Before Orca, every pentest seemed to tread the same ground: familiar misconfigurations, identity issues the team already knew about, and a focus on traditional workloads instead of the AI agents doing the real work on our behalf. With Orca in place, we used this context to clean up the most exploitable paths involving the agents ahead of the test—from over-permitted agent identities to exposed endpoints and risky tool stacks. Review collected by and hosted on G2.com.
The first cleanup cycle before the pentest required some focused effort, especially around agents whose access had expanded over time, but it ultimately gave us a much cleaner baseline going into the exercise. Review collected by and hosted on G2.com.