Cloud Security Compare

How to read these cloud security comparisons

Cloud Security Compare editors · Matchups reviewed September 2026 · Editorial assessment

The short version

Every vendor gets a 0 to 5 score on seven criteria, each with a one-line reason. Totals are weighted averages computed from published weights, ties are shown as ties, and each head-to-head draws one tug-of-war bar per criterion. The scores are an editorial assessment of public vendor material, not the result of hands-on testing.

What does a tug-of-war bar show?

Runtime protection depth: Orca 3.8, Upwind 4.7. Upwind stronger by 0.9.OrcaUpwind3.84.7evenUpwind +0.9
Figure 1. Upwind is stronger on runtime by 0.9, so the marker sits well toward Upwind.

The left vendor is the first name in the page title. The marker starts at the center and moves toward the stronger vendor. A gap of 1.5 points or more pins it to the end. The label above the marker names the stronger vendor and the size of the gap. Under every bar are the two reasons behind the two scores, so you can disagree with a specific judgement rather than with a total.

Which seven criteria do we score?

The seven criteria, their weights and what we look for.
CriterionWeightWhat we look for
Agentless coverage and time to value18%How much of the estate (VMs, containers, serverless, PaaS, AI services) is visible without installing anything, across how many clouds, and how fast.
Runtime protection depth16%Detection and prevention inside running workloads: sensor technology, blocking, investigation, response.
Risk prioritization and attack paths18%How findings are correlated into exploitable paths and ranked, so teams fix the few things that matter.
Code-to-cloud and AppSec14%SCA, SAST, IaC, secrets and image scanning, and tracing a cloud risk back to the code and owner that caused it.
AI workload security12%Inventory and posture for models, AI services, pipelines, agents and MCP servers, plus runtime detection for AI-specific threats.
Ecosystem and integrations12%Integrations, partner and marketplace reach, platform breadth around the CNAPP, and market footprint.
Pricing transparency10%Whether a buyer can model cost from public material before talking to sales.

What do the numbers mean?

What each score band means in this rubric.
ScoreMeaning
4.5 to 5.0Leading. A buyer comparing on this criterion would shortlist it.
4.0 to 4.4Strong. Covers the criterion well with a named gap.
3.5 to 3.9Adequate. Present, but narrower or tied to an add-on or another product.
2.0 to 3.4Partial. Exists in limited form or only as a published unit without prices.
0 to 1.9Minimal. For pricing, 1.5 means quote only.

How are totals and ties handled?

Total = sum of (score x weight) / 100, computed in code from the data on the matrix page, never typed by hand. We sort by the exact value and show one decimal. When two displayed totals are equal we show a tie (for example, 3=). On a head-to-head, a criterion where both vendors have the same score is counted as tied and the marker sits at the center.

Where does the evidence come from?

Vendor product pages, documentation, pricing pages and press releases, fetched and reviewed in September 2026. Each comparison lists its sources under the fact table. Vendor claims such as detection times, noise reduction percentages or customer counts are attributed to the vendor and are not our measurements. Where a vendor does not publish a detail, we write "Not published" and score conservatively.

What are the limitations?

Limitations

  • Public sources only. We did not run the products, attend demos or interview vendors.
  • Marketing pages describe capabilities, not how well they work in a specific environment. Use these comparisons to decide what to test in a proof of concept, not as the result of one.
  • Scores are a snapshot. Vendors ship quickly; we re-review every vendor at least once a quarter and date every page.
  • Weights reflect a general multicloud buyer. A Kubernetes-heavy team would weight runtime higher; an Azure-only team would weight pricing and ecosystem differently.

How do I report an error?

Email editors@cloudsecuritycompare.com with the page, the claim and a public source. We check corrections within five business days and note material changes on the page.

Frequently asked questions

Are these scores based on testing?

No. They are an editorial assessment of public vendor material, reviewed in September 2026. We did not run the products.

Why are the weights not equal?

Buyers weigh coverage and prioritization more heavily than pricing when choosing a CNAPP, so those criteria carry 18% each and pricing transparency 10%. The weights are published so you can apply your own.

Why is the left vendor on the left?

It is the first vendor named in the page title. The order says nothing about which vendor is stronger.