Skip to content
Wiz logo

Wiz

Verified

DevOps · www.wiz.io

Is this your tool? Claim this listing →

Overview

Wiz is an agentless cloud-native application protection platform (CNAPP) that connects code, cloud infrastructure, and runtime activity into a single security graph so teams can find and prioritize the risks that actually matter across AWS, Azure, GCP, OCI, and Kubernetes. It bundles cloud security posture management, vulnerability and runtime threat detection (Wiz Defend), and developer-facing code security (Wiz Code) into one console. Wiz was acquired by Google/Alphabet in March 2026 but continues to operate and sell as a multi-cloud product independent of Google Cloud.

The problem Wiz solves

Security and platform teams running workloads across multiple clouds often end up stitching together separate tools for posture management, vulnerability scanning, and runtime threat detection, then manually routing findings into SIEM and ticketing systems. Wiz solves this by connecting code, cloud configuration, and runtime signals into one agentless security graph so teams can see and prioritize the risks that matter instead of drowning in disconnected alerts — though buyers report it takes real tuning to avoid alert overload and its workload-based pricing scales quickly for large environments.

Decision context

Use these points to test whether the product fits your operation, not just whether it has a long feature list.

  • Published starting price: Custom pricing. Confirm user, usage, and feature limits for the plan you would actually buy.
  • Deployment: cloud. Check security, data-residency, and access requirements for every team that will use it.
  • Verified integrations include AWS (EventBridge, S3, CloudTrail Lake, Security Hub), Microsoft Azure, Google Cloud Platform, GitHub, GitLab, Jenkins. Validate sync direction and plan limits for the connections that matter.
  • This record was last checked on 7/31/2026; pricing and features can change.

How to evaluate Wiz

A listing helps create a shortlist; a trial with the team’s real workflow decides whether the tool fits. Use this reading with the structured facts and confirm changes with the vendor.

Workflow fit

The record describes it as a fit for Multi-cloud enterprises (AWS/Azure/GCP/OCI/Kubernetes) that need agentless, unified visibility across code, cloud, and runtime, Security teams that want automated vulnerability and misconfiguration prioritization without deploying agents across every workload, Organizations that must hit strict compliance frameworks (FedRAMP High, HIPAA, PCI DSS) quickly, since Wiz ships mapped compliance reporting. Check that this context matches the volume, roles, and processes your team needs it to support.

Pilot questions

  • Can Wiz complete the critical workflow without manual work outside the product?
  • Do the recorded connections (AWS (EventBridge, S3, CloudTrail Lake, Security Hub), Microsoft Azure, Google Cloud Platform, GitHub) support the sync direction, permissions, and volume we need?
  • What user, usage, storage, support, or security limits appear after the headline starting price?

Evidence and freshness

This record was checked on 7/31/2026. That date tells you when the record was reviewed, not that the vendor has left its terms unchanged since then.

Best for

  • Multi-cloud enterprises (AWS/Azure/GCP/OCI/Kubernetes) that need agentless, unified visibility across code, cloud, and runtime
  • Security teams that want automated vulnerability and misconfiguration prioritization without deploying agents across every workload
  • Organizations that must hit strict compliance frameworks (FedRAMP High, HIPAA, PCI DSS) quickly, since Wiz ships mapped compliance reporting

Not a fit if

  • Small teams or startups with tight budgets — buyer-guide data (Vendr) puts median annual contracts around $150K, and pricing scales with workload count
  • Teams wanting one tool for general observability, log management, or APM — Wiz integrates with (rather than replaces) tools like Datadog, Splunk, and Snowflake for that

Why it’s listed

  • Independently verified 4.7/5 rating across roughly 770 G2 reviews and 'Top Rated' status on TrustRadius (34 reviews), plus recognition as G2's #1 CDR vendor.
  • Real, checkable enterprise adoption (65%+ of Fortune 100 per Wiz's own site) and a concrete published AWS Marketplace price point for its SMB bundle, not just marketing claims.

Pricing

Wiz Go Bundle (SMB)

$74,000 per year (AWS Marketplace 36-month list price)

All-in-one bundle built for small teams, covering code through runtime in a single package.

  • 300 Cloud Advanced workloads
  • 150 Defend Ingestion Units (GB)
  • 100 Runtime Sensors
  • 50 Code Active Developers per month
  • Bundles Wiz Cloud, Wiz Code, Wiz Defend, and Wiz Sensor

Wiz Cloud

Custom pricing

Core CNAPP module for cloud infrastructure and data security posture.

  • Agentless cloud misconfiguration and posture scanning
  • Vulnerability and identity risk prioritization
  • Data security posture management (DSPM)
  • Compliance framework mapping

Wiz Code

Custom pricing

Developer-facing security from IDE through CI/CD pipelines.

  • IaC and code scanning
  • CI/CD pipeline integration
  • AI-generated automated code fixes (Wiz Green agent)

Wiz Defend

Custom pricing

Cloud detection and response for runtime threats.

  • Runtime threat detection
  • Automated threat hunting/investigation (Wiz Blue agent)
  • SIEM/SOAR integration for response workflows

Wiz Sensor

Custom pricing

eBPF-based runtime sensor add-on for deeper workload-level telemetry.

  • eBPF runtime sensor deployment
  • Feeds Wiz Defend's detection engine

Features

AI featuresShips three named AI agents (Wiz Green for automated code-fix generation, Wiz Red for automated pentesting, Wiz Blue for automated threat hunting/investigation) per Wiz's own site.
Alerting & on-callWiz surfaces findings and routes them into on-call tools it integrates with (PagerDuty, Opsgenie, Slack, Teams) rather than acting as a standalone on-call/paging system itself.
Application performance monitoring (APM)Wiz is a security platform, not an APM tool; it integrates with Datadog rather than providing performance monitoring itself.
CI/CD pipelinesWiz Code plugs into CI/CD (GitHub, GitLab, Jenkins, CircleCI, Azure DevOps, AWS CodeBuild, Harness, etc.) for pre-deployment IaC and code scanning.
Distributed tracingNo distributed tracing capability found; not part of Wiz's stated product scope.
Incident managementWiz Defend does runtime threat detection and response and integrates with incident tools (Rootly, PagerDuty, Cortex XSOAR), but is not a general-purpose incident management system.
Infrastructure monitoringProvides agentless cloud infrastructure visibility and risk/security monitoring, but not general performance/infra monitoring — that's left to integrated tools like Datadog.
Log managementWiz Defend ingests logs (billed as 'Ingestion Units') for threat detection, but is not a general-purpose log management platform; integrates with Splunk, Sumo Logic, and Datadog for that.
Public APIPublishes a documented GraphQL API (api.<tenant>.app.wiz.io/graphql) with OAuth2 service-account auth, cursor-based pagination, and a Postman collection, per Wiz support docs.
Self-hosting / on-premWiz is a SaaS-only, agentless platform; no self-hosted/on-premise deployment option was found.

Integrations

AWS (EventBridge, S3, CloudTrail Lake, Security Hub)Microsoft AzureGoogle Cloud PlatformGitHubGitLabJenkinsSplunkDatadogMicrosoft SentinelSlackPagerDutyJiraServiceNowHCP TerraformSnowflake

Security & compliance

SOC 2 Type IISOC 3ISO 27001ISO 27017ISO 27018ISO 27701PCI DSS v4.0.1HIPAAFedRAMP HighCSA STAR

Pros & cons

Pros

  • Agentless deployment with fast onboarding — AWS Marketplace reviewers describe setup taking only a few minutes with full cloud visibility in one console
  • Strong G2 scores for ease of setup (9.1) and quality of support (9.2), with reviewers citing actionable risk prioritization that cuts alert noise
  • Broad integration ecosystem spanning SIEM, SOAR, ticketing, and CI/CD tools so findings route directly into existing workflows

Cons

  • Pricing scales by workload/ingestion volume and can get expensive quickly in large or hybrid environments (Vendr: annual contracts ranging $29,826–$536,300)
  • The breadth of features and a powerful but complex search/query engine create a real learning curve; some reviewers say it's hard to extract full value without tuning
  • Reviewers note gaps in real-time coverage — Wiz relies on periodic scans, with near-real-time updates limited to a subset of cloud services

What we found

4.7/5
770 reviews aggregatedLast checked 2026-07-31

G2 shows a 4.7/5 average across roughly 770 reviews and named Wiz the #1 Cloud Detection and Response (CDR) vendor in its Winter 2025 Grid Report; TrustRadius lists Wiz as 'Top Rated' in Cloud Computing Security with 34 reviews.

Ratings and review counts come from public review platforms. We link to the original source and keep the underlying review text out of this profile.

User reviews

Written by Audyense accounts · moderated before publishing

No user reviews yet.

Used Wiz? Be the first to tell other buyers what actually worked.