Orca Security

United States · owned by Independent (United States) · orca.security · 37 vendors

Orca Security is an AI-powered cloud security platform and Cloud-Native Application Protection Platform (CNAPP) that provides comprehensive security coverage across multi-cloud environments. The company uses agentless technology to detect vulnerabilities, misconfigurations, and threats across cloud workloads from build to runtime. It serves enterprises seeking unified visibility and protection across AWS, Azure, Google Cloud, and other cloud providers.

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 37 sub-vendors.

Insights

Last updated 2026-05-05 · revision 6

37 direct vendors, 330 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Orca Security's migration readiness is assessed as medium, largely due to substantial unknowns regarding its internal technology stack and financial capacity, coupled with known complexities in its regulatory environment. There is no available data on the company's internal tech stack (e.g., cloud-native adoption, containerization, microservices), which is a critical factor for determining migration effort and feasibility. Similarly, financial stability data (revenue concentration, growth history) is missing, making it impossible to assess the company's ability to fund a significant migration initiative. The regulatory landscape presents several challenges: GDPR, HIPAA, SOC2, and ISO 27001 are all marked 'Assessment Required' with high or medium risk, indicating that compliance considerations would add significant complexity, cost, and time to any migration effort, particularly concerning data handling, security controls, and potential re-certifications. Data residency requirements are also 'Unable to determine' but are noted as potentially diverse (customer-specific, US government, EU, industry-specific), which could introduce considerable complexity in data relocation and infrastructure planning. The vendor landscape, with 42 services from vendors in 6 diverse countries, suggests a potentially complex ecosystem to manage during migration, although the specific vendor lock-in risk is 'Unknown'. While geographic diversity in vendors can be a resilience strength, it can also complicate migration logistics and contract renegotiations.

Compliance

5 in-scope frameworks identified; showing 3.

NIS2 (source) — Assessment Required

NIS2 applies to Essential and Important Entities in the EU. Orca Security is a cybersecurity services provider, which could potentially fall under 'digital service providers' or 'ICT service management' categories. However, the company's primary operations appear to be US-based with limited direct EU infrastructure operations. The risk level is low because even if applicable, Orca's cybersecurity focus means they likely already implement many NIS2-required security measures.

GDPR (source) — Compliant

Orca Security demonstrates GDPR compliance through their comprehensive privacy policy, data processing agreements, and explicit GDPR compliance certification in their trust center. However, as a US-headquartered company processing EU personal data, they face ongoing compliance obligations and potential enforcement risks. The company has implemented appropriate technical and organizational measures, but cross-border data transfers and evolving regulatory landscape present medium-level risks.

Evidence: https://trustcenter.orca.security/, https://orca.security/privacy-policy/

ISO 27001 (source) — Compliant

Orca Security has achieved multiple ISO certifications including ISO/IEC 27001, 27017, 27018, and 27701, demonstrating comprehensive information security management. As a cybersecurity company, this certification is critical for customer trust and regulatory compliance. Risk is low due to active certifications and the company's security expertise.

Evidence: https://trustcenter.orca.security/, https://orca.security/

Financials

Three-year financials

Financial Resilience Score: 6/10

Orca Security is a venture-backed private company with strong cash reserves from approximately US$700M+ raised across Series A–E rounds, supported by top-tier investors including GGV Capital, ICONIQ Growth, CapitalG (Alphabet), Redpoint, and Temasek. The company has built a diversified enterprise customer base (SAP, Autodesk, Lemonade, Carlsberg, RSA Security, etc.) and holds key compliance certifications (FedRAMP Moderate, SOC 2 Type II, ISO 27001) that open both regulated commercial and US-Government markets. Its differentiated agentless SideScanning™ technology and hyperscaler partnerships (AWS Strategic Collaboration Agreement, Azure, GCP) provide commercial defensibility. However, financial resilience is constrained by intense competition in the CNAPP space, particularly from Wiz (acquired by Google for $32B in 2025), Palo Alto Prisma Cloud, CrowdStrike, and Microsoft Defender for Cloud. The valuation has remained flat at ~US$1.8B since the October 2021 Series C, signaling that ARR growth has not kept pace with original investor expectations. Two reported rounds of layoffs (2023 and 2024) and a CEO transition reflect belt-tightening. With no audited financial statements, no disclosed EBIT, and presumed material cash burn typical of venture-stage SaaS, plus no announced IPO path, the company's resilience depends on continued investor support and execution against well-funded competitors.

Key strengths: Approximately US$700M+ total funding raised across Series A–E, Marquee enterprise customer base diversified across geographies and verticals, Patented agentless SideScanning™ technology reducing onboarding friction, Strategic Collaboration Agreement with AWS (March 2026) and strong hyperscaler partnerships, Comprehensive compliance certifications (FedRAMP Moderate, SOC 2 Type II, ISO 27001, IRAP, PCI), Product breadth expanded via M&A (RapidSec 2022, Opus Security 2025), Top-tier investor syndicate (GGV, ICONIQ, CapitalG, Redpoint, Temasek)

Risk factors: Intense competition from Wiz (Google), Palo Alto Prisma Cloud, CrowdStrike, Microsoft Defender for Cloud, Flat valuation at ~US$1.8B since 2021 Series C indicates decelerating growth vs. expectations, Two reported rounds of layoffs (2023 and 2024), No audited financial statements or disclosed EBIT/revenue figures, No publicly announced IPO path; liquidity dependent on IPO window or strategic sale, Patent lawsuit against Wiz creating distraction, Presumed material negative EBIT typical of venture-stage SaaS, Cash-burn opacity for lenders and partners

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report