

Imperva Application Security Platform and Orca Security both compete in the web application protection space. Based on the data comparisons, Orca Security may have the upper hand due to its innovative agentless architecture and ease of cloud integration, despite some room for improvement.
Features: Imperva offers a comprehensive suite focused on DDoS and WAF, extensive configuration options, and ease of use without requiring HTTP knowledge. Orca Security features agentless architecture, cloud-native application protection, and seamless CI/CD pipeline integration, providing automated scanning, vulnerability prioritization, and resource efficiency.
Room for Improvement: Imperva users suggest enhancements in the GUI, user-specific policy applications, false positive reduction, analytics depth, and bot protection. Orca Security could benefit from a simpler alert monitoring dashboard, improved non-standard ticketing system integration, more automation for remediation, and user education on platform updates.
Ease of Deployment and Customer Service: Imperva is versatile, supporting on-prem, cloud, and hybrid environments, although response times vary, especially on-prem. Orca Security excels in cloud deployment, with excellent support responsiveness but lacks broader on-prem support, which could limit companies with significant on-prem infrastructures.
Pricing and ROI: Imperva can be costly with expenses tied to specific features and environments, leading to higher investments for broader coverage with ROI in threat prevention and compliance. Orca Security's competitive pricing in its niche is workload-based, providing value through comprehensive security insights that justify the investment.
They know how much money they are losing while the system is down, so by increasing the possibility of not having a down website or web application, return on investment can be calculated easily.
I was able to save over seven million dollars last year as return on investment in the company.
I have seen a return on investment with Imperva Application Security Platform, as it is generally associated with time savings, because the review of alerts and the visibility it gives saves us significant operational time.
Orca Security significantly improved our visibility from 30% to 100%, enabling better security posture improvements rather than just general cost savings.
This is because you do not need a team of five persons to install and update the agents in thousands of servers.
I see the benefits of Orca Security immediately because you can see the issues right after deployment, and you can correct the critical issues, so the proof of value is immediate.
I would rate the technical support of Imperva DDoS as ten.
They need to work faster on the response time because of issues of urgent replies.
Responsive support addressing urgent needs.
I would rate the quality of support as nine stars out of ten due to their quick and helpful responses.
The expertise levels could be improved.
The support team assists with issues and provides information on new updates.
99% of customers are using the cloud version of Imperva DDoS protection, so they just purchase the new license and scale as needed.
I have not even needed support after deployment, since it has remained stable.
It is easy to always scale to add more users.
Orca Security provides a highly scalable architecture for us.
The main limitation was that the findings were often siloed because they are different platforms.
When you onboard an organization, Orca will find new projects, folders, and resources without any additional effort required.
It is also a stable product without much glitch or downtime.
One notable drawback is that, unlike Fortinet, which offers fast track labs and continuous enablement, Imperva Application Security Platform lacks lab access and fast track labs for enablement and product advertising.
We experienced downtime or crashes with Imperva Application Security Platform when traffic went really strong or fast because people tried to get tickets.
When I need any support, it's very fast to get an answer from the support team.
The agentless part of it and the fact that it integrates directly with a cloud provider such as AWS helps to reduce operational overhead and potential points of failure that come with managing agents across multiple systems.
I personally have not encountered any bugs or issues with the console.
To convince my clients, a purely on-prem solution would be ideal since they are financial institutions.
Maybe Imperva DDoS could use endpoints to get information about the attacks before they commence from the endpoint level or establish cooperation with endpoint vendors to share this information.
Regarding return on investment, ROI, I can say it is noticeable with Imperva Application Security Platform.
Another improvement is in handling alerts for multiple files with the same CVE; it should provide an option to manage each file separately without affecting others.
Orca Security could improve in reporting OS package vulnerabilities, such as missing MS patches or Linux patches.
Security in today's age is important, and if a company can afford it, they should get it as it's the most valuable protection against threats.
I would rate the pricing of Imperva DDoS as five, where one is very cheap and ten is very expensive.
the setup cost was high, with the hardware installation in the data center being particularly expensive.
We have noticed faster response times and fewer security alerts because after doing some custom policy tuning, everything seemed to be aligned and we have fewer attacks to monitor and fewer alerts to monitor.
The initial price seemed high, however, after negotiation, the final price was ideal.
Orca Security's pricing is known to be a bit high.
Its license is a bit expensive.
The API security feature is particularly valuable because most attackers do not try to come in from where it is expected.
If someone attempts to access the server, the WAF blocks that SSRF alert, or RCE, Remote Code Execution alert, blocking immediately based on the signature, not only by the payload or the IP address.
It reduces the DDoS attacks and reduces the attacks from threat actors, including SQL Injection and zero-day attacks, by using dynamic application profiling from Imperva.
Additionally, it covers a large scope of vulnerabilities, CVEs, malware, and misconfiguration.
It provided us with visibility from a central point, increasing our view from the previous thirty percent to a full one hundred percent of our cloud environment.
This technology allows for coverage of almost all cloud assets without interrupting their operations.
| Product | Mindshare (%) |
|---|---|
| Imperva Application Security Platform | 9.5% |
| Orca Security | 5.7% |
| Other | 84.8% |

| Company Size | Count |
|---|---|
| Small Business | 88 |
| Midsize Enterprise | 25 |
| Large Enterprise | 70 |
| Company Size | Count |
|---|---|
| Small Business | 18 |
| Midsize Enterprise | 9 |
| Large Enterprise | 16 |
Imperva Application Security Platform delivers comprehensive and continuous web threat protection. Renowned for its ease of use, it shields web applications and databases from various cyber threats while integrating seamlessly with cloud and on-premises environments.
Imperva Application Security Platform protects web environments by offering advanced security measures against threats like DDoS attacks, SQL injections, and cross-site scripting. As a robust web application firewall, it provides extensive monitoring and bot management capabilities. The platform integrates content delivery networks for enhanced performance and scalability, while real-time traffic analysis ensures consistent protection. Despite its strengths, improvements can be made in policy management and customization options. Users seek better integration with third-party tools and more competitive pricing models. The inclusion of AI for enhanced analytics is also anticipated.
What are the key features of Imperva Application Security Platform?Imperva Application Security Platform is implemented in industries needing strong database and application protection. Companies use it to enforce geolocation restrictions and manage bots, benefiting sectors like finance and e-commerce where data security and threat monitoring are critical. Its ability to protect and ensure data accessibility makes it integral to business operations prioritizing cyber resilience.
Orca Security provides comprehensive security management with agentless visibility and SideScanning technology, ensuring efficient threat detection without performance impact.
Orca Security offers agentless visibility across multi-cloud environments, streamlining security management with features like SideScanning technology and centralized security tools. It focuses on automation, vulnerability management, and compliance checks, enhancing a company's security posture with real-time alerts and integrated threat detection. Its intuitive interface prioritizes critical issues, making it suitable for managing DevSecOps processes efficiently.
What are the key features of Orca Security?
What benefits and ROI should companies look for in Orca Security?
Companies in industries such as finance, healthcare, and technology leverage Orca Security for cloud security posture management, ensuring compliance with standards and securing applications and databases. Its agentless approach provides comprehensive visibility across AWS, GCP, and Azure, enhancing risk assessment and vulnerability management without impacting asset performance.
We monitor all API Security reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.