Orca Security

Orca Security

Agentless cloud security platform for multi-cloud

Overview

Company Does Not Provide H1B Sponsorship

Orca Security provides cloud security solutions through a Cloud Security Platform that unifies vulnerability management, cloud posture management, container security, cloud workload security, and multi-cloud compliance. It works by connecting to a client’s cloud environment and using its agentless CNAPP built on patented SideScanning to scan the entire cloud estate, revealing misconfigurations, vulnerabilities, identity risks, data exposure, API risks, and threats. The platform prioritizes the most significant cloud risks, identifies critical assets, and provides risk context across multi-cloud environments, enabling faster remediation. It also uses Generative AI to streamline tasks and improve understanding of the cloud landscape. Orca’s goal is to give organizations complete visibility and strong protection for all cloud-based assets across multi-cloud environments, reducing risk and simplifying security operations.

About Orca Security

Simplify's Rating
Why Orca Security is rated
B-
Rated B on Competitive Edge
Rated B on Growth Potential
Rated C on Differentiation

Industries

Data & Analytics

Enterprise Software

Cybersecurity

AI & Machine Learning

Company Size

501-1,000

Company Stage

Series C

Total Funding

$632M

Headquarters

Portland, Oregon

Founded

2019

Get referred to Orca Security

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • April 13, 2026 TD SYNNEX expands Orca's North American distribution and partner scale.
  • July 29, 2026 Black Hat launches target Lovable, Supabase, Claude, and AI-assisted builders.
  • July 2026 telemetry across 1,200 environments reinforces demand for shadow AI and code risk visibility.

What critics are saying

  • March and April 2026 layoffs totaled 150 employees, signaling cost pressure and organizational churn.
  • Microsoft Defender, Palo Alto Networks, and Wiz intensify CNAPP competition, compressing pricing and loyalty.
  • Hyperscaler-native security and Microsoft bundling commoditize core CNAPP features, squeezing Orca's standalone growth story.

What makes Orca Security unique

  • Orca's SideScanning agentless architecture inventories cloud and AI risks without deployment friction.
  • July 2026 Claude Compliance API integration extends coverage from cloud infrastructure into enterprise AI governance.
  • July 2026 AI AppGen Security and Code Security Auditor unify shadow apps and exploitable code.

Help us improve and share your feedback! Did you find this helpful?

Funding

Total Funding

$632M

Above

Industry Average

Funded Over

5 Rounds

Series C funding is usually for startups that are doing well and are looking for more money to fuel major growth, such as acquiring other companies, expanding into global markets, or launching new product lines. Investors typically include larger venture capital firms and private equity.
Series C Funding Comparison
Above Average

Industry standards

$50M
$50M
Medium
$62M
SeatGeek
$100M
Oura
$340M
Orca Security

Benefits

Professional Development Budget

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
News4Hackers
Jul 30th, 2026
Orca Security protects ai-powered & developer-built applications.

Orca Security protects ai-powered & developer-built applications. Post Views: 1 Orca Security has unveiled two AI-powered solutions designed to address evolving risks in application development. Orca Security's ai-powered solutions. Orca Security has unveiled two AI-powered solutions designed to address evolving risks in application development. The first, Orca AI AppGen Security, identifies and protects applications created outside traditional development pipelines using AI platforms such as Claude, Supabase, and Lovable. The second, AI Code Security Auditor, employs deep static analysis to detect vulnerabilities in code generated through conventional software development processes. These additions expand the Orca Platform's capabilities to secure applications across all stages of creation, from enterprise engineering teams to AI-assisted developers. Key findings from Orca Research Pod. A 2026 report from Orca Research Pod, analyzing anonymized data from over 1,200 cloud environments, revealed that 52% of organizations now construct custom applications with AI assistance. As business units deploy AI-generated applications connected to APIs, cloud infrastructure, and sensitive data, traditional security oversight is increasingly insufficient. Simultaneously, exploitable flaws persist within development pipelines. IBM's research indicates that breaches involving shadow AI systems cost organizations an average of $670,000 more than standard incidents, emphasizing the urgency of comprehensive security measures. "Modern software development is no longer confined to engineering teams. Developers, non-technical employees, and even advanced AI models are generating applications across multiple environments. Security frameworks must adapt to this reality without hindering innovation," stated Gil Geron, CEO of Orca Security. "Our AI Code Security Auditor equips teams to proactively identify critical vulnerabilities in AI-assisted workflows, while AI AppGen Security ensures visibility over applications created outside traditional pipelines. Together, these tools provide unified protection for all software creation methods." Addressing critical challenges. The solutions address two critical challenges in contemporary development. Orca AI AppGen Security provides security teams with visibility into AI-generated applications by: * Identifying applications built outside formal pipelines and tracing their creators * Assessing risk exposure across API integrations, data access points, and third-party dependencies * Prioritizing threats based on potential business impact Orca Code Security Auditor enhances traditional static analysis by: * Detecting vulnerabilities overlooked by conventional SAST tools through AI-driven code evaluation * Conducting comprehensive repository scans to identify risks associated with frontier AI models * Focusing on exploitable weaknesses that pose immediate threats to systems "Developers and business teams are deploying applications at a pace that outstrips our ability to manually review them. Applications created outside our pipeline were previously invisible, creating significant blind spots," said Sangram Dash, CISO at Sisense. "These tools allow us to maintain control while enabling rapid development, ensuring we can govern all software without impeding progress." Expanding risks and industry trends. The report highlights growing risks as AI integration expands. Organizations must now secure applications developed through hybrid models where human and machine-generated code coexist. The tools emphasize the need for context-aware security strategies that balance innovation with risk mitigation. Additional findings from the State of AI Security Report 2026 include: * 78% of surveyed organizations reported increased complexity in managing AI-generated code * 43% of security teams lack tools to assess risks in AI-assisted development * 61% of breaches involving AI systems originated from unmonitored third-party integrations Adaptive security architectures. The report underscores the necessity of adaptive security architectures capable of evolving with emerging technologies. As AI-generated software becomes more prevalent, the focus shifts toward proactive risk assessment and real-time threat detection. The solutions are part of a broader industry trend toward AI-enhanced security. Recent studies show that organizations using AI-driven security tools experience 34% faster threat response times and 22% lower incident resolution costs compared to peers relying on traditional methods. Conclusion. The findings align with growing concerns about AI's role in cybersecurity. While AI accelerates development, it also introduces new attack vectors that require specialized mitigation strategies. The report recommends that organizations adopt unified security platforms capable of addressing both human and machine-generated software risks.

Orca Security
Jul 29th, 2026
Orca Security extends its Platform to the new generation of AI builders.

Orca Security extends its Platform to the new generation of AI builders. Ahead of Black Hat USA 2026, Orca unveils AI AppGen Security and AI Code Security Auditor, giving security teams one platform to find truly exploitable code in development and discover shadow builders, safely enable them, and govern the AI applications employees build outside engineering LAS VEGAS - July 29, 2026 - Software is no longer built solely by professional developers inside traditional development pipelines. As AI turns employees across the business into builders, organizations need security that protects software wherever it gets built. Today, Orca Security, a leader in cloud and AI security, announced two new AI-powered capabilities: Orca AI AppGen Security, which discovers and secures AI applications built outside the development pipeline on AI-powered platforms like Claude, Supabase, and Lovable, and AI Code Security Auditor, which delivers deep AI-driven static analysis for code developed within traditional pipelines. Together, the capabilities extend the Orca Platform to secure software across the full spectrum of modern application development, from professional engineering teams to the growing population of AI-assisted builders. The shift is already well underway. Orca's newly released State of AI Security Report 2026, based on anonymized telemetry from more than 1,200 production cloud environments analyzed by the Orca Research Pod, found that 52% of organizations now build custom applications with AI. As business teams increasingly deploy AI-generated applications connected to APIs, cloud resources, and sensitive data, software development is expanding beyond security's traditional visibility. At the same time, exploitable risks continue to persist within development pipelines. IBM estimates breaches involving shadow AI cost organizations an average of $670,000 more than other incidents, underscoring the need for organizations to secure software consistently, whether it's built by developers in the pipeline or employees using AI outside of it. "Everyone is a builder now. Developers are creating software in the pipeline, employees are building AI applications outside it, and the next generation of frontier AI models will increasingly generate and modify software on their own. Organizations need security that can keep pace with this shift without slowing innovation. Our AI Code Security Auditor prepares customers for the next wave of AI-assisted software development, while giving security teams the deep, accurate context they need to understand what's truly exploitable. Combined with AI AppGen Security, Orca helps organizations secure every builder and every application, wherever and however it's created." Gil Geron, CEO and Co-Founder, Orca Security Whether software is written by professional developers or generated by AI-powered builders, security teams need the same outcome: complete visibility, meaningful context, and the ability to prioritize real risk. Together, Orca AI AppGen Security and Orca Code Security Auditor extend the Orca platform to secure modern software development wherever it happens. Orca AI AppGen Security: secure the new generation of AI builders. As AI expands software development beyond engineering, Orca AI AppGen Security gives security teams visibility and control over applications built outside the development pipeline by: * Discovering AI-generated applications and who built them. * Mapping application risk across APIs, integrations, and data access. * Prioritizing high-risk exposures based on real business impact. Orca Code Security Auditor: secure ai-assisted development. Orca Code Security Auditor helps developers identify and prioritize the vulnerabilities that matter most by: * Finding vulnerabilities traditional SAST misses with AI-powered code analysis. * Full repository scanning to uncover Mythos class frontier model vulnerabilities. * Prioritizing exploitable risk so teams can focus on what attackers can actually reach. "My developers and my business teams are both shipping software faster than my team can review it, and the apps built outside our pipeline were a complete blind spot. Seeing exploitable code and the AI apps our employees stand up in one platform lets us say yes to builders instead of slowing them down - and still know exactly what we're governing." Sangram Dash, Chief Information Security Officer, Sisense One platform for everyone who builds. Software is no longer built solely by developers. Employees across the business are creating applications with AI, while autonomous agents increasingly contribute to how software is developed and deployed. As the population of builders continues to grow, organizations need a single platform to secure and govern every application, regardless of who - or what - built it. Recent additions, including support for Anthropic Claude through its Compliance API, further extend Orca's unified approach to AI governance. Orca delivers on its promise of security for the companies that build by providing unified visibility and risk prioritization across the entire software lifecycle, enabling organizations to innovate with confidence while keeping every builder building. Availability. Orca AI AppGen Security and Code Security Auditor will be unveiled at Black Hat USA 2026 and will be generally available later in 2026. Orca will demonstrate both capabilities at booth 5115 at Black Hat USA 2026 in Las Vegas. The State of AI Security Report 2026 is available now at orca.security. About Orca Security. Orca Security delivers security for the companies that build. As cloud, applications, AI and app generation expand the attack surface, Orca transforms security risk into the context teams need to act. The Orca Platform provides complete visibility across cloud, AI, and application environments, correlates risk across every layer, and prioritizes the exposures that matter most so organizations can remediate faster and innovate with confidence. Trusted by hundreds of organizations, including SAP, Autodesk, Gannett, Lemonade, and Digital Turbine, Orca is backed by leading investors including Temasek, CapitalG, ICONIQ Capital, and Redpoint Ventures. Learn more at orca.security. Connect your first account in minutes: https://orca.security or book a personalized demo.

Associated Press
Jul 21st, 2026
Orca Security integrates Claude's Compliance API for unified AI and cloud security

Orca Security has integrated with Claude's Compliance API to extend its AI security capabilities to Claude Enterprise. The integration provides organisations with visibility into AI activity, helping identify security and compliance risks whilst applying consistent governance. The platform enables security teams to monitor Claude activity alongside cloud infrastructure, applications, identities, and runtime environments. Through the integration, Orca offers continuous inventory of users, groups, roles, and permissions across Claude environments, whilst detecting risks including excessive privileges and unsafe retention settings. According to Orca's 2026 State of AI Security Report, 56% of organisations have already deployed AI agents into production. The integration is available for organisations using both Orca Security and Claude Enterprise in Anthropic-hosted environments.

IANS
Jul 8th, 2026
Inflow Technologies partners with Orca Security to enhance cloud security in India.

Inflow Technologies partners with Orca Security to enhance cloud security in India. * July 08, 2026 5:22 AM Bengaluru, India - 08 July, 2026 - Inflow Technologies, a leading value-added distributor of ICT infrastructure solutions, has partnered with Orca Security, the pioneer of agentless cloud security. The collaboration brings together Inflow's strong regional presence with Orca Security's AI-powered Cloud-Native Application Protection Platform (CNAPP) to help organisations improve visibility and security across cloud environments. By adding Orca Security's CNAPP platform to its cybersecurity portfolio, Inflow enables partners and customers to identify, prioritise, and remediate cloud risks with speed and zero operational friction. "We are proud to announce our strategic partnership with Inflow Technologies, a collaboration that bridges their formidable market presence with our mission to secure the cloud. By integrating Inflow's deep regional expertise with Orca Security's industry-leading AI platform, we are providing Indian enterprises with unparalleled visibility into their digital estates. Together, we empower organisations to identify, prioritise, and remediate evolving threats, ensuring a secure and resilient foundation for scalable growth." - John Tavares, SVP Global Partnerships & Alliances "We are thrilled to announce our partnership with Orca Security. As organisations across the region accelerate their cloud migration, the demand for comprehensive, scalable security has never been higher. By adding Orca's industry-leading CNAPP platform to our portfolio, Inflow is empowering our partners and customers to secure their cloud environments with unprecedented speed and zero friction. This collaboration marks a significant step forward in our mission to deliver best-in-class cybersecurity innovation to the market." - Rajesh Kumar, Senior Vice President Tech BU, Inflow Technologies About Inflow Technologies Founded in 2005, Inflow Technologies is a leading value-added distributor of ICT infrastructure solutions across India and South Asia. The company delivers solutions spanning Networking, Cybersecurity, Unified Communications & Collaboration, AIDC, Surveillance, Servers, Storage, and Software. Headquartered in Bengaluru, Inflow operates in over 50 locations and supports 3,000+ channel partners with 200+ certified technical professionals. About Orca Security Orca enables organizations to make cloud security a strategic advantage. With the most comprehensive coverage and visibility across multi-cloud environments, the agentless-first Orca Platform unites teams to eliminate complexities, vulnerabilities, and risks - including the attack surface introduced by AI. Orca's Security for AI secures your models, training data, and AI pipelines, while Orca AI accelerates detection, investigation, and response across your entire cloud environment. Backed by Temasek, CapitalG, ICONIQ Capital, Redpoint Ventures and others, Orca is trusted by hundreds of organizations, including SAP, Gannett, Autodesk, Lemonade and Digital Turbine. Connect your first account in minutes: https://orca.security or book a personalized demo. Disclaimer: The content provided in this section is part of a third party press release service and does not reflect the editorial views or opinions of IANS. The responsibility for the accuracy, authenticity, and legality of the information lies solely with the content provider. IANS assumes no liability for the content published under this arrangement and encourages readers to verify the information independently before consuming it.

Xenaris
Jun 26th, 2026
Orca Security: rising star in cloud security M&A landscape.

Orca Security: rising star in cloud security M&A landscape. Introduction. In the dynamic world of mergers and acquisitions, cloud security continues to take center stage. Recently, Orca Security, an Israeli-founded private unicorn, has emerged as a pivotal player, ranking 20th in the latest M&A intelligence analysis. Company overview. Orca Security specializes in cloud security, providing solutions that empower businesses to secure their cloud environments effectively. The company is recognized for its innovative approaches, particularly through its automated cloud-risk remediation capabilities. This technology is crucial for organizations that seek to enhance their cloud security posture while managing complex risk environments. Strategic M&A activity. With a strong focus on consolidation within the cloud security sector, Orca Security has recently made significant strides by engaging in a tuck-in acquisition. This strategic move enhances its platform completeness, positioning it as a likely buyer for smaller cloud-security teams looking to integrate into a larger infrastructure. Recent Deals and future prospects. * Recent Israel-Linked Deals (2024-2026): Orca Security is actively engaged in the cloud security ecosystem, with noted actions such as the acquisition of Opus 2025. * Estimated Recent Deal Count: The company has completed 1 notable deal recently, although financial specifics remain undisclosed. Key M&A signals. According to its analysis, Orca Security's signal strength is assessed as medium. The main signals driving their M&A activities include: * Automated cloud-risk remediation solutions. * Enhancing platform completeness to offer more comprehensive security solutions. * A strong interest in acquiring small cloud security teams to expand their capabilities. Conclusion. As the demand for cloud security solutions burgeons, Orca Security stands out as a leading consolidator within the sector. Their proactive approach to mergers and acquisitions, coupled with innovative technology, indicates a strong future ahead in the competitive landscape of cloud security. "In a world where cloud adoption is growing rapidly, businesses must prioritize security. Orca Security's strategic moves illustrate a deep commitment to leading this charge through thoughtful acquisitions and innovation."

Recently Posted Jobs

Sign up to get curated job recommendations

Orca Security is Hiring for 8 Jobs on Simplify!

Find jobs on Simplify and start your career today

Don't see your dream role? Check out thousands of other roles on Simplify. Browse all jobs →