AA
Ahmed A.
Enterprise (> 1000 emp.)
"Orca Unifies AI Agent Risk in One Clear Posture View for Leadership"
5/5
What do you like best about Orca Security?

Our CISO used to get disparate stories about the AI agents: AppSec had one view, cloud security had another, and no one owned a single picture of how agent identities and the data all fit together. Orca’s top-level posture view now gives leadership one pane where every AI agent shows up alongside traditional services, with clear exposure, effective permissions, and blast radius. When the CISO walks into a meeting, they can see which agents carry meaningful risk, what data is at stake, and how that ties back to what the business is building next. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

We still produce the simplified roll-up for the board decks, so there’s some translation effort involved in turning the rich agent context into a higher-level narrative. That said, it’s a much better starting point than what we had before. Review collected by and hosted on G2.com.

MK
Manohar K.
Enterprise (> 1000 emp.)
"Orca Brings AI Agents Into Focus With Prioritized, Business-Relevant Risk Views"
5/5
What do you like best about Orca Security?

Our teams are drowning in alerts, and the dashboards barely mention AI agents, even though those agents are quietly involved in many of the riskiest paths. Orca changes that by presenting a prioritized view where AI agents, their permissions, and the data they can touch show up alongside traditional services. As a result, we spend less time flipping between tools and more time focused on the short list of agent-driven attack paths that actually matter to the business. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

We took some time to align the Orcas risk views with how our teams talk about the agents and services, including a few naming and tagging conventions. That small investment made it much easier for engineers and analysts to immediately recognize the agents and the paths tied to their work. Review collected by and hosted on G2.com.

AV
Alvaro V.
Enterprise (> 1000 emp.)
"Orca Makes Least Privilege Practical with Clear Permission and Usage Visibility"
5/5
What do you like best about Orca Security?

Least privilege is always the goal, but in a world where the marketer writes the Python and the analyst ships the agents, it was hard to know where to start. Orca shows the effective permissions and the actual usage across agents and identities tied to the systems our team builds, so the effort can go first to the agents and roles with the largest blast radius around the assets that drive the business. That makes the CISO’s least-privilege goal something the team can realistically chip away at each sprint—for agents and humans—instead of leaving it as a theoretical aspiration. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

We took care to test the changes around some legacy applications and the older agents before tightening access based on the Orcas findings, which helped us roll out least privilege safely. Review collected by and hosted on G2.com.

BJ
Bilal J.
Enterprise (> 1000 emp.)
"Orca Makes Shadow AI Agents Visible and Governable Across Our Cloud"
5/5
What do you like best about Orca Security?

We’re used to talking about shadow infrastructure, but now the real story is shadow AI. Almost anyone in the company can spin up an AI agent that talks to real systems, calls APIs, and acts on behalf of users. Many of those agents were created without a formal process and quietly became part of our attack surface. Orca discovers AI agents wherever they appear across our cloud estate, shows which identities they run as, which systems they can reach, and what data sits behind those paths. Shadow AI agents go from invisible to mapped in a way we can actually govern. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

We chose to invest some time in tagging agents with the owners and the business units in Orca, and it turned visibility into clear accountability for each shadow agent we discovered. That work also made every follow-up conversation much more concrete and easier to act on. Review collected by and hosted on G2.com.

SJ
Samuel J.
Enterprise (> 1000 emp.)
"Orca Unifies AppSec, Cloud, and Agent Context in One Clear View"
5/5
What do you like best about Orca Security?

We used to split our view of risk: AppSec tools looked at the code, cloud tools looked at the infrastructure, and nobody owned the full picture for the agents that sit on top of both. In reality, the marketer was writing the Python, the analyst was shipping the agents, and those agents call the APIs, touch the containers, and invoke serverless functions across clouds. Orca ties the application, cloud, and agent context together in one unified model. When there’s an issue, we can see the agent, the vulnerable code it relies on, the service it runs on, and the data it touches—all in a single view. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

Our appsec engineers broadened their focus to include agent behaviour and the cloud context, and that shift has helped them collaborate more closely with the rest of the security team. Review collected by and hosted on G2.com.

KJ
Kevin J.
Enterprise (> 1000 emp.)
"Orca Gives Us a Single View of AI Agent Risk Across AWS, Azure, and GCP"
5/5
What do you like best about Orca Security?

We build across AWS, Azure, and GCP. Different teams own each cloud and ship features independently, and our AI agents follow those same paths, calling services across multiple providers at once. Before Orca, that meant three different stories about where the agents lived and what they could reach. Orca connects to every account and subscription and gives us a single, contextual view of the risk tied to the AI agents and the services our business depends on. Our CISO can see the agents, their identities, and their blast radius across clouds in one place instead of chasing separate dashboards. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

Cloud specialists sometimes want more provider-specific detail at the top level, but the ability to drill down is there. Our teams have found a good balance between the unified agent view and the depth available for each cloud. Review collected by and hosted on G2.com.

PC
Pious C.
Enterprise (> 1000 emp.)
"Orca Brings Clear, Actionable Context to Kubernetes Security at Scale"
5/5
What do you like best about Orca Security?

Our Kubernetes footprint grew faster than our security efforts could keep up with. Engineers and analysts were pushing workloads across clusters, and misconfigurations were getting lost in the complexity. Orca surfaces Kubernetes issues in the same unified context as everything else, and it helps show which misconfigurations are actually reachable from the internet or from the identities tied to our critical services. It also makes it clearer which Kubernetes misconfigurations sit on the paths that the AI agents, or the services they drive, could realistically reach. That added context is what lets a small team keep up with the clusters that power the features our business depends on. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

Some of the Kubernetes terminology in the findings required a quick internal primer for non-cluster specialists, but once that foundation was in place, the insights became much easier to understand and act on. Review collected by and hosted on G2.com.

DC
Deepika C.
Enterprise (> 1000 emp.)
"Orca Cuts Container CVE Noise and Highlights Real Exposure Along AI Agent Paths"
5/5
What do you like best about Orca Security?

We used to drown in container CVE lists that didn’t reflect how our teams—or the AI agents—actually use those services. Developers were shipping images quickly, product managers were prototyping and pushing features, and the agents were calling into containers in ways that security couldn’t easily prioritize.

Orca shows which container vulnerabilities sit on the assets that are truly exposed, and more importantly, which ones fall along the paths our AI agents and their tools actually traverse. It filters out the noise and surfaces the container risks that could affect real agent workflows, not just theoretical package issues. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

The container view had a lot of depth, so we spent some time tuning the filters and groupings to match how our teams and the agents use services and environments. That tuning made it much easier for both builders and security to focus on the container risks that affect agent-driven paths. Review collected by and hosted on G2.com.

SJ
Santo J.
Enterprise (> 1000 emp.)
"Orca Makes Serverless Security Clear and Actionable"
5/5
What do you like best about Orca Security?

Our teams leaned hard into serverless. Developers, analysts, and even marketers writing Python scripts ended up shipping Lambda functions that touched important data. Traditional tools treated those functions as an afterthought. Orca sees serverless as part of the same unified risk surface, showing permissions, data access, and exposure in the context of the features we’re building. It lets our CISO enable that speed of creation instead of asking teams to slow down. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

We still rely on separate tools for performance and latency, so we’ve had to be clear internally about which findings are security-related versus operational. That distinction is straightforward to make. Review collected by and hosted on G2.com.

AS
Alphonse S.
Enterprise (> 1000 emp.)
"Orca Delivers Crucial Visibility Into AI Agent Permissions and Blast Radius"
5/5
What do you like best about Orca Security?

The analyst spun up the AI agent with access to fourteen internal systems. Orca mapped the trust relationships the agent could traverse and surfaced the blast radius of its permissions well before we would have tripped over it during an incident. Shadow agents and their access used to be a complete blind spot for us, but now, as part of our regular posture reviews, we can quickly see what any new agents are able to reach. That visibility is really the only way to govern this stuff at the speed people are creating it. Review collected by and hosted on G2.com.

What do you dislike about Orca Security?

The agent and the identity graph have a lot of depth, so we spent some time learning how to read them properly. That effort has paid off in the quality of the insights we’re now getting. Review collected by and hosted on G2.com.