Aqua Security

Security for AI Cloud Security also known as Scalock

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Defensible: Defensibility of 15 or above. A position that stays hard for rivals to replicate.
Founded 2015
Last updated 2026-07-08

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Aqua Security, a decade-old cloud-native security company used by more than 40 percent of the Fortune 100, holds a FedRAMP High authorization that is the hardest part of its position for a rival to take away. Sponsored by the Department of Education, it lets Aqua sell to federal agencies a competitor without the same clearance cannot reach quickly. The cloud-native scanning is reproducible by a funded rival, the capability Google signaled it wanted by buying Wiz. In November 2025 the founders moved to advisory roles, a CrowdStrike sales leader became chief executive, and a third round of layoffs followed. Most defensible for regulated and federal buyers, weakest where a cloud platform could bundle equivalent coverage into a bill the buyer already pays.

Sourced Details

Description Cloud native application protection platform (CNAPP) that secures containers, serverless functions, and cloud workloads from code to runtime, with an Aqua Secure AI line that discovers and protects AI applications. [f1]
Founded 2015 [f2]
HQ Boston, Massachusetts, United States and Ramat Gan, Israel [f3]
Latest funding Series E extension ($60M, Evolution Equity Partners-led, 2024) [f2]

Products

Product What it does
Aqua Platform Cloud native application protection platform combining agent and agentless coverage across code, supply chain, posture, and runtime for containers, serverless functions, and VMs.
Aqua Secure AI Lifecycle protection for AI applications that discovers AI usage, governs models across SaaS and self-hosted deployments, and enforces runtime policy against prompt-based threats without code changes.
Software Supply Chain Security Shifts security left across application code, infrastructure as code, and LLM components before risks reach production.
Runtime Protection Real-time detection and prevention for running cloud native workloads, stopping attacks in production across the container lifecycle.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

Aqua Secure AI discovers AI usage across SaaS, managed, and self-hosted models, applies posture checks to AI services, and enforces runtime policy against prompt injection and post-compromise activity where AI applications run. These capabilities are mapped to the AI Defense Matrix. [f4]

Cyber Defense Matrix

IdentifyProtectDetectRespondRecover
Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware.
Applications Software, interactions, and application flows on the devices.
Networks Connections and traffic flowing among devices and apps, plus communication paths.
Data Content at rest, in transit, or in use across devices, apps, and networks.
Users The people using the devices, apps, networks, and data.

The Aqua Platform CNAPP secures conventional cloud native workloads across containers, serverless functions, and VMs, scanning supply chain and code, enforcing pre-deployment posture, and detecting and stopping attacks at runtime in production. It is mapped to the Cyber Defense Matrix. [f1]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 28 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 Aqua defines the cloud-native security problem precisely, but the 40 percent of the Fortune 100 figure is vendor-reported reach rather than an independent quantification of buyer pain, so problem clarity is present but unproven. [s1, s2, s5]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 4/5 The platform spans code, supply chain, posture, and runtime with both agent and agentless coverage, documented across the product pages, and Aqua maintains the open-source Trivy scanner, which draws independent outside scrutiny: academic security research evaluates Trivy by name, and a disclosed credential-handling flaw Aqua patched in version 0.51.2 shows the product is examined and maintained beyond the company's own marketing. [s1, s2, s3, s6, s13, s14]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 4/5 CNAPP is an established budget line enterprises actively buy, and the new Aqua Secure AI line meets fresh demand to secure AI applications, a present buyer pull rather than a vendor-argued need. [s1, s3, s10]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 3/5 Co-founders Dror Davidoff and Amir Jerbi built a decade-long category leader, but both stepped to advisory roles in November 2025, replaced by a chief executive whose background is enterprise sales at CrowdStrike and Splunk rather than a verifiable security-product build. [s7]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 4/5 Named reference customers span PayPal, Netflix, Samsung, and Audi, the company reports protecting over 500 enterprises and 40 percent of the Fortune 100, and a FedRAMP marketplace listing opens federal sales, multiple corroborated traction signals. [s1, s5, s6, s9]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 Aqua raised about 195 million dollars across its Series E and extension, but no revenue or margin is disclosed and three rounds of layoffs make the cash-flow-independence push read as cost correction rather than confirmed efficiency, so funding efficiency is unconfirmed. [s4, s5, s8]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 4/5 Aqua helped create the container-security category and fits the now-established CNAPP slot buyers and analysts place without vendor coaching, a clear stack position alongside Wiz, Orca, and Prisma Cloud. [s1, s2, s10]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 Core CNAPP scanning is a capability cloud platforms can bundle, shown by Google acquiring the rival Wiz, so the value proposition is absorbable absent a structural moat, level with the agentless cloud-security cluster. [s2, s10]
Business Risks A cloud platform could bundle equivalent CNAPP coverage into a bill the buyer already pays, as Google did by acquiring Wiz, eroding Aqua's standalone value…
  • A cloud platform could bundle equivalent CNAPP coverage into a bill the buyer already pays, as Google did by acquiring Wiz, eroding Aqua's standalone value.
  • The November 2025 move to a sales-led chief executive and a third round of layoffs could slow product investment relative to better-capitalized rivals.
  • Aqua Secure AI remains exclusive access rather than general availability, so a faster rival could define the AI-application-security category first.
  • Without a funding round since January 2024, Aqua could fall behind competitors backed by hyperscaler balance sheets in a capital-intensive category.
Problem & Market Aqua secures cloud native applications across their lifecycle, from source code and the software supply chain through cloud posture and into runtime in production. The company frames the problem as protecting everything that runs in the cloud, spanning containers, serverless functions, and virtual machines, and now extends the same lifecycle to AI applications. The buyer is the enterprise security team running cloud native workloads at scale. Aqua quantifies that base concretely, reporting use by more than 40 percent of the Fortune 100 and named customers including PayPal, Netflix, Samsung, and Audi, which removes the ambiguity that weakens a marketing-only problem statement. The timing rests on two demand sources. Cloud native adoption made CNAPP a standing budget line, and the rapid enterprise move to build AI applications created fresh need to discover and govern AI usage, which the Aqua Secure AI line targets directly…

Aqua secures cloud native applications across their lifecycle, from source code and the software supply chain through cloud posture and into runtime in production. The company frames the problem as protecting everything that runs in the cloud, spanning containers, serverless functions, and virtual machines, and now extends the same lifecycle to AI applications.

The buyer is the enterprise security team running cloud native workloads at scale. Aqua quantifies that base concretely, reporting use by more than 40 percent of the Fortune 100 and named customers including PayPal, Netflix, Samsung, and Audi, which removes the ambiguity that weakens a marketing-only problem statement.

The timing rests on two demand sources. Cloud native adoption made CNAPP a standing budget line, and the rapid enterprise move to build AI applications created fresh need to discover and govern AI usage, which the Aqua Secure AI line targets directly. [s1, s2, s3]

Product Capabilities The Aqua Platform combines agent and agentless coverage in one product, scanning code, infrastructure as code, and LLM components in the supply chain, enforcing posture before deployment, and detecting and stopping attacks at runtime. The breadth from code to cloud to prompt is documented across the product pages rather than asserted in taglines. Aqua Secure AI adds discovery of AI models and usage across SaaS, managed, and self-hosted deployments, posture checks on AI services, and runtime enforcement against prompt injection and post-compromise activity inside the containers where AI applications run. The vendor offers the line as exclusive access rather than a fully general-availability product, so its capability depth trails the mature platform around it. The platform earns external validation uncommon among rivals. Aqua maintains the open-source Trivy scanner, which independent academic security research evaluates by name and which carries a disclosed credential-handling vulnerability Aqua patched in 2024, both signs the product is examined outside the company. In 2025 Aqua achieved FedRAMP High authorization for its federal CNAPP, a control-heavy government assessment that corroborates engineering depth beyond the company's own claims…

The Aqua Platform combines agent and agentless coverage in one product, scanning code, infrastructure as code, and LLM components in the supply chain, enforcing posture before deployment, and detecting and stopping attacks at runtime. The breadth from code to cloud to prompt is documented across the product pages rather than asserted in taglines.

Aqua Secure AI adds discovery of AI models and usage across SaaS, managed, and self-hosted deployments, posture checks on AI services, and runtime enforcement against prompt injection and post-compromise activity inside the containers where AI applications run. The vendor offers the line as exclusive access rather than a fully general-availability product, so its capability depth trails the mature platform around it.

The platform earns external validation uncommon among rivals. Aqua maintains the open-source Trivy scanner, which independent academic security research evaluates by name and which carries a disclosed credential-handling vulnerability Aqua patched in 2024, both signs the product is examined outside the company. In 2025 Aqua achieved FedRAMP High authorization for its federal CNAPP, a control-heavy government assessment that corroborates engineering depth beyond the company's own claims. [s2, s3, s6, s13, s14]

Competitive Positioning Aqua competes in CNAPP, a crowded category whose vendors sell overlapping code-to-cloud coverage. Aqua's longer history in container and runtime security and its agent-plus-agentless approach are its differentiators. The category is consolidating around platforms that can absorb the capability. Google's purchase of Wiz put a hyperscaler behind a CNAPP vendor, which pressures standalone vendors on price and reach. Against that pressure, Aqua's distinguishing position is its federal foothold and installed base. The FedRAMP High authorization and a federal CNAPP hosted on AWS GovCloud open public-sector pipelines a competitor without the same authorization cannot enter quickly, and the Fortune 100 install base raises the cost of displacement even where the underlying scanning is reproducible…

Aqua competes in CNAPP, a crowded category whose vendors sell overlapping code-to-cloud coverage. Aqua's longer history in container and runtime security and its agent-plus-agentless approach are its differentiators.

The category is consolidating around platforms that can absorb the capability. Google's purchase of Wiz put a hyperscaler behind a CNAPP vendor, which pressures standalone vendors on price and reach.

Against that pressure, Aqua's distinguishing position is its federal foothold and installed base. The FedRAMP High authorization and a federal CNAPP hosted on AWS GovCloud open public-sector pipelines a competitor without the same authorization cannot enter quickly, and the Fortune 100 install base raises the cost of displacement even where the underlying scanning is reproducible. [s6, s10]

Go-to-Market & Traction Aqua shows traction beyond design partners…

Aqua shows traction beyond design partners. The company reports protecting over 500 enterprises and more than 40 percent of the Fortune 100, and press and its own customer wall name reference customers including PayPal, Netflix, Samsung, and Audi.

The federal channel is a distinct motion. The 2025 FedRAMP High authorization and a marketplace listing for Aqua U.S. Gov open direct sales to federal, state, and local agencies that require FedRAMP-authorized cloud services.

The 2025 restructuring tempers the growth read. Three rounds of layoffs in recent years and a stated push toward cash flow independence indicate a stronger efficiency component alongside the company's stated growth. [s1, s5, s6, s8, s9]

Team & Credibility Co-founders Dror Davidoff and Amir Jerbi built Aqua over a decade into a category leader, originally as Scalock in 2015, an established build in the container-security domain. Israel's company registry independently records the entity as Aqua Security Software Ltd, an active Israeli private company incorporated in 2015, corroborating the decade-long operating history. Leadership turned over in November 2025. Both founders stepped to advisory roles, Mike Dube, who joined from a senior enterprise sales role at CrowdStrike, became chief executive, and a former engineering vice president took the product and technology seat. The new chief executive's public track record is in enterprise sales rather than a verifiable security-product build, which is why the team signal sits at the adequate rather than strong level. The transition reads as a shift from founder-led product growth to a commercial-execution phase, consistent with the simultaneous cost cutting…

Co-founders Dror Davidoff and Amir Jerbi built Aqua over a decade into a category leader, originally as Scalock in 2015, an established build in the container-security domain. Israel's company registry independently records the entity as Aqua Security Software Ltd, an active Israeli private company incorporated in 2015, corroborating the decade-long operating history.

Leadership turned over in November 2025. Both founders stepped to advisory roles, Mike Dube, who joined from a senior enterprise sales role at CrowdStrike, became chief executive, and a former engineering vice president took the product and technology seat. The new chief executive's public track record is in enterprise sales rather than a verifiable security-product build, which is why the team signal sits at the adequate rather than strong level.

The transition reads as a shift from founder-led product growth to a commercial-execution phase, consistent with the simultaneous cost cutting. [s7, s8, s12]

Trust Readiness Aqua publishes a substantive security posture…

Aqua publishes a substantive security posture. Its trust center lists SOC 2 Type II, ISO 27001 from 2022, ISO 27017, ISO 27018, ISO 27701, CSA STAR, GDPR, and NIST 800-53 alignment, with controls and subprocessor disclosures available on request.

The federal authorization sets Aqua apart on trust. Aqua holds FedRAMP authorization at the High impact level, sponsored by the Department of Education and listed in the FedRAMP marketplace, which Aqua reached ahead of the CNAPP peers cited here.

Taken together, the commercial attestations meet enterprise procurement expectations and the federal authorization clears a higher public-sector bar, so trust readiness is a strength rather than a gap. [s6, s11]

Competitors Wiz, Orca Security, Palo Alto Networks, Sysdig…
Company Relationship Note Compare
Wiz competes with The agentless cloud-security rival Google acquired in a deal that closed in 2026, placing a hyperscaler behind a direct competitor.
Orca Security competes with An agentless CNAPP rival that also holds a FedRAMP authorization and serves regulated enterprise and federal buyers. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Palo Alto Networks competes with Prisma Cloud is a competing CNAPP from a platform incumbent with broad enterprise distribution. N/AWe scored these companies at different scopes, so the totals measure different things.
Sysdig competes with A runtime and container-security rival rooted in cloud native workload protection, overlapping Aqua's original strength. N/AWe scored these companies at different scopes, so the totals measure different things.

Add analyzed competitors to compare them side by side with Aqua Security.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Defensible 15 /21 Defensible: Defensibility of 15 or above. A position that stays hard for rivals to replicate. press the advantage

Aqua Security is durable on engineering depth and a federal compliance posture and exposed on what the customer buys and what the platform accumulates. Its agent-plus-agentless coverage from code to runtime is years of specialized work, and its FedRAMP High authorization is a clearance a copycat cannot clear quickly, opening public-sector pipelines to the company. Against that, the customer buys software it configures and runs rather than a service that accepts accountability, and the record names no cross-customer data asset a rival could not rebuild. The hardest part for a rival to take away is the federal foothold, not the scanning. The heaviest exposure is a cloud platform bundling equivalent coverage with the cloud the buyer already pays for, a path Google signaled by buying Wiz.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Customers buy a software platform that scans code, supply chain, and runtime and that they configure and operate themselves, rather than a service in which Aqua accepts judgment or accountability for the outcome.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Wiring agent and agentless coverage, pre-deployment posture gates, and runtime policies into CI/CD and production creates real friction to replace, while the deploy-and-scan model keeps the underlying cloud data portable, short of the data-residency or system-of-record lock a 3 would need.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 3/3 Aqua holds a FedRAMP High authorization with a federal sponsor, listed in the FedRAMP marketplace and delivered through Aqua U.S. Gov on AWS GovCloud, a federal clearance that opens public-sector pipelines a replacement cannot obtain quickly. That federal clearance places Aqua above vendors that hold no comparable authorization.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Building one platform that combines agent and agentless coverage and correlates code, supply chain, posture, and runtime risk across containers, serverless functions, and VMs is real-time, multi-system engineering that takes years of specialized work.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 3/3 The buyers are regulated large enterprises and US federal agencies that procure through negotiated deals and strict reviews, with more than 40 percent of the Fortune 100 named and a FedRAMP authorization serving the public sector, the population whose legal and security review sits between the vendor and replacement.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 The Aqua Platform is a control plane that scans, gates, and protects across the clouds and pipelines an enterprise runs, a platform with application features rather than infrastructure customer traffic is forced through inline.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 The public record shows no named non-public dataset or detection corpus behind the platform, and the company's flagship Trivy database is open source, so the advantage is the platform's engineering and breadth a well-funded rival could rebuild rather than an asset no one else owns.
Strategic Market Segmentation Aqua sells to enterprise security teams that run cloud native workloads at scale, and it serves them deeply, reporting more than 40 percent of the Fortune 100 and over 500 enterprises with named logos including PayPal, Netflix, Samsung, and Audi. The buyer knows the budget line, since CNAPP is an established category Aqua helped create from its origins in container security. Aqua also targets public-sector buyers through a tailored federal offering. Aqua U.S. Gov, hosted on AWS GovCloud and carrying a FedRAMP High authorization sponsored by the Department of Education, targets federal, state, and local agencies that require FedRAMP-authorized cloud services. The Aqua Secure AI line extends the same base into a new use case rather than a new buyer. It is offered as exclusive access rather than general availability, so it currently reads as a feature expansion for existing cloud native customers adopting AI, not a separate go-to-market motion…

Aqua sells to enterprise security teams that run cloud native workloads at scale, and it serves them deeply, reporting more than 40 percent of the Fortune 100 and over 500 enterprises with named logos including PayPal, Netflix, Samsung, and Audi. The buyer knows the budget line, since CNAPP is an established category Aqua helped create from its origins in container security.

Aqua also targets public-sector buyers through a tailored federal offering. Aqua U.S. Gov, hosted on AWS GovCloud and carrying a FedRAMP High authorization sponsored by the Department of Education, targets federal, state, and local agencies that require FedRAMP-authorized cloud services.

The Aqua Secure AI line extends the same base into a new use case rather than a new buyer. It is offered as exclusive access rather than general availability, so it currently reads as a feature expansion for existing cloud native customers adopting AI, not a separate go-to-market motion.

Product Capabilities & AI Advantages The Aqua Platform combines agent and agentless coverage in one product across code, software supply chain, cloud posture, and runtime. The runtime and container-lifecycle depth is the company's original strength, and Aqua offers the open-source Trivy scanner as part of its open-source projects, which it describes as trusted by security professionals, an external signal of capability beyond vendor claims. Aqua Secure AI applies that runtime vantage point to AI applications. It discovers AI usage across SaaS, managed, and self-hosted models, runs posture checks on AI services, and enforces policy against prompt injection and post-compromise activity inside the containers where AI workloads run, without requiring SDKs, proxies, or code changes. The AI line's advantage is positional rather than proprietary. Securing AI from inside the container runtime, where Aqua already operates, is a coherent extension of the platform, but no named non-public dataset backs the line, and absent a proprietary data asset the underlying detection and posture techniques appear reproducible by well-funded CNAPP rivals…

The Aqua Platform combines agent and agentless coverage in one product across code, software supply chain, cloud posture, and runtime. The runtime and container-lifecycle depth is the company's original strength, and Aqua offers the open-source Trivy scanner as part of its open-source projects, which it describes as trusted by security professionals, an external signal of capability beyond vendor claims.

Aqua Secure AI applies that runtime vantage point to AI applications. It discovers AI usage across SaaS, managed, and self-hosted models, runs posture checks on AI services, and enforces policy against prompt injection and post-compromise activity inside the containers where AI workloads run, without requiring SDKs, proxies, or code changes.

The AI line's advantage is positional rather than proprietary. Securing AI from inside the container runtime, where Aqua already operates, is a coherent extension of the platform, but no named non-public dataset backs the line, and absent a proprietary data asset the underlying detection and posture techniques appear reproducible by well-funded CNAPP rivals.

Sales Engagement & Go-to-Market Aqua runs a sales-led enterprise motion routed through demos rather than self-serve signup, consistent with negotiated deals into large organizations. The traction is broad and corroborated, with more than 40 percent of the Fortune 100 and named customers including PayPal, Netflix, and Samsung. A distinct federal channel runs alongside the commercial one. The FedRAMP High authorization and a marketplace listing for Aqua U.S. Gov open direct sales to government agencies, a motion that requires comparable federal authorization for similar deployments. The 2025 restructuring reframes the growth posture. Three rounds of layoffs and a stated push toward cash flow independence indicate a stronger efficiency component alongside the company's stated growth and expansion…

Aqua runs a sales-led enterprise motion routed through demos rather than self-serve signup, consistent with negotiated deals into large organizations. The traction is broad and corroborated, with more than 40 percent of the Fortune 100 and named customers including PayPal, Netflix, and Samsung.

A distinct federal channel runs alongside the commercial one. The FedRAMP High authorization and a marketplace listing for Aqua U.S. Gov open direct sales to government agencies, a motion that requires comparable federal authorization for similar deployments.

The 2025 restructuring reframes the growth posture. Three rounds of layoffs and a stated push toward cash flow independence indicate a stronger efficiency component alongside the company's stated growth and expansion.

Pricing Model Aqua publishes no list pricing in the fetched pages, so the charged unit and list price stay private. The demo-gated packaging and enterprise positioning point to a negotiated sales motion, though the deal size and billing unit are not publicly confirmed. The unified platform implies value scaling with the size of the cloud estate under protection rather than a simple per-seat charge, but the public record does not document the metric, so the budget-anchoring signal some peers publish is absent here…

Aqua publishes no list pricing in the fetched pages, so the charged unit and list price stay private. The demo-gated packaging and enterprise positioning point to a negotiated sales motion, though the deal size and billing unit are not publicly confirmed.

The unified platform implies value scaling with the size of the cloud estate under protection rather than a simple per-seat charge, but the public record does not document the metric, so the budget-anchoring signal some peers publish is absent here.

Product Delivery & Operations Aqua sells a software platform for teams to scan code and supply chain, gate posture before deployment, and protect workloads at runtime, blending agent and agentless coverage. The company states the Aqua Secure AI line enforces policy without requiring SDKs, proxies, or code changes, lowering the operational cost of adoption. A separate federal delivery exists for government buyers. Aqua U.S. Gov is hosted on AWS GovCloud and carries the FedRAMP High authorization, a delivery footprint tailored to public-sector requirements that the commercial SaaS does not by itself satisfy…

Aqua sells a software platform for teams to scan code and supply chain, gate posture before deployment, and protect workloads at runtime, blending agent and agentless coverage. The company states the Aqua Secure AI line enforces policy without requiring SDKs, proxies, or code changes, lowering the operational cost of adoption.

A separate federal delivery exists for government buyers. Aqua U.S. Gov is hosted on AWS GovCloud and carries the FedRAMP High authorization, a delivery footprint tailored to public-sector requirements that the commercial SaaS does not by itself satisfy.

Earning Customers' Trust Aqua publishes a substantive security posture through a trust center listing SOC 2 Type II, ISO 27001 from 2022, ISO 27017, ISO 27018, ISO 27701, CSA STAR, GDPR, and NIST 800-53 alignment, with controls and subprocessor disclosures available on request. The federal authorization is the strongest trust signal. Aqua holds FedRAMP authorization at the High impact level, sponsored by the Department of Education and listed in the FedRAMP marketplace, a credential regulated buyers weigh heavily…

Aqua publishes a substantive security posture through a trust center listing SOC 2 Type II, ISO 27001 from 2022, ISO 27017, ISO 27018, ISO 27701, CSA STAR, GDPR, and NIST 800-53 alignment, with controls and subprocessor disclosures available on request.

The federal authorization is the strongest trust signal. Aqua holds FedRAMP authorization at the High impact level, sponsored by the Department of Education and listed in the FedRAMP marketplace, a credential regulated buyers weigh heavily.

Platform Strategy & Ecosystem Positioning Aqua positions a single platform spanning code, software supply chain, cloud posture, and runtime rather than a point tool, which lets a buyer consolidate several cloud native security functions with one vendor. The open-source ecosystem is a genuine asset. Aqua maintains Trivy, an open-source scanner it describes as trusted by security professionals, which seeds awareness among practitioners and feeds a community pipeline, though it is open source and so confers reach rather than a proprietary lock…

Aqua positions a single platform spanning code, software supply chain, cloud posture, and runtime rather than a point tool, which lets a buyer consolidate several cloud native security functions with one vendor.

The open-source ecosystem is a genuine asset. Aqua maintains Trivy, an open-source scanner it describes as trusted by security professionals, which seeds awareness among practitioners and feeds a community pipeline, though it is open source and so confers reach rather than a proprietary lock.

Team & Execution Capability Aqua was founded in 2015 by Dror Davidoff and Amir Jerbi, who built it over a decade into a recognized category leader from its origins in container security as Scalock. Leadership changed materially in November 2025. Both founders moved to strategic advisory roles, Mike Dube, who joined from a senior enterprise sales role at CrowdStrike, became chief executive, and a former engineering vice president took the product and technology seat. The new top of the company is weighted toward commercial execution rather than a fresh founder-led product vision…

Aqua was founded in 2015 by Dror Davidoff and Amir Jerbi, who built it over a decade into a recognized category leader from its origins in container security as Scalock.

Leadership changed materially in November 2025. Both founders moved to strategic advisory roles, Mike Dube, who joined from a senior enterprise sales role at CrowdStrike, became chief executive, and a former engineering vice president took the product and technology seat. The new top of the company is weighted toward commercial execution rather than a fresh founder-led product vision.

Sources

Company Detail Sources (4)
Id Source Tier Accessed
f1 Aqua CNAPP products overview official 2026-06-25
f2 Aqua Security raises $60M and remains a unicorn (TechCrunch) press 2026-06-25
f3 Aqua Security raises $135M at a $1B valuation (TechCrunch) press 2026-06-25
f4 AI Defense Matrix Catalog mapping (Aqua Secure AI) official 2026-06-25
Profile Analysis Sources (14)
Id Source Tier Accessed
s1 Aqua Security homepage (protect what runs in the cloud, 40% of the Fortune 100)
“Trusted by more than 40% of the Fortune 100”
official 2026-06-25
s2 Aqua CNAPP products (code to cloud to prompt)
“Secure every phase, protect every workload and reduce cloud and AI risk everywhere applications run. Aqua delivers full lifecycle security from code to cloud to prompt.”
official 2026-06-25
s3 Aqua Secure AI (protect AI apps from code to cloud to prompt)
“Gain visibility into prompt and model behavior inside containers where AI applications are hosted and run. Aqua enforces policy in real time without requiring SDKs, proxies, or rewrites.”
official 2026-06-25
s4 Aqua Security raises $135M at a $1B valuation (TechCrunch)
“raised a $135 million Series E funding round at a $1 billion valuation. The round was led by ION Crossover Partners.”
press 2026-06-25
s5 Aqua Security raises $60M and remains a unicorn (TechCrunch)
“raised $60 million in funding, extending its previously announced $135 million Series E round of funding to $195 million. Founded in 2015, Tel Aviv- and Boston-based Aqua Security claims customers such as PayPal, Netflix and Samsung”
press 2026-06-25
s6 Aqua Security Achieves FedRAMP High Authorization (GlobeNewswire wire)
“it has achieved the Federal Risk and Authorization Management Program's (FedRAMP) high impact authorization status and is listed in the FedRAMP marketplace. Sponsored by the Department of Education”
press 2026-06-25
s7 Aqua Security Announces Leadership Transition (GlobeNewswire wire, Nov 2025)
“Co-founders Dror Davidoff and Amir Jerbi will step back from their day-to-day roles as chief executive officer and chief technology officer ... Mike Dube ... has been appointed CEO ... Prior to joining Aqua, Dube served as vice president, North America Strategic Sales at CrowdStrike”
press 2026-06-25
s8 Aqua Security lays off staff weeks after management shake-up (CTech)
“Cyber unicorn Aqua Security is laying off dozens of employees, including about 20 in Israel. This is the company's third round of layoffs in recent years. Aqua employs roughly 360 people in total.”
press 2026-06-25
s9 Aqua Security homepage customer wall (Audi container platform at scale)
“Audi uses Aqua to Protect Container Platform at Scale”
official 2026-06-25
s10 Google completes acquisition of Wiz (Cybersecurity Dive)
“Google completes acquisition of Wiz”
press 2026-06-25
s11 Aqua Security Trust Center (SOC 2 Type II, ISO 27001 2022, CSA STAR, NIST 800-53)
“Compliance: CSA Star, GDPR, NIST 800-53 Low Baseline, ISO 27017:2015, SOC 2 Type II, ISO 27001:2022, ISO27018:2019, ISO 27701:2019”
official 2026-06-25
s12 Israeli Registrar of Companies: AQUA SECURITY SOFTWARE LTD (company 515317972, incorporated 24/09/2015, status active, annual report 2025)
“"שם באנגלית":"AQUA SECURITY SOFTWARE LTD","סוג תאגיד":"ישראלית חברה פרטית","סטטוס חברה":"פעילה","תאור חברה":"","מטרת החברה":"לעסוק בכל עיסוק חוקי","תאריך התאגדות":"24/09/2015"”
regulatory 2026-06-29
s13 NVD CVE-2024-35192: credential leak in Aqua's Trivy scanner before 0.51.2
“it could result in the leakage of credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google Cloud Artifact/Container Registry, or Azure Container Registry (ACR)”
regulatory 2026-06-29
s14 arXiv gh0stEdit (2506.08218): independent security evaluation naming Aqua's Trivy scanner
“a vulnerability scanner provided by Aqua Security, functions similarly to Docker Scout and Grype”
research 2026-06-29
Deep-Dive Sources (10)
Id Source Tier Accessed
s1 Aqua Security homepage (protect what runs in the cloud, 40% of the Fortune 100)
“Trusted by more than 40% of the Fortune 100”
official 2026-06-25
s2 Aqua CNAPP products (code to cloud to prompt)
“Secure every phase, protect every workload and reduce cloud and AI risk everywhere applications run. Aqua delivers full lifecycle security from code to cloud to prompt.”
official 2026-06-25
s3 Aqua Secure AI (protect AI apps from code to cloud to prompt)
“Gain visibility into prompt and model behavior inside containers where AI applications are hosted and run. Aqua enforces policy in real time without requiring SDKs, proxies, or rewrites.”
official 2026-06-25
s4 Aqua Security raises $60M and remains a unicorn (TechCrunch)
“raised $60 million in funding, extending its previously announced $135 million Series E round of funding to $195 million. Founded in 2015, Tel Aviv- and Boston-based Aqua Security claims customers such as PayPal, Netflix and Samsung”
press 2026-06-25
s5 Aqua Security Achieves FedRAMP High Authorization (GlobeNewswire wire)
“it has achieved the Federal Risk and Authorization Management Program's (FedRAMP) high impact authorization status and is listed in the FedRAMP marketplace. Sponsored by the Department of Education”
press 2026-06-25
s6 Aqua Security Announces Leadership Transition (GlobeNewswire wire, Nov 2025)
“Co-founders Dror Davidoff and Amir Jerbi will step back from their day-to-day roles ... Mike Dube ... has been appointed CEO ... Prior to joining Aqua, Dube served as vice president, North America Strategic Sales at CrowdStrike”
press 2026-06-25
s7 Aqua Security lays off staff weeks after management shake-up (CTech)
“This is the company's third round of layoffs in recent years. Aqua employs roughly 360 people in total. The company was founded in 2015 by CEO Dror Davidoff and CTO Amir Jerbi.”
press 2026-06-25
s8 Aqua Security Trust Center (SOC 2 Type II, ISO 27001 2022, CSA STAR, NIST 800-53)
“Compliance: CSA Star, GDPR, NIST 800-53 Low Baseline, ISO 27017:2015, SOC 2 Type II, ISO 27001:2022, ISO27018:2019, ISO 27701:2019”
official 2026-06-25
s9 Google completes acquisition of Wiz (Cybersecurity Dive)
“Google completes acquisition of Wiz”
press 2026-06-25
s10 Aqua Software Supply Chain Security (code, IaC, LLM components)
“Shift security left to protect every link in the software supply chain, including application code, IaC, and LLM components, before risks reach production.”
official 2026-06-25

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.