Brand Intelligence Graph
Company Overview
About Orca Security
Orca Security is a Tel Aviv-based cloud security platform — backed with $550 million raised at a $1.8 billion valuation from investors including ICONIQ Growth, GGV Capital, and Redpoint — providing enterprises with agentless cloud security visibility, vulnerability management, compliance monitoring, and threat detection across AWS, Azure, GCP, and Kubernetes environments through its patented SideScanning technology. Founded in 2019 by Avi Shua and Gil Geron and serving 1,000+ enterprise customers including Box, Databricks, and Postman, Orca scans cloud workloads from outside (without installing agents on VMs or containers) to provide complete visibility in minutes.
Business Model & Competitive Advantage
Orca's SideScanning technology reads cloud workload configurations, package inventories, and file contents directly from cloud storage snapshots rather than through network-based scanning or agent deployment on each asset — the agentless approach provides full visibility into cloud configurations (open ports, encryption status, IAM permissions), installed packages and vulnerabilities (CVEs, patches), and sensitive data exposure (PII, credentials in files) without the operational overhead of agent lifecycle management. The context-aware risk prioritization (ranking vulnerabilities by the actual attack path risk — a critical CVE on an internet-facing VM with admin credentials is higher priority than the same CVE on an internal, isolated instance) reduces the 10,000+ alerts most cloud security tools generate to the 10-50 that actually matter.
Competitive Landscape 2025–2026
In 2025, Orca Security competes in the cloud security posture management (CSPM), cloud workload protection (CWPP), and agentless vulnerability management market with Wiz (cloud security, $900M raised at $12B valuation, the market leader), Lacework (cloud security, $1.3B raised, merged with Fortinet in 2024), and Prisma Cloud (Palo Alto Networks, NASDAQ: PANW) for enterprise cloud security platform. Wiz's aggressive growth and Google's $23B acquisition attempt (blocked, 2024) reflected the importance of the cloud security category. Orca's differentiation focuses on depth of coverage (application layer visibility from SideScanning versus Wiz's API-based approach) and the data security capabilities (sensitive data discovery in cloud storage). The 2025 strategy focuses on Orca's AI Security module for AI/LLM workload protection, growing the data security posture management (DSPM) feature, and expanding the international enterprise market.
The Orca Security Story
The Breakthrough Moment
Avi Shua and Gil Geron (ex-Check Point) founded Orca Security in Tel Aviv in 2019 with agentless SideScanning technology for cloud security, reached $1.8B valuation with comprehensive CSPM and CWPP
Original Mission
"Provide complete cloud security without agents using SideScanning technology"
Founders
Recent Activity
View all →Why the industry needs The Builder Exchange Software development traditionally ran through a narrow channel that involved a defined set of engineers, pipelines, and a review process security could have control over. That model worked because building took experience and effort to execute. Now, AI app generators let anyone in an organization describe an app […] The post Introducing The Builder Exchange: Inside Security Stories From the Companies Building Fastest With AI appeared first on Orca Security .
What is the Orca Security plugin for ChatGPT and Codex? The Orca Security plugin for ChatGPT and Codex connects both tools to Orca’s MCP server, giving security teams and developers access to their Orca data where they already work. ChatGPT and Codex can pull alerts, assets, attack paths, effective permissions, and code origins from your […] The post Connect Orca’s ChatGPT Plugin: Cloud Risk Context in Chat and Codex appeared first on Orca Security .
Executive Summary: NetScaler RCE Risk and Patch Deadline Two critical vulnerabilities (CVE-2026-88771 and CVE-2026-88772, both CVSS 9.5) were disclosed affecting Citrix NetScaler ADC and NetScaler Gateway, allowing attackers to achieve unauthenticated remote code execution via improper input validation and memory overflow flaws. Due to confirmed active exploitation globally and their inclusion in CISA’s Known Exploited […] The post Critical Citrix NetScaler Zero-Days Under Active Exploitation appeared first on Orca Security .
What a routine security ticket revealed about how fast business builders are shipping software, and what still has to catch up. Dudi Peretz, Information Security Engineer, has spent more than ten years in security review. What he saw when he opened the ticket for Orca’s new partner portal, built over a weekend by a colleague […] The post Amazing and Terrifying: Securing an App Built By AI in a Weekend appeared first on Orca Security .
Last week, Orca refreshed its global Partner Program to mark the debut of an all-new, AI-powered Partner Success Platform. Take a look at the launch announcement for  the full story. Now that both are live, let’s take a closer look at what has changed and what partners can expect. Before we drill in, the Orca […] The post An Inside Look at Orca’s New Partner POD and Partner Success Platform appeared first on Orca Security .
Executive Summary A high-severity vulnerability (CVE-2026-93485, CVSS 7.1) was disclosed affecting WordPress Core, allowing attackers to achieve full remote code execution via a stored cross-site scripting flaw in the comment rendering pipeline. Due to the potential for complete server compromise, immediate patching is required. About CVE-2026-93485 The issue originates from the wpautop() function in wp-includes/formatting.php, […] The post WordPress “Comment2Shell” XSS-to-RCE Chain Lets Unauthenticated Attackers Compromise Servers via Malicious Comments appeared first on Orca Security .
Executive Summary A high-severity supply-chain attack was disclosed affecting the npm package @dforge-core/dforge-mcp, allowing attackers to distribute a remote-shell implant via a legitimate-looking update carrying valid npm provenance signatures. Due to the potential for full system compromise and the difficulty of forensic detection, immediate action is recommended for any organization that consumed version 0.2.21. Technical […] The post npm Supply-Chain Attack Abuses Trusted Publishing to Ship GHAPPIER Loader appeared first on Orca Security .
Shannon McWilliams, Head of Distribution, had been at Orca Security a few months when he was asked to look at something specific: what it actually feels like to be one of the company’s reseller partners. How do they experience Orca once they sign on? What are they given to work with? A partner portal built […] The post Building Orca’s Partner Portal: What Happens When a Non-Engineer Builds With AI appeared first on Orca Security .
Key Takeaways A maturity assessment scores a defined capability against a documented set of levels or criteria, using evidence rather than opinion. The method belongs to no single field. Procurement teams, data teams, and security teams all run one. This guide covers what a level asserts, what evidence a level claim requires, and how the […] The post Maturity Assessment: Benchmark Organizational Growth appeared first on Orca Security .
Key Takeaways An attack surface is the complete set of points and paths through which an attacker could enter a system, affect it, or extract data. Those points span cloud infrastructure, identities, applications, and the people who run them. An asset inventory and an attack surface are related, but they are not the same thing. […] The post Attack Surface Explained: Types & Reduction Tips appeared first on Orca Security .
Key Takeaways Compliance automation is the practice of turning written control obligations into scheduled machine tests. Those tests collect the evidence, check it, and record the result with a timestamp. That can replace much of the manual work of gathering screenshots and spreadsheets ahead of an audit. The obligation does not change, but the artifact […] The post Compliance Automation: Benefits, Tools & Best Practices appeared first on Orca Security .
Executive Summary A critical vulnerability (CVE-2026-85706, CVSS 10.0) was disclosed affecting GitLab CE and EE self-managed instances, allowing attackers to read arbitrary server files without authentication via a single HTTP request to the commits API. Due to the potential for complete infrastructure compromise through exposed secrets, immediate patching is required. About CVE-2026-85706 The issue originates […] The post Breaking: GitLab Critical Path Traversal Flaw Exploited in the Wild — Patch Immediately appeared first on Orca Security .
Company Timeline
Major milestones in Orca Security's journey
Leadership Team
Meet the leaders behind Orca Security
Patricia Davis
Patricia Davis serves as Chief Technology Officer at Orca Security, bringing extensive industry experience and leadership.
William Johnson
William Johnson serves as Chief Marketing Officer at Orca Security, bringing extensive industry experience and leadership.
Richard Thomas
Richard Thomas serves as Chief Operating Officer at Orca Security, bringing extensive industry experience and leadership.
Lisa Garcia
Lisa Garcia serves as Chief Financial Officer at Orca Security, bringing extensive industry experience and leadership.
Sarah Chen
Sarah Chen serves as Chief Product Officer at Orca Security, bringing extensive industry experience and leadership.
Lisa Johnson
Lisa Johnson serves as VP of Engineering at Orca Security, bringing extensive industry experience and leadership.
Key Differentiators
Emerging Innovator
Orca Security is an emerging player bringing innovative solutions to the Compliance & GRC market.
Frequently Asked Questions
Estimated Visibility Trend (Beta)
Simulated 8-week rolling score
Based on estimated brand signals. Historical tracking coming soon.
Similar Brands
OneTrust
OneTrust is an Atlanta-based privacy, security, and governance technology platform that helps enterprises automate compliance with data privacy regulations (GDPR, CCPA/CPRA, LGPD, PDPA), manage risk a
ServiceNow GRC
ServiceNow GRC (Governance, Risk, and Compliance) is the integrated risk management module within the ServiceNow Now Platform — operated by ServiceNow, Inc. (NYSE: NOW), a Santa Clara, California-base
AuditBoard
AuditBoard is a cloud-based audit, risk, and compliance management platform founded in 2014 in Los Angeles by Scott Arnold and Bidhan Roy. The company was built on the insight that enterprise audit an
Guidewire
Guidewire Software is a San Mateo, California-based enterprise software company — listed on NYSE (NYSE: GWRE) — providing the core operating platform for property and casualty (P&C) insurance carriers
Duck Creek Technologies
Duck Creek Technologies is a Boston-based insurance core systems software company providing cloud-native policy management, billing, and claims processing platforms for property and casualty (P&C) ins
Applied Epic
Applied Epic is the flagship agency management system (AMS) from Applied Systems — a Chicago-based insurance technology company providing end-to-end management software for independent insurance agenc
Compare Orca Security with Competitors
Side-by-side AI visibility scores, platform breakdown, and market position.
Claim This Profile
Are you from Orca Security? Claim your profile to see full AI mention excerpts, get weekly visibility change alerts, and optimize how AI systems describe your brand.
Claim Orca Security Profile →Track AI Visibility in Real Time
Monitor how ChatGPT, Gemini, Perplexity, and Claude mention Orca Security vs competitors. Get alerts when AI recommendations shift.
Start Free Tracking →