FortiCNAPP is a comprehensive cloud security platform focusing on ease of use and machine learning-driven anomaly detection. It offers robust compliance reporting, seamless integration, and continuous monitoring, making it an essential tool for organizations managing multi-cloud environments and security configurations.

| Product | Mindshare (%) |
|---|---|
| FortiCNAPP | 1.8% |
| Wiz | 5.5% |
| Qualys VMDR | 4.4% |
| Other | 88.3% |
| Title | Rating | Mindshare | Recommending | |
|---|---|---|---|---|
| Cloudflare | 4.3 | N/A | 96% | 79 interviewsAdd to research |
| SentinelOne Singularity Cloud Security | 4.3 | 2.6% | 99% | 120 interviewsAdd to research |
| Company Size | Count |
|---|---|
| Small Business | 5 |
| Midsize Enterprise | 3 |
| Large Enterprise | 4 |
| Company Size | Count |
|---|---|
| Small Business | 128 |
| Midsize Enterprise | 68 |
| Large Enterprise | 198 |
FortiCNAPP provides significant capabilities in cloud security, compliance, and vulnerability management. Designed for organizations needing efficient monitoring, it enables detection of anomalies across cloud infrastructures while optimizing security posture and ensuring compliance with environments like AWS and GCP. The platform offers in-depth insights through scanning of IAC scripts, host systems, and cloud configurations. Recognized for effectively managing security posture, it safeguards Kubernetes and container environments, providing comprehensive threat detection and response. However, some areas like visibility, IAM security controls, and compliance metrics need improvement. Users face challenges with alert setup and lack intuitive design, alongside issues like FedRAMP authorization absence and complexity in the data model.
What are the key features of FortiCNAPP?FortiCNAPP is implemented extensively by industries needing reliable cloud security, such as finance, healthcare, and technology sectors. It supports organizations in enhancing cloud infrastructure protection, ensuring compliance, and strengthening vulnerability management. By integrating with platforms like AWS and GCP, businesses can optimize security posture in their cloud deployments.
FortiCNAPP was previously known as Polygraph, FortiCNP, Lacework.
J.Crew, AdRoll, Snowflake, VMWare, Iterable, Pure Storage, TrueCar, NerdWallet, and more.
| Author info | Rating | Review Summary |
|---|---|---|
| Client Manager at MLL Telecom Ltd | 4.5 | I find FortiCNAPP a robust, competitive solution for network access control, offering strong segmentation and automated responses, backed by great support and pricing. My main wish is for a more intuitive and user-friendly interface. |
| Software Engineer at a university with 5,001-10,000 employees | 3.0 | I use Lacework FortiCNAPP for security, valuing its ML threat detection and automated policies. However, its UI, vulnerability management, scalability, and integrations need major improvement; initial setup is complicated. It has a long way to go. |
| Owner at IT CARE | 4.5 | I find FortiCNAPP a reliable and affordable security solution, saving time with good support. While policy implementation is complex and stability takes time, its benefits lead me to rate it 9/10. |
| Cloud security director at Medallia | 4.5 | Lacework significantly reduces our alert noise, providing quick visibility across our hybrid environment and saving us money. It frees up resources and improves our security posture, despite needing better SIEM integrations. |
| Techology Operations Lead at a computer software company with 11-50 employees | 5.0 | I primarily use Lacework for compliance and security insights, valuing its multi-standard reporting and continuous monitoring. However, communication around changes needs improvement. Despite this, it offers a significant ROI by reducing manpower requirements. |
| Director of Security Operations at a insurance company with 51-200 employees | 3.5 | I value this tool for vulnerability management, especially its mature cloud compliance and agent's active package scanning. However, I find data extraction difficult due to a poor data model and limited reporting, though support is good. |
| Senior Manager at a educational organization with 10,001+ employees | 2.5 | We use Lacework for monitoring security vulnerabilities in the cloud, particularly AWS. While it effectively identifies vulnerabilities and monitors configurations, it's complex and not intuitive. We've seen no ROI and are considering switching due to slow scanning and high alert volume. |
| VP of Engineering Security at a tech services company with 201-500 employees | 4.0 | I find Lacework valuable for anomaly detection and security compliance, with effective severity prioritization and continuous AWS monitoring. However, the lack of FedRAMP moderate authorization limits its use in government environments, leading to potential challenges requiring multiple tools. |