Try our new research platform with insights from 80,000+ expert users
Head - Cybersecurity at a retailer with 1,001-5,000 employees
Real User
Valuable on-demand patching, but the licensing model could be better
Pros and Cons
  • "Their sandboxing service is also really good."
  • "Aqua Security lacks a lot in reporting."

What is most valuable?

The most valuable feature is the on-demand patching. There are times when vulnerabilities don't have available fixes, and Aqua Security allows it to pass the vulnerability in real-time while the fix is being developed.

Their sandboxing service is also really good. When we download an open source tool, we can run it in a sandbox environment and see if there are any back holes or trap doors in the code. However, we don't like that their services are in the US.

What needs improvement?

Aqua Security lacks a lot in reporting. It provides all the open issues, but no actionable solution is provided. There's no intelligence behind the reporting, so that can be improved. Also, it could be a cheaper solution. However, it is costly because it's a very small market and the first of its kind.

Regarding additional features, we would like to see better log ingestion. For example, if we have an EDR or a SOC, we want the SOC, the cloud and the container security to interact better. That means the cloud should have better ingestion of logs and SOC logs and be able to give more heuristic analysis of security issues rather than just ones and zeros.

The licensing model could be better because it has a scalable container environment. If we're working in a small environment, it is fine, but if we have a large environment, we can't predict the traffic for the day. If the marketing team decides to launch a campaign with high traffic, then we won't have licenses available for all our ports. Therefore, the licensing model needs to be rethought, and we can't have per-port licenses because ports can increase.

For how long have I used the solution?

We have been using this solution for over a year. It is a managed service and deployed on cloud.

What do I think about the stability of the solution?

It is a good solution and is stable. Their services are good, and they provide good responses. If there are business-related issues, they will contact you and answer your questions on priority.

Buyer's Guide
Aqua Cloud Security Platform
February 2025
Learn what your peers think about Aqua Cloud Security Platform. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
832,138 professionals have used our research since 2012.

What do I think about the scalability of the solution?

Swisslog and Aqua Security work with a very similar pricing model as they have an agent deployed in a cluster that covers all the containers or namespaces in that cluster. Now, if clusters are also scalable, which is the case in containers, the number of licenses consumed increases.

Aqua Security charges per license. So we usually take their licenses in our testing and QA environment. However, we limit it in the production environment because, in QA testing, our environment expands and collapses because developers are testing. So in production, we can forecast how many licenses we may need in the future.

However, if there is no production system, we cannot account for the number of fraud and containers and we will have to pay through the roof for these solutions because they charge for containers per port for every single agent they deploy.

About 20 to 30 people use Aqua Security from the DevOps and security team. They use the solution because they handle the infrastructure and security.

How are customer service and support?

The technical support is good, and they reply on time.

How was the initial setup?

The initial setup was easy.

What's my experience with pricing, setup cost, and licensing?

I rate the price a four out of ten, with one being a high price and ten being a reasonable price. It is a costly solution.

Which other solutions did I evaluate?

Aqua Security is an on-demand service. Swisslog just launched a product, but it is not as good as Aqua Security in terms of accuracy. Swisslog is integrated with the package and with Aqua Security, you need to pay more for the first scan.

What other advice do I have?

I rate this solution a seven out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior Principal Consultant Cloud/DevOps/ML/Kubernetes at Opticca
Real User
Good technical support and new releases improve usability issues
Pros and Cons
  • "We use Aqua Security for the container security features."
  • "I would like Aqua Security to look into is the development of a web security portal."

What is our primary use case?

We use Aqua Security for the container security features.

How has it helped my organization?

We use Aqua Security across the software development lifecycle.

What is most valuable?

We find the Docker and Kubernetes support for container security most valuable.

What needs improvement?

I would like Aqua Security to look into is the development of a web security portal. That is what I want them to look into next.

For how long have I used the solution?

We have been using the solution for two and a half years.

What do I think about the scalability of the solution?

We have thousands of dedicated users. They are pharmacists, healthcare providers, doctors, insurance companies, etc. They are the end users. On our staff are the administrators.

How are customer service and technical support?

The technical support is good. Whenever we open a ticket, the people are quite helpful about it.

How was the initial setup?

Setup was initially complex before the 3.9 version. We were on version 3.7 and it has been a challenge compared to version 3.11. Deployment was done once or twice in a week.

We are using an in-house regiment. For deployment, we are using automation.

What about the implementation team?

We used a reseller to provide quality. He's the guy who we bought the license from initially. He managed the implementation.

What other advice do I have?

I would rate this product between 7 and 8 out of 10 for container security features.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Aqua Cloud Security Platform
February 2025
Learn what your peers think about Aqua Cloud Security Platform. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
832,138 professionals have used our research since 2012.
reviewer1699062 - PeerSpot reviewer
Sales Engineer at a computer software company with 51-200 employees
Real User
Top 10
Provides workload protection and helps identify security misconfigurations, vulnerabilities, and risks
Pros and Cons
  • "The DTA, which stands for Dynamic Threat Analysis, allows me to analyze Docker images in a sandbox environment before deployment, helping me anticipate risks."
  • "The user interface could be improved, especially in terms of organization and clarity."

What is our primary use case?

I'm using it for workload protection. So, in most cases, for protecting containers, verifying Kubernetes configurations, cloud configurations, and identifying security misconfigurations, vulnerabilities, and risks.

How has it helped my organization?

I use it to demonstrate to customers because I'm a sales engineer. Many customers want to protect their workloads and applications. 

For example, when I am using a Docker image with multiple vulnerabilities, I need to know which vulnerabilities are inside. Then I create security policies to allow or deny the deployment of containers from this image and also create a security policy for runtime. This way, when the application is running in the wild, we can guarantee that the security blocks any kind of exploitation.

What is most valuable?

There are many features that I really like. For example, the runtime policies are very easy to configure, and they are scalable across all environments. The DTA, which stands for Dynamic Threat Analysis, allows me to analyze Docker images in a sandbox environment before deployment, helping me anticipate risks.

What needs improvement?

The user interface could be improved, especially in terms of organization and clarity. Additionally, more comprehensive examples for deployments and feature usage would be helpful.

Maybe more plugins or something that makes it easier to integrate with CICD pipelines or interact with APIs.

For how long have I used the solution?

I've been using it for about three years. I'm using the SaaS version.

What do I think about the stability of the solution?

I would rate the stability an eight out of ten.

What do I think about the scalability of the solution?

It is a scalable solution. I would rate the scalability a ten out of ten. 

How are customer service and support?

The customer service and support are good. 

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup was very straightforward.

What's my experience with pricing, setup cost, and licensing?

For me, it's a fair price.

What other advice do I have?

I would definitely recommend using the solution. It's a very scalable solution with multiple features that help us protect our cloud environment effectively.

Overall, I would rate the solution a nine out of ten. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1991016 - PeerSpot reviewer
Data Scientist at a computer software company with 1,001-5,000 employees
Real User
Strong runtime protection but needs more open documentation, better code analysis
Pros and Cons
  • "The most helpful feature of Aqua Security is Drift Prevention, which is a feature that allows images to be immutable. In addition, one of the main reasons we went with Aqua Security is because it provides strong protection when it comes to runtime security."
  • "Aqua Security could provide more open documentation so that their learning resources can be more easily accessed and searched through online. Right now, a lot of the documentation is closed and not available to the public."

What is our primary use case?

We use Aqua Security for securing our container applications, particularly when it comes to the runtime stage.

There are about five of us from the security side of my company who directly use this solution.

What is most valuable?

The most helpful feature of Aqua Security is Drift Prevention, which is a feature that allows images to be immutable. In addition, one of the main reasons we went with Aqua Security is because it provides strong protection when it comes to runtime security.

What needs improvement?

Aqua Security could provide more open documentation so that their learning resources can be more easily accessed and searched through online. Right now, a lot of the documentation is closed and not available to the public. I would be much happier if they chose to share more documentation and resources when it comes to their knowledge base.

As for extra features that I would like to see, source code scanning is on the top of my list. To be clear, I don't mean code scanning in terms of source code composition, but rather I would like to see more in the way of code analysis that tells you whether the code you're writing adheres to the current best practices or not.

For how long have I used the solution?

I have been using Aqua Security for about a year now.

What do I think about the stability of the solution?

In terms of stability, I would give Aqua Security 4/5 stars.

What do I think about the scalability of the solution?

I would give the scalability a 5/5 stars because it basically scales by itself. It's just the licensing that restricts your usage.

How are customer service and support?

The technical support is sometimes quick and responsive, but at other times it may take a bit longer to get assistance.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

Aqua Security is one of the first solutions I have used for container security, however I have also taken a look at ACS from Red Hat, Snyk, and Prisma from Palo Alto.

We went with Aqua Security mainly because we believe they offer the strongest protection in terms of runtime security.

How was the initial setup?

The setup was a little complex but not too complicated. The difficulty level lies somewhere in the middle between easy and hard.

What about the implementation team?

We implemented Aqua Security mostly by ourselves, but we also took advice from a consultant. Our implementation strategy mainly involved the use of Java forms with manifest files, then we slowly deployed one component at a time.

In all, the basic deployment took just a few hours, but there is always more work to be done afterwards in terms of configuration, integrations, and properly getting started with it in our environment. It's hard to put a number on the hours required, but it probably took a few days to get everything configured and ready to be used.

What's my experience with pricing, setup cost, and licensing?

Dealing with licensing costs isn't my responsibility, but I know that the licenses don't depend on the number of users, but instead are priced according to your workload.

What other advice do I have?

I would rate Aqua Security a seven out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Lizeth Zuluaga - PeerSpot reviewer
Cloud Security Specialist at Telstra
Real User
The most advanced solution in the market for container security
Pros and Cons
  • "Aqua Security helps us to check the vulnerability of image assurance and check for malware."
  • "In the next release, Aqua Security should add the ability to automatically send reports to customers."

How has it helped my organization?

Aqua Security allows us to check for vulnerabilities in the CI/CD pipeline, so application teams can remediate issues before going into production.

What is most valuable?

Aqua Security helps us to check the vulnerability of image assurance and check for malware.

What needs improvement?

In the next release, Aqua Security should add the ability to automatically send reports to customers.

For how long have I used the solution?

I've been using Aqua Security for between two to three years.

What do I think about the stability of the solution?

Aqua Security's stability is very good.

What do I think about the scalability of the solution?

Aqua Security can be scaled up and down depending on your needs.

How are customer service and support?

Aqua Security's technical support is usually quite responsive.

How would you rate customer service and support?

Positive

How was the initial setup?

There were some challenges with the initial setup.

What about the implementation team?

We used an in-house team.

What other advice do I have?

Aqua Security is the most advanced solution in the market for container security. I would rate it as eight out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1699062 - PeerSpot reviewer
Sales Engineer at a computer software company with 51-200 employees
Real User
Top 10
Cloud native security solution used to secure cloud media applications that offers good performance
Pros and Cons
  • "The CSPM product is great at securing our cloud accounts and I really like the runtime protection for containers and functions too."
  • "The integrations on CICD could be improved. If Aqua had more plugins or container images to integrate and automate more easily on CICD, it would be better."

What is our primary use case?

We use this solution to secure cloud media applications that are developed for containers and cloud-native services like ETS, AKS and GCP.

I am the only one using this product in our company.

What is most valuable?

The CSPM product is great at securing our cloud accounts and I really like the runtime protection for containers and functions too. This solution helps us add an extra secure layer to protect applications and the infrastructure.

What needs improvement?

The integrations on CICD could be improved. If Aqua had more plugins or container images to integrate and automate more easily on CICD, it would be better. An integration with WAF would be very good too.

For how long have I used the solution?

I have been using this solution for two years. 

What do I think about the stability of the solution?

This is a stable solution that offers good performance. 

What do I think about the scalability of the solution?

No, this is not a very scalable product. 

How are customer service and support?

In general, the support for this solution is good. It could be improved if it catered for customers in different countries to meet their specific demands. 

How was the initial setup?

The initial setup is a little bit complex for an on-premises deployment. We needed to have many specialized people on Kubernetes to maintain this deployment and keep it up to date. It is a little bit complex because of Kubernetes, not because of Aqua itself, but Aqua have some features to facilitate the deployment.

You need three or four people for the deployment. For a small environment, deployment would take two to three hours. For larger environments, it would take longer than that. 

This is an easy solution to maintain. The main thing is to maintain the databases.

What's my experience with pricing, setup cost, and licensing?

The pricing of this solution could be improved. 

What other advice do I have?

I would recommend this solution to companies have many cloud-native applications.

I would rate this solution a seven out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Technology Director at IPV Network
Real User
Has solid security but the setup is complex
Pros and Cons
  • "The most valuable feature is the security."
  • "Since we are working from home, we would like to have the proper training for Aqua."

What is most valuable?

The most valuable feature is the security. Our clientele cares about the speed of the integration especially if they're doing digital transformation. If you compare it to other container security Aqua is not as caught up in terms of the migration. 

What needs improvement?

We work with another Philippine company that will be providing local support, but our company has more traction with the executives of our clientele. We'd rather have the same skillset or improve our skillsets to be trained by our Aqua counterpart. We haven't done any trainings apart from a webinar. Since we are working from home, we would like to have the proper training for Aqua.

For how long have I used the solution?

I have been using Aqua Security for two years. 

What do I think about the scalability of the solution?

Our client has around 5,000 users. 

How are customer service and technical support?

I'm the person who manages technical support. I have contacted the team in Singapore. They're pretty good. The person who has been helping us is very knowledgable. 

Which solution did I use previously and why did I switch?

We previously used Alcide. Aqua gives us more features and is more solid in terms of security. Aqua is more of a market share leader. There is more of a technology advantage. 

How was the initial setup?

The initial setup was straightforward. We spent around 12 days on the planning during our POC. Planning, testing, and mitigation took around 10-12 days.

What's my experience with pricing, setup cost, and licensing?

Aqua is a bit expensive so you have to really justify going for it or not. 

What other advice do I have?

The deployment should be improved. After this pandemic, half of the workforce has been working from so we need to provide our clients a solution that will have an easier deployment. 

I would rate it a seven out of ten. 

Which deployment model are you using for this solution?

Private Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer: reseller
PeerSpot user
reviewer1078902 - PeerSpot reviewer
Security manager at a tech services company with 11-50 employees
Real User
Solves a lot o problems and is easy to use and manage
Pros and Cons
  • "The most valuable features are that it's easy to use and manage."
  • "They want to release improvements to their product to work with other servers because now there are more focused on the Kubernetes environment. They need to improve the normal servers. I would like to have more options."

What is our primary use case?

Our primary use case is to sequelize all of the ACD and to review the images. 

What is most valuable?

The most valuable features are that it's easy to use and manage.

What needs improvement?

They want to release improvements to their product to work with other servers because now there are more focused on the Kubernetes environment. They need to improve the normal servers. I would like to have more options. 

What do I think about the stability of the solution?

It is stable.

What do I think about the scalability of the solution?

Scalability is pretty good. It's easy to scale. 

In my company, three or four people use this product. 

How are customer service and technical support?

They aren't so good. They don't always follow up with the problems. Support needs improvement, they should be more proactive. They're not always as helpful as we want them to be. 

How was the initial setup?

The initial setup was straightforward. The first time you deploy you, you need support but after that, it's easy to understand the documentation that they provide. After two or three times it's easy. 

It takes around one week to get all of the environments in place but to do a PoC is only two days. 

What other advice do I have?

I would rate it a nine out of ten. 

My advice would be to go for it. This solution solves a lot of problems. I would recommend it. 

Aqua focuses more on Kubernetes and Docker but they don't have the option to have an environment with other servers so I would like for them to provide more options. There should be more integration with the cloud. 

Which deployment model are you using for this solution?

Private Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Buyer's Guide
Download our free Aqua Cloud Security Platform Report and get advice and tips from experienced pros sharing their opinions.
Updated: February 2025
Buyer's Guide
Download our free Aqua Cloud Security Platform Report and get advice and tips from experienced pros sharing their opinions.