on G2.com.

What problems is Orca Security solving and how is that benefiting you?

Orca Security is helping us tackle several key challenges in cloud security, especially around maintaining a strong, unified security posture across multiple cloud accounts. By providing deep visibility into misconfigurations, vulnerabilities, and compliance gaps, Orca enables us to proactively identify and mitigate risks before they become critical issues. This all-in-one approach has streamlined our security workflows and allows our team to focus on strategic improvements rather than being bogged down by manual checks or constant tool-switching. It’s a huge boost in terms of efficiency and confidence, knowing we have a clearer picture of our cloud environment’s security health. Review collected by and hosted on G2.com.

💡 Aristide B.
💡B
Head of Product Security & Sr Staff Engineer
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
(Original )Information
What do you like best about Orca Security?

Very easy to configure and get start with.

Excellent support for the 3 main Cloud providers.

They invested a lot in their product and it is incredibly more extensive than it was a couple years ago.

The pricing is relatively reasonable for smaller organizations.

Excellent Customer Success and Executive Teams.

The flexibility of its API, Sonar Queries and automations.

The full revamp of the Discovery feature has been impressive.

So many new perks have been keep coming up as part of the Premium plan: Shifleft, DSPM, API security, ThreatOptix.

The support is incredibly quick even during weekend. I've in all honesty never experienced a vendor as prompt as Orca to support their customers. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

I'm still waiting for a dark mode since the UI change.

Automations don't use Sonar querying language yet.

Could be interesting to have a Terraform module to manage configurations.

The new pricing model is a bit confusing. Review collected by and hosted on G2.com.

What problems is Orca Security solving and how is that benefiting you?

Before Orca we didn't have visibility on the vulnerabilities and configuration issues of our Cloud environment. Orca addressed one of our big compliance gap in a couple days and could easily be customized to our needs in a few weeks. Review collected by and hosted on G2.com.

Verified User in Insurance
EI
Enterprise(> 1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
(Original )Information
What do you like best about Orca Security?

It still has the best technology in the cloud security space. I've compared it to Wiz, side-by-side just recently, and still find Orca to have the

- Highest quality findings

- Most accurate prioritization

- Best integration with related systems

- Easiest—much, much easier—UI and best UX

- Implemenation ease, and

- Best customer support.

I and my team use Orca daily, multiple times a day. It's a foundational security product for us. After testing out Wiz for a month, side by side, I appreciate Orca even more. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

I would love to see Orca expand into the area of more automated remediation. Review collected by and hosted on G2.com.

Recommendations to others considering Orca Security:

This product is clearly the next generation in TVM. Only Prisma comes close, but Orca is easier and gives more useful information to get to resolution. Review collected by and hosted on G2.com.

What problems is Orca Security solving and how is that benefiting you?

Accurate identification of risks and threats with easy-to-investigate tools. We have gained back one FTE’s time, and replaced two products for a net-zero cost. Review collected by and hosted on G2.com.

Verified User in Security and Investigations
AS
Enterprise(> 1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Orca Security?

I love how Orca brings everything together in one place, making it an excellent tool for someone specializing in vulnerability management. Its ease of use and ease of implementation streamline our work, and the number of features it offers is impressive. Orca has significantly helped us reduce vulnerabilities and address each item effectively. Although Orca sometimes flags any visible item as vulnerable, it’s still one of the best tools I've enountered so far.

The customer support is exceptional; I can get a support representative on a call within five minutes, which only enhances my desire to use it. Their support team has also been incredibly helpful with integrations, which has made the tool even easier to integrate and use frequently. This outstanding support and ease of integration contribute to our high frequency of use, making Orca an invaluable asset in our security toolkit. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

There are several minor issues in Orca that have accumulated into larger challenges. For example, the same vulnerability path is sometimes duplicated across multiple Orca alert IDs, which leads to confusion. Additionally, when a scan is performed on a server, it doesn't display the exact time the scan was completed, nor does it provide backend visibility into scan failures, making it difficult to troubleshoot assets effectively.

We've submitted multiple feature requests, including support for asset scanning on devices like Fortinet and Ivanti, which our organization heavily relies on but aren’t currently detected by Orca. Furthermore, we occasionally encounter issues with hardening scan reports for specific assets, and pulling an inventory report is challenging due to the vast number of assets—over 3 to 4 million. While it's understandable given the scale, it’s still a limitation. Another significant issue is the inability to fetch more than 10,000 alerts through the API when retrieving data for a particular CVE.

Despite these drawbacks, I appreciate Orca’s efforts to adapt to our needs and continuously improve the tool. Review collected by and hosted on G2.com.

What problems is Orca Security solving and how is that benefiting you?

Orca Security has really helped us tackle some big challenges in managing vulnerabilities and securing our assets. One of the best things is that it gives us full visibility across our cloud environment without needing agents, which saves us a lot of hassle and time. We can deploy it across all our systems quickly, and it scans everything that’s visible in our environment, so we don’t miss any potential issues.

Having all our vulnerability data in one place has been a game-changer. With Orca’s centralized dashboard, it’s much easier to see what’s critical and what needs our attention first, helping us to reduce risks more effectively. It’s streamlined our process, making it a lot easier to track and fix vulnerabilities.

Their customer support has also been fantastic. I can reach someone in minutes if there’s an issue, which is so helpful when you’re trying to keep things running smoothly. Plus, their support team has been great with helping us integrate Orca with our other tools, which has improved our workflow and made us more efficient.

Overall, Orca has made a real difference by giving us a stronger grip on cloud security, helping us manage vulnerabilities more easily, and scaling well to fit our organization’s needs. It feels like they’re really working to meet our specific needs, and that’s been invaluable. Review collected by and hosted on G2.com.

Verified User in Mechanical or Industrial Engineering
AM
Enterprise(> 1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Orca Security?

The tool provides a pragmatic view of you security posture. We all know CVEs err on the side of more severe criticality. Orca is aware of this too and tries to reserve the Critical status for things that should be looked at now.

Attack paths provide a seed for internal investigations.

Webhook oriented scans for your repositories are easy to implement.

Customer support is very good. Just a click and you get a chat bot that is quickly picked up by a human. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

Attack paths aren't always accurate. For example, a ddos vulnerability won't lead to a pivot to an internal access. Not by itself anyway.

Out of the box scans are fairly infrequent in an environment where changes happen often. Review collected by and hosted on G2.com.

What problems is Orca Security solving and how is that benefiting you?

Outside of the obvious security benefits, Orca provides a view of neglected resources which has led to significant resource clean up. Review collected by and hosted on G2.com.

Verified User in Food & Beverages
AF
Enterprise(> 1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Orca Security?

Orca's implementation was very fast and straight forward. All my contacts with Orca stay in touch with me to see if everything is working as intended. The product is very straight forward and very simple ones you login and you can immedatly see everything from a single pane of glass.

The integrations and features that are provided are world class. We are constantly using the product in order to acheive our goals in stregthening our security posture here. A solution like Orca is really a next gen product that every organization should have.

I stand by my decision by choosing Orca and we are seeing our ROI with the tool. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

Documentation could be updated and be a bit more straight forward when trying to solve issues on our own or seeing what other capabilities are there, but the support team has been wonderful in helping us solve our issues. Review collected by and hosted on G2.com.

What problems is Orca Security solving and how is that benefiting you?

Orca helps me know what is going on in my cloud environment to help secure our organization. It is also helping our infrastructure teams know what all is out there in our environment. It helps me build out a vulnerabilityh mangement platform with ease. Review collected by and hosted on G2.com.

Verified User in Biotechnology
EB
Enterprise(> 1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Orca Security?

Context-driven security was considered the future of Cloud Security, and Orca led the charge. The level of depth provided around resources and assets in your cloud is one of the best out there.

We love the ability to clone and customize "baked-in" alerts to meet our environmental needs, specifically around asset tagging/labeling. Their Code Security capabilities are starting to rival those of Synk and others in the space. The potential there is promising, and the product teams are constantly keeping us in the loop.

The Custmoziable Alerts dashboard, which meets my leadership needs, is easy to use. My team can also create and share customized views without much effort.

Searching and "Discovery" have greatly improved in the latest iteration of the product, and the speed at which we find assets and configurations has improved.

Orca provides very in-depth "attack path" visualizations that are easy to follow, clearly visualize risks, and tell an attack story. Although this would be considered intimidating to view, their visual representation is strong.

Side-scanning continues to provide tremendous value to us. It still amazes me how quickly they scan our entire environment and report back changes, threats, risks associated with "data" or storage.

There is a lot more to mention, but lastly, our customer support and sales team has been top-notch. One of the best we have worked with. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

Reporting on containerization vulnerabilities has improved, but it needs to be better. (Orca has been investing a lot in this space and the future is promising).

Infrastructure as Code custom policy creation is effective but challenging and needs to be more closely linked to the UI. (There might be technical challenges here but overall, we need more visualizations in the UI around this)

Identity-based reporting around "inactive" non-human accounts is an area that needs more attention. (GCP Support is a little behind.) Review collected by and hosted on G2.com.

What problems is Orca Security solving and how is that benefiting you?

Agentless cloud storage and data monitoring is benefiting us. We can confidently deploy compute as needed and still scan and detect at the file level.

Comprehensive coverage of all of our major cloud providers.

Context-aware risk prioritization is proving to have its benefits for minizing the overall organizational risk. Review collected by and hosted on G2.com.