Company Overview
Aqua Security is a cloud-native security company co-founded in 2015 by Dror Davidoff and Amir Jerbi, with dual headquarters in Tel Aviv, Israel, and Boston, Massachusetts. As a pioneer in container security, Aqua Security delivered security solutions early in the Docker and Kubernetes ecosystem, helping enterprises securely adopt containerization and cloud-native architectures.
The company has raised over $265 million in total funding (Series E completed in 2021) and is globally recognized as a leader in container and cloud-native security. Beyond its commercial products, Aqua actively contributes to the open-source community — its Trivy project has become one of the industry's most widely used vulnerability scanners for container images, filesystems, and Infrastructure as Code (IaC), with over 25,000 stars on GitHub.
Related providers: Cloud Security Services
Core Products
- Aqua Cloud Security:Unified CNAPP platform integrating container security, Kubernetes security, serverless security, and cloud workload protection across the full lifecycle of cloud-native applications.
- Aqua Container Security:Core product covering container image scanning, registry security, admission control, runtime security protection, and compliance auditing. Supports Docker and containerd runtimes.
- Aqua Serverless Security:Security detection and runtime protection for serverless environments including AWS Lambda, Azure Functions, and Google Cloud Functions.
- Aqua DTA (Dynamic Threat Analysis):Behavioral analysis-based container runtime threat detection engine capable of detecting unknown malicious behavior and zero-day attacks at runtime.
- Aqua Trivy (Open Source Vulnerability Scanner):One of the industry's most popular open-source vulnerability scanners, supporting container images, filesystems, Git repositories, Kubernetes, and IaC (Terraform, CloudFormation) security scanning. Over 25,000 stars on GitHub.
- Aqua CSPM (Cloud Security Posture Management):Continuous monitoring of cloud environment configurations to detect misconfigurations and compliance drift.
- Aqua CI/CD Integration:Deep integration with Jenkins, GitLab CI, GitHub Actions, CircleCI, and other CI/CD tools for embedding security scanning at build time.
- Aqua Risk Explorer:Visualized risk assessment and attack path analysis for cloud-native environments.
Core Strengths
- Container Security Pioneer:Established security products early in the container technology era, with the deepest container runtime security expertise and broadest ecosystem integrations.
- Open Source Influence:Trivy, as one of the most popular open-source container security tools, significantly drives Aqua's brand awareness and community influence while serving as a commercial product entry point.
- Full Lifecycle Coverage:From image scanning in CI/CD pipelines to runtime protection in production, covering the complete security lifecycle from build to run.
- Deep Kubernetes Integration:As a CNCF member, Aqua deeply integrates Kubernetes security mechanisms (OPA/Gatekeeper, Pod Security Standards, Admission Controllers).
- Dynamic Threat Analysis:The DTA engine uses behavioral analysis to detect anomalous process execution, network connections, and filesystem changes within containers, identifying threats undetectable by traditional signatures.
Key Milestones
- 2015:Co-founded by Dror Davidoff and Amir Jerbi in Tel Aviv, Israel.
- 2016:Completed Series A funding; released first version of the Aqua Container Security Platform.
- 2017:Completed Series B funding; named a representative vendor in the Gartner Container Security Market Guide.
- 2018:Released open-source Trivy vulnerability scanner, quickly gaining community traction.
- 2019:Completed Series C funding; accelerated global expansion with Boston office opening.
- 2020:Launched Aqua Serverless Security, extending to serverless security.
- 2021:Completed Series E funding with $265M+ total raised.
- 2023:Launched Aqua DTA (Dynamic Threat Analysis), enhancing AI-driven runtime security detection.
- 2026:Trivy continues to grow as one of the most widely used cloud-native security scanning tools.
Market Position
Aqua Security competes with the following providers in the container security and cloud-native security markets:
- Sysdig:Sysdig is Aqua's most direct competitor in container security and runtime threat detection, competing head-on in Kubernetes security and container runtime protection.
- Palo Alto Networks (Prisma Cloud - formerly Twistlock):Twistlock was Aqua's competitor before being acquired by Palo Alto Networks, now continuing as the Prisma Cloud container security module.
- Lacework:Lacework competes with Aqua in cloud workload protection and container security.
- Wiz:Wiz's agentless container security scanning capabilities compete with Aqua in the CNAPP market.
- CrowdStrike (Falcon Cloud Security):CrowdStrike's Falcon platform competes with Aqua in the cloud workload protection market.