Breaking profile

Company profile / Cloud security

Orca Security Bet Cloud Defense Was a Deployment Problem - Now AI Has to Fix What It Finds

Eight Check Point veterans built a $1.8 billion cloud-security company around an unglamorous insight: protection that takes months to deploy is protection full of holes. Orca’s next test is harder - turning its celebrated visibility into safe, useful action.

The most consequential thing Orca Security did was not discover a new species of hacker. It deleted an installation chore. In 2019, cloud-security teams were still being asked to put monitoring software on individual machines, persuade DevOps to maintain it, and hope that every short-lived workload appeared long enough to receive its electronic ankle bracelet. The scanners could be clever. The rollout was where coverage quietly went to die.

Avi Shua and Gil Geron had watched that failure from unusually good seats. They left Check Point with six other executives and architects - eight co-founders carrying more than 150 combined years of security-product experience - and built Orca around a different premise. Give the platform read-only cloud permissions. Read workload block storage out of band. Pull configuration metadata through the cloud providers’ APIs. Assemble the evidence without installing an agent on every asset. Orca called the method SideScanning.

The name came from an orca’s sonar: wide coverage, limited disturbance. It is an unusually literal startup metaphor. The product connects to AWS, Microsoft Azure, Google Cloud, Oracle Cloud, Alibaba Cloud and Kubernetes environments, inventories what is there, and looks for the dangerous combinations - an exposed machine, a known vulnerability, an overpowered identity and sensitive data connected by one plausible route. The customer is buying fewer blind spots and a shorter argument over what to fix first.

8Co-founders, all former Check Point executives or architects
~$630MCombined funding cited by Orca
$1.8BValuation reached in October 2021

What failed first: the rollout

Security vendors traditionally blamed incomplete coverage on incomplete implementation. Orca treated implementation as part of the product. Its early demonstration boiled connection down to three steps, with a scanner operating beside the customer’s workloads rather than inside their running processes. There was no months-long agent campaign and no workload performance tax from the inspection itself. New and forgotten assets could join the inventory without waiting for a ticket.

That distinction matters because cloud assets are disposable by design. A container may live for minutes. A team may open a test account on Friday and forget it by Monday. The machine everyone remembers is usually not the machine an attacker wants. Orca’s founding thesis was that neglected rear doors deserve at least as much attention as the polished front gate.

Orca Security co-founders Gil Geron and Avi Shua standing in front of a geometric orca mural
THE POD BEFORE THE PLATFORM. Gil Geron and Avi Shua traded the standard security-agent rollout for a scanner that looks in from the side. The whale mural understood the branding assignment.

The first customers changed the founders’ question. Instead of asking whether a product could detect malware once it reached a machine, they asked what share of the estate it could reliably reach and how often it looked. A 99 percent detection rate across 80 percent of the environment is not 99 percent protection. SideScanning made coverage the wedge; Orca’s Unified Data Model made the resulting evidence useful.

“A vulnerability score is a fact. An exposed path to customer data is a Monday-morning plan.”The practical promise of Orca’s context model

The product is an opinion about attention

Orca now sits in the market category with the heroic acronym: CNAPP, or cloud-native application protection platform. The platform bundles jobs that once required separate tools. Cloud security posture management finds bad configurations. Workload protection examines machines and containers. Identity entitlement management spots excessive permissions. Data security posture management locates sensitive information. Other modules cover compliance, APIs, vulnerabilities, Kubernetes, application code, cloud detection and response, and AI systems.

The connective tissue is more important than the checklist. A raw scanner can produce ten thousand findings and congratulate itself. Orca tries to connect them. Is the vulnerable workload reachable from the internet? Can its identity move laterally? Does the path reach a database holding personal information? Has the workload shown suspicious behavior? The graph demotes isolated red badges and elevates combinations with business consequence.

This is why customers span industries rather than one tidy niche. SAP, Autodesk, Gannett, Unity, Lemonade and Digital Turbine appear on Orca’s public roster. Swiggy used it across more than 10,000 containers. Pump, a cloud-cost platform, says compliance preparation fell by roughly half and remediation time dropped 50 to 75 percent after consolidating its view. The precise savings depend on each estate, but the buyer is consistent: a security or cloud team with more assets than patience.

The business is enterprise subscription software. Orca markets one all-inclusive SKU, priced primarily by protected workload count, with credits that can move as a customer’s needs change. There is no public dollar menu; contracts are quote-based. The honest cost calculation therefore includes the people-hours required to deploy agents, reconcile consoles, prepare audit evidence and research vague findings. A lower license that requires three extra tools can be expensive theater.

Visibility was act one

Orca’s funding curve suggests how strongly investors liked the wedge. A $6.5 million seed round in June 2019 was followed by a $20.5 million Series A in May 2020 and a $55 million Series B that December. In March 2021, CapitalG and Redpoint led a $210 million Series C at a $1.2 billion valuation. Seven months later, an extension led by Temasek took the round to $550 million total and the valuation to $1.8 billion.

That money funded a broad platform, international sales and the expensive work of enterprise trust. Orca won AWS Global Security Partner of the Year in 2022 and later obtained FedRAMP Moderate authorization. Its distribution now runs through cloud marketplaces and channel partners, including TD SYNNEX and QBS Software. AWS signed a strategic collaboration agreement with Orca in 2026 focused on AI-powered cloud security. These are procurement achievements as much as technical ones.

Leadership also changed shape. In 2023, Geron moved from chief product officer to CEO while Shua became chief innovation officer. It looked less like a split than a specialization: one founder nearer customers and operations, the other nearer invention. By then the argument had shifted. Simply seeing risk was no longer enough. Customers wanted the last mile - getting the issue fixed.

Orca bought Opus in May 2025 for an undisclosed price. The small automation startup was founded by veterans of Siemplify, the security-orchestration company acquired by Google Cloud. Opus supplied talent and agentic workflow technology intended to move Orca from observation and prioritization toward remediation and prevention. That acquisition is the clearest answer to what changed the company’s mind: the dashboard had become good enough that the unsolved bottleneck moved downstream.

“The answers we get from Orca get straight to the point.”Ham Williams-Tracy, solutions architect at Pump

Now everyone is a builder - and a target

The 2026 product line stretches beyond conventional cloud infrastructure. Orca announced autonomous security agents, runtime AI threat detection and an integration with Claude’s Compliance API. The latter brings Claude Enterprise users, permissions, projects and settings into the same contextual model as cloud resources and identities. The theory is sensible: an AI tool becomes more interesting to security when it can reach a sensitive database or act with an overpowered credential.

In July, Orca announced AI AppGen Security, which discovers applications made by employees on services such as Claude, Supabase and Lovable, and AI Code Security Auditor, a full-repository analysis product meant to identify exploitable code. Both were scheduled for general availability later in 2026. Geron’s neat phrase is that “everyone is a builder now.” The less neat reality is that every improvised app can connect an API, an identity and company data before the security team knows it exists.

This makes Orca more useful and more accountable. Recommending a patch is different from applying one. An autonomous remediation agent can close an exposed port and break a production integration in the same movement. The winning product will need permissions that are narrow, actions that are reversible, approvals matched to risk, and an audit trail legible to humans. Agentless discovery reduced operational friction. Agentic action must not reduce judgment.

Where the approach bendsAgentless-first is strongest in public-cloud estates where a buyer can grant the required API and snapshot permissions. It is not a universal endpoint-security substitute, it may need sensors for richer live runtime behavior, and it fits poorly when most critical systems sit on premises. A tiny team seeking one narrow control may also find a broad platform unnecessary.

The part worth stealing

Orca’s most reusable lesson is not “add AI” or even “go agentless.” It is to find the ritual incumbents have trained buyers to tolerate. The founders saw months of deployment, partial coverage and alert reconciliation described as unavoidable implementation work. They made that pain the architectural brief. Removing it produced faster time to value and a broader dataset; the broader dataset made contextual prioritization possible; prioritization created permission to sell more of the security stack.

01
Delete the hated ritualChoose an operational bottleneck buyers have stopped questioning.
02
Turn convenience into coverageMake lower friction improve the core product, not merely the demo.
03
Correlate before expandingA shared data model makes bundled products feel like one product.
04
Automate only what can be governedAdd approval, reversibility and evidence before autonomous action.

There is a condition attached. The trick works when the platform underneath exposes enough data for a side-door inspection. Cloud providers supply snapshots, APIs and consistent asset metadata. Many industries do not. A startup copying the pattern must identify the enabling infrastructure, the permissions customers will actually grant, and the blind spots its shortcut creates. Convenience without dependable coverage is merely a quicker way to be wrong.

Orca belongs among the broad cloud-security platforms competing with Wiz, Prisma Cloud, CrowdStrike, CloudGuard, Microsoft Defender for Cloud and the native tools from each hyperscaler. Its original distinction remains crisp: inspect widely without installing everywhere, then use one model to show which risks combine into an attack path. The market has adopted much of that vocabulary, so Orca’s future difference will be measured after the alert - in how safely, quickly and cheaply the problem disappears.