Orca Security logo

Orca Security

Emerging#11 in Insurance & Risk

Tel Aviv agentless cloud security with SideScanning technology for AWS/Azure/GCP workload visibility; $550M raised at $1.8B valuation serving 1,000+ enterprises competing with Wiz for CSPM and cloud vulnerability management.

Best for: Cloud Compliance AutomationEmerging, rapid growth
43
AI Score
Grade C
AI Visibility Score (Beta)
Insurance & RiskCloud Compliance AutomationWebsiteUpdated October 2026

Brand Intelligence Graph

Capabilities
Cloud Compliance Automation

Company Overview

About Orca Security

Orca Security is a Tel Aviv-based cloud security platform — backed with $550 million raised at a $1.8 billion valuation from investors including ICONIQ Growth, GGV Capital, and Redpoint — providing enterprises with agentless cloud security visibility, vulnerability management, compliance monitoring, and threat detection across AWS, Azure, GCP, and Kubernetes environments through its patented SideScanning technology. Founded in 2019 by Avi Shua and Gil Geron and serving 1,000+ enterprise customers including Box, Databricks, and Postman, Orca scans cloud workloads from outside (without installing agents on VMs or containers) to provide complete visibility in minutes.

Business Model & Competitive Advantage

Orca's SideScanning technology reads cloud workload configurations, package inventories, and file contents directly from cloud storage snapshots rather than through network-based scanning or agent deployment on each asset — the agentless approach provides full visibility into cloud configurations (open ports, encryption status, IAM permissions), installed packages and vulnerabilities (CVEs, patches), and sensitive data exposure (PII, credentials in files) without the operational overhead of agent lifecycle management. The context-aware risk prioritization (ranking vulnerabilities by the actual attack path risk — a critical CVE on an internet-facing VM with admin credentials is higher priority than the same CVE on an internal, isolated instance) reduces the 10,000+ alerts most cloud security tools generate to the 10-50 that actually matter.

Competitive Landscape 2025–2026

In 2025, Orca Security competes in the cloud security posture management (CSPM), cloud workload protection (CWPP), and agentless vulnerability management market with Wiz (cloud security, $900M raised at $12B valuation, the market leader), Lacework (cloud security, $1.3B raised, merged with Fortinet in 2024), and Prisma Cloud (Palo Alto Networks, NASDAQ: PANW) for enterprise cloud security platform. Wiz's aggressive growth and Google's $23B acquisition attempt (blocked, 2024) reflected the importance of the cloud security category. Orca's differentiation focuses on depth of coverage (application layer visibility from SideScanning versus Wiz's API-based approach) and the data security capabilities (sensitive data discovery in cloud storage). The 2025 strategy focuses on Orca's AI Security module for AI/LLM workload protection, growing the data security posture management (DSPM) feature, and expanding the international enterprise market.

Founded
2019
Headquarters
Tel Aviv, Israel
Curated content • Fact-checked and verified

The Orca Security Story

Tel Aviv, Israel
Founded by Avi Shua, Gil Geron (2019 Tel Aviv Check Point agentless)

The Breakthrough Moment

Avi Shua and Gil Geron (ex-Check Point) founded Orca Security in Tel Aviv in 2019 with agentless SideScanning technology for cloud security, reached $1.8B valuation with comprehensive CSPM and CWPP

Original Mission

"Provide complete cloud security without agents using SideScanning technology"

Founders

Avi Shua, Gil Geron (2019 Tel Aviv Check Point agentless)

Recent Activity

View all →
blog_post
Introducing The Builder Exchange: Inside Security Stories From the Companies Building Fastest With AI

Why the industry needs The Builder Exchange Software development traditionally ran through a narrow channel that involved a defined set of engineers, pipelines, and a review process security could have control over. That model worked because building took experience and effort to execute. Now, AI app generators let anyone in an organization describe an app […] The post Introducing The Builder Exchange: Inside Security Stories From the Companies Building Fastest With AI appeared first on Orca Security .

blog_post
Connect Orca’s ChatGPT Plugin: Cloud Risk Context in Chat and Codex

What is the Orca Security plugin for ChatGPT and Codex? The Orca Security plugin for ChatGPT and Codex connects both tools to Orca’s MCP server, giving security teams and developers access to their Orca data where they already work. ChatGPT and Codex can pull alerts, assets, attack paths, effective permissions, and code origins from your […] The post Connect Orca’s ChatGPT Plugin: Cloud Risk Context in Chat and Codex appeared first on Orca Security .

blog_post
Critical Citrix NetScaler Zero-Days Under Active Exploitation

Executive Summary: NetScaler RCE Risk and Patch Deadline Two critical vulnerabilities (CVE-2026-88771 and CVE-2026-88772, both CVSS 9.5) were disclosed affecting Citrix NetScaler ADC and NetScaler Gateway, allowing attackers to achieve unauthenticated remote code execution via improper input validation and memory overflow flaws. Due to confirmed active exploitation globally and their inclusion in CISA’s Known Exploited […] The post Critical Citrix NetScaler Zero-Days Under Active Exploitation appeared first on Orca Security .

blog_post
Amazing and Terrifying: Securing an App Built By AI in a Weekend

What a routine security ticket revealed about how fast business builders are shipping software, and what still has to catch up. Dudi Peretz, Information Security Engineer, has spent more than ten years in security review. What he saw when he opened the ticket for Orca’s new partner portal, built over a weekend by a colleague […] The post Amazing and Terrifying: Securing an App Built By AI in a Weekend appeared first on Orca Security .

blog_post
An Inside Look at Orca’s New Partner POD and Partner Success Platform

Last week, Orca refreshed its global Partner Program to mark the debut of an all-new, AI-powered Partner Success Platform. Take a look at the launch announcement for  the full story. Now that both are live, let’s take a closer look at what has changed and what partners can expect. Before we drill in, the Orca […] The post An Inside Look at Orca’s New Partner POD and Partner Success Platform appeared first on Orca Security .

blog_post
WordPress “Comment2Shell” XSS-to-RCE Chain Lets Unauthenticated Attackers Compromise Servers via Malicious Comments

Executive Summary A high-severity vulnerability (CVE-2026-93485, CVSS 7.1) was disclosed affecting WordPress Core, allowing attackers to achieve full remote code execution via a stored cross-site scripting flaw in the comment rendering pipeline. Due to the potential for complete server compromise, immediate patching is required. About CVE-2026-93485 The issue originates from the wpautop() function in wp-includes/formatting.php, […] The post WordPress “Comment2Shell” XSS-to-RCE Chain Lets Unauthenticated Attackers Compromise Servers via Malicious Comments appeared first on Orca Security .

blog_post
npm Supply-Chain Attack Abuses Trusted Publishing to Ship GHAPPIER Loader

Executive Summary A high-severity supply-chain attack was disclosed affecting the npm package @dforge-core/dforge-mcp, allowing attackers to distribute a remote-shell implant via a legitimate-looking update carrying valid npm provenance signatures. Due to the potential for full system compromise and the difficulty of forensic detection, immediate action is recommended for any organization that consumed version 0.2.21. Technical […] The post npm Supply-Chain Attack Abuses Trusted Publishing to Ship GHAPPIER Loader appeared first on Orca Security .

blog_post
Building Orca’s Partner Portal: What Happens When a Non-Engineer Builds With AI

Shannon McWilliams, Head of Distribution, had been at Orca Security a few months when he was asked to look at something specific: what it actually feels like to be one of the company’s reseller partners. How do they experience Orca once they sign on? What are they given to work with? A partner portal built […] The post Building Orca’s Partner Portal: What Happens When a Non-Engineer Builds With AI appeared first on Orca Security .

blog_post
Maturity Assessment: Benchmark Organizational Growth

Key Takeaways A maturity assessment scores a defined capability against a documented set of levels or criteria, using evidence rather than opinion. The method belongs to no single field. Procurement teams, data teams, and security teams all run one. This guide covers what a level asserts, what evidence a level claim requires, and how the […] The post Maturity Assessment: Benchmark Organizational Growth appeared first on Orca Security .

blog_post
Attack Surface Explained: Types & Reduction Tips

Key Takeaways An attack surface is the complete set of points and paths through which an attacker could enter a system, affect it, or extract data. Those points span cloud infrastructure, identities, applications, and the people who run them. An asset inventory and an attack surface are related, but they are not the same thing. […] The post Attack Surface Explained: Types & Reduction Tips appeared first on Orca Security .

blog_post
Compliance Automation: Benefits, Tools & Best Practices

Key Takeaways Compliance automation is the practice of turning written control obligations into scheduled machine tests. Those tests collect the evidence, check it, and record the result with a timestamp. That can replace much of the manual work of gathering screenshots and spreadsheets ahead of an audit. The obligation does not change, but the artifact […] The post Compliance Automation: Benefits, Tools & Best Practices appeared first on Orca Security .

blog_post
Breaking: GitLab Critical Path Traversal Flaw Exploited in the Wild — Patch Immediately

Executive Summary A critical vulnerability (CVE-2026-85706, CVSS 10.0) was disclosed affecting GitLab CE and EE self-managed instances, allowing attackers to read arbitrary server files without authentication via a single HTTP request to the commits API. Due to the potential for complete infrastructure compromise through exposed secrets, immediate patching is required. About CVE-2026-85706 The issue originates […] The post Breaking: GitLab Critical Path Traversal Flaw Exploited in the Wild — Patch Immediately appeared first on Orca Security .

Company Timeline

Major milestones in Orca Security's journey

5
Total Events
3
Funding Rounds

Leadership Team

Meet the leaders behind Orca Security

Patricia Davis

Chief Technology Officer

Patricia Davis serves as Chief Technology Officer at Orca Security, bringing extensive industry experience and leadership.

William Johnson

Chief Marketing Officer

William Johnson serves as Chief Marketing Officer at Orca Security, bringing extensive industry experience and leadership.

Richard Thomas

Chief Operating Officer

Richard Thomas serves as Chief Operating Officer at Orca Security, bringing extensive industry experience and leadership.

Lisa Garcia

Chief Financial Officer

Lisa Garcia serves as Chief Financial Officer at Orca Security, bringing extensive industry experience and leadership.

Sarah Chen

Chief Product Officer

Sarah Chen serves as Chief Product Officer at Orca Security, bringing extensive industry experience and leadership.

Lisa Johnson

VP of Engineering

Lisa Johnson serves as VP of Engineering at Orca Security, bringing extensive industry experience and leadership.

Key Differentiators

Emerging Innovator

Orca Security is an emerging player bringing innovative solutions to the Compliance & GRC market.

Frequently Asked Questions

Estimated Visibility Trend (Beta)

Simulated 8-week rolling score

43
↓ Declining

Based on estimated brand signals. Historical tracking coming soon.

Similar Brands

OneTrust logo

OneTrust

Compliance & GRC
B2bEnterpriseFortune500GlobalSaasSecurityInsuranceFintech

OneTrust is an Atlanta-based privacy, security, and governance technology platform that helps enterprises automate compliance with data privacy regulations (GDPR, CCPA/CPRA, LGPD, PDPA), manage risk a

ServiceNow GRC logo

ServiceNow GRC

Compliance & GRC
B2bEnterprisePlatformSaasSecurityPublicInsuranceFintech

ServiceNow GRC (Governance, Risk, and Compliance) is the integrated risk management module within the ServiceNow Now Platform — operated by ServiceNow, Inc. (NYSE: NOW), a Santa Clara, California-base

AuditBoard logo

AuditBoard

Compliance & GRC
B2bEnterpriseFortune500SaasSecurityInsuranceFintech

AuditBoard is a cloud-based audit, risk, and compliance management platform founded in 2014 in Los Angeles by Scott Arnold and Bidhan Roy. The company was built on the insight that enterprise audit an

Guidewire logo

Guidewire

Insurance Tech
B2bSaasInsurancePlatformEnterprisePublicCloud NativeFintech

Guidewire Software is a San Mateo, California-based enterprise software company — listed on NYSE (NYSE: GWRE) — providing the core operating platform for property and casualty (P&C) insurance carriers

Duck Creek Technologies logo

Duck Creek Technologies

Insurance Tech
B2bSaasInsurancePlatformEnterprisePublicFintech

Duck Creek Technologies is a Boston-based insurance core systems software company providing cloud-native policy management, billing, and claims processing platforms for property and casualty (P&C) ins

Applied Epic logo

Applied Epic

Insurance Tech
B2bSaasInsuranceEnterpriseFintech

Applied Epic is the flagship agency management system (AMS) from Applied Systems — a Chicago-based insurance technology company providing end-to-end management software for independent insurance agenc

For Orca Security

Claim This Profile

Are you from Orca Security? Claim your profile to see full AI mention excerpts, get weekly visibility change alerts, and optimize how AI systems describe your brand.

Claim Orca Security Profile →
For competitors & analysts

Track AI Visibility in Real Time

Monitor how ChatGPT, Gemini, Perplexity, and Claude mention Orca Security vs competitors. Get alerts when AI recommendations shift.

Start Free Tracking →