FF
Information Security Engineer
Mid-Market (51-1000 emp.)
"Real Threats, Real Fixes, Near Zero Noise"
4.5/5
What do you like best about Sweet Security?

The team's pedigree shows immediately... Palo Alto / Aqua / Wiz caliber DNA and it comes through in how fast the product has matured since we got in early. Two things stand out most: the EDR like telemetry lets us take raw behavioral data and turn it into an actual detection rule in a couple of clicks, no separate workflow for writing rules bolted on but it's there if that's your thing. And their AI driven incident triage is some of the best I've used... it doesn't just flag an alert and leave you to figure out what it means, it explains the context behind it in plain terms. If someone on the team isn't deep in cloud attack TTPs, they're not left guessing what a given technique actually is or why it matters, the triage walks you through it. That matters a lot when you're trying to get a whole team, not just your most senior person, moving fast on the right things.

What really sold me was watching their SweetAttack red teaming live in a demo. If it finds an RCE, it patches the exploit in place without breaking the underlying app, then layers a network block on top so it can't be reused. And if there's the all too common crypto miner that snuck in during that window, it kills the process automatically, no manual cleanup, no waiting for someone to notice CPU spiking. They've designed a thing of beauty.

It's not noticeable in terms of resource consumption. Like, at all.Any security guy will tell you what a joy it is to not hear a peep from the infrastructure side of the house blaming their tools for all their problems. It's great to forget it's even there. That's a point of pride I hope they take, because a lot of vendors in this space cannot say the same.

I've been doing my own AI red teaming work on the side across a range of agent architectures and role setups... single agent tool calling loops, orchestrator and worker patterns, layered sub agent delegation, peer to peer agent swarms, you name it, I've tried the combo. So I've got a real basis for comparison, and I can say confidently: a lot of tools in this space show you a plausible looking attack path. Sweet actually runs the exploit and proves it's real. That's a meaningfully different posture than the Wiz/Upwind style tools, which mostly show static theoretical paths.

The UI itself is easy to navigate, not a black hole you get lost in trying to find where something is. It's fun and friendly to use, and yes, it has dark mode.

On integrations, we've had it working across our GreyMatter/ReliaQuest pipeline and Azure environment side by side, cloud and on prem both covered, so it's not just a point tool that only talks to itself. And the support side has been genuinely good, the team is quick to hop on a call, and patiently go through troubleshooting, and they bring their technical lead into demos when the questions get specific instead of leaving you with a someone who is just "going to get back to you". Its done properly the first time around. Review collected by and hosted on G2.com.

What do you dislike about Sweet Security?

Still maturing in a few spots you'd expect from a company growing this fast some integration docs needed extra clarification with support to get right and one lower-severity alert type could use better default tuning so triage time stays low even before customization. But they took that feedback and its not an issue anymore. For the sake of transparency im including it.

My one bigger wish is that the offering felt a little more unified instead of broken into separate modules/add-ons but once I thought it through, it makes sense given how they likely have to account for token usage under the hood for the AI-driven pieces. If you're pricing or metering based on token consumption, breaking it out is the sane way to do it. Review collected by and hosted on G2.com.

See what 2 reviewers think of Sweet Security

4.3 out of 5 · Verified reviews from real users

Read all reviews