#4 among 12 vendors · still absent from 84.7% of tracked prompt responses
Top-3 citations across 150 prompt × platform pairs
+0.37
Sentiment
-1.00.0+1.0
Positive
#4of 12
Peer Ranking
#1#12
Above averagein DevSecOps & Application Security
Key Metrics
Presence Rate
15.3%
Share of Voice
15.2%
Avg Position
#26.0
Docs Presence
0.0%
Blog Presence
0.0%
Brand Mentions
20.0%
Platform Breakdown
Grok
76%19/25 prompts
Research dossierCapabilities, use cases, sources, reviews, pricing, and FAQ
Overview
Wiz is a cloud-native application protection platform (CNAPP) founded in January 2020 and acquired by Google Cloud in March 2026 for $32 billion. Built by veterans of Israel's Unit 8200 intelligence corps, Wiz connects code, cloud, and runtime into a unified Security Graph that surfaces contextual attack paths and prioritizes risk across multi-cloud environments—AWS, Azure, GCP, OCI, and Kubernetes. Its agentless architecture deploys via read-only APIs in hours without requiring software installation. The platform consolidates CSPM, CWPP, CIEM, DSPM, IaC scanning, vulnerability management, and cloud detection and response into a single interface. Wiz Code extends coverage into developer workflows and CI/CD pipelines, while Wiz Defend delivers runtime threat detection via an eBPF sensor. Trusted by more than 50% of Fortune 100 companies, Wiz is ranked #1 CNAPP on G2 and named a Leader in the Forrester Wave CNAPP Q1 2026.
ChatGPT
8%2/25 prompts
Gemini Search
4%1/25 prompts
Bing Copilot
4%1/25 prompts
Perplexity
0%0/25 prompts
Google AI Mode
0%0/25 prompts
Visible, but narrative can improve. Wiz ranks #4 on presence but #5 on sentiment. The brand appears relatively often, but competitors may be getting more favorable language when they appear.
Where Wiz is losing
Prompts where competitors are visible and Wiz is not.
These prompt-level losses are the first prompts to track and repair.
Where Wiz is winning5
Which security scanning platforms have the best support for SBOM generation workflows for compliance and audit requirements?
Avg # 2.0 · 1 platform
Which application security tools offer the best IDE-native experience vs. CI-only scanning — and what are the tradeoffs for developer adoption?
Avg # 2.0 · 1 platform
What cloud security posture management tools integrate well with container and orchestration platform security scanning?
Avg # 4.5 · 2 platforms
Which security vendors update their vulnerability databases fastest after major CVE disclosures like Log4Shell?
Avg # 10.0 · 1 platform
Which application security platforms go beyond known CVEs to detect logic-level vulnerabilities and misconfigurations?
Avg # 13.0 · 2 platforms
Where Wiz is losing5
I'm rolling out a software composition analysis tool across an engineering org — which platforms have the smoothest onboarding for large teams?
Wiz is a unified CNAPP platform that provides agentless, graph-based security across code, cloud infrastructure, and runtime. Its Security Graph connects misconfigurations, vulnerabilities, exposed identities, and sensitive data to model real attack paths—surfacing only the 'toxic combinations' that pose actual breach risk. The platform spans Wiz Cloud (CSPM, CWPP, CIEM, DSPM, compliance), Wiz Code (shift-left IaC, CI/CD, and IDE security), and Wiz Defend (cloud detection and response). AI agents automate risk remediation, penetration testing, and threat hunting. Since March 2026, Wiz operates as part of Google Cloud while remaining multi-cloud.
Assaf Rappaport, Yinon Costica, Roy Reznik +1 more
Employees
1000-5000
Funding
$1.9B
ARR
~$500M (mid-2024)
Customers
50%+ of Fortune 100
Valuation
$32B (acquisition price)
Status
Acquired by Google (Google Cloud), March 2026
Target users
CISOs and cloud security teams at mid-to-large enterprisesCloud security architects and engineers managing multi-cloud environmentsDevSecOps and DevOps teams integrating security into CI/CD pipelinesSecurity operations center (SOC) analysts performing cloud threat detection and responseCompliance and governance teams needing automated cloud compliance reportingFrontier AI companies and cloud-native organizations securing AI workloads
Bridgewater deployed Wiz to gain cloud-native visibility across its AWS environment, enabling its security team to understand and prioritize real risks across identities and network exposure during its cloud migration.
Cushman & Wakefield
Full environment visibility within 60 minutes of deployment
Cushman & Wakefield's CISO reported that Wiz provided immediate, comprehensive visibility across its cloud environment shortly after deployment and subsequently standardized on Wiz enterprise-wide.
Colgate-Palmolive
Colgate-Palmolive used Wiz across its hybrid multi-cloud environment (AWS, GCP, Snowflake) to detect excessive privileges and previously unidentified misconfigurations, and to rapidly assess and confirm data protection during the 2024 Snowflake-targeted threat campaign.
Amplitude
Digital analytics platform Amplitude used Wiz CNAPP to build a unified DevSecOps program across 5,000+ VMs and 30+ Kubernetes clusters, enabling faster software shipping with a secure, visible risk posture.
Blackstone
Blackstone consolidated CSPM, CWPP, secrets management, breach path detection, and container management into Wiz's single agentless platform, replacing isolated point solutions and gaining advanced network exposure and identity analysis for its AWS-only environment.
Wiz holds the #1 CNAPP and CSPM ranking on G2 for multiple consecutive quarters and was named a Leader with the highest Current Offering score in the Forrester Wave CNAPP Q1 2026.
Its core differentiator is the Security Graph—a contextual engine that correlates risks across code, cloud, identities, and runtime to surface 'toxic combinations' (attack-path-level risk chains) rather than flat vulnerability lists.
This graph-based, agentless architecture enables faster deployment and broader multi-cloud coverage than most peers.
Now part of Google Cloud since March 2026, Wiz is positioned as the 'code-to-cloud' security standard for enterprise, trusted by 50%+ of Fortune 100.
Agentless deployment and fast time-to-value (hours not days)
Comprehensive multi-cloud visibility across AWS, Azure, GCP, and Kubernetes
Security Graph and toxic combinations cutting alert noise
Contextual risk prioritization over raw CVE severity scores
Intuitive, visually clear UI accessible to non-security teams
Strong customer support and responsive technical account managers
Unified CNAPP consolidating CSPM, CWPP, CIEM, DSPM in one platform
Wiz earns strong ratings across major review platforms, scoring 4.7/5 on G2 (776 reviews) and 4.7/5 on Gartner Peer Insights (94 verified reviews as of December 2024), with a 95% willingness-to-recommend score in the Gartner report. Users consistently praise the agentless deployment speed, comprehensive multi-cloud visibility, and the Security Graph's ability to cut alert noise by surfacing only actionable attack paths. Reviewers highlight how the unified platform enables security and development teams to collaborate in a shared context. Criticisms center on premium pricing, limited native SAST/SCA depth, restricted reporting formats (CSV-only), and occasional alert noise in large-scale deployments. Wiz was named the G2 #1 Cloud Detection and Response (CDR) solution in Winter 2025 with a 98% satisfaction score, 8% higher than the next vendor.
Pricing
Wiz does not publish standard pricing; all contracts are custom-quoted based on cloud workload count, feature modules selected, and contract term. Third-party procurement data (Vendr) indicates contract values ranging from approximately $24,000 to $354,350 per year, with a median around $111,500. Entry-level coverage for ~100 workloads is estimated at ~$24,000/year. Add-on modules—container security, DSPM, CDR (Wiz Defend), and Wiz Code—are priced incrementally or bundled. Multi-year commitments and module bundling typically yield meaningful discounts. Wiz is also available via AWS Marketplace with custom private-offer pricing. Perceived by users as premium-tier; free trials and demos are available on request.
Limitations
Premium, workload-based pricing (estimated $24K–$354K/year) is cost-prohibitive for SMBs; no transparent public pricing is published.
Native SAST and full SCA code scanning capabilities are limited compared to dedicated AppSec tools such as Checkmarx or Snyk, leaving teams reliant on external tools for deeper application-layer coverage.
Reporting is largely confined to CSV export formats with limited executive summary templates.
Alert noise and duplicate alerts under different categories can surface in large environments.
Fine-grained access control and on-demand manual scan triggering have been cited as gaps by users.
Professional and managed services offerings are limited compared to broader platform vendors.
Coverage for on-premises and hybrid environments is minimal.
Some users note perceived innovation slowdown post-Google acquisition.
Topic coverageCoverage by buyer topic
Topic Coverage
Prompt-Level Results
Brand citedCompetitor citedNot cited
Prompt
Perplexity
Gemini Search
ChatGPT
Bing Copilot
Google AI Mode
Grok
Capability2/5 cited (40%)
What tools cover SAST, DAST, and SCA in one platform — and which do teams use to cover all three vulnerability types without tool sprawl?
Sign up to unlock project-level analytics, daily tracking, actionable insights, custom prompt configurations, adoption tracking, AI traffic analytics and more.
Free trial. Setup comes pre-filled from this report.
What cloud security posture management tools integrate well with container and orchestration platform security scanning?
chatgpt-searchDirect Wiz mention
Against CNAPP peers like Aqua Security, Wiz competes on breadth and ease of consolidation; against AppSec-first tools like Snyk and Checkmarx, it competes on cloud infrastructure context; against platform players like CrowdStrike and Palo Alto Networks, it competes on agentless simplicity and cloud-native depth.