Dossier · Private startup · 0 independent sources

Orca Security

Cybersecurity Dual-Use Technology Priority Signal Founded 2019

Last updated: Jul 31, 2026

Orca Security is a privately held cloud-native application protection platform (CNAPP) that combines agentless cloud discovery, contextual risk prioritization, vulnerability and posture management, runtime protection, and guided remediation across multi-cloud and hybrid environments. Its main strategic relevance is defensive cyber resilience for enterprises, regulated operators, and government workloads rather than defense-native mission systems.

Visit Website

Company Overview

Orca Security provides a cloud security platform for AWS, Microsoft Azure, Google Cloud, Kubernetes, and other cloud and hybrid environments. Its foundational SideScanning approach collects cloud configuration and workload data out of band, reducing the need to deploy and maintain a conventional security agent on every asset. The platform has expanded beyond its original posture-management proposition into a CNAPP spanning cloud security posture management, cloud workload protection, entitlement and identity risk, data security posture, vulnerability management, API security, container and Kubernetes security, application and infrastructure-as-code security, compliance, and AI-related cloud controls. Orca Sensor adds runtime visibility and protection for Linux, Windows, Kubernetes, and other critical workloads through an eBPF-based sensor, so the company now combines agentless-first coverage with targeted runtime telemetry rather than relying on a single collection method.

The customer problem is the fragmentation and low actionability of cloud-security findings. Security teams need to understand not only whether a workload is vulnerable or misconfigured, but whether it is reachable, connected to sensitive data, exposed through an identity or API path, and important to the business. Orca's Unified Data Model and attack-path analysis are intended to join those signals and rank risk by severity, accessibility, exploitability, and business impact. This creates a credible workflow advantage when it works: fewer disconnected consoles, less alert fatigue, and more direct routing of fixes into Git, ticketing, and developer workflows. The tradeoff is that the platform's value depends on broad cloud-provider permissions, accurate asset and identity modeling, and customer confidence that contextual prioritization does not hide a low-frequency but consequential risk.

Commercially, Orca is a late-stage private vendor with substantial enterprise scale. The company announced a $550 million extended Series C in 2021 at a reported $1.8 billion valuation, and its current materials describe nearly $630 million in combined funding. Those figures are historical company disclosures rather than a current valuation or proof of present growth. Current public positioning shows continued product expansion into runtime security, AI security, application and API security, and code-to-cloud remediation, alongside a partner-led route to market. LinkedIn lists 201–500 employees and Portland as the primary headquarters, while Orca's own contact page lists additional offices including Tel Aviv, London, Austin, and Bengaluru. This supports a mature private-company classification, but diligence should still request current ARR or growth, retention, gross margin, deployment mix, renewal performance, and the extent to which platform breadth converts into durable adoption rather than module sprawl.

The dual-use case is substantive and unusually concrete for a commercial cybersecurity company. Orca markets a FedRAMP Moderate and GovRAMP-authorized platform, describes deployment in customer-controlled or government-cloud boundaries, and documents government use cases around cloud migration, continuous risk assessment, compliance, and remediation. Its 2021 financing announcement also described a strategic relationship with SAIC for federal cloud-security work. These signals establish public-sector relevance, but they do not make Orca a defense contractor or demonstrate classified, tactical, or weapons-system deployment. The strongest strategic thesis is protection of government, critical-infrastructure, defense-industrial, and other sensitive cloud estates: inventorying rapidly changing assets, finding exploitable paths, detecting runtime behavior, and compressing remediation cycles. The main diligence question is whether authorizations and partner references translate into repeatable government revenue and operational performance in constrained, segmented, or disconnected environments.

Dual-Use Assessment

Military & Commercial Applications

Orca's core technology has substantive defensive-security applicability beyond ordinary commercial SaaS: agentless cloud inventory, attack-path analysis, workload and identity context, runtime detection, and compliance automation can protect government, critical-infrastructure, defense-industrial, and regulated cloud environments. FedRAMP Moderate and GovRAMP positioning, government deployment options, and the documented SAIC relationship strengthen the adjacency. The company is not a defense prime and there is no evidence here of specialized military mission, weapons, ISR, or classified-system capability, so the dual-use thesis is cloud and infrastructure defense rather than defense-native technology.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

Orca remains a credible strategic priority signal for a dual-use cybersecurity database because it operates in a large, budgeted cloud-security category and its core product translates into government and sensitive-infrastructure protection. The strongest evidence is the combination of agentless-first coverage, contextual attack-path prioritization, runtime expansion, FedRAMP/GovRAMP positioning, and public-sector channel relationships. This is not an investment recommendation: the company is mature, privately held, and exposed to intense CNAPP competition. Diligence should test current growth and retention, module adoption, deployment performance, authorization scope, public-sector revenue, and whether its data model produces measurably better outcomes than platform suites and specialist tools.

Strategic Value to U.S.-Israel Alliance

Orca's strategic value is concentrated in cloud visibility and defensive decision support. It can give an operator one risk graph connecting cloud control-plane configuration, identities, workloads, vulnerabilities, APIs, data, code, and runtime events, then route prioritized remediation into existing engineering and security operations systems. That is useful for organizations migrating sensitive workloads faster than their security teams can inventory them, especially where agent deployment is difficult or operationally costly. Government authorizations and flexible deployment claims improve relevance for public-sector buyers, but the strategic assessment should distinguish documented authorization and partner activity from proof of mission-critical, classified, or disconnected-environment adoption.

Key Technologies

  • Agentless SideScanning of cloud configuration and workload block storage
  • Unified cloud security data model
  • Reachability and attack-path analysis
  • eBPF-based runtime sensor for cloud workloads
  • Cloud-native application protection across posture, workload, identity, data, API, and code layers
  • AI-assisted investigation, prioritization, and remediation
  • Cloud, Kubernetes, CI/CD, Git, SIEM, SOAR, and ticketing integrations

Use Cases & Applications

  • Continuous posture and compliance monitoring across AWS, Azure, Google Cloud, and Kubernetes
  • Prioritizing exploitable vulnerabilities by reachability and business impact
  • Discovering exposed APIs, identities, secrets, data stores, and cloud attack paths
  • Runtime detection and response for Linux, Windows, containers, Kubernetes, and virtual machines
  • Tracing production cloud risk back to infrastructure-as-code, images, or source commits
  • Supporting FedRAMP, GovRAMP, CMMC, NIST, and other regulated cloud-control workflows
  • Hardening government, critical-infrastructure, and defense-industrial cloud estates
  • Reducing security-tool sprawl and remediation toil in enterprise DevSecOps programs

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.

This record lists 9 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.