Orca Security
By Orca Security
The typical implementation process for Orca Security software is designed to be straightforward and efficient, allowing organizations to quickly secure their cloud environments. Here is a step-by-step overview of the process:
Initial Setup: The process begins with the creation of an Orca Security account and connecting your cloud environments (AWS, Azure, Google Cloud) to the Orca platform. This is done through a simple onboarding process that requires read-only access to your cloud accounts.
SideScanning™ Deployment: Orca's patented SideScanning™ technology is deployed to scan your entire cloud estate. This agentless approach ensures that there are no performance hits or manual updates required.
Asset Discovery and Enumeration: Orca automatically discovers and enumerates all cloud assets, including virtual machines, containers, storage buckets, databases, and serverless applications.
Control Plane and Data Plane Analysis: The platform performs a thorough analysis of both the control plane and data plane, identifying vulnerabilities, misconfigurations, and compliance issues.
Risk Prioritization and Remediation: Orca provides contextual security insights and prioritizes risks based on their potential impact. This allows security teams to focus on the most critical issues first.
Continuous Monitoring and Reporting: The platform continuously monitors the cloud environment for new risks and provides detailed reports and dashboards for ongoing security management.
The entire implementation process typically takes a few hours to a couple of days, depending on the size and complexity of the cloud environment.
Orca Security offers extensive customization options to fit specific business needs. The platform's Automation & Customization feature allows organizations to prioritize, customize, and integrate alerts into existing workflows. This includes creating custom queries and alerts, automating ticketing with partner integrations, and setting up compliance control rules for various frameworks. Orca's simple query language enables users to create powerful contextual queries without any development experience, ensuring that the platform can be tailored to meet unique security requirements.
Orca Security's pricing is primarily based on an annual subscription model, determined by the average number of workloads scanned. There are no additional setup fees, and the platform does not charge extra for cloud storage or databases. Maintenance and support are typically included in the subscription cost, ensuring that customers receive continuous updates and support without incurring extra charges.
Orca Security offers comprehensive training and support to new users. This includes:
Training Programs: Orca offers both in-person and online training sessions tailored to different user needs. These sessions cover various aspects of the platform, from basic usage to advanced security features.
Documentation and Resources: Extensive documentation, including user guides, tutorials, and best practices, is available to help users get the most out of the platform.
Orca Security employs robust security measures to protect data, including:
Encryption: All data is encrypted both in transit and at rest using industry-standard encryption protocols.
Access Controls: Orca implements strict access controls to ensure that only authorized personnel can access sensitive data.
Continuous Monitoring: The platform continuously monitors cloud environments for security threats and vulnerabilities, providing real-time alerts and automated remediation.
Orca Security releases updates regularly to ensure the platform remains secure and up-to-date with the latest features and improvements. These updates are managed seamlessly through the platform's cloud-native architecture, which allows for automatic deployment without requiring manual intervention from users. This approach ensures that all customers benefit from the latest enhancements and security patches as soon as they are available.
Orca Security's policy on data ownership is clear: customers retain full ownership of their data. The platform is designed to ensure that data is portable, allowing customers to export their data at any time. This ensures that organizations can maintain control over their data and move it as needed, whether for compliance reasons or to integrate with other systems. Orca also adheres to strict data protection standards, ensuring that customer data is handled securely and in compliance with relevant regulations.
Orca Security offers flexible terms for scaling up or down based on organizational needs. The platform's pricing is based on the average number of workloads scanned, allowing organizations to adjust their subscription as their cloud environment grows or shrinks. This flexibility ensures that businesses can scale their security coverage without incurring unnecessary costs. Additionally, Orca's agentless architecture makes it easy to add or remove cloud assets without disrupting operations.
Orca Security's contracts typically renew automatically for equal terms unless either party provides written notice of termination at least 30 calendar days before the expiration of the current term. This notice can be given via mail or email. If the contract is not terminated within this period, it will automatically renew for another term of the same length. Upon termination, the customer must cease using the platform, and Orca will delete or return all customer data as per the agreement.
Orca Security meets a wide range of compliance standards to ensure robust security and regulatory adherence. The platform supports over 150 compliance frameworks and CIS benchmarks, providing continuous compliance checks across cloud workloads, configurations, identities, and data. Some of the key compliance standards Orca adheres to include:
PCI DSS: Payment Card Industry Data Security Standard, which ensures secure handling of credit card information.
Orca's comprehensive compliance tools help organizations maintain continuous compliance and reduce the risk of regulatory breaches.