Israeli-founded cloud-native application protection platform. Dror Davidoff and Amir Jerbi, 2015. Ramat Gan HQ. Insight-led $135M Series E March 2021 unicorn round. $325M+ raised. Trivy open-source moat. Longest-tenured independent in the container-security category.
Aqua Security is an Israeli-founded cloud-native application protection platform — the software layer that scans and secures the containers, Kubernetes clusters, serverless functions, and cloud infrastructure that modern applications run on. The company was one of the earliest commercial entrants in what became the CNAPP (Cloud-Native Application Protection Platform) category, and remains one of the most-cited independent players in a market that has consolidated around a small number of scaled competitors.
Aqua was founded in 2015 by Dror Davidoff and Amir Jerbi and is headquartered in Ramat Gan with U.S. operations in Boston. The company reached unicorn valuation in March 2021 on a $135 million Series E led by Insight Partners, at a valuation exceeding $1 billion. Total capital raised sits above $325 million across investor cohorts that have included Insight, Lightspeed Venture Partners, Greylock, TLV Partners, Capital One Ventures, and Microsoft's M12.
What the product actually does
Software architecture has changed shape twice in the past decade in ways that broke traditional security tooling. The first change was the shift from monolithic applications running on dedicated servers to microservices running in containers — self-contained software packages orchestrated by Kubernetes. The second change was the shift from on-premises data centers to public cloud infrastructure operated by AWS, Azure, and Google Cloud, where the customer no longer controls the underlying servers, networks, or physical security.
Traditional security tools were built for the earlier world. Cloud-native security tools have to secure a fundamentally different substrate: containers that spin up and down in seconds, orchestration systems that move workloads across hardware automatically, cloud APIs that create and destroy infrastructure programmatically, and code pipelines that push new software into production dozens of times per day.
Aqua's platform covers this stack end-to-end. It scans container images for vulnerabilities before they reach production. It monitors running containers for runtime attacks — attempts to escape the container boundary, compromise the orchestration layer, or move laterally through cloud infrastructure. It secures the Kubernetes control plane and the cloud APIs the orchestration system depends on. And it produces the audit trail that security and compliance teams use to demonstrate to regulators that the cloud infrastructure is being operated safely.
The founders
Dror Davidoff — CEO and co-founder. Prior career in enterprise security software, including senior operating roles that produced direct exposure to the cloud-migration transition. Davidoff has been the public face of the company through its category-establishment years.
Amir Jerbi — CTO and co-founder. Longtime cybersecurity engineer with prior work on virtualization and endpoint security. Jerbi built the original container-scanning architecture and continues to lead the technical direction.
The founders identified the container-security opportunity earlier than most: Aqua began productizing in 2015, when Docker had reached commercial visibility but Kubernetes had not yet consolidated as the orchestration standard. That early entry produced the training-data and product-experience advantage that Aqua has traded on through subsequent cycles.
The Trivy acquisition and the open-source play
Aqua's strategic differentiator through the mid-2020s has been its aggressive open-source posture. The company acquired Trivy in 2019 — an open-source container vulnerability scanner that has since become the most-installed tool in its category globally. Trivy runs inside continuous-integration pipelines at a substantial portion of the world's software-development organizations, produces no direct revenue, and functions instead as a wide-mouth funnel through which enterprise buyers discover Aqua's commercial platform.
The pattern — commercial company owns and invests in a leading open-source project that seeds enterprise sales — is now widely used across cloud-native software, but Aqua was one of the earlier and cleaner executions of the model in the security category specifically.
Beyond Trivy, Aqua operates additional open-source projects including Kube-Bench (Kubernetes benchmark scanner), Kube-Hunter (Kubernetes penetration testing), and Tracee (runtime security tracing). Together they form what the company calls the Aqua open-source portfolio and constitute the largest single open-source footprint in the cloud-native security category.
Category position
Aqua competes primarily with Palo Alto Networks Prisma Cloud, Wiz (Israeli-founded, U.S.-headquartered), Sysdig, Snyk (Israeli-founded), CrowdStrike Cloud Security, and Microsoft Defender for Cloud. The competitive environment has been unusually active. Wiz's rapid rise through 2020–2024 and its $32 billion sale to Google in early 2026 reshaped buyer expectations across the CNAPP category. Palo Alto Networks and CrowdStrike have moved aggressively to consolidate cloud-security capabilities inside their broader platform sales. Microsoft's bundling of Defender for Cloud into enterprise-agreement pricing has changed mid-market economics.
Aqua's competitive posture through this window has emphasized platform depth — the argument that scanning-plus-runtime-plus-orchestration coverage as a single platform is meaningfully different from scanning-only competitors — combined with the open-source-first go-to-market that competitors cannot easily replicate without ceding revenue.
The Israeli cloud-security cohort
Aqua sits inside what is now the most concentrated cybersecurity sub-cohort in Israel: the cloud-native security cluster. That cluster includes Wiz in cloud posture management (acquired by Google), Orca Security in agentless cloud scanning, Cato Networks in secure access, Snyk in developer-first application security, Island in enterprise browsers, and Sweet Security and multiple 2023–2025 entrants in cloud detection and response.
Within that cluster, Aqua holds the longest tenure and the deepest open-source footprint. It is the category-establishing name in container security specifically — the position that Wiz never contested because Wiz was built for the different (agentless-cloud-posture) side of the CNAPP category.
The overall Israeli cloud-security cohort now anchors the largest concentration of technical talent applied to a single sub-category anywhere in the global cybersecurity market. Aqua's engineering base has remained substantially in Israel through the growth cycle.
Position in the broader Israeli cybersecurity cohort
Aqua fits inside the broader Israeli cybersecurity cohort that also includes Check Point Software, CyberArk, Palo Alto Networks (Israeli-founded), Cybereason, Armis, SentinelOne, Snyk, and the large tail of specialized security companies below them. Within that cohort, Aqua's positioning is one of the clearer examples of Israeli engineering talent applied to a specific cloud-infrastructure sub-category earlier than the U.S. competitive field.
Current standing
Aqua Security operates as one of the two or three most-cited independent players in the cloud-native security category, with the deepest open-source footprint and one of the earlier product entries in the container-security sub-category specifically. The competitive environment has consolidated around Wiz (now inside Google), Palo Alto Networks, CrowdStrike, and Microsoft on the platform side, with Aqua occupying the independent-specialist position alongside Sysdig and Orca. The Trivy-anchored open-source distribution model continues to compound: every year, more of the world's software-development infrastructure runs a piece of Aqua-owned open-source code, and every year, a fraction of that user base converts to the enterprise product. The company's Ramat Gan engineering base and open-source-first commercial posture remain the two most durable structural characteristics of its competitive position.








