Orca Security Reviews (314)

View 1 Video Reviews
Reviews

Orca Security Reviews (314)

View 1 Video Reviews
4.7
314 reviews

What do users say?

Generated using AI from real user reviews
Users consistently praise the product for its agentless setup and clear visibility into cloud security risks, which simplifies monitoring and management across multiple environments. The platform's ability to prioritize risks effectively allows teams to focus on critical issues without being overwhelmed by alerts. However, some users note that the reporting features could benefit from greater customization.

Pros & Cons

Generated from real user reviews
View All Pros and Cons
Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
SJ
Sara J.
Enterprise (> 1000 emp.)
"Rapid Visibility into Inherited AI Agents and Their Risk Paths"
5/5
What do you like best about Orca Security?

When we acquire a new business or bring a new cloud environment into the fold, we’re not just inheriting infrastructure; we’re inheriting their agents, their workflows, and their data paths. Orca lets us connect the new accounts quickly and immediately see which AI agents exist there, what identities they use, and which systems and data stores they can reach. Instead of months of manual discovery, we get a clear picture of inherited AI agent risk within days. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

We chose to standardize some basic tagging and ownership conventions for newly onboarded agents, and that upfront work has already made cross-business-unit reviews much smoother. Review collected by and hosted on G2.com.

JM
Jayden M.
Enterprise (> 1000 emp.)
"Orca Brings Clear Visibility and Control to Our Growing Fleet of AI Agents"
5/5
What do you like best about Orca Security?

Inside our company, the population of spun-up AI agents has increased a lot. Marketing is writing agents into campaigns, analysts are shipping autonomous workflows, and the PM team is trying agents in new features. Almost everyone in the building can now launch an agent that talks to real systems, and that used to raise serious concerns for our security team. Orca gives us visibility and context across every one of those agents. We can catch over-permissioned agent access or a misconfigured role before a workflow runs away or an attacker would, and the builder almost never has to slow down. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

It helped our non-technical builders understand the agent findings as they related to their work. We did need a bit of internal education on our side, but once they saw the results in the context of what their agents were actually doing, it clicked. Review collected by and hosted on G2.com.

JC
Juan C.
Enterprise (> 1000 emp.)
"Orca’s Unified Data Model Made Agentic Workflow Governance Clear and Actionable"
5/5
What do you like best about Orca Security?

The CISO here was accountable for everyone who ships: the developer, the data scientist, the analyst deploying the agents, the PM, and the marketer writing the Python. Last month, an analyst spun up an agentic workflow with access to multiple internal systems, and nobody had told security. Orca surfaced it, mapped what the agent could reach, and we were able to govern it before it became an exposure. That’s what the unified data model actually means in practice: code, cloud, AI services, and now agents, all in one place. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

With so much consolidated into one platform, we decided to rethink some internal team boundaries around who owns the agents and their policies. That change improved clarity more than anything else. Review collected by and hosted on G2.com.

TT
Tatiana T.
Enterprise (> 1000 emp.)
"Orca Gives Full Visibility Into AI Agents and Data Access—Security Finally Keeps Pace"
5/5
What do you like best about Orca Security?

Inside our company, the number of people shipping to production has exploded. It’s no longer just engineers anymore—analysts are running automations, PMs are prototyping on Friday and pushing on Monday, and AI agents are now embedded in almost every workflow. Security used to find our issues only after something had already shipped. Orca gives us visibility into everything that has been built, including every AI agent, the identities they run as, and the data they can reach, without asking teams to change how they work. For the first time, security is keeping pace with how fast the business creates, especially across the agent layer. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

Because Orca showed us so much so quickly, the first few weeks required some tuning to separate the most urgent risks from the rest. That focused effort helped us quickly zero in on the AI agents and the paths that mattered most, and it has paid off with much clearer priorities. Review collected by and hosted on G2.com.

AJ
Ahsan J.
Enterprise (> 1000 emp.)
"Orca Quickly Flagged and Secured Our Exposed AI Agent Endpoint"
5/5
What do you like best about Orca Security?

The data scientist on our team deployed an agent backed by a model endpoint connected directly to production data. Orca immediately flagged the exposed inference endpoint, mapped the agent’s access, and gave us the context we needed to lock it down. The agent and the model stayed live; the risk didn’t. For an AI-heavy org, having a platform that understands agents, their model endpoints, and the data they touch as part of the attack surface was exactly what we needed. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

As new managed AI agent services come to market, we keep connecting them to Orca so our visibility stays in step with how quickly our teams adopt those services. Review collected by and hosted on G2.com.

JJ
Jibin J.
Enterprise (> 1000 emp.)
"Clear Agent Context Helps Us Put the Right Guardrails in Place"
5/5
What do you like best about Orca Security?

Our agents can chain actions across systems—invoking tools, writing to storage, and updating records—and that kind of power carries real risk if the workflows aren’t properly governed. Orcas context makes it clear that agents may touch sensitive data, change configurations, or even reach the public edge, so we can see exactly where strong guardrails and human-in-the-loop checks need to sit. Rather than discovering risky agent behavior only after something breaks, we’re able to put policy in place where it matters most. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

We invested a bit of effort in aligning Orcas agent views with our internal guardrail policy and naming conventions, which made it easier for teams to understand and act on the insights. Review collected by and hosted on G2.com.

"Orca Security Review"
5/5
What do you like best about Orca Security?

From a day-to-day operational center perspective, Orca’s native webhook integrations and alerting pathways are exceptional. We’ve wired Orca directly into our central IT notification channels and DevOps environments, so the exact second a high-priority risk or cloud misconfiguration is detected, Orca pushes a highly detailed data payload straight to our engineers. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

Navigating and configuring deeply nested, role-based access permissions within the master Orca Management console can feel overly complex, especially when attempting to provision highly restricted, read-only dashboard access for a regional business lead. It’s difficult to set things up so they can track only their specific sub-department’s cloud security posture without getting pulled into layers of permissions that are hard to interpret and configure correctly. Review collected by and hosted on G2.com.

Shivam S.
SS
Shivam S.
AI Data Annotator
Information Technology and Services
Small-Business (50 or fewer emp.)
"Orca SideScanning: Fast, Agentless Multi-Cloud Visibility with Zero Blind Spots"
5/5
What do you like best about Orca Security?

Orca's SideScanning technology delivers total visibility across our entire multi-cloud environment (AWS, Azure, GCP) within minutes. Because it’s completely agentless, there is zero operational friction—no software to install, no performance impact on live workloads, and absolutely zero blind spots. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

Limited Dashboard & Reporting Customization: The out-of-the-box dashboards can feel somewhat rigid and more technical than executive-friendly. Customizing metrics or building bespoke KPI reports for non-technical stakeholders is difficult, often forcing our team to export raw data via API to external BI tools or spreadsheets to get the specific views we need. Review collected by and hosted on G2.com.

MV
Marisol V.
Application Security Manager
Enterprise (> 1000 emp.)
"Agentless Cloud Visibility That Keeps Security in Step with Fast Dev Cycles"
5/5
What do you like best about Orca Security?

What stands out most to me is the agentless approach. We were able to get visibility across our cloud environment without having to ask teams to install agents or change the way they work. As development cycles have sped up, it’s become even more important for security to keep pace without introducing delays. Orca provides the insights we need while still letting teams deliver at their usual speed. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

During the initial rollout, the platform surfaced more risks than we expected. That level of visibility was helpful, but it also took us some time to sort through the findings, set clear priorities, and decide which items needed immediate action. Review collected by and hosted on G2.com.

SJ
Sara J.
Enterprise (> 1000 emp.)
"Orca Helped Us Secure AI Agents and Reduce Pentest Exposure"
5/5
What do you like best about Orca Security?

Before Orca, every pentest seemed to tread the same ground: familiar misconfigurations, identity issues the team already knew about, and a focus on traditional workloads instead of the AI agents doing the real work on our behalf. With Orca in place, we used this context to clean up the most exploitable paths involving the agents ahead of the test—from over-permitted agent identities to exposed endpoints and risky tool stacks. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

The first cleanup cycle before the pentest required some focused effort, especially around agents whose access had expanded over time, but it ultimately gave us a much cleaner baseline going into the exercise. Review collected by and hosted on G2.com.