Aqua provides a Cloud‑Native Application Protection Platform that secures container, serverless, VM, and Kubernetes workloads across hybrid and multi‑cloud environments. The platform combines static and dynamic scanning, software‑supply‑chain verification, runtime protection, and cloud‑security posture management into a single console with CI/CD integration and automated compliance reporting.
Funding
$60M raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.





Founders
Product
Problem
Enterprises adopting containers, serverless functions, and multi‑cloud workloads face fragmented security controls, invisible supply‑chain vulnerabilities, and runtime threats that are difficult to detect and remediate without slowing development pipelines.
Solution
Aqua delivers a unified Cloud‑Native Application Protection Platform (CNAPP) that secures applications from code commit through production. The platform combines agent‑based and agentless scanning, software‑supply‑chain assurance, and AI‑enhanced runtime protection into a single console. Integrated posture management provides continuous visibility across Kubernetes, VM, and serverless environments in hybrid and multi‑cloud deployments. Automated policy enforcement and compliance reporting enable DevSecOps teams to embed security into CI/CD pipelines without manual overhead. All findings are correlated and prioritized, allowing security operations to respond to threats in real time while maintaining development velocity.
Target Audience
The primary customers are enterprise DevSecOps teams and security operations centers that manage containerized, serverless, and VM workloads across hybrid and multi‑cloud environments, particularly in regulated industries such as finance, healthcare, and government.
Features
- Trivy‑powered static and dynamic scanning that inspects container images, IaC templates, and serverless code for known CVEs, misconfigurations, and AI‑specific risks.
- Software supply‑chain security that validates dependencies, build pipelines, and third‑party artifacts against provenance and SBOM data.
- Runtime workload protection (CWPP) with behavior‑based detection, threat intelligence feeds, and prompt‑injection safeguards for AI workloads.
- Cloud Security Posture Management (CSPM) that aggregates configuration data from AWS, Azure, GCP, and on‑premise platforms, delivering risk scores and automated remediation.
- Kubernetes and OpenShift hardening modules that enforce pod security standards, network policies, and RBAC best practices at scale.
- Seamless CI/CD integration via native plugins for Jenkins, GitLab, GitHub Actions, and Tekton, enabling shift‑left security checks.
- Centralized compliance dashboards supporting PCI‑DSS, HIPAA, GDPR, and FedRAMP controls with audit‑ready reporting.
- Extensible API and pre‑built integrations with major registries, secret managers, and SIEM solutions for end‑to‑end workflow automation.