Skip to content
Wiz logo

Wiz

Verificado

DevOps · www.wiz.io

¿Es tu herramienta? Reclama esta ficha →

Resumen

Wiz is an agentless cloud-native application protection platform (CNAPP) that connects code, cloud infrastructure, and runtime activity into a single security graph so teams can find and prioritize the risks that actually matter across AWS, Azure, GCP, OCI, and Kubernetes. It bundles cloud security posture management, vulnerability and runtime threat detection (Wiz Defend), and developer-facing code security (Wiz Code) into one console. Wiz was acquired by Google/Alphabet in March 2026 but continues to operate and sell as a multi-cloud product independent of Google Cloud.

El problema que resuelve Wiz

Security and platform teams running workloads across multiple clouds often end up stitching together separate tools for posture management, vulnerability scanning, and runtime threat detection, then manually routing findings into SIEM and ticketing systems. Wiz solves this by connecting code, cloud configuration, and runtime signals into one agentless security graph so teams can see and prioritize the risks that matter instead of drowning in disconnected alerts — though buyers report it takes real tuning to avoid alert overload and its workload-based pricing scales quickly for large environments.

Contexto para decidir

Usa estos puntos para comprobar si el producto encaja con tu operación, no solo con la lista de funciones.

  • Precio de entrada publicado: Custom pricing. Confirma límites de usuarios, uso y funciones por plan.
  • Despliegue: cloud. Comprueba requisitos de seguridad, residencia de datos y acceso para todos los equipos que lo utilizarán.
  • Integraciones verificadas: AWS (EventBridge, S3, CloudTrail Lake, Security Hub), Microsoft Azure, Google Cloud Platform, GitHub, GitLab, Jenkins. Valida el sentido de sincronización y los límites del plan elegido.
  • La ficha se comprobó por última vez el 31/7/2026; los precios y las funciones pueden cambiar.

Cómo evaluar Wiz

Una ficha ayuda a crear una lista corta; una prueba con el flujo real del equipo decide si la herramienta encaja. Usa esta lectura junto con los datos estructurados y confirma cualquier cambio con el proveedor.

Encaje de flujo

El registro la considera especialmente adecuada para Multi-cloud enterprises (AWS/Azure/GCP/OCI/Kubernetes) that need agentless, unified visibility across code, cloud, and runtime, Security teams that want automated vulnerability and misconfiguration prioritization without deploying agents across every workload, Organizations that must hit strict compliance frameworks (FedRAMP High, HIPAA, PCI DSS) quickly, since Wiz ships mapped compliance reporting. Comprueba que ese contexto coincide con el volumen, los roles y los procesos que debe soportar tu equipo.

Preguntas del piloto

  • ¿Puede Wiz completar el flujo crítico sin trabajo manual fuera de la herramienta?
  • ¿Las conexiones registradas (AWS (EventBridge, S3, CloudTrail Lake, Security Hub), Microsoft Azure, Google Cloud Platform, GitHub) cubren el sentido de sincronización, los permisos y el volumen que necesitamos?
  • ¿Qué límites de usuarios, uso, almacenamiento, soporte o seguridad aparecen después del precio inicial?

Evidencia y vigencia

Esta ficha se comprobó el 31/7/2026. La fecha indica cuándo se revisó el registro, no una garantía de que el proveedor no haya cambiado sus condiciones después.

Ideal para

  • Multi-cloud enterprises (AWS/Azure/GCP/OCI/Kubernetes) that need agentless, unified visibility across code, cloud, and runtime
  • Security teams that want automated vulnerability and misconfiguration prioritization without deploying agents across every workload
  • Organizations that must hit strict compliance frameworks (FedRAMP High, HIPAA, PCI DSS) quickly, since Wiz ships mapped compliance reporting

No encaja si

  • Small teams or startups with tight budgets — buyer-guide data (Vendr) puts median annual contracts around $150K, and pricing scales with workload count
  • Teams wanting one tool for general observability, log management, or APM — Wiz integrates with (rather than replaces) tools like Datadog, Splunk, and Snowflake for that

Por qué está listada

  • Independently verified 4.7/5 rating across roughly 770 G2 reviews and 'Top Rated' status on TrustRadius (34 reviews), plus recognition as G2's #1 CDR vendor.
  • Real, checkable enterprise adoption (65%+ of Fortune 100 per Wiz's own site) and a concrete published AWS Marketplace price point for its SMB bundle, not just marketing claims.

Precios

Wiz Go Bundle (SMB)

$74,000 per year (AWS Marketplace 36-month list price)

All-in-one bundle built for small teams, covering code through runtime in a single package.

  • 300 Cloud Advanced workloads
  • 150 Defend Ingestion Units (GB)
  • 100 Runtime Sensors
  • 50 Code Active Developers per month
  • Bundles Wiz Cloud, Wiz Code, Wiz Defend, and Wiz Sensor

Wiz Cloud

Custom pricing

Core CNAPP module for cloud infrastructure and data security posture.

  • Agentless cloud misconfiguration and posture scanning
  • Vulnerability and identity risk prioritization
  • Data security posture management (DSPM)
  • Compliance framework mapping

Wiz Code

Custom pricing

Developer-facing security from IDE through CI/CD pipelines.

  • IaC and code scanning
  • CI/CD pipeline integration
  • AI-generated automated code fixes (Wiz Green agent)

Wiz Defend

Custom pricing

Cloud detection and response for runtime threats.

  • Runtime threat detection
  • Automated threat hunting/investigation (Wiz Blue agent)
  • SIEM/SOAR integration for response workflows

Wiz Sensor

Custom pricing

eBPF-based runtime sensor add-on for deeper workload-level telemetry.

  • eBPF runtime sensor deployment
  • Feeds Wiz Defend's detection engine

Funciones

AI featuresShips three named AI agents (Wiz Green for automated code-fix generation, Wiz Red for automated pentesting, Wiz Blue for automated threat hunting/investigation) per Wiz's own site.
Alerting & on-callWiz surfaces findings and routes them into on-call tools it integrates with (PagerDuty, Opsgenie, Slack, Teams) rather than acting as a standalone on-call/paging system itself.
Application performance monitoring (APM)Wiz is a security platform, not an APM tool; it integrates with Datadog rather than providing performance monitoring itself.
CI/CD pipelinesWiz Code plugs into CI/CD (GitHub, GitLab, Jenkins, CircleCI, Azure DevOps, AWS CodeBuild, Harness, etc.) for pre-deployment IaC and code scanning.
Distributed tracingNo distributed tracing capability found; not part of Wiz's stated product scope.
Incident managementWiz Defend does runtime threat detection and response and integrates with incident tools (Rootly, PagerDuty, Cortex XSOAR), but is not a general-purpose incident management system.
Infrastructure monitoringProvides agentless cloud infrastructure visibility and risk/security monitoring, but not general performance/infra monitoring — that's left to integrated tools like Datadog.
Log managementWiz Defend ingests logs (billed as 'Ingestion Units') for threat detection, but is not a general-purpose log management platform; integrates with Splunk, Sumo Logic, and Datadog for that.
Public APIPublishes a documented GraphQL API (api.<tenant>.app.wiz.io/graphql) with OAuth2 service-account auth, cursor-based pagination, and a Postman collection, per Wiz support docs.
Self-hosting / on-premWiz is a SaaS-only, agentless platform; no self-hosted/on-premise deployment option was found.

Integraciones

AWS (EventBridge, S3, CloudTrail Lake, Security Hub)Microsoft AzureGoogle Cloud PlatformGitHubGitLabJenkinsSplunkDatadogMicrosoft SentinelSlackPagerDutyJiraServiceNowHCP TerraformSnowflake

Seguridad y cumplimiento

SOC 2 Type IISOC 3ISO 27001ISO 27017ISO 27018ISO 27701PCI DSS v4.0.1HIPAAFedRAMP HighCSA STAR

Pros y contras

Pros

  • Agentless deployment with fast onboarding — AWS Marketplace reviewers describe setup taking only a few minutes with full cloud visibility in one console
  • Strong G2 scores for ease of setup (9.1) and quality of support (9.2), with reviewers citing actionable risk prioritization that cuts alert noise
  • Broad integration ecosystem spanning SIEM, SOAR, ticketing, and CI/CD tools so findings route directly into existing workflows

Contras

  • Pricing scales by workload/ingestion volume and can get expensive quickly in large or hybrid environments (Vendr: annual contracts ranging $29,826–$536,300)
  • The breadth of features and a powerful but complex search/query engine create a real learning curve; some reviewers say it's hard to extract full value without tuning
  • Reviewers note gaps in real-time coverage — Wiz relies on periodic scans, with near-real-time updates limited to a subset of cloud services

Qué muestra el registro

4.7/5
770 reviews agregadasÚltima comprobación 2026-07-31

G2 shows a 4.7/5 average across roughly 770 reviews and named Wiz the #1 Cloud Detection and Response (CDR) vendor in its Winter 2025 Grid Report; TrustRadius lists Wiz as 'Top Rated' in Cloud Computing Security with 34 reviews.

Resumen y puntuación agregados de plataformas públicas de reseñas. Enlazamos a las reseñas originales en lugar de reproducirlas — lee la fuente antes de decidir.

Reseñas de usuarios

Escritas por cuentas de Audyense · moderadas antes de publicarse

Todavía no hay reseñas de usuarios.

¿Has usado Wiz? Sé el primero en contarles a otros compradores qué funcionó de verdad.