Orca Security

Orca Security

Agentless cloud security platform for multi-cloud

Overview

Company Does Not Provide H1B Sponsorship

Orca Security provides cloud security solutions through a Cloud Security Platform that unifies vulnerability management, cloud posture management, container security, cloud workload security, and multi-cloud compliance. It works by connecting to a client’s cloud environment and using its agentless CNAPP built on patented SideScanning to scan the entire cloud estate, revealing misconfigurations, vulnerabilities, identity risks, data exposure, API risks, and threats. The platform prioritizes the most significant cloud risks, identifies critical assets, and provides risk context across multi-cloud environments, enabling faster remediation. It also uses Generative AI to streamline tasks and improve understanding of the cloud landscape. Orca’s goal is to give organizations complete visibility and strong protection for all cloud-based assets across multi-cloud environments, reducing risk and simplifying security operations.

About Orca Security

Simplify's Rating
Why Orca Security is rated
B-
Rated B on Competitive Edge
Rated B on Growth Potential
Rated C on Differentiation

Industries

Data & Analytics

Enterprise Software

Cybersecurity

AI & Machine Learning

Company Size

501-1,000

Company Stage

Series C

Total Funding

$632M

Headquarters

Portland, Oregon

Founded

2019

Get referred to Orca Security

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • September 2026 TD SYNNEX and Partner POD broaden North American reach quickly.
  • July 2026 AI AppGen Security and Code Security Auditor expand into AI-built software.
  • March 2026 autonomous agents and runtime AI detection answer urgent buyer demand for visibility.

What critics are saying

  • March and April 2026 layoffs cut 150 employees, signaling operating pressure and churn.
  • Google’s March 2026 Wiz acquisition weaponizes a $32 billion rival inside cloud distribution.
  • If hyperscalers bundle CNAPP and AI security, Orca loses standalone pricing power within 18 months.

What makes Orca Security unique

  • Agentless SideScanning gives visibility without workload agents, reducing deployment friction and blind spots.
  • Orca unifies cloud, AI, and application security in one platform.
  • September 2026 Partner Success Platform turns partners into guided sellers and operators.

Help us improve and share your feedback! Did you find this helpful?

Funding

Total Funding

$632M

Above

Industry Average

Funded Over

5 Rounds

Series C funding is usually for startups that are doing well and are looking for more money to fuel major growth, such as acquiring other companies, expanding into global markets, or launching new product lines. Investors typically include larger venture capital firms and private equity.
Series C Funding Comparison
Above Average

Industry standards

$50M
$50M
Medium
$62M
SeatGeek
$100M
Oura
$340M
Orca Security

Benefits

Professional Development Budget

Growth & Insights and Company News

Headcount

6 month growth

↑ 0%

1 year growth

↑ 0%

2 year growth

↑ 0%
VMblog
Sep 16th, 2026
Orca Security launches new global Partner Program and ai-powered Partner Success Platform.

Orca Security launches new global Partner Program and ai-powered Partner Success Platform. Orca Security announced its new global Partner POD Program and integrated, AI-powered Partner Success Platform (PSP). The program rewards partners across the full customer lifecycle, including net retention, while custom AI teammates within PSP help them identify opportunities, create content, build expertise and grow more efficiently. The program and platform are directly linked: what the Partner POD Program promises, PSP helps partners execute. Unlike traditional partner portals that primarily provide access to static information and resources, PSP is designed to actively help partners get work done. AI embedded throughout the platform can analyze data, generate materials, surface relevant intelligence, answer technical questions and automate time-intensive tasks. "AI gives us the opportunity to rethink not only what a partner platform can be, but the partner program itself," said Gil Geron, CEO and Co-Founder of Orca Security. "We're moving beyond traditional portals and static resources toward an intelligent experience that can anticipate needs, connect insights and help partners take action. Together, the Partner POD Program and Partner Success Platform create a foundation for AI to become a true growth engine, helping partners uncover opportunities and create more value for customers." The Partner POD Program is built around three principles: making Orca easy to do business with, engineering profitability into the program rather than negotiating it deal by deal, and extending Orca's innovation beyond its security product into how partners transact, sell and get rewarded. Partners are recognized for the value they create across the customer lifecycle, from new business through expansion and net retention. The Partner Success Platform brings marketing, intelligence, enablement and business planning into one AI-powered partner operating system. Key capabilities include: * AI-powered expertise: An AI assistant trained on Orca product documentation, answers partner questions and links directly to relevant source materials. * Intelligent account analysis: The Demand Center analyzes prospective accounts against Orca's ideal customer profile across 11 vectors, returning a match score, relevant intelligence, contacts, and downloadable preparation materials in under 30 seconds. * AI-generated campaigns: Partners can generate co-branded social content and lead-capture landing pages in approximately one minute, replacing processes that can otherwise require weeks and outside agency support. * AI-powered enablement: AI-generated quizzes, certifications, demos, and other activities help partners build expertise while tracking progress directly in the platform. * Automated planning and content: AI can generate business plans, QBR-ready materials, solution briefs, integration guides, and technology alliance battle cards. Together, the program and platform give partners a connected way to build expertise, create demand, support customers and grow their Orca businesses. The program establishes the incentives and rewards, while PSP helps partners put them into action with greater speed and less manual work. "We built the Partner Success Platform around the way partners actually work, making it easier to build expertise, find answers, understand where to focus, and get more done," said John Tavares, SVP, Worldwide Partner and Alliances, Orca Security. "By making benefits easier to access, rewarding outcomes across the customer lifecycle and putting AI directly in partners' hands, we're helping them move faster and build more profitable cloud security practices." For partners, the value is greater speed, efficiency and access to capabilities that traditionally require more time and resources. By automating repetitive work and making Orca expertise, intelligence, content creation and enablement available on demand, PSP helps partners spend less time searching for information, building materials and managing manual processes, and more time applying their expertise to customers and growing their businesses. "As someone who works across a broad portfolio of vendor partnerships, efficiency and precision matter," said Emily Doornbos, Director of Alliances & Programs, GuidePoint Security. "The Orca Partner Success Platform gives us the tools to move faster and smarter... the AI campaign agent removes the heavy lifting from demand generation, and the deal coaching capability means we're not just creating pipeline, we're closing it. It's the kind of platform that turns a good partnership into a great one, and I'm excited to see what it unlocks for our go-to-market motion together." The Partner POD Program combines PSP with enablement, incentives, deal protection and support for partners building their cloud security capabilities. Every partner receives access to the platform, with progress and activities tracked directly through PSP. The Orca Partner POD Program and Partner Success Platform are available globally and localized in six languages at launch. Partners can access PSP at psp.orca.security. Learn more at orca.security/partners/overview. David Marshall is the founder of VMblog.com, one of the industry's longest-running independent publications covering modern data center technologies. What began as a focus on virtualization and cloud computing has expanded to cover the full spectrum of enterprise IT, including AI, security, and DevOps, making VMblog a trusted destination for vendor news, technology analysis, and industry commentary.Beyond publishing, David has spent his career at the intersection of technology and business, inventing, marketing, and launching a number of successful software companies and products, and building a reputation as a skilled marketing executive in the enterprise IT space.David is also a published author, having written two well-regarded books on virtualization and served as technical editor for two "For Dummies" titles covering virtualization and cloud computing. He co-founded CloudCow.com, a publication focused on cloud computing, and has been named a VMware vExpert every year since 2009, one of the longest continuous honoree streaks in the program's history.Connect with David on LinkedIn: https://www.linkedin.com/in/davidmarshall/

Techflier
Sep 5th, 2026
Cloud security firm Upwind scores $300M from Bessemer and TCV.

Cloud security firm Upwind scores $300M from Bessemer and TCV. The cloud security startup banks $300M at a $3.8B valuation led by Bessemer and TCV. Last updated: September 5, 2026 5:32 am Upwind Security has closed another nine-figure round as cloud security spending keeps climbing. The company raised $300M in Series C funding led by returning backers Bessemer and TCV, with Salesforce Ventures, Greylock and Craft Ventures among the participants, SiliconANGLE reported. The round values Upwind at $3.8B, roughly $2B more than at the start of the year. The raise comes eight months after the company's previous nine-figure round. Upwind sells a platform that automatically maps every asset in a cloud environment, refreshing its view every 30 seconds to catch configuration changes, new workloads and account shifts before they become exposures. Its approach leans on eBPF, a Linux feature that lets the company collect kernel-level telemetry without risky operating system changes. Upwind then applies AI to scan those assets for weak points, comparing each workload's configuration against known attack patterns. The platform can also generate AI-BOMs, bills of materials that list the components inside AI applications so administrators can spot risky software. The funding round underscores how investors are rewarding security startups that target the messy reality of modern clouds, where developers add and remove workloads constantly. Upwind competes with the likes of Wiz and Orca Security in the red-hot cloud security category.

News4Hackers
Jul 30th, 2026
Orca Security protects ai-powered & developer-built applications.

Orca Security protects ai-powered & developer-built applications. Post Views: 1 Orca Security has unveiled two AI-powered solutions designed to address evolving risks in application development. Orca Security's ai-powered solutions. Orca Security has unveiled two AI-powered solutions designed to address evolving risks in application development. The first, Orca AI AppGen Security, identifies and protects applications created outside traditional development pipelines using AI platforms such as Claude, Supabase, and Lovable. The second, AI Code Security Auditor, employs deep static analysis to detect vulnerabilities in code generated through conventional software development processes. These additions expand the Orca Platform's capabilities to secure applications across all stages of creation, from enterprise engineering teams to AI-assisted developers. Key findings from Orca Research Pod. A 2026 report from Orca Research Pod, analyzing anonymized data from over 1,200 cloud environments, revealed that 52% of organizations now construct custom applications with AI assistance. As business units deploy AI-generated applications connected to APIs, cloud infrastructure, and sensitive data, traditional security oversight is increasingly insufficient. Simultaneously, exploitable flaws persist within development pipelines. IBM's research indicates that breaches involving shadow AI systems cost organizations an average of $670,000 more than standard incidents, emphasizing the urgency of comprehensive security measures. "Modern software development is no longer confined to engineering teams. Developers, non-technical employees, and even advanced AI models are generating applications across multiple environments. Security frameworks must adapt to this reality without hindering innovation," stated Gil Geron, CEO of Orca Security. "Our AI Code Security Auditor equips teams to proactively identify critical vulnerabilities in AI-assisted workflows, while AI AppGen Security ensures visibility over applications created outside traditional pipelines. Together, these tools provide unified protection for all software creation methods." Addressing critical challenges. The solutions address two critical challenges in contemporary development. Orca AI AppGen Security provides security teams with visibility into AI-generated applications by: * Identifying applications built outside formal pipelines and tracing their creators * Assessing risk exposure across API integrations, data access points, and third-party dependencies * Prioritizing threats based on potential business impact Orca Code Security Auditor enhances traditional static analysis by: * Detecting vulnerabilities overlooked by conventional SAST tools through AI-driven code evaluation * Conducting comprehensive repository scans to identify risks associated with frontier AI models * Focusing on exploitable weaknesses that pose immediate threats to systems "Developers and business teams are deploying applications at a pace that outstrips our ability to manually review them. Applications created outside our pipeline were previously invisible, creating significant blind spots," said Sangram Dash, CISO at Sisense. "These tools allow us to maintain control while enabling rapid development, ensuring we can govern all software without impeding progress." Expanding risks and industry trends. The report highlights growing risks as AI integration expands. Organizations must now secure applications developed through hybrid models where human and machine-generated code coexist. The tools emphasize the need for context-aware security strategies that balance innovation with risk mitigation. Additional findings from the State of AI Security Report 2026 include: * 78% of surveyed organizations reported increased complexity in managing AI-generated code * 43% of security teams lack tools to assess risks in AI-assisted development * 61% of breaches involving AI systems originated from unmonitored third-party integrations Adaptive security architectures. The report underscores the necessity of adaptive security architectures capable of evolving with emerging technologies. As AI-generated software becomes more prevalent, the focus shifts toward proactive risk assessment and real-time threat detection. The solutions are part of a broader industry trend toward AI-enhanced security. Recent studies show that organizations using AI-driven security tools experience 34% faster threat response times and 22% lower incident resolution costs compared to peers relying on traditional methods. Conclusion. The findings align with growing concerns about AI's role in cybersecurity. While AI accelerates development, it also introduces new attack vectors that require specialized mitigation strategies. The report recommends that organizations adopt unified security platforms capable of addressing both human and machine-generated software risks.

Orca Security
Jul 29th, 2026
Orca Security extends its Platform to the new generation of AI builders.

Orca Security extends its Platform to the new generation of AI builders. Ahead of Black Hat USA 2026, Orca unveils AI AppGen Security and AI Code Security Auditor, giving security teams one platform to find truly exploitable code in development and discover shadow builders, safely enable them, and govern the AI applications employees build outside engineering LAS VEGAS - July 29, 2026 - Software is no longer built solely by professional developers inside traditional development pipelines. As AI turns employees across the business into builders, organizations need security that protects software wherever it gets built. Today, Orca Security, a leader in cloud and AI security, announced two new AI-powered capabilities: Orca AI AppGen Security, which discovers and secures AI applications built outside the development pipeline on AI-powered platforms like Claude, Supabase, and Lovable, and AI Code Security Auditor, which delivers deep AI-driven static analysis for code developed within traditional pipelines. Together, the capabilities extend the Orca Platform to secure software across the full spectrum of modern application development, from professional engineering teams to the growing population of AI-assisted builders. The shift is already well underway. Orca's newly released State of AI Security Report 2026, based on anonymized telemetry from more than 1,200 production cloud environments analyzed by the Orca Research Pod, found that 52% of organizations now build custom applications with AI. As business teams increasingly deploy AI-generated applications connected to APIs, cloud resources, and sensitive data, software development is expanding beyond security's traditional visibility. At the same time, exploitable risks continue to persist within development pipelines. IBM estimates breaches involving shadow AI cost organizations an average of $670,000 more than other incidents, underscoring the need for organizations to secure software consistently, whether it's built by developers in the pipeline or employees using AI outside of it. "Everyone is a builder now. Developers are creating software in the pipeline, employees are building AI applications outside it, and the next generation of frontier AI models will increasingly generate and modify software on their own. Organizations need security that can keep pace with this shift without slowing innovation. Our AI Code Security Auditor prepares customers for the next wave of AI-assisted software development, while giving security teams the deep, accurate context they need to understand what's truly exploitable. Combined with AI AppGen Security, Orca helps organizations secure every builder and every application, wherever and however it's created." Gil Geron, CEO and Co-Founder, Orca Security Whether software is written by professional developers or generated by AI-powered builders, security teams need the same outcome: complete visibility, meaningful context, and the ability to prioritize real risk. Together, Orca AI AppGen Security and Orca Code Security Auditor extend the Orca platform to secure modern software development wherever it happens. Orca AI AppGen Security: secure the new generation of AI builders. As AI expands software development beyond engineering, Orca AI AppGen Security gives security teams visibility and control over applications built outside the development pipeline by: * Discovering AI-generated applications and who built them. * Mapping application risk across APIs, integrations, and data access. * Prioritizing high-risk exposures based on real business impact. Orca Code Security Auditor: secure ai-assisted development. Orca Code Security Auditor helps developers identify and prioritize the vulnerabilities that matter most by: * Finding vulnerabilities traditional SAST misses with AI-powered code analysis. * Full repository scanning to uncover Mythos class frontier model vulnerabilities. * Prioritizing exploitable risk so teams can focus on what attackers can actually reach. "My developers and my business teams are both shipping software faster than my team can review it, and the apps built outside our pipeline were a complete blind spot. Seeing exploitable code and the AI apps our employees stand up in one platform lets us say yes to builders instead of slowing them down - and still know exactly what we're governing." Sangram Dash, Chief Information Security Officer, Sisense One platform for everyone who builds. Software is no longer built solely by developers. Employees across the business are creating applications with AI, while autonomous agents increasingly contribute to how software is developed and deployed. As the population of builders continues to grow, organizations need a single platform to secure and govern every application, regardless of who - or what - built it. Recent additions, including support for Anthropic Claude through its Compliance API, further extend Orca's unified approach to AI governance. Orca delivers on its promise of security for the companies that build by providing unified visibility and risk prioritization across the entire software lifecycle, enabling organizations to innovate with confidence while keeping every builder building. Availability. Orca AI AppGen Security and Code Security Auditor will be unveiled at Black Hat USA 2026 and will be generally available later in 2026. Orca will demonstrate both capabilities at booth 5115 at Black Hat USA 2026 in Las Vegas. The State of AI Security Report 2026 is available now at orca.security. About Orca Security. Orca Security delivers security for the companies that build. As cloud, applications, AI and app generation expand the attack surface, Orca transforms security risk into the context teams need to act. The Orca Platform provides complete visibility across cloud, AI, and application environments, correlates risk across every layer, and prioritizes the exposures that matter most so organizations can remediate faster and innovate with confidence. Trusted by hundreds of organizations, including SAP, Autodesk, Gannett, Lemonade, and Digital Turbine, Orca is backed by leading investors including Temasek, CapitalG, ICONIQ Capital, and Redpoint Ventures. Learn more at orca.security. Connect your first account in minutes: https://orca.security or book a personalized demo.

Associated Press
Jul 21st, 2026
Orca Security integrates Claude's Compliance API for unified AI and cloud security

Orca Security has integrated with Claude's Compliance API to extend its AI security capabilities to Claude Enterprise. The integration provides organisations with visibility into AI activity, helping identify security and compliance risks whilst applying consistent governance. The platform enables security teams to monitor Claude activity alongside cloud infrastructure, applications, identities, and runtime environments. Through the integration, Orca offers continuous inventory of users, groups, roles, and permissions across Claude environments, whilst detecting risks including excessive privileges and unsafe retention settings. According to Orca's 2026 State of AI Security Report, 56% of organisations have already deployed AI agents into production. The integration is available for organisations using both Orca Security and Claude Enterprise in Anthropic-hosted environments.

Recently Posted Jobs

Sign up to get curated job recommendations

Orca Security is Hiring for 7 Jobs on Simplify!

Find jobs on Simplify and start your career today

Don't see your dream role? Check out thousands of other roles on Simplify. Browse all jobs →