All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Orca Security reports that Forrester named it a Strong Performer among the 14 cloud-security platforms it evaluated in early 2026. Orca sells enterprises software that inspects the storage behind their cloud machines and reports the risks it finds, without installing an agent on each one. On Gartner's buyer-review site Orca holds a 4.6 average across 257 ratings, against 4.7 across 629 for the Wiz platform Google now owns. Orca publishes customer case studies on Swiggy, C6 Bank and Blue Yonder, and its patent notice lists twelve granted US patent numbers. It holds a US federal authorization at the moderate level. No verified or company-disclosed revenue figure appears in the reviewed sources to set beside those credentials.
| Description | Orca's AI-SPM uses agentless scanning to discover deployed AI models, including shadow AI, and flags misconfigurations and exposed sensitive data to protect against data tampering and leakage. | [f1] |
|---|---|---|
| Founded | 2019 | [f2] |
| HQ | Portland, Oregon, United States | [f3] |
| Funding | $632M total | [f4] |
| Latest funding | Series C extension (Temasek-led) | [f5] |
| Deployment | SaaS | [f6] |
| Compliance | CSA STAR, FedRAMP Certified Class C, GDPR, GovRAMP, ISO 27001, ISO 27017, ISO 27018, ISO 27701, PCI DSS, SOC 2 | [f6] |
| Product | What it does |
|---|---|
| Orca | Agentless AI security posture management in the Orca cloud platform that discovers AI models including shadow AI, inventories them, and flags misconfigurations and exposed data. |
| Agentic AI Remediation (Opus) | Agentic AI-driven remediation and prevention built on the acquired Opus technology, adding autonomous risk resolution to the Orca CNAPP beyond identification and prioritization. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Orca provides agentless AI security posture management that discovers AI models including shadow AI, inventories them, and flags misconfigurations and exposed data. It is mapped to the AI Defense Matrix. [f7]
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
The Orca CNAPP secures conventional cloud assets and is mapped to the Cyber Defense Matrix. Agentless SideScanning inventories workloads, apps, and data posture, and detects vulnerabilities, malware, and IAM risk. [f8]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | Orca names the cloud and DevOps team that cannot put an agent on every workload and states its own finding that fewer than half of assets are covered by agent-based solutions (s2). Gartner lists the product in an established buyer category (s12), so the problem is real and placed, but the reviewed sources measure its scale only through Orca's own findings. [s1, s2, s3, s12] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | Orca documents the SideScanning mechanism down to reading runtime block storage and rebuilding a read-only file system, plus an AI bill of materials covering more than fifty AI software packages and the major cloud AI services (s2, s3). Forrester assessed 14 vendors in early 2026, and Orca's account of that report claims its highest scores in six current-offering criteria (s10). A banking reviewer on Gartner's site writes up a cut of over 90% in high and critical vulnerabilities in a first year of use across three clouds (s12). [s2, s3, s10, s12] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 | Two analyst houses carry current notes on this category: Forrester assessed 14 vendors in it in early 2026 (s10), and Gartner lists Orca in two of its markets with 257 buyer ratings and reviews dated July 2026 (s12). The enabler is the spread of application building into AI tools beyond engineering teams, which Orca's own 2026 telemetry report puts at 52% of organizations (s17). [s10, s12, s17] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | Both co-founders and the product chief held senior cybersecurity posts at Check Point, with Avi Shua its prior chief technologist, and the revenue chief came from Lacework (s4), and the Orca Research Pod publishes dated vulnerability findings through 2026 (s8). An earlier disclosure, Super FabriXss, is tracked as CVE-2023-23383 with Microsoft Corporation recorded as the NVD source, and carries independent trade coverage (s18, s19). No prior in-domain founder exit appears in the reviewed sources. [s4, s8, s18, s19] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 | Orca publishes case studies on Swiggy, C6 Bank and Blue Yonder (s9) and names SAP, Gannett, Autodesk, Unity, Lemonade and Digital Turbine among the hundreds of organizations it says it serves (s11), and a partner-led motion runs through named regional partners (s11). Gartner carries 257 buyer ratings (s12), and CTech named eight clients in 2021 (s13). The scale figures are Orca's own, and no verified revenue or exact customer count appears, holding it below the top mark. [s9, s11, s12, s13] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | Orca extended its Series C to $550 million in October 2021 and no later round appears in the reviewed sources (s13, s15). Its commercial proof is not early: named enterprise references, a partner-led motion across regions, 2024 platform-scale figures Orca reports itself, and the 2025 Opus acquisition whose financial terms SecurityWeek says were not released (s9, s11, s15), so the raise is broadly proportional to stage and motion with visible shipping. No verified revenue, margin or growth-efficiency figure appears, so efficiency itself is unconfirmed (s20). [s9, s11, s13, s15, s20] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | Gartner lists Orca in its cloud-native application protection and API protection markets with 257 buyer ratings (s12), and Forrester assessed it among 14 vendors in that category in early 2026 (s10). Buyers place the product without vendor coaching, and Orca sat in Forrester's Strong Performer tier rather than its Leader tier while Gartner carries 629 ratings for the Wiz platform Google acquired against Orca's 257, which is short of the category-defining mark. [s10, s12, s16] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | Orca's federal authorization and the twelve granted US patent numbers its notice lists against two of its products raise the cost of a straight substitution (s5, s7). Google now owns the rival a research page calls Orca's primary competitor (s16, s20), and Gartner's own alternatives list for Orca names platform vendors selling competing coverage (s12). Nothing in the reviewed record shows an asset a funded platform could not eventually assemble. [s5, s7, s12, s16, s20] |
Orca Security sells to the cloud and DevOps team that cannot install an agent on every workload. The company frames the pain as blind spots where agents are missing, a significant impact on asset performance and system resources where agents do run, and integration friction that leads to remediation delays (s2). Its own figure for the gap is that on average fewer than half of assets are covered by agent-based solutions (s2).
The category around that pain is established rather than coined. Gartner lists Orca in its cloud-native application protection and API protection markets, and Forrester assessed 14 vendors in the same category in early 2026 (s10, s12). A buyer arrives with the budget line already named.
The AI turn narrows the same buyer rather than replacing it. Orca extends the agentless scan to find deployed models, including shadow AI the team does not know about, and warns that sensitive data accidentally included in training data can make models expose it (s3). [s2, s3, s10, s12]
Orca documents its mechanism rather than asserting it. SideScanning collects data from a workload's runtime block storage without an agent, rebuilds the file system as a virtual read-only view, and runs the risk analysis against that copy (s2). Orca states the scan reaches an asset inventory in minutes and prioritized gaps within 24 hours.
The AI module applies the same scan to AI. Orca says it inventories more than fifty of the commonly used AI software packages, covers Azure OpenAI, Amazon Bedrock and SageMaker and Google Vertex AI, builds a bill of materials for every deployed model, and detects keys and tokens to AI services exposed in code repositories (s3). In July 2026 it announced AI AppGen Security, which looks for applications employees build on AI platforms outside the development pipeline, and an AI Code Security Auditor for code written inside it, with general availability for both due later in 2026 (s17).
Two outside reads now sit beside the vendor pages. Orca reports that Forrester assessed 14 vendors in early 2026 and gave it the highest scores in six current-offering criteria (s10). The independently hosted one is Gartner, where a banking reviewer records cutting high and critical vulnerabilities by more than 90% in a first year of use across three clouds (s12). [s2, s3, s10, s12, s17]
Orca competes against a rival a cloud operator now owns. A research page calls Wiz the primary competitor to Orca, and records that Orca sued Wiz in 2023 claiming it copied its patented agentless technology (s20). Cybersecurity Dive reported in March 2026 that Google completed the $32 billion deal and will integrate Wiz under Google Cloud while the brand continues, and that the deal lets Google sell a comprehensive security offering to government and enterprise buyers running across multiple clouds (s16). That is the pressure Orca sells against, and it is announced rather than hypothetical.
Two outside signals place Orca behind the front of the field, and they differ in provenance. Orca reports that Forrester named it a Strong Performer rather than a Leader among the 14 vendors it assessed in early 2026 (s10). Gartner, which hosts its ratings independently, carries 744 for InsightVM, 680 for Tenable Nessus and 629 for Wiz against Orca's 257 (s12).
Orca's patent position is the asset a rival would have to reckon with. Its virtual patent marking notice lists twelve granted US patent numbers against the Orca Security Platform and ShiftLeft and states those products may be covered by one or more of them (s7). The reviewed sources establish neither the scope nor the validity of those claims, and the 2023 suit against Wiz shows Orca trying to enforce them with the outcome unsettled (s20). [s7, s10, s12, s16, s20]
Orca's named references span published case studies and independent buyer reviews. The company publishes case studies on Swiggy, C6 Bank and Blue Yonder (s9), and Gartner carries 257 buyer ratings for the product with reviews dated July 2026 (s12). CTech named Databricks, Robinhood, Autodesk, News Corp, NCR, Duolingo, Unity Technologies and Druva as clients in 2021 and quoted the chief executive saying more than 100 organizations were then buying it (s13). That client list is five years old.
Distribution runs through partners. Orca attributes its Latin American growth to a partner-led motion and names Oplium, Connect.lat and NetGlobe as regional partners (s11), and a research page reports 270% growth in EMEA deal registrations announced in May 2024 (s20).
What a buyer cannot check is the money. Orca states it is trusted by hundreds of organizations, including SAP, Gannett, Autodesk, Unity, Lemonade and Digital Turbine, and reports scanning more than 9 million workloads and 300 petabytes a day in 2024 (s11), all of them its own measurements. No verified revenue or exact customer count appears, and the one 2024 revenue figure in the reviewed sources is one the research page itself labels an unverified estimate (s20). SentinelOne's $2.5 billion takeover talks in 2021 fell through over deal terms, Calcalist reported (s14). [s9, s11, s12, s13, s14, s20]
Orca's leadership bench is verifiable and in-domain. Gil Geron directed a large team of cyber professionals at Check Point before co-founding the company, co-founder Avi Shua was Check Point's chief technologist and served in Unit 8200, and Gera Dorfman came from Check Point as vice president of network security products, where he led research and development in that product group (s4).
The bench extends past engineering. Chief revenue officer Raf Chiodo joined from Lacework, where he ran the Americas go-to-market team, and chief financial officer Oded Edri was chief accounting officer at Payoneer through its initial public offering (s4).
The research record is the strongest independent signal. The Orca Research Pod publishes dated vulnerability findings through 2026, including an nginx flaw traced to Tengine servers and a ksmbd locking bug carrying its own CVE (s8). An earlier disclosure, Super FabriXss, carries a Microsoft-assigned CVE record and independent trade coverage (s18, s19). No prior in-domain founder exit appears in the reviewed sources. [s4, s8, s18, s19]
Orca clears the federal procurement bar. The Orca Cloud Security Platform achieved FedRAMP authorization at the moderate level, which the company states requires a federal sponsor and a rigorous evaluation to reach an Authority to Operate (s5).
The published credential set is broader than the federal one. Orca's trust centre records ISO/IEC 27018:2025, CSA STAR, FedRAMP Moderate, GDPR, GovRAMP, IRAP, ISO/IEC 27001, 27017:2015 and 27701, PCI DSS v4.0.1 and SOC 2, and lists a network diagram, a penetration-test report and a SOC 2 report among its documents (s6).
What the record does not carry is verified operating proof. Orca states it is trusted by hundreds of organizations and reports 2024 platform-scale figures of its own (s11), but no independently verified revenue and no exact current customer count appear, and the one 2024 revenue figure in the reviewed sources is one the research page itself labels an unverified estimate (s20). [s5, s6, s11, s20]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Wiz | competes with | A research page calls it Orca's primary competitor, and Google completed a $32 billion acquisition of it. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Palo Alto Networks | competes with | Orca's own comparisons list names Prisma Cloud, the Palo Alto product that competes for the same cloud-security budget. | N/AWe scored these companies at different scopes, so the totals measure different things. |
| CrowdStrike | competes with | Orca's own comparisons list names CrowdStrike as a product buyers weigh against the Orca platform. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Tenable | competes with | Gartner's alternatives list for Orca names Tenable Nessus, and Orca's own comparisons list names Tenable. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Rapid7 | competes with | Gartner's alternatives list for Orca names InsightVM, and Orca's own comparisons list names Rapid7. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
Add analyzed competitors to compare them side by side with Orca Security.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
press the advantage
What the record evidences for Orca Security is patent-protected intellectual property. Its notice lists twelve granted US patent numbers against two of its products and states they may be covered by one or more. A research page records a 2023 infringement suit against Wiz whose outcome the reviewed sources do not settle. Customers connect their own cloud accounts and run the software themselves, so Orca sells a product rather than an operated service. Its FedRAMP Moderate authorization is one a funded competitor can earn. Its research arm draws on telemetry from more than 1,200 production cloud environments, which the reviewed sources do not establish as a retained product asset. The patents raise a rival's cost to copy the scanning method, a head start rather than a settled lead.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Customers connect their own cloud accounts and operate the platform themselves, buying scanning, prioritization and automated remediation as product capability (s1, s2, s16). The reviewed sources describe no delivery layer in which Orca runs the security programme or owns the outcome, so the customer's team operates it and carries the result. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Wiring risk correlation, prioritization and remediation workflows around the agentless platform builds the integration and learned-workflow friction rung 2 names (s1, s16). The cited record describes how fast the scan is to adopt rather than what leaving costs, and it does not size a migration, so the switching mechanism is documented and the cited record does not size the exit. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 2/3 | Orca holds FedRAMP authorization at the moderate level, which the company states requires a federal sponsor and an Authority to Operate, alongside GovRAMP, IRAP, ISO 27001-family, PCI DSS and SOC 2 records on its trust centre (s5, s6). Those are regulator-mediated approvals a funded competitor must independently earn rather than a mandate carried by the product that blocks substitution. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Reading a workload's runtime block storage out of band, rebuilding its file system as a read-only view and correlating vulnerabilities, malware, identity risk, data and AI posture across the major clouds is the multi-system engineering this rung names (s2, s3), and Orca lists a twelve-patent portfolio over that work (s7). |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | The FedRAMP authorization establishes US federal eligibility and the trust centre adds GovRAMP and IRAP records (s5, s6). The published references and buyer reviews are regulated enterprises, including C6 Bank, Paidy, which its case study calls a Japanese financial institution in the cloud, and two banking reviewers on Gartner's site (s9, s10, s13). |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | Orca reads the cloud estate from outside without sending a packet over the network or running code in the environment, and analyses that read-only view to rank risk (s2). The Opus technology adds remediation orchestration alongside it (s16). Nothing in the cited record shows applications depending on Orca to run, so it is a platform with application features rather than infrastructure beneath them. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 2/3 | The evidenced asset is intellectual property rather than data. Orca's patent notice lists twelve granted US patent numbers against the Orca Security Platform and ShiftLeft and states those products may be covered by one or more (s7), and a research page records a 2023 infringement suit against Wiz whose outcome the reviewed sources do not settle (s21). Its research arm analyses telemetry from more than 1,200 production cloud environments (s18), which the reviewed sources report as input to a published report rather than a retained corpus. The patents are the evidenced asset here. |
Orca Security sells to the enterprise cloud and DevOps team that cannot install an agent on every workload. The company frames the pain as blind spots where agents are missing, a significant impact on asset performance and system resources where agents do run, and integration friction that leads to remediation delays, and states its own finding that fewer than half of assets are covered by agent-based solutions (s2).
The segment sits inside an established category rather than a coined one. Gartner lists Orca in its cloud-native application protection and API protection markets, and Forrester assessed 14 vendors in the same category in early 2026 (s11, s13). Its published references run to regulated industries, including C6 Bank and Paidy, which its case study describes as a Japanese financial institution in the cloud (s9, s10).
The federal authorization extends the same segment into US public-sector procurement, where reviews gate on credentials Orca holds (s5). The AI turn narrows the buyer rather than replacing it, since the same team now answers for models running in the cloud it already owns (s3).
Orca documents its mechanism rather than asserting it. SideScanning collects data from a workload's runtime block storage without an agent, rebuilds the file system as a virtual read-only view, and runs the risk analysis against that copy (s2). Orca states the scan reaches an asset inventory in minutes and prioritized gaps within 24 hours.
The AI module applies that same scan to AI. Orca says it inventories more than fifty of the commonly used AI software packages, covers Azure OpenAI, Amazon Bedrock and SageMaker and Google Vertex AI, builds a bill of materials for every deployed model, and detects keys and tokens to AI services exposed in code repositories (s3). Orca has announced AI AppGen Security for applications employees build on AI platforms outside the development pipeline, and an AI Code Security Auditor for code written inside it (s18), with general availability for both arriving later in 2026 (s22).
Two outside reads sit beside the vendor's own pages, and they differ in provenance. Orca reports that Forrester assessed 14 vendors in early 2026 and gave it the highest scores in six current-offering criteria (s11). The independently hosted one is Gartner, where a banking reviewer records cutting high and critical vulnerabilities by more than 90% in a first year of use across three clouds (s13).
Orca's named references span published case studies and independent buyer reviews. The company publishes case studies on Swiggy, C6 Bank and Blue Yonder (s9), and Gartner carries 257 buyer ratings with reviews dated July 2026 (s13). CTech named Databricks, Robinhood, Autodesk, News Corp, NCR, Duolingo, Unity Technologies and Druva as clients in 2021 and quoted the chief executive saying more than 100 organizations were then buying the product (s14). That client list is five years old.
Distribution runs through partners. Orca attributes its Latin American growth to a partner-led motion and names Oplium, Connect.lat and NetGlobe as regional partners (s12), and a research page reports 270% growth in EMEA deal registrations announced in May 2024 (s21).
What a buyer cannot check is the money. Orca states it is trusted by hundreds of organizations, including SAP, Gannett, Autodesk, Unity, Lemonade and Digital Turbine, and reports scanning more than 9 million workloads and 300 petabytes a day across more than 120,000 code repositories in 2024 (s12), all of them its own measurements. No verified revenue or exact customer count appears, and the one 2024 revenue figure in the reviewed sources is one the research page itself labels an unverified estimate (s21). SentinelOne's $2.5 billion takeover talks fell through over deal terms, Calcalist reported in December 2021 (s15).
Orca charges by cloud workloads rather than by seat, which ties the bill to the size of the estate being secured. A research page states that offerings are based on organization cloud assets, and reports that an organization of 200 can expect to pay between $17.5K and $34.9K, and one of 1,000 between $64.6K and $103.7K (s21).
No rate card appears on the vendor pages reviewed here, which put a demo request in front of the buyer instead (s1). Gartner's product page describes the model as subscription pricing structured around cloud asset coverage and environment size (s13), which is the shape of a negotiated enterprise agreement rather than a listed price.
The July 2026 additions are not yet priced in public. An independent analysis of that launch records that Orca has not disclosed pricing for either new product (s22), so a buyer sizing the AI additions is working without a published benchmark.
Orca is delivered as SaaS the customer connects its cloud accounts to. The buyer attaches its cloud accounts and the platform reads them from outside, without sending a packet over the network or running code in the environment, which is what keeps the rollout light (s2).
Operations centre on continuous posture and prioritization. Orca names a Unified Data Model for risk correlation and a Risk Prioritization layer doing dynamic scoring and attack-path analysis (s1), and the Paidy case study records twelve AWS accounts connected, with insight into all of them inside thirty minutes, and an imminent compromise Orca identified in a test environment (s10).
The Opus acquisition moved operations toward closing risk rather than only finding it, adding orchestration and automated remediation of cloud security findings (s16). A careful buyer will test how far it trusts autonomous fixes before relying on them, and the reviewed sources carry no published benchmark of that remediation.
Orca clears the federal procurement bar. The Orca Cloud Security Platform achieved FedRAMP authorization at the moderate level, which the company states requires a federal sponsor and a rigorous evaluation to reach an Authority to Operate (s5).
The published credential set is broader than the federal one. Orca's trust centre records ISO/IEC 27018:2025, CSA STAR, FedRAMP Moderate, GDPR, GovRAMP, IRAP, ISO/IEC 27001, 27017:2015 and 27701, PCI DSS v4.0.1 and SOC 2, and lists a network diagram, a penetration-test report and a SOC 2 report among its documents (s6).
What the record does not carry is independently verified operating proof. Orca reports 2024 platform-scale figures and a claim of hundreds of organizations served (s12), and Gartner carries 257 independent buyer ratings (s13), but no independently verified revenue and no exact current customer count appear (s21). An independent analysis of its July 2026 launch records that the company has not disclosed pricing for either new product (s22).
Orca positions itself as the one platform an enterprise standardizes on across its clouds rather than a tool bound to one provider. The company frames the offering as covering code, cloud, runtime and AI in a single view with the context that drives a decision (s1).
Outward, breadth across providers is the ecosystem play. The agentless scan spans the major clouds and the AI module discovers models across that same footprint (s2, s3). Distribution rides on named regional partners rather than a direct-only motion (s12).
Inward, the newer pieces are assembled as much as built. The remediation layer came with the Opus acquisition (s16), and the July 2026 AI additions extend the platform to software built outside the development pipeline (s18). The reviewed sources show an integration directory and a partner programme, and describe no marketplace in which third parties publish their own extensions.
Orca's leadership bench is verifiable and in-domain. Gil Geron directed a large team of cyber professionals at Check Point before co-founding the company, co-founder Avi Shua was Check Point's chief technologist and served in Unit 8200, and Gera Dorfman came from Check Point as vice president of network security products, where he led research and development in that product group (s4).
The bench extends past engineering. Chief revenue officer Raf Chiodo joined from Lacework, where he ran the Americas go-to-market team, and chief financial officer Oded Edri was chief accounting officer at Payoneer through its initial public offering (s4).
The research record is the strongest independent signal. The Orca Research Pod publishes dated vulnerability findings through 2026, including an nginx flaw traced to Tengine servers and a ksmbd locking bug carrying its own CVE (s8). An earlier disclosure, Super FabriXss, carries a Microsoft-assigned CVE record and independent trade coverage (s19, s20). No prior in-domain founder exit appears in the reviewed sources.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Orca Security: AI Security Posture Management (AI-SPM) | official | 2026-08-23 |
| f2 | CTech: Orca Security raises another $340 million, boosts valuation to $1.8 billion | press | 2026-08-23 |
| f3 | Contrary Research: Orca Security business breakdown | research | 2026-08-23 |
| f4 | SecurityWeek: Orca Snaps Up Opus in Cloud Security Automation Push | press | 2026-08-23 |
| f5 | Temasek leads $550M Series C extension into Orca Security | press | 2026-06-14 |
| f6 | AI Defense Matrix Catalog entry | other | 2026-06-13 |
| f7 | AI Defense Matrix Catalog mapping | other | 2026-06-23 |
| f8 | Orca Security: Orca Platform overview page | official | 2026-08-23 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Orca Security: Orca Platform overview page “Comparisons
CrowdStrike
Wiz
Check Point CloudGuard
Lacework FortiCNAPP
Rapid7
Tenable
Qualys
Prisma Cloud” | official | 2026-08-23 |
| s2 | Orca Security: agentless SideScanning technology page “Running agents on workloads has a significant impact on asset performance and system resources, especially if assets need multiple agents installed for different point solutions.” | official | 2026-08-23 |
| s3 | Orca Security: AI Security Posture Management product page “Orca ensures that AI models are configured securely, covering network security, data protection, access controls, and IAM.” | official | 2026-08-23 |
| s4 | Orca Security: About page with the leadership roster “Oded Edri is Chief Financial Officer of Orca Security. Oded brings more than 15 years of experience across diverse aspects of executive leadership, financial management, human resources management, and operations.” | official | 2026-08-23 |
| s5 | Orca Security: blog post announcing FedRAMP authorization “We’re thrilled to announce that the Orca Cloud Security Platform, a leading Cloud Native Application Protection Platform (CNAPP), has achieved FedRAMP Ⓡ authorization at the moderate level.” | official | 2026-08-23 |
| s6 | Orca Security: probe of trustcenter.orca.security by direct fetch on 2026-08-23, compliance surface found “ISO/IEC 27018:2025
AWS Qualified Software
CSA STAR
FedRAMP Moderate
GDPR
GovRAMP
IRAP
ISO/IEC 27001
ISO/IEC 27017:2015
ISO/IEC 27701
PCI DSS v4.0.1
SOC 2” | official | 2026-08-23 |
| s7 | Orca Security: virtual patent marking notice “The following products are protected by patents in the U.S. and elsewhere for Orca Security.” | official | 2026-08-23 |
| s8 | Orca Security: Orca Research Pod index of published findings “Compromised keyv Maintainer Account Triggers Massive npm Supply Chain Attack” | official | 2026-08-23 |
| s9 | Orca Security: customer case-study index “Find out how we help customers with multi-cloud security across numerous industries.” | official | 2026-08-23 |
| s10 | Orca Security: blog post on the Forrester Wave CNAPP Q1 2026 result “Forrester has named Orca as a Strong Performer in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026.” | official | 2026-08-23 |
| s11 | Orca Security: press release on Latin America customer growth “Orca is trusted by hundreds of organizations, including SAP, Gannett, Autodesk, Unity, Lemonade and Digital Turbine.” | official | 2026-08-23 |
| s12 | Gartner Peer Insights: Orca Security product profile and ratings “Manager, IT Security and Risk Management
3B - 10B USD, Banking
CRITICAL
"Strong CSPM and DSPM capabilities"
3.0
Jul 30, 2026” | research | 2026-08-23 |
| s13 | CTech: Orca Security raises another $340 million, boosts valuation to $1.8 billion “Meir Orbach 15:00 05.10.21” | press | 2026-08-23 |
| s14 | CTech: SentinelOne's $2.5 billion takeover of Orca Security falls through “Golan Hazani 10:30 23.12.21” | press | 2026-08-23 |
| s15 | SecurityWeek: Orca Snaps Up Opus in Cloud Security Automation Push “By
Ryan Naraine
|
May 13, 2025 (6:00 AM ET)” | press | 2026-08-23 |
| s16 | Cybersecurity Dive: Google completes $32B acquisition of Wiz “The cloud security specialist will continue to operate under its own brand and across multiple platforms.” | press | 2026-08-23 |
| s17 | Help Net Security: Orca Security secures AI-built and developer-created applications “Industry News
July 30, 2026” | press | 2026-08-23 |
| s18 | NVD: CVE-2023-23383 record “Source:
Microsoft Corporation” | other | 2026-08-23 |
| s19 | The Hacker News: article on the Super FabriXss vulnerability in Azure SFX “Tracked as CVE-2023-23383 (CVSS score: 8.2), the issue has been dubbed "Super FabriXss" by Orca Security, a nod to the FabriXss flaw (CVE-2022-35829, CVSS score: 6.2) that was fixed by Microsoft in October 2022.” | press | 2026-08-23 |
| s20 | Contrary Research: Orca Security business breakdown “Headquarters
Portland, OR” | research | 2026-08-23 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Orca Security: Orca Platform overview page “Comparisons
CrowdStrike
Wiz
Check Point CloudGuard
Lacework FortiCNAPP
Rapid7
Tenable
Qualys
Prisma Cloud” | official | 2026-08-23 |
| s2 | Orca Security: agentless SideScanning technology page “Running agents on workloads has a significant impact on asset performance and system resources, especially if assets need multiple agents installed for different point solutions.” | official | 2026-08-23 |
| s3 | Orca Security: AI Security Posture Management product page “Orca ensures that AI models are configured securely, covering network security, data protection, access controls, and IAM.” | official | 2026-08-23 |
| s4 | Orca Security: About page with the leadership roster “Oded Edri is Chief Financial Officer of Orca Security. Oded brings more than 15 years of experience across diverse aspects of executive leadership, financial management, human resources management, and operations.” | official | 2026-08-23 |
| s5 | Orca Security: blog post announcing FedRAMP authorization “We’re thrilled to announce that the Orca Cloud Security Platform, a leading Cloud Native Application Protection Platform (CNAPP), has achieved FedRAMP Ⓡ authorization at the moderate level.” | official | 2026-08-23 |
| s6 | Orca Security: probe of trustcenter.orca.security by direct fetch on 2026-08-23, compliance surface found “ISO/IEC 27018:2025
AWS Qualified Software
CSA STAR
FedRAMP Moderate
GDPR
GovRAMP
IRAP
ISO/IEC 27001
ISO/IEC 27017:2015
ISO/IEC 27701
PCI DSS v4.0.1
SOC 2” | official | 2026-08-23 |
| s7 | Orca Security: virtual patent marking notice “The following products are protected by patents in the U.S. and elsewhere for Orca Security.” | official | 2026-08-23 |
| s8 | Orca Security: Orca Research Pod index of published findings “Compromised keyv Maintainer Account Triggers Massive npm Supply Chain Attack” | official | 2026-08-23 |
| s9 | Orca Security: customer case-study index “Find out how we help customers with multi-cloud security across numerous industries.” | official | 2026-08-23 |
| s10 | Orca Security: Paidy customer case study “Paidy – a Japanese Financial Institution in the Cloud” | official | 2026-08-23 |
| s11 | Orca Security: blog post on the Forrester Wave CNAPP Q1 2026 result “Forrester has named Orca as a Strong Performer in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026.” | official | 2026-08-23 |
| s12 | Orca Security: press release on Latin America customer growth “Orca is trusted by hundreds of organizations, including SAP, Gannett, Autodesk, Unity, Lemonade and Digital Turbine.” | official | 2026-08-23 |
| s13 | Gartner Peer Insights: Orca Security product profile and ratings “Manager, IT Security and Risk Management
3B - 10B USD, Banking
CRITICAL
"Strong CSPM and DSPM capabilities"
3.0
Jul 30, 2026” | research | 2026-08-23 |
| s14 | CTech: Orca Security raises another $340 million, boosts valuation to $1.8 billion “Meir Orbach 15:00 05.10.21” | press | 2026-08-23 |
| s15 | CTech: SentinelOne's $2.5 billion takeover of Orca Security falls through “Golan Hazani 10:30 23.12.21” | press | 2026-08-23 |
| s16 | SecurityWeek: Orca Snaps Up Opus in Cloud Security Automation Push “By
Ryan Naraine
|
May 13, 2025 (6:00 AM ET)” | press | 2026-08-23 |
| s17 | Cybersecurity Dive: Google completes $32B acquisition of Wiz “The cloud security specialist will continue to operate under its own brand and across multiple platforms.” | press | 2026-08-23 |
| s18 | Help Net Security: Orca Security secures AI-built and developer-created applications “Industry News
July 30, 2026” | press | 2026-08-23 |
| s19 | NVD: CVE-2023-23383 record “Source:
Microsoft Corporation” | other | 2026-08-23 |
| s20 | The Hacker News: article on the Super FabriXss vulnerability in Azure SFX “Tracked as CVE-2023-23383 (CVSS score: 8.2), the issue has been dubbed "Super FabriXss" by Orca Security, a nod to the FabriXss flaw (CVE-2022-35829, CVSS score: 6.2) that was fixed by Microsoft in October 2022.” | press | 2026-08-23 |
| s21 | Contrary Research: Orca Security business breakdown “Headquarters
Portland, OR” | research | 2026-08-23 |
| s22 | Shashi Bellamkonda: analysis of the Orca AI AppGen Security launch “General availability for both arrives later in 2026.” | press | 2026-08-23 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.