Orca Security

Security for AI Cloud Security

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Defensible: Defensibility of 15 or above. A position that stays hard for rivals to replicate.
Founded 2019
Funding $632M
Last updated 2026-08-23

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Orca Security reports that Forrester named it a Strong Performer among the 14 cloud-security platforms it evaluated in early 2026. Orca sells enterprises software that inspects the storage behind their cloud machines and reports the risks it finds, without installing an agent on each one. On Gartner's buyer-review site Orca holds a 4.6 average across 257 ratings, against 4.7 across 629 for the Wiz platform Google now owns. Orca publishes customer case studies on Swiggy, C6 Bank and Blue Yonder, and its patent notice lists twelve granted US patent numbers. It holds a US federal authorization at the moderate level. No verified or company-disclosed revenue figure appears in the reviewed sources to set beside those credentials.

Sourced Details

Description Orca's AI-SPM uses agentless scanning to discover deployed AI models, including shadow AI, and flags misconfigurations and exposed sensitive data to protect against data tampering and leakage. [f1]
Founded 2019 [f2]
HQ Portland, Oregon, United States [f3]
Funding $632M total [f4]
Latest funding Series C extension (Temasek-led) [f5]
Deployment SaaS [f6]
Compliance CSA STAR, FedRAMP Certified Class C, GDPR, GovRAMP, ISO 27001, ISO 27017, ISO 27018, ISO 27701, PCI DSS, SOC 2 [f6]

Products

Product What it does
Orca Agentless AI security posture management in the Orca cloud platform that discovers AI models including shadow AI, inventories them, and flags misconfigurations and exposed data.
Agentic AI Remediation (Opus) Agentic AI-driven remediation and prevention built on the acquired Opus technology, adding autonomous risk resolution to the Orca CNAPP beyond identification and prioritization.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

Orca provides agentless AI security posture management that discovers AI models including shadow AI, inventories them, and flags misconfigurations and exposed data. It is mapped to the AI Defense Matrix. [f7]

Cyber Defense Matrix

IdentifyProtectDetectRespondRecover
Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware.
Applications Software, interactions, and application flows on the devices.
Networks Connections and traffic flowing among devices and apps, plus communication paths.
Data Content at rest, in transit, or in use across devices, apps, and networks.
Users The people using the devices, apps, networks, and data.

The Orca CNAPP secures conventional cloud assets and is mapped to the Cyber Defense Matrix. Agentless SideScanning inventories workloads, apps, and data posture, and detects vulnerabilities, malware, and IAM risk. [f8]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 29 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 Orca names the cloud and DevOps team that cannot put an agent on every workload and states its own finding that fewer than half of assets are covered by agent-based solutions (s2). Gartner lists the product in an established buyer category (s12), so the problem is real and placed, but the reviewed sources measure its scale only through Orca's own findings. [s1, s2, s3, s12]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 4/5 Orca documents the SideScanning mechanism down to reading runtime block storage and rebuilding a read-only file system, plus an AI bill of materials covering more than fifty AI software packages and the major cloud AI services (s2, s3). Forrester assessed 14 vendors in early 2026, and Orca's account of that report claims its highest scores in six current-offering criteria (s10). A banking reviewer on Gartner's site writes up a cut of over 90% in high and critical vulnerabilities in a first year of use across three clouds (s12). [s2, s3, s10, s12]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 4/5 Two analyst houses carry current notes on this category: Forrester assessed 14 vendors in it in early 2026 (s10), and Gartner lists Orca in two of its markets with 257 buyer ratings and reviews dated July 2026 (s12). The enabler is the spread of application building into AI tools beyond engineering teams, which Orca's own 2026 telemetry report puts at 52% of organizations (s17). [s10, s12, s17]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 4/5 Both co-founders and the product chief held senior cybersecurity posts at Check Point, with Avi Shua its prior chief technologist, and the revenue chief came from Lacework (s4), and the Orca Research Pod publishes dated vulnerability findings through 2026 (s8). An earlier disclosure, Super FabriXss, is tracked as CVE-2023-23383 with Microsoft Corporation recorded as the NVD source, and carries independent trade coverage (s18, s19). No prior in-domain founder exit appears in the reviewed sources. [s4, s8, s18, s19]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 4/5 Orca publishes case studies on Swiggy, C6 Bank and Blue Yonder (s9) and names SAP, Gannett, Autodesk, Unity, Lemonade and Digital Turbine among the hundreds of organizations it says it serves (s11), and a partner-led motion runs through named regional partners (s11). Gartner carries 257 buyer ratings (s12), and CTech named eight clients in 2021 (s13). The scale figures are Orca's own, and no verified revenue or exact customer count appears, holding it below the top mark. [s9, s11, s12, s13]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 Orca extended its Series C to $550 million in October 2021 and no later round appears in the reviewed sources (s13, s15). Its commercial proof is not early: named enterprise references, a partner-led motion across regions, 2024 platform-scale figures Orca reports itself, and the 2025 Opus acquisition whose financial terms SecurityWeek says were not released (s9, s11, s15), so the raise is broadly proportional to stage and motion with visible shipping. No verified revenue, margin or growth-efficiency figure appears, so efficiency itself is unconfirmed (s20). [s9, s11, s13, s15, s20]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 4/5 Gartner lists Orca in its cloud-native application protection and API protection markets with 257 buyer ratings (s12), and Forrester assessed it among 14 vendors in that category in early 2026 (s10). Buyers place the product without vendor coaching, and Orca sat in Forrester's Strong Performer tier rather than its Leader tier while Gartner carries 629 ratings for the Wiz platform Google acquired against Orca's 257, which is short of the category-defining mark. [s10, s12, s16]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 Orca's federal authorization and the twelve granted US patent numbers its notice lists against two of its products raise the cost of a straight substitution (s5, s7). Google now owns the rival a research page calls Orca's primary competitor (s16, s20), and Gartner's own alternatives list for Orca names platform vendors selling competing coverage (s12). Nothing in the reviewed record shows an asset a funded platform could not eventually assemble. [s5, s7, s12, s16, s20]
Business Risks Google could win Orca's multi-cloud accounts once Wiz is integrated under Google Cloud, since Cybersecurity Dive reported the deal lets Google sell a comprehensive security offering to government and enterprise buyers running across multiple clouds…
  • Google could win Orca's multi-cloud accounts once Wiz is integrated under Google Cloud, since Cybersecurity Dive reported the deal lets Google sell a comprehensive security offering to government and enterprise buyers running across multiple clouds.
  • The twelve granted US patent numbers Orca lists could stop deterring rival implementations if its 2023 infringement suit against Wiz resolves against it, an outcome the reviewed sources do not settle.
  • The July 2026 AI AppGen Security and Code Security Auditor products could fail to widen Orca's buyer if security teams do not treat AI-built applications outside the development pipeline as their responsibility, the premise Orca states for both.
Problem & Market Orca Security sells to the cloud and DevOps team that cannot install an agent on every workload. The company frames the pain as blind spots where agents are missing, a significant impact on asset performance and system resources where agents do run, and integration friction that leads to remediation delays (s2). Its own figure for the gap is that on average fewer than half of assets are covered by agent-based solutions (s2). The category around that pain is established rather than coined. Gartner lists Orca in its cloud-native application protection and API protection markets, and Forrester assessed 14 vendors in the same category in early 2026 (s10, s12). A buyer arrives with the budget line already named. The AI turn narrows the same buyer rather than replacing it. Orca extends the agentless scan to find deployed models, including shadow AI the team does not know about, and warns that sensitive data accidentally included in training data can make models expose it (s3)…

Orca Security sells to the cloud and DevOps team that cannot install an agent on every workload. The company frames the pain as blind spots where agents are missing, a significant impact on asset performance and system resources where agents do run, and integration friction that leads to remediation delays (s2). Its own figure for the gap is that on average fewer than half of assets are covered by agent-based solutions (s2).

The category around that pain is established rather than coined. Gartner lists Orca in its cloud-native application protection and API protection markets, and Forrester assessed 14 vendors in the same category in early 2026 (s10, s12). A buyer arrives with the budget line already named.

The AI turn narrows the same buyer rather than replacing it. Orca extends the agentless scan to find deployed models, including shadow AI the team does not know about, and warns that sensitive data accidentally included in training data can make models expose it (s3). [s2, s3, s10, s12]

Product Capabilities Orca documents its mechanism rather than asserting it…

Orca documents its mechanism rather than asserting it. SideScanning collects data from a workload's runtime block storage without an agent, rebuilds the file system as a virtual read-only view, and runs the risk analysis against that copy (s2). Orca states the scan reaches an asset inventory in minutes and prioritized gaps within 24 hours.

The AI module applies the same scan to AI. Orca says it inventories more than fifty of the commonly used AI software packages, covers Azure OpenAI, Amazon Bedrock and SageMaker and Google Vertex AI, builds a bill of materials for every deployed model, and detects keys and tokens to AI services exposed in code repositories (s3). In July 2026 it announced AI AppGen Security, which looks for applications employees build on AI platforms outside the development pipeline, and an AI Code Security Auditor for code written inside it, with general availability for both due later in 2026 (s17).

Two outside reads now sit beside the vendor pages. Orca reports that Forrester assessed 14 vendors in early 2026 and gave it the highest scores in six current-offering criteria (s10). The independently hosted one is Gartner, where a banking reviewer records cutting high and critical vulnerabilities by more than 90% in a first year of use across three clouds (s12). [s2, s3, s10, s12, s17]

Competitive Positioning Orca competes against a rival a cloud operator now owns…

Orca competes against a rival a cloud operator now owns. A research page calls Wiz the primary competitor to Orca, and records that Orca sued Wiz in 2023 claiming it copied its patented agentless technology (s20). Cybersecurity Dive reported in March 2026 that Google completed the $32 billion deal and will integrate Wiz under Google Cloud while the brand continues, and that the deal lets Google sell a comprehensive security offering to government and enterprise buyers running across multiple clouds (s16). That is the pressure Orca sells against, and it is announced rather than hypothetical.

Two outside signals place Orca behind the front of the field, and they differ in provenance. Orca reports that Forrester named it a Strong Performer rather than a Leader among the 14 vendors it assessed in early 2026 (s10). Gartner, which hosts its ratings independently, carries 744 for InsightVM, 680 for Tenable Nessus and 629 for Wiz against Orca's 257 (s12).

Orca's patent position is the asset a rival would have to reckon with. Its virtual patent marking notice lists twelve granted US patent numbers against the Orca Security Platform and ShiftLeft and states those products may be covered by one or more of them (s7). The reviewed sources establish neither the scope nor the validity of those claims, and the 2023 suit against Wiz shows Orca trying to enforce them with the outcome unsettled (s20). [s7, s10, s12, s16, s20]

Go-to-Market & Traction Orca's named references span published case studies and independent buyer reviews. The company publishes case studies on Swiggy, C6 Bank and Blue Yonder (s9), and Gartner carries 257 buyer ratings for the product with reviews dated July 2026 (s12). CTech named Databricks, Robinhood, Autodesk, News Corp, NCR, Duolingo, Unity Technologies and Druva as clients in 2021 and quoted the chief executive saying more than 100 organizations were then buying it (s13). That client list is five years old. Distribution runs through partners. Orca attributes its Latin American growth to a partner-led motion and names Oplium, Connect.lat and NetGlobe as regional partners (s11), and a research page reports 270% growth in EMEA deal registrations announced in May 2024 (s20). What a buyer cannot check is the money. Orca states it is trusted by hundreds of organizations, including SAP, Gannett, Autodesk, Unity, Lemonade and Digital Turbine, and reports scanning more than 9 million workloads and 300 petabytes a day in 2024 (s11), all of them its own measurements. No verified revenue or exact customer count appears, and the one 2024 revenue figure in the reviewed sources is one the research page itself labels an unverified estimate (s20). SentinelOne's $2.5 billion takeover talks in 2021 fell through over deal terms, Calcalist reported (s14)…

Orca's named references span published case studies and independent buyer reviews. The company publishes case studies on Swiggy, C6 Bank and Blue Yonder (s9), and Gartner carries 257 buyer ratings for the product with reviews dated July 2026 (s12). CTech named Databricks, Robinhood, Autodesk, News Corp, NCR, Duolingo, Unity Technologies and Druva as clients in 2021 and quoted the chief executive saying more than 100 organizations were then buying it (s13). That client list is five years old.

Distribution runs through partners. Orca attributes its Latin American growth to a partner-led motion and names Oplium, Connect.lat and NetGlobe as regional partners (s11), and a research page reports 270% growth in EMEA deal registrations announced in May 2024 (s20).

What a buyer cannot check is the money. Orca states it is trusted by hundreds of organizations, including SAP, Gannett, Autodesk, Unity, Lemonade and Digital Turbine, and reports scanning more than 9 million workloads and 300 petabytes a day in 2024 (s11), all of them its own measurements. No verified revenue or exact customer count appears, and the one 2024 revenue figure in the reviewed sources is one the research page itself labels an unverified estimate (s20). SentinelOne's $2.5 billion takeover talks in 2021 fell through over deal terms, Calcalist reported (s14). [s9, s11, s12, s13, s14, s20]

Team & Credibility Orca's leadership bench is verifiable and in-domain…

Orca's leadership bench is verifiable and in-domain. Gil Geron directed a large team of cyber professionals at Check Point before co-founding the company, co-founder Avi Shua was Check Point's chief technologist and served in Unit 8200, and Gera Dorfman came from Check Point as vice president of network security products, where he led research and development in that product group (s4).

The bench extends past engineering. Chief revenue officer Raf Chiodo joined from Lacework, where he ran the Americas go-to-market team, and chief financial officer Oded Edri was chief accounting officer at Payoneer through its initial public offering (s4).

The research record is the strongest independent signal. The Orca Research Pod publishes dated vulnerability findings through 2026, including an nginx flaw traced to Tengine servers and a ksmbd locking bug carrying its own CVE (s8). An earlier disclosure, Super FabriXss, carries a Microsoft-assigned CVE record and independent trade coverage (s18, s19). No prior in-domain founder exit appears in the reviewed sources. [s4, s8, s18, s19]

Trust Readiness Orca clears the federal procurement bar…

Orca clears the federal procurement bar. The Orca Cloud Security Platform achieved FedRAMP authorization at the moderate level, which the company states requires a federal sponsor and a rigorous evaluation to reach an Authority to Operate (s5).

The published credential set is broader than the federal one. Orca's trust centre records ISO/IEC 27018:2025, CSA STAR, FedRAMP Moderate, GDPR, GovRAMP, IRAP, ISO/IEC 27001, 27017:2015 and 27701, PCI DSS v4.0.1 and SOC 2, and lists a network diagram, a penetration-test report and a SOC 2 report among its documents (s6).

What the record does not carry is verified operating proof. Orca states it is trusted by hundreds of organizations and reports 2024 platform-scale figures of its own (s11), but no independently verified revenue and no exact current customer count appear, and the one 2024 revenue figure in the reviewed sources is one the research page itself labels an unverified estimate (s20). [s5, s6, s11, s20]

Competitors Wiz, Palo Alto Networks, CrowdStrike, Tenable, Rapid7…
Company Relationship Note Compare
Wiz competes with A research page calls it Orca's primary competitor, and Google completed a $32 billion acquisition of it. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Palo Alto Networks competes with Orca's own comparisons list names Prisma Cloud, the Palo Alto product that competes for the same cloud-security budget. N/AWe scored these companies at different scopes, so the totals measure different things.
CrowdStrike competes with Orca's own comparisons list names CrowdStrike as a product buyers weigh against the Orca platform. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Tenable competes with Gartner's alternatives list for Orca names Tenable Nessus, and Orca's own comparisons list names Tenable. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Rapid7 competes with Gartner's alternatives list for Orca names InsightVM, and Orca's own comparisons list names Rapid7. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.

Add analyzed competitors to compare them side by side with Orca Security.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Defensible 15 /21 Defensible: Defensibility of 15 or above. A position that stays hard for rivals to replicate. press the advantage

What the record evidences for Orca Security is patent-protected intellectual property. Its notice lists twelve granted US patent numbers against two of its products and states they may be covered by one or more. A research page records a 2023 infringement suit against Wiz whose outcome the reviewed sources do not settle. Customers connect their own cloud accounts and run the software themselves, so Orca sells a product rather than an operated service. Its FedRAMP Moderate authorization is one a funded competitor can earn. Its research arm draws on telemetry from more than 1,200 production cloud environments, which the reviewed sources do not establish as a retained product asset. The patents raise a rival's cost to copy the scanning method, a head start rather than a settled lead.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Customers connect their own cloud accounts and operate the platform themselves, buying scanning, prioritization and automated remediation as product capability (s1, s2, s16). The reviewed sources describe no delivery layer in which Orca runs the security programme or owns the outcome, so the customer's team operates it and carries the result.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Wiring risk correlation, prioritization and remediation workflows around the agentless platform builds the integration and learned-workflow friction rung 2 names (s1, s16). The cited record describes how fast the scan is to adopt rather than what leaving costs, and it does not size a migration, so the switching mechanism is documented and the cited record does not size the exit.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 2/3 Orca holds FedRAMP authorization at the moderate level, which the company states requires a federal sponsor and an Authority to Operate, alongside GovRAMP, IRAP, ISO 27001-family, PCI DSS and SOC 2 records on its trust centre (s5, s6). Those are regulator-mediated approvals a funded competitor must independently earn rather than a mandate carried by the product that blocks substitution.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Reading a workload's runtime block storage out of band, rebuilding its file system as a read-only view and correlating vulnerabilities, malware, identity risk, data and AI posture across the major clouds is the multi-system engineering this rung names (s2, s3), and Orca lists a twelve-patent portfolio over that work (s7).
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 3/3 The FedRAMP authorization establishes US federal eligibility and the trust centre adds GovRAMP and IRAP records (s5, s6). The published references and buyer reviews are regulated enterprises, including C6 Bank, Paidy, which its case study calls a Japanese financial institution in the cloud, and two banking reviewers on Gartner's site (s9, s10, s13).
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 Orca reads the cloud estate from outside without sending a packet over the network or running code in the environment, and analyses that read-only view to rank risk (s2). The Opus technology adds remediation orchestration alongside it (s16). Nothing in the cited record shows applications depending on Orca to run, so it is a platform with application features rather than infrastructure beneath them.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 2/3 The evidenced asset is intellectual property rather than data. Orca's patent notice lists twelve granted US patent numbers against the Orca Security Platform and ShiftLeft and states those products may be covered by one or more (s7), and a research page records a 2023 infringement suit against Wiz whose outcome the reviewed sources do not settle (s21). Its research arm analyses telemetry from more than 1,200 production cloud environments (s18), which the reviewed sources report as input to a published report rather than a retained corpus. The patents are the evidenced asset here.
Strategic Market Segmentation Orca Security sells to the enterprise cloud and DevOps team that cannot install an agent on every workload. The company frames the pain as blind spots where agents are missing, a significant impact on asset performance and system resources where agents do run, and integration friction that leads to remediation delays, and states its own finding that fewer than half of assets are covered by agent-based solutions (s2). The segment sits inside an established category rather than a coined one. Gartner lists Orca in its cloud-native application protection and API protection markets, and Forrester assessed 14 vendors in the same category in early 2026 (s11, s13). Its published references run to regulated industries, including C6 Bank and Paidy, which its case study describes as a Japanese financial institution in the cloud (s9, s10). The federal authorization extends the same segment into US public-sector procurement, where reviews gate on credentials Orca holds (s5). The AI turn narrows the buyer rather than replacing it, since the same team now answers for models running in the cloud it already owns (s3)…

Orca Security sells to the enterprise cloud and DevOps team that cannot install an agent on every workload. The company frames the pain as blind spots where agents are missing, a significant impact on asset performance and system resources where agents do run, and integration friction that leads to remediation delays, and states its own finding that fewer than half of assets are covered by agent-based solutions (s2).

The segment sits inside an established category rather than a coined one. Gartner lists Orca in its cloud-native application protection and API protection markets, and Forrester assessed 14 vendors in the same category in early 2026 (s11, s13). Its published references run to regulated industries, including C6 Bank and Paidy, which its case study describes as a Japanese financial institution in the cloud (s9, s10).

The federal authorization extends the same segment into US public-sector procurement, where reviews gate on credentials Orca holds (s5). The AI turn narrows the buyer rather than replacing it, since the same team now answers for models running in the cloud it already owns (s3).

Product Capabilities & AI Advantages Orca documents its mechanism rather than asserting it…

Orca documents its mechanism rather than asserting it. SideScanning collects data from a workload's runtime block storage without an agent, rebuilds the file system as a virtual read-only view, and runs the risk analysis against that copy (s2). Orca states the scan reaches an asset inventory in minutes and prioritized gaps within 24 hours.

The AI module applies that same scan to AI. Orca says it inventories more than fifty of the commonly used AI software packages, covers Azure OpenAI, Amazon Bedrock and SageMaker and Google Vertex AI, builds a bill of materials for every deployed model, and detects keys and tokens to AI services exposed in code repositories (s3). Orca has announced AI AppGen Security for applications employees build on AI platforms outside the development pipeline, and an AI Code Security Auditor for code written inside it (s18), with general availability for both arriving later in 2026 (s22).

Two outside reads sit beside the vendor's own pages, and they differ in provenance. Orca reports that Forrester assessed 14 vendors in early 2026 and gave it the highest scores in six current-offering criteria (s11). The independently hosted one is Gartner, where a banking reviewer records cutting high and critical vulnerabilities by more than 90% in a first year of use across three clouds (s13).

Sales Engagement & Go-to-Market Orca's named references span published case studies and independent buyer reviews. The company publishes case studies on Swiggy, C6 Bank and Blue Yonder (s9), and Gartner carries 257 buyer ratings with reviews dated July 2026 (s13). CTech named Databricks, Robinhood, Autodesk, News Corp, NCR, Duolingo, Unity Technologies and Druva as clients in 2021 and quoted the chief executive saying more than 100 organizations were then buying the product (s14). That client list is five years old. Distribution runs through partners. Orca attributes its Latin American growth to a partner-led motion and names Oplium, Connect.lat and NetGlobe as regional partners (s12), and a research page reports 270% growth in EMEA deal registrations announced in May 2024 (s21). What a buyer cannot check is the money. Orca states it is trusted by hundreds of organizations, including SAP, Gannett, Autodesk, Unity, Lemonade and Digital Turbine, and reports scanning more than 9 million workloads and 300 petabytes a day across more than 120,000 code repositories in 2024 (s12), all of them its own measurements. No verified revenue or exact customer count appears, and the one 2024 revenue figure in the reviewed sources is one the research page itself labels an unverified estimate (s21). SentinelOne's $2.5 billion takeover talks fell through over deal terms, Calcalist reported in December 2021 (s15)…

Orca's named references span published case studies and independent buyer reviews. The company publishes case studies on Swiggy, C6 Bank and Blue Yonder (s9), and Gartner carries 257 buyer ratings with reviews dated July 2026 (s13). CTech named Databricks, Robinhood, Autodesk, News Corp, NCR, Duolingo, Unity Technologies and Druva as clients in 2021 and quoted the chief executive saying more than 100 organizations were then buying the product (s14). That client list is five years old.

Distribution runs through partners. Orca attributes its Latin American growth to a partner-led motion and names Oplium, Connect.lat and NetGlobe as regional partners (s12), and a research page reports 270% growth in EMEA deal registrations announced in May 2024 (s21).

What a buyer cannot check is the money. Orca states it is trusted by hundreds of organizations, including SAP, Gannett, Autodesk, Unity, Lemonade and Digital Turbine, and reports scanning more than 9 million workloads and 300 petabytes a day across more than 120,000 code repositories in 2024 (s12), all of them its own measurements. No verified revenue or exact customer count appears, and the one 2024 revenue figure in the reviewed sources is one the research page itself labels an unverified estimate (s21). SentinelOne's $2.5 billion takeover talks fell through over deal terms, Calcalist reported in December 2021 (s15).

Pricing Model Orca charges by cloud workloads rather than by seat, which ties the bill to the size of the estate being secured. A research page states that offerings are based on organization cloud assets, and reports that an organization of 200 can expect to pay between $17.5K and $34.9K, and one of 1,000 between $64.6K and $103.7K (s21). No rate card appears on the vendor pages reviewed here, which put a demo request in front of the buyer instead (s1). Gartner's product page describes the model as subscription pricing structured around cloud asset coverage and environment size (s13), which is the shape of a negotiated enterprise agreement rather than a listed price. The July 2026 additions are not yet priced in public. An independent analysis of that launch records that Orca has not disclosed pricing for either new product (s22), so a buyer sizing the AI additions is working without a published benchmark…

Orca charges by cloud workloads rather than by seat, which ties the bill to the size of the estate being secured. A research page states that offerings are based on organization cloud assets, and reports that an organization of 200 can expect to pay between $17.5K and $34.9K, and one of 1,000 between $64.6K and $103.7K (s21).

No rate card appears on the vendor pages reviewed here, which put a demo request in front of the buyer instead (s1). Gartner's product page describes the model as subscription pricing structured around cloud asset coverage and environment size (s13), which is the shape of a negotiated enterprise agreement rather than a listed price.

The July 2026 additions are not yet priced in public. An independent analysis of that launch records that Orca has not disclosed pricing for either new product (s22), so a buyer sizing the AI additions is working without a published benchmark.

Product Delivery & Operations Orca is delivered as SaaS the customer connects its cloud accounts to…

Orca is delivered as SaaS the customer connects its cloud accounts to. The buyer attaches its cloud accounts and the platform reads them from outside, without sending a packet over the network or running code in the environment, which is what keeps the rollout light (s2).

Operations centre on continuous posture and prioritization. Orca names a Unified Data Model for risk correlation and a Risk Prioritization layer doing dynamic scoring and attack-path analysis (s1), and the Paidy case study records twelve AWS accounts connected, with insight into all of them inside thirty minutes, and an imminent compromise Orca identified in a test environment (s10).

The Opus acquisition moved operations toward closing risk rather than only finding it, adding orchestration and automated remediation of cloud security findings (s16). A careful buyer will test how far it trusts autonomous fixes before relying on them, and the reviewed sources carry no published benchmark of that remediation.

Earning Customers' Trust Orca clears the federal procurement bar…

Orca clears the federal procurement bar. The Orca Cloud Security Platform achieved FedRAMP authorization at the moderate level, which the company states requires a federal sponsor and a rigorous evaluation to reach an Authority to Operate (s5).

The published credential set is broader than the federal one. Orca's trust centre records ISO/IEC 27018:2025, CSA STAR, FedRAMP Moderate, GDPR, GovRAMP, IRAP, ISO/IEC 27001, 27017:2015 and 27701, PCI DSS v4.0.1 and SOC 2, and lists a network diagram, a penetration-test report and a SOC 2 report among its documents (s6).

What the record does not carry is independently verified operating proof. Orca reports 2024 platform-scale figures and a claim of hundreds of organizations served (s12), and Gartner carries 257 independent buyer ratings (s13), but no independently verified revenue and no exact current customer count appear (s21). An independent analysis of its July 2026 launch records that the company has not disclosed pricing for either new product (s22).

Platform Strategy & Ecosystem Positioning Orca positions itself as the one platform an enterprise standardizes on across its clouds rather than a tool bound to one provider. The company frames the offering as covering code, cloud, runtime and AI in a single view with the context that drives a decision (s1). Outward, breadth across providers is the ecosystem play. The agentless scan spans the major clouds and the AI module discovers models across that same footprint (s2, s3). Distribution rides on named regional partners rather than a direct-only motion (s12). Inward, the newer pieces are assembled as much as built. The remediation layer came with the Opus acquisition (s16), and the July 2026 AI additions extend the platform to software built outside the development pipeline (s18). The reviewed sources show an integration directory and a partner programme, and describe no marketplace in which third parties publish their own extensions…

Orca positions itself as the one platform an enterprise standardizes on across its clouds rather than a tool bound to one provider. The company frames the offering as covering code, cloud, runtime and AI in a single view with the context that drives a decision (s1).

Outward, breadth across providers is the ecosystem play. The agentless scan spans the major clouds and the AI module discovers models across that same footprint (s2, s3). Distribution rides on named regional partners rather than a direct-only motion (s12).

Inward, the newer pieces are assembled as much as built. The remediation layer came with the Opus acquisition (s16), and the July 2026 AI additions extend the platform to software built outside the development pipeline (s18). The reviewed sources show an integration directory and a partner programme, and describe no marketplace in which third parties publish their own extensions.

Team & Execution Capability Orca's leadership bench is verifiable and in-domain…

Orca's leadership bench is verifiable and in-domain. Gil Geron directed a large team of cyber professionals at Check Point before co-founding the company, co-founder Avi Shua was Check Point's chief technologist and served in Unit 8200, and Gera Dorfman came from Check Point as vice president of network security products, where he led research and development in that product group (s4).

The bench extends past engineering. Chief revenue officer Raf Chiodo joined from Lacework, where he ran the Americas go-to-market team, and chief financial officer Oded Edri was chief accounting officer at Payoneer through its initial public offering (s4).

The research record is the strongest independent signal. The Orca Research Pod publishes dated vulnerability findings through 2026, including an nginx flaw traced to Tengine servers and a ksmbd locking bug carrying its own CVE (s8). An earlier disclosure, Super FabriXss, carries a Microsoft-assigned CVE record and independent trade coverage (s19, s20). No prior in-domain founder exit appears in the reviewed sources.

Sources

Company Detail Sources (8)
Id Source Tier Accessed
f1 Orca Security: AI Security Posture Management (AI-SPM) official 2026-08-23
f2 CTech: Orca Security raises another $340 million, boosts valuation to $1.8 billion press 2026-08-23
f3 Contrary Research: Orca Security business breakdown research 2026-08-23
f4 SecurityWeek: Orca Snaps Up Opus in Cloud Security Automation Push press 2026-08-23
f5 Temasek leads $550M Series C extension into Orca Security press 2026-06-14
f6 AI Defense Matrix Catalog entry other 2026-06-13
f7 AI Defense Matrix Catalog mapping other 2026-06-23
f8 Orca Security: Orca Platform overview page official 2026-08-23
Profile Analysis Sources (20)
Id Source Tier Accessed
s1 Orca Security: Orca Platform overview page
“Comparisons CrowdStrike Wiz Check Point CloudGuard Lacework FortiCNAPP Rapid7 Tenable Qualys Prisma Cloud”
official 2026-08-23
s2 Orca Security: agentless SideScanning technology page
“Running agents on workloads has a significant impact on asset performance and system resources, especially if assets need multiple agents installed for different point solutions.”
official 2026-08-23
s3 Orca Security: AI Security Posture Management product page
“Orca ensures that AI models are configured securely, covering network security, data protection, access controls, and IAM.”
official 2026-08-23
s4 Orca Security: About page with the leadership roster
“Oded Edri is Chief Financial Officer of Orca Security. Oded brings more than 15 years of experience across diverse aspects of executive leadership, financial management, human resources management, and operations.”
official 2026-08-23
s5 Orca Security: blog post announcing FedRAMP authorization
“We’re thrilled to announce that the Orca Cloud Security Platform, a leading Cloud Native Application Protection Platform (CNAPP), has achieved FedRAMP Ⓡ authorization at the moderate level.”
official 2026-08-23
s6 Orca Security: probe of trustcenter.orca.security by direct fetch on 2026-08-23, compliance surface found
“ISO/IEC 27018:2025 AWS Qualified Software CSA STAR FedRAMP Moderate GDPR GovRAMP IRAP ISO/IEC 27001 ISO/IEC 27017:2015 ISO/IEC 27701 PCI DSS v4.0.1 SOC 2”
official 2026-08-23
s7 Orca Security: virtual patent marking notice
“The following products are protected by patents in the U.S. and elsewhere for Orca Security.”
official 2026-08-23
s8 Orca Security: Orca Research Pod index of published findings
“Compromised keyv Maintainer Account Triggers Massive npm Supply Chain Attack”
official 2026-08-23
s9 Orca Security: customer case-study index
“Find out how we help customers with multi-cloud security across numerous industries.”
official 2026-08-23
s10 Orca Security: blog post on the Forrester Wave CNAPP Q1 2026 result
“Forrester has named Orca as a Strong Performer in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026.”
official 2026-08-23
s11 Orca Security: press release on Latin America customer growth
“Orca is trusted by hundreds of organizations, including SAP, Gannett, Autodesk, Unity, Lemonade and Digital Turbine.”
official 2026-08-23
s12 Gartner Peer Insights: Orca Security product profile and ratings
“Manager, IT Security and Risk Management 3B - 10B USD, Banking CRITICAL "Strong CSPM and DSPM capabilities" 3.0 Jul 30, 2026”
research 2026-08-23
s13 CTech: Orca Security raises another $340 million, boosts valuation to $1.8 billion
“Meir Orbach 15:00 05.10.21”
press 2026-08-23
s14 CTech: SentinelOne's $2.5 billion takeover of Orca Security falls through
“Golan Hazani 10:30 23.12.21”
press 2026-08-23
s15 SecurityWeek: Orca Snaps Up Opus in Cloud Security Automation Push
“By Ryan Naraine | May 13, 2025 (6:00 AM ET)”
press 2026-08-23
s16 Cybersecurity Dive: Google completes $32B acquisition of Wiz
“The cloud security specialist will continue to operate under its own brand and across multiple platforms.”
press 2026-08-23
s17 Help Net Security: Orca Security secures AI-built and developer-created applications
“Industry News July 30, 2026”
press 2026-08-23
s18 NVD: CVE-2023-23383 record
“Source: Microsoft Corporation”
other 2026-08-23
s19 The Hacker News: article on the Super FabriXss vulnerability in Azure SFX
“Tracked as CVE-2023-23383 (CVSS score: 8.2), the issue has been dubbed "Super FabriXss" by Orca Security, a nod to the FabriXss flaw (CVE-2022-35829, CVSS score: 6.2) that was fixed by Microsoft in October 2022.”
press 2026-08-23
s20 Contrary Research: Orca Security business breakdown
“Headquarters Portland, OR”
research 2026-08-23
Deep-Dive Sources (22)
Id Source Tier Accessed
s1 Orca Security: Orca Platform overview page
“Comparisons CrowdStrike Wiz Check Point CloudGuard Lacework FortiCNAPP Rapid7 Tenable Qualys Prisma Cloud”
official 2026-08-23
s2 Orca Security: agentless SideScanning technology page
“Running agents on workloads has a significant impact on asset performance and system resources, especially if assets need multiple agents installed for different point solutions.”
official 2026-08-23
s3 Orca Security: AI Security Posture Management product page
“Orca ensures that AI models are configured securely, covering network security, data protection, access controls, and IAM.”
official 2026-08-23
s4 Orca Security: About page with the leadership roster
“Oded Edri is Chief Financial Officer of Orca Security. Oded brings more than 15 years of experience across diverse aspects of executive leadership, financial management, human resources management, and operations.”
official 2026-08-23
s5 Orca Security: blog post announcing FedRAMP authorization
“We’re thrilled to announce that the Orca Cloud Security Platform, a leading Cloud Native Application Protection Platform (CNAPP), has achieved FedRAMP Ⓡ authorization at the moderate level.”
official 2026-08-23
s6 Orca Security: probe of trustcenter.orca.security by direct fetch on 2026-08-23, compliance surface found
“ISO/IEC 27018:2025 AWS Qualified Software CSA STAR FedRAMP Moderate GDPR GovRAMP IRAP ISO/IEC 27001 ISO/IEC 27017:2015 ISO/IEC 27701 PCI DSS v4.0.1 SOC 2”
official 2026-08-23
s7 Orca Security: virtual patent marking notice
“The following products are protected by patents in the U.S. and elsewhere for Orca Security.”
official 2026-08-23
s8 Orca Security: Orca Research Pod index of published findings
“Compromised keyv Maintainer Account Triggers Massive npm Supply Chain Attack”
official 2026-08-23
s9 Orca Security: customer case-study index
“Find out how we help customers with multi-cloud security across numerous industries.”
official 2026-08-23
s10 Orca Security: Paidy customer case study
“Paidy – a Japanese Financial Institution in the Cloud”
official 2026-08-23
s11 Orca Security: blog post on the Forrester Wave CNAPP Q1 2026 result
“Forrester has named Orca as a Strong Performer in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026.”
official 2026-08-23
s12 Orca Security: press release on Latin America customer growth
“Orca is trusted by hundreds of organizations, including SAP, Gannett, Autodesk, Unity, Lemonade and Digital Turbine.”
official 2026-08-23
s13 Gartner Peer Insights: Orca Security product profile and ratings
“Manager, IT Security and Risk Management 3B - 10B USD, Banking CRITICAL "Strong CSPM and DSPM capabilities" 3.0 Jul 30, 2026”
research 2026-08-23
s14 CTech: Orca Security raises another $340 million, boosts valuation to $1.8 billion
“Meir Orbach 15:00 05.10.21”
press 2026-08-23
s15 CTech: SentinelOne's $2.5 billion takeover of Orca Security falls through
“Golan Hazani 10:30 23.12.21”
press 2026-08-23
s16 SecurityWeek: Orca Snaps Up Opus in Cloud Security Automation Push
“By Ryan Naraine | May 13, 2025 (6:00 AM ET)”
press 2026-08-23
s17 Cybersecurity Dive: Google completes $32B acquisition of Wiz
“The cloud security specialist will continue to operate under its own brand and across multiple platforms.”
press 2026-08-23
s18 Help Net Security: Orca Security secures AI-built and developer-created applications
“Industry News July 30, 2026”
press 2026-08-23
s19 NVD: CVE-2023-23383 record
“Source: Microsoft Corporation”
other 2026-08-23
s20 The Hacker News: article on the Super FabriXss vulnerability in Azure SFX
“Tracked as CVE-2023-23383 (CVSS score: 8.2), the issue has been dubbed "Super FabriXss" by Orca Security, a nod to the FabriXss flaw (CVE-2022-35829, CVSS score: 6.2) that was fixed by Microsoft in October 2022.”
press 2026-08-23
s21 Contrary Research: Orca Security business breakdown
“Headquarters Portland, OR”
research 2026-08-23
s22 Shashi Bellamkonda: analysis of the Orca AI AppGen Security launch
“General availability for both arrives later in 2026.”
press 2026-08-23

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.