Buyer note
Code-to-cloud security in CNAPPs: what nine vendors scan
Cloud Security Compare editors · · Editorial assessment
The short version
Wiz leads our code-to-cloud criterion at 4.6, with Palo Alto Networks Cortex Cloud at 4.5, Orca Security at 4.4 and Aqua Security at 4.2. The vendors that trail, SentinelOne, CrowdStrike and Sysdig, focus on images, workloads or application mapping rather than source code. The scanner lists overlap more than they differ; tracing a cloud finding back to the file and owner is where to test.
What does our code criterion measure?
Code-to-cloud and AppSec carries a 14% weight. It scores software composition analysis, static analysis, infrastructure-as-code, secrets and image scanning, and above all the ability to trace a cloud risk back to the code and owner that caused it. Definitions for each scanner are in our lesson Code security in a CNAPP.
| Vendor | Code score | What the vendor lists |
|---|---|---|
| Wiz | 4.6 | Wiz Code: SCA and SBOM, IaC, secrets and malware scanning, IDE scanning, GitHub integration, an MCP server, ASPM and code-to-cloud tracing |
| Palo Alto Networks Cortex Cloud (formerly Prisma Cloud) | 4.5 | Application security as one of the platform's four pillars, aimed at stopping risk before it reaches production |
| Orca Security | 4.4 | SCM posture, SCA, SAST, secrets, IaC and container image scanning; GitHub, GitLab and Azure DevOps; Jenkins, Bitbucket and CircleCI; cloud-to-code tracing that opens pull requests |
| Aqua Security | 4.2 | Image and repository scanning for vulnerabilities, secrets and misconfigurations; blocks noncompliant artifacts in the pipeline; maintains Trivy |
| Microsoft Defender for Cloud | 3.8 | Code-to-cloud mapping and agentless code-to-cloud container assessment in Defender CSPM |
| Upwind | 3.8 | IaC security, SCA and SBOM, DAST and a container admission controller; SAST not among its listed modules |
| SentinelOne Singularity Cloud | 3.7 | Scans repositories, IaC templates and container images; validates 850+ secret types |
| CrowdStrike Falcon Cloud Security | 3.6 | ASPM mapping business applications onto cloud infrastructure; source-code scanning is not the focus |
| Sysdig Secure | 3.4 | Vulnerability management for images and workloads; source-code scanning not a stated focus on the pages we reviewed |
What do the leaders list?
Wiz (4.6) lists the widest set, in Wiz Code: SCA and SBOM, IaC, secrets and malware scanning, IDE scanning, GitHub integration, an MCP server, application security posture management and code-to-cloud tracing. Orca Security (4.4) lists SCM posture, SCA, SAST, secrets, IaC and container image scanning, integrations with GitHub, GitLab and Azure DevOps and with Jenkins, Bitbucket and CircleCI, and cloud-to-code tracing that opens pull requests. Cortex Cloud (4.5) makes application security one of the platform's four pillars, aimed at stopping risk before it reaches production. Ask Palo Alto Networks for the scanner list in writing, since the pages we reviewed describe the module at a higher level than Wiz's or Orca's pages do.
Where does Aqua's pipeline focus fit?
Aqua Security (4.2) is strongest before deployment. It scans images and repositories for vulnerabilities, secrets and misconfigurations and blocks noncompliant artifacts in the pipeline, and it maintains Trivy, the Apache-2.0 open-source scanner. That makes Aqua the code leader among the container specialists: it scores 0.8 higher than Sysdig here, one of the two criteria Aqua wins in Sysdig vs Aqua.
Why do some platforms score lower?
Microsoft Defender for Cloud and Upwind (3.8 each) cover part of the list. Defender CSPM includes code-to-cloud mapping and agentless code-to-cloud container assessment. Upwind lists IaC security, SCA and SBOM, DAST and a container admission controller, but SAST is not among its listed modules. SentinelOne (3.7) scans repositories, IaC templates and container images and says it validates 850+ secret types. CrowdStrike (3.6) centers on application security posture management, mapping business applications onto cloud infrastructure, rather than on scanning source code. Sysdig (3.4) covers vulnerability management for images and workloads; source-code scanning is not a stated focus on the pages we reviewed.
What should you test?
- Connect the same repositories and CI systems to both products, and check that your source control platform is supported.
- Take one real cloud misconfiguration and one vulnerable image and ask each product to trace them to a file, a commit and an owner.
- Check whether a fix can be opened as a pull request, and whether findings from code and cloud are merged into one item.
- Check where developers see findings: in the IDE, in pull request comments, or only in the security console.
- Ask whether pipeline blocking is included, and how exceptions are approved.
If developers will own most fixes, weight this criterion higher on the score calculator and see how the order changes.
Sources
- Wiz Code wiz.io
- Orca application security orca.security
- Cortex Cloud paloaltonetworks.com
- Aqua platform aquasec.com
- Trivy trivy.dev
- Microsoft Defender for Cloud: cloud security posture management learn.microsoft.com
- Upwind home upwind.io
- SentinelOne Cloud Native Security sentinelone.com
- CrowdStrike Falcon Cloud Security crowdstrike.com
- Sysdig Secure sysdig.com
Related pages
- Code security in a CNAPPThe scanners, defined
- Wiz vs Prisma CloudThe two code leaders head to head
- Sysdig vs AquaPipeline gating against runtime depth
- Score calculatorWeight code higher and re-rank