Aqua Security

Aqua Security is a cloud native security company focused on protecting containerized, Kubernetes-based, serverless, and AI-enabled applications from development through runtime. Its flagship Aqua Platform is a cloud native application protection platform that unifies code, software supply chain, posture, vulnerability, and runtime security so teams can manage risk from build to production across hybrid and multi-cloud environments.

Alongside its commercial platform, Aqua Security develops Aqua Trivy, an open source scanner used for vulnerability, misconfiguration, and infrastructure as code scanning. The company was founded in 2015 and operates from Boston and Ramat Gan. Its portfolio is built for organizations modernizing software delivery and cloud operations while keeping security, compliance, and remediation tightly integrated with developer and platform workflows.

Offerings, Capabilities, and Integrations

Aqua Security delivers lifecycle controls that span scanning, assurance, posture management, runtime protection, and threat detection for cloud native and AI application environments. Its approach combines agent and agentless coverage, policy-driven governance, and runtime telemetry so customers can prioritize exposure, enforce guardrails, and respond to active threats without relying on disconnected point tools.

Aqua Security integrates with container registries, CI/CD systems, Kubernetes environments, serverless services, and operational tooling such as ticketing, alerting, and monitoring platforms. It also supports deployments and workflows across AWS, Microsoft Azure, Google Cloud, and hybrid or multi-cloud environments, helping teams apply consistent controls across varied application stacks.

Products and Services

  • Aqua Platform: A cloud native application protection platform that secures applications from code to cloud with integrated capabilities for software supply chain, posture, vulnerability, and runtime security.
  • Aqua Trivy: An open source scanner for vulnerabilities, misconfigurations, secrets, and infrastructure as code that is designed for fast adoption in developer and DevSecOps workflows.
  • Scanning and Assurance: Universal scanning and assurance policies for source code, images, packages, and other artifacts across the software development lifecycle.
  • Software Supply Chain Security: Controls that protect code, infrastructure as code, build systems, tools, and processes against supply chain risks before they reach production.
  • Vulnerability Management: Code-to-cloud vulnerability prioritization and remediation capabilities that reduce noise and help teams focus on material risk.
  • Container Security: Full lifecycle security for containerized applications with controls that reduce attack surface and enforce protection in production.
  • Cloud Workload Protection (CWPP): Runtime protection for containers, Kubernetes workloads, serverless functions, virtual machines, and AI workloads using layered detection and enforcement.
  • Kubernetes Security (KSPM): Kubernetes security posture management and runtime controls for cluster configuration, compliance monitoring, admission control, and workload protection.
  • Cloud & AI Security Posture Management (CSPM, AI-SPM): Unified posture management for cloud and AI environments that identifies misconfigurations, prioritizes exposure, and supports policy-driven remediation.
  • Dynamic Threat Analysis (DTA): A sandbox-based analysis capability that runs container images before production to uncover hidden malware, suspicious behavior, and other indicators of compromise.
  • CI/CD Pipeline Security: Security controls for DevOps and MLOps pipelines that help catch vulnerabilities and policy violations earlier in the delivery process.

Target Customers

Aqua Security primarily targets enterprises and digitally mature organizations that build and run modern applications on containers, Kubernetes, serverless platforms, and cloud workloads. Its buyers typically span cloud security, platform engineering, DevOps, DevSecOps, and security operations teams that need shared visibility and policy enforcement from code through runtime.

Customer adoption is visible across financial services, government, retail, energy, software, internet services, and other regulated or high-scale sectors. Aqua Security is especially relevant for organizations standardizing on AWS, Microsoft Azure, Google Cloud, or hybrid environments and looking to align software delivery speed with security and compliance requirements.

Cloud Integrations and Marketplace

  • AWS Marketplace: Aqua Security offers the Aqua Cloud Native Application Protection Platform through AWS Marketplace and supports AWS services and runtimes including Amazon EKS, Amazon ECS, AWS Fargate, AWS Lambda, Security Hub, Security Lake, and Secrets Manager.
  • Microsoft Azure Marketplace: Aqua Security has a Microsoft Azure Marketplace presence for its platform and integrates with Azure services including Azure Kubernetes Service, Azure Container Registry, Azure Container Instances, Azure Container Apps, Azure Functions, and Azure DevOps.
  • Google Cloud Marketplace: Aqua Security is available through Google Cloud Marketplace and supports Google Cloud environments including Google Kubernetes Engine, GKE Autopilot, Google Artifact Registry, Google Cloud Functions, and Anthos.

Key People

  • Michael Dube: CEO
  • Matthew Richards: Chief Operating Officer
  • Nir Makovski: Chief Technology Officer
  • Sean McGowan: Chief Revenue Officer
  • Hadas Finkelman: Chief Finance Officer
  • Maayan Arbili: Chief Customer Success Officer
  • Ayelet Hammar: Chief HR Officer
  • Moshe Weis: CISO
  • Tsvi Korren: Field CTO

Key Facts

  • Headquarters: Burlington, Massachusetts, United States; Ramat Gan, Israel
  • Employees: 501-1,000
  • Annual Revenue: Undisclosed
  • Parent Company: None
  • Subsidiaries: Aqua Security Software Inc.; Aqua Security Software India Pvt. Ltd.; Aqua Security Software Singapore PTE. Ltd.
  • Publicly Listed: Privately held

Analyst Recognitions

  • Gartner: 2024 Gartner Market Guide for Cloud-Native Application Protection Platforms (CNAPP): Representative Vendor. 2021 Gartner Innovation Insight for Cloud-Native Application Protection Platforms (CNAPP): Representative Vendor.
Aqua Security

Enter a search