Aqua Security
Container and Kubernetes-native cloud security pioneer combining commercial CNAPP tooling with the widely used open-source Trivy scanner.
Visit Website ↗Overview
Aqua Security was founded in 2015 by Dror Davidoff and Amir Jerbi, dual-headquartered in Boston and Ramat Gan, Israel. Founded before the CNAPP acronym existed, Aqua built its reputation on container and Kubernetes runtime security, spanning pre-deployment scanning, runtime behavioral observation, and policy enforcement that blocks unsafe actions rather than relying purely on static scoring.
Aqua maintains and sponsors Trivy, an open-source vulnerability and misconfiguration scanner that has become a de facto standard embedded in many other vendors’ and open-source tools’ pipelines — an independent-adoption signal distinct from Aqua’s own commercial platform. The company states its commercial platform protects more than 40% of the Fortune 100 and more than 500 large enterprises.
Aqua announced a leadership transition in November 2025, with co-founders Davidoff and Jerbi stepping back from day-to-day roles; no recent (2024-2026) large new funding round was found, suggesting its last major disclosed raise remains the ~$1B-valuation round from 2021.
Innovation Matrix Assessment
Steady incremental releases (Aqua Secure AI, expanded Trivy partner ecosystem) but a slower cadence of category-redefining launches than agentless-native rivals.
Deep, purpose-built container/Kubernetes runtime enforcement plus the widely embedded open-source Trivy scanner give real operational reach beyond Aqua's own paying customer base.
No major new funding round or customer-count milestone found since its ~$1B 2021 valuation; a November 2025 founder leadership transition suggests a maturing rather than hyper-growth phase.
An early and legitimate pioneer of container-native security, but its architecture is not agentless-first, competing as one of several vendors in a category others have redefined.
Trivy's broad independent open-source adoption is a real efficacy signal, but no independent red-team or MITRE-style evaluation of the commercial runtime protection claims was found.
Container and Kubernetes security remains foundational to cloud-native infrastructure, and Trivy's ubiquity keeps Aqua technically relevant.
Why CISOs Should Care
A CISO running containerized workloads gets purpose-built runtime enforcement plus the ability to standardize on Trivy, an open-source scanner already embedded across much of the DevOps tooling ecosystem.
What Makes It Different
Behavioral runtime enforcement — observing what a running container actually does and blocking unsafe actions in real time — rather than relying solely on pre-deployment posture scoring, paired with an open-source scanner with independent adoption well beyond Aqua's own customer base.
The Matrix Verdict
60/100 — INCREMENTAL INNOVATOR
A credible, technically deep container-security specialist whose open-source Trivy footprint gives it real independent validation, scoring in the middle tier here given slower recent momentum and a less disruptive architecture than agentless category leaders.
Editorial Note: Claims vs. Verified Findings
The Fortune 100 and enterprise customer figures are vendor-published and not independently re-verified; Trivy's status as a widely embedded open-source tool and the November 2025 leadership transition were corroborated via Aqua's own newsroom. Current total funding/valuation should be treated as approximate, based on prior reporting of the 2021 round.
Sources
Alternatives to Aqua Security
Wiz
Agentless, graph-based cloud security platform that maps multi-cloud risk end-to-end, now owned by Google after a record $32B…
Chainguard
Provides hardened, minimal, continuously-rebuilt container images and software packages to eliminate vulnerabilities before they reach production.
Microsoft Defender for Cloud
Microsoft's built-in cloud-native application protection platform, unifying CSPM, workload protection, and DevOps security natively across Azure, AWS, and…
Sysdig
The company behind Falco, the CNCF's runtime security standard, offering an eBPF/kernel-level CNAPP built on live syscall-based threat…
Upwind Security
Fast-growing, venture-backed CNAPP startup combining agentless scanning with eBPF runtime sensors for real-time cloud and AI workload risk…
Tenable Cloud Security
An agentless, graph-based cloud identity and posture platform, born as Israeli startup Ermetic, now folded into Tenable's exposure-management…