Best Cloud-Native Application Protection Platform (CNAPP) - Page 3

How Many Cloud-Native Application Protection Platform (CNAPP) Products Does G2 Track?

Total Products under this Category: 37

Category Stats (Sep 2026)

  • Average Rating: 4.55/5 (↓0.02 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Orca Security (+0.09%) - Among all products in this category, Orca Security recorded the largest rating increase compared to last month

Last updated: September 01, 2026

How Does G2 Rank Cloud-Native Application Protection Platform (CNAPP) Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 3,400+ Authentic Reviews
  • 37+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Cloud-Native Application Protection Platform (CNAPP)

G2 Grid® for Cloud-Native Application Protection Platform (CNAPP) plotting products by satisfaction and market presence

Highlighted products: Wiz, CrowdStrike Falcon Cloud Security, Microsoft Defender for Cloud, Orca Security, SentinelOne Singularity Cloud Security, Sysdig Secure, Cortex Cloud, and Aikido Security.

Underlying data: [Grid® JSON](https://www.g2.com/categories/cloud-native-application-protection-platform-cnapp/grids.json?focus%5B%5D=wiz-wiz&focus%5B%5D=crowdstrike-falcon-cloud-security&focus%5B%5D=microsoft-defender-for-cloud&focus%5B%5D=orca-security&focus%5B%5D=sentinelone-singularity-cloud-security&focus%5B%5D=sysdig-sysdig-secure&focus%5B%5D=cortex-cloud&focus%5B%5D=aikido-security)

onamsecurity

onamsecurity is a cloud-native application protection platform that integrates [redacted]. The platform operates through an agentless architecture that requires read-only IAM roles or service accounts for setup. onamsecurity evaluates 549 cloud services against 11,346 security rules while continuously monitoring configurations to detect misconfigurations. The platform features cross-cloud attack path analysis and quantifies exposure with the FAIR model to prioritize [redacted] capabilities locate sensitive information. Code security integrates multiple analysis methods. Compliance coverage spans 78 frameworks with audit-ready evidence collection.

Who Is the Company Behind onamsecurity?

Runecast

Runecast is an enterprise CNAPP platform which saves your Security and Operations teams time and resources by enabling a proactive approach to ITOM, CSPM, and compliance. It helps you proactively remediate vulnerabilities for continuous compliance, whether on-prem, cloud or containers. By proactively using our agentless scanning in real-time admins discover potential risks and remediation solutions before any issues can develop into a major outage. Runecast’s AI-RAIKA, leverages advanced natural language processing (NLP) capabilities to interpret a vast amount of information to provide automated audits for security compliance standards, vulnerabilities (such as KEVs, CVEs or VMSAs) and technology vendor best practices. The platform has been recognized with Frost & Sullivan's 2023 European New Product Innovation Award in the CNAPP industry for its strong overall performance and commitment to user experience. NAVIGATING YOUR COMPLEXITY Runecast helps teams with a simpler transition to cloud, enabling admins to fully understand their hybrid environments and Cloud Security Posture Management (CSPM) and Kubernetes Security Posture Management (KSPM). Running securely on-premises, it provides insights into what is happening both in the cloud and on-site. IMMEDIATE VALUE FOR TEAMS As Runecast helps teams to stabilize availability and ensure security compliance, it contributes also to greater ROI for both existing and future investments with AWS, Azure, Kubernetes and VMware. FULLY ON-PREM SECURE Operates fully on-prem to analyze your hybrid-cloud environment, so that your data remains safely on-site. To provide additional security, Runecast features a customizable, transparent rules engine. RUNECAST FOR SECURITY AND COMPLIANCE Vulnerability Management Regular automated scanning, recommendations, remediation, and the ability to set up vulnerability management policies are just some of the requirements many enterprises have. The Runecast platform is constantly updated to detect the latest vulnerabilities for all of the supported technologies. Container Security Runecast scans container images for known vulnerabilities and misconfigurations, and can also detect runtime issues such as exposed ports and running processes. It also provides a public API which can be used in your CI/CD platform to analyze the container images and whether they are vulnerable or not to known vulnerabilities, before deploying them in production. Compliance with Security Standards Runecast offers automated audits against security hardening guidelines and common industry standards like CIS Benchmarks, NIST 800-53, PCI DSS, HIPAA, DISA STIG 6, GDPR, KVKK (Turkey), ISO 27001, BSI IT-Grundschutz, Essential 8 and Cyber Essentials Security Standard. RUNECAST FOR IT OPERATIONS TEAMS Vendor Best Practices for Security Hardening Runecast continuously monitors your complex environment, reporting violations and providing recommendations against Vendor Best Practices. It maintains a database with Best Practices of the latest AWS, Azure, Kubernetes, GCP, VMware and Windows and Linux OS. It analyzes your environment to detect any configuration issues against Vendor Best Practices. This delivers valuable insights to improve the stability and security of your infrastructure. Configuration Vault Tracks your configuration to help you prevent drift. Reports your entire configuration and provides the ability to compare your configurations over time. Hardware Compatibility and Upgrade Stimulations Runecast has automated the process of validating the hardware compliance of hosts and clusters against a selected ESXi version, ensuring compliance with the VMware Compatibility Guide (VCG) and vSAN Hardware Compatibility List (vSAN HCL). The AI-powered platform runs a quick and automated analysis using the latest HCL for your servers, I/O devices, and vSAN controllers. For upgrade planning, admins can see the results of multiple HCL upgrade simulation scenarios within seconds, and the findings are presented in a comprehensive way with details about any non-compatibility and how to resolve it. Validates your hardware, drivers, and firmware against current and upstream releases of ESXi for faster upgrade planning. Remediation Scripts A growing number of findings in Runecast offer remediation actions – allowing you to download the customized script to perform the reconfiguration. Some rules offer more than one remediation option, for example PowerCLI and Ansible. SUPPORTED SERVICES SUPPORTED SYSTEMS: AWS, Azure GCP, Kubernetes (1.20 and above), VMware (VMware vSphere, NSX-V, NSX-T, VMware Horizon, VMware Cloud Director, AP HANA for VMware, VMware on Nutanix, Pure Storage), Windows (Microsoft Windows) and Linux OS (RHEL 8, CentOS 7). SECURITY STANDARDS: CIS Benchmarks, NIST 800-53, PCI DSS, HIPAA, DISA STIG 6, GDPR, KVKK (Turkey), ISO 27001, BSI IT-Grundschutz, Essential 8 and Cyber Essentials Security Standard. INTEGRATIONS: Jira, ServiceNow, vSphere Client Plugin, OpenID Connect, REST API, HPE Ezmeral. REMEDIATION TOOLS: Ansible (VMware), PowerCLI (VMware), AWS CLI (AWS), AWS Tools for PowerShell (AWS), GCP CLI

Average Rating: 4.8/5.0

Total Reviews: 21

Who Is the Company Behind Runecast?

  • Seller: Runecast Solutions
  • Year Founded: 2014
  • HQ Location: London, London
  • Twitter: @Runecast
    1,093 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    14 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 48% Large, 24% Medium

What Are Recent G2 Reviews of Runecast?

Saner Cloud

Saner Cloud is an AI-fortified Cloud-Native Application Protection Platform (CNAPP) that moves beyond detection. It empowers organizations with intelligent, real-time, and automated attack prevention. Unlike traditional cloud security solutions that overwhelm security teams with alerts but fail to act, Saner Cloud automatically fixes vulnerabilities, misconfigurations, identity risks, and compliance violations across multicloud environments. Why choose Saner Cloud? - Unified dashboard with real-time updates and interactive visuals for a single source of truth - Complete asset visibility with watchlists, exposure detection, region-based categorization, deprecated services, and cost analysis - AI-driven anomaly detection with confidence levels, severity distribution, whitelisting options, and one-click remediation - Continuous posture management with built-in benchmarks, quick misconfiguration checks, trend tracking, and drift detection - Risk prioritization with scoring, top-risk lists, and context across assets, posture, and anomalies to focus on which risk to remediate first - Identity and entitlement governance with policy maps, RBAC, resource groups, excessive permission detection, and activity logging - Enhanced Remediation with scheduling and approval workflows, Top 10 patches, patch aging, most-impactful-patches charts, and grouped remediation - Multi-cloud coverage across AWS, GCP and Azure with a prevention-first workflow - Smart tagging for fast filtering across thousands of resources and audit logs with tool-specific job codes for full traceability

Who Is the Company Behind Saner Cloud?

  • Seller: SecPod
  • Company Website:
  • Year Founded: 2008
  • HQ Location: Redwood City, California
  • Twitter: @secpod
    542 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    182 employees on LinkedIn®

Skyhigh Cloud-Native Application Protection Platform

Skyhigh Cloud Native Application Protection Platform CNAPP is the industry’s first platform to extend Cloud Access Security Broker CASB, bringing application and data context to converge Cloud Security Posture Management CSPM with IaaS Data Loss Prevention DLP for IaaS public clouds. Skyhigh CNAPP provides consistent data protection, threat prevention, governance, and compliance throughout the cloud-native application development lifecycle. Skyhigh CNAPP is consolidated into a fully converged platform and managed from the same single console as the rest of the Skyhigh SSE services.

Average Rating: 4.8/5.0

Total Reviews: 2

Who Is the Company Behind Skyhigh Cloud-Native Application Protection Platform?

  • Seller: Skyhigh Security
  • Year Founded: 2022
  • HQ Location: San Jose, CA
  • Twitter: @SkyhighSecurity
    17,573 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    751 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Medium

What Are Recent G2 Reviews of Skyhigh Cloud-Native Application Protection Platform?

Stream Security

SecOps deserve better than raw cloud telemetry. Most tools patch over noise, ignoring the state of your cloud. We fix the root cause. Stream turns raw cloud telemetry into a stateful real-time model, powering risk-based detection and response.

Who Is the Company Behind Stream Security?

ThreatStryker

ThreatStryker builds on the ThreatMapper open source platform. ThreatStryker extends the vulnerability discovery capabilities, adding runtime attack detection, prediction and protection. Map your applications, know the weak points, prioritise vulnerabilities for remediation. Observe security events (indicators of attack and indicators of compromise) using deep packet inspection and lightweight on-host sensors. Correlate events and vulnerabilities to track the risk posed by attacker behaviour, then intervene with quarantine and firewall actions to stop attackers in their tracks.

Average Rating: 4.0/5.0

Total Reviews: 1

Who Is the Company Behind ThreatStryker?

  • Seller: Deepfence
  • Year Founded: 2018
  • HQ Location: Palo Alto, US
  • Twitter: @deepfence
    574 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    5 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Medium

What Are Recent G2 Reviews of ThreatStryker?

TigerGate

TigerGate is a unified CNAPP platform that secures code, cloud infrastructure, identities, applications, data, containers, Kubernetes, and runtime environments from a single platform. By combining CSPM, CWPP, KSPM, CIEM, DSPM, and application security, TigerGate helps organizations replace fragmented security tools with unified cloud security operations. Built for cloud-native and AI-driven environments, TigerGate correlates signals across code, cloud, identity, and runtime into a unified attack-path graph, enabling teams to prioritize real risk, reduce alert fatigue, and accelerate remediation. From agent identities and ephemeral workloads to automated remediation and runtime protection, TigerGate delivers security designed for modern cloud operations.

Who Is the Company Behind TigerGate?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated April 23, 2025