Lacework

Lacework

Automated cloud security with machine learning anomaly detection for multi-cloud and containerized environments.

70/100Safe BetPaidPaid

Lacework is a solid choice for cloud-native organizations seeking automated security that minimizes manual rule-tuning. Its Polygraph ML effectively reduces noise, but the lack of transparent published pricing and a dated vendor page may give buyers pause. Compare against Wiz for similar capabilities and consider your budget before committing.

Verified 9d ago · liveness 70/100 · cite: rightaichoice.com/tools/lacework

Best for
  • DevOps teams embedding security into CI/CD pipelines
  • Cloud architects managing multi-cloud environments
  • Security teams needing anomaly detection without manual rules
  • Enterprises adopting containerized or serverless architectures
Not ideal for
  • Small teams with simple static cloud setups needing minimal security
  • Organizations primarily on-premises or legacy infrastructure
  • Teams preferring lightweight, open-source security tools
Visit Website

IntermediateFor a DevOps engineer, initial setup to connect AWS and enable agentless scanning can take a few hours; the Polygraph learning period typically observes baseline behavior for 24–72 hours before alerts are meaningful.Web · APIAPI available4.3k viewsVerified 9d ago
Pricing
Paid
Paid2 hidden costs
Learning curve
Intermediate
For a DevOps engineer, initial setup to connect AWS and enable agentless scanning can take a few hours; the Polygraph learning period typically observes baseline behavior for 24–72 hours before alerts are meaningful.
Runs on
WebAPI
API available · 15 integrations
Who it's for
DevOps engineerSecurity analyst
Live sentiment
Is Lacework actually worth it?

We scan live Reddit threads, YouTube comments, X posts, G2 reviews and other communities — and hand you an honest verdict in under a minute.

  • Honest verdict, not marketing
  • Real pros & cons from real users
  • Attributed quotes with receipts
Run a free scan

3 free scans · no card needed

Skip it if

Skip Lacework if you are a small team with a simple, single-cloud setup that needs basic alerts, or if you are on a tight budget and require transparent per-workload pricing out of the gate.

The 30-second take
Biggest gripe

Lacework does not publish per-workload pricing, so you may need to commit to an annual contract to get a reasonable quote, which can surprise buyers expecting a usage-based model.

Price reality

Lacework pricing is enterprise-oriented, typically requiring a sales conversation and annual commitment. If you are a small team, consider open-source tools like Falco or Cloud Custodian, or lighter paid options like Wiz for more transparent pricing.

In short

Lacework — Automated cloud security with machine learning anomaly detection for multi-cloud and containerized environments. Best for DevOps teams embedding security into CI/CD pipelines, Cloud architects managing multi-cloud environments, Security teams needing anomaly detection without manual rules. Paid pricing.

What people actually say about Lacework — is it worth it?

We ran a structured research pass across product reviews, community discussions, and post-purchase forum threads to surface the patterns vendors won't publish themselves. Below: the recurring strengths, the hidden costs people mention most, and the cohort that consistently regrets adopting this tool.

44 mentions across 4 sources (Hacker News, YouTube, Bluesky, Lemmy) · researched Jul 25, 2026.

18% positive82% critical

Average across the 4 sources that answered — each source counts once, not each post.

Recurring strengths
  • +Polygraph technology learns normal behavior to identify cloud security anomalies.
  • +Supports multi-cloud deployments on AWS, GCP, and Azure.
  • +Offers both agent-based and agentless deployment options.
  • +Integrates with major CI/CD tools like Jenkins and GitLab CI.
  • +Includes compliance monitoring for SOC 2, HIPAA, and PCI DSS.
Recurring frustrations
  • No community discusses actual security effectiveness—only business failure.
  • Perceived as crushed by competitor Wiz on technical and business fronts.
  • Fortinet acquisition likely reduces future innovation and standalone support.
  • Lack of positive user reviews makes evaluation difficult.
  • Massive funding loss suggests poor product-market fit or execution.
Patterns worth knowing
Business failure overshadows any product discussion
Seen on Hacker News, Bluesky
Wiz is seen as the superior alternative that crushed Lacework
Seen on Hacker News
Leadership hubris blamed for demise
Seen on Hacker News, Bluesky
Learning curve
intermediateProductive in ~A few hours for initial setup (agent-based)
Hidden costs people mention
  • Potential migration costs if Fortinet changes or discontinues the platform

Viability Score

70/100
Safe Bet

How well maintained and how widely used is Lacework? Built from what the vendor actually publishes (docs, changelog, tutorials, integrations, pricing), whether the site is live, and how much real users discuss it. How we calculate this

Recent activity
not measured
Traction
100
Site health
95
User sentiment
18
What the vendor publishes
40

Last calculated: September 2026

How we score →

Key Features

  • Automated threat detection via machine learning
  • Polygraph-based anomaly detection
  • Vulnerability management for containers and hosts
  • Container image scanning
  • Cloud security posture management (CSPM)
  • Infrastructure compliance monitoring (SOC 2, HIPAA, PCI DSS)
  • Runtime protection for cloud workloads
  • Agent-based and agentless deployment options
  • Real-time alerting and incident response
  • Kubernetes security
  • Serverless security
  • Infrastructure-as-code scanning
  • Multi-cloud support (AWS, GCP, Azure)
  • CI/CD integration with Jenkins, GitLab CI

About Lacework

PaidIntermediateAPI availableWeb · API

Lacework provides cloud-native security through automated threat detection, compliance, and risk assessment across multi-cloud and containerized environments. Using Polygraph-based anomaly detection, it monitors cloud workloads without manual rules, reducing alert fatigue. Core capabilities include vulnerability management for containers and hosts, cloud security posture management (CSPM), runtime protection, and infrastructure compliance auditing for standards like SOC 2, HIPAA, and PCI DSS. It supports agent-based and agentless deployment, integrates with major cloud providers (AWS, GCP, Azure), container orchestration (Kubernetes, Docker), and CI/CD tools (Jenkins, GitLab CI). Compared to competitors like Wiz or Prisma Cloud, Lacework emphasizes autonomous ML-driven detection.

Behind the Verdict

Lacework is an enterprise-focused cloud security platform that differentiates via its Polygraph machine learning engine, which builds behavioral baselines across your cloud environment to flag anomalies without requiring you to write and maintain detection rules. This is a genuine strength if you’re drowning in alerts from rules-based tools and want a solution that adapts automatically. That said, the platform assumes a public-cloud-first footprint—AWS, GCP, Azure—and deep Kubernetes and container adoption. If you’re heavily on-premises or running a static, minimal cloud estate, you’ll be paying for capability you won’t use. Lacework’s compliance features (SOC 2, HIPAA, PCI DSS) are handy, but they’re table stakes for this category. The biggest practical friction is pricing: Lacework doesn’t publish per-workload numbers and relies on sales conversations, which makes it harder to compare against Wiz or Prisma Cloud. If you’re a small team or budget-sensitive, you may want to look at open-source alternatives or lighter tools first.

Researching Lacework? Get your full AI stack in 60 seconds.

Free, no signup — tell us your goal and get tools matched to your budget & existing stack.

Real-world workflow fit

Concrete scenarios for the personas Lacework actually fits — and what changes day-one when you adopt it.

DevOps engineer

Embedding Lacework into a CI/CD pipeline

Outcome: Within a day, you connect GitLab CI to run image scans and IaC checks on every merge request, catching misconfigurations before they reach production.

Security analyst

Investigating runtime anomalies

Outcome: After a few hours of configuration, you receive Polygraph-driven alerts in Slack, enabling you triage and respond to potential threats without writing detection rules.

Use Cases

  • Detecting anomalous activity in cloud accounts without configuring rules
  • Automating compliance auditing for industry standards
  • Securing containerized workloads in Kubernetes clusters
  • Scanning infrastructure-as-code for misconfigurations pre-deployment
  • Monitoring runtime behavior of cloud-native applications

Limitations

  • Primarily focused on public cloud environments; on-premises support is limited.
  • Requires cloud APIs to be enabled for full visibility.
  • Agent-based deployment can add overhead.
  • Pricing is not published, which complicates budget planning.

as of 2026-08-28

Verification history

We have re-verified Lacework 17 times since . Each pass re-reads the vendor's own pages and re-checks every listed field against that evidence; passes where nothing had changed are marked as such.

  1. re-checked, vendor evidence unchanged
  2. re-checked, vendor evidence unchanged
  3. re-checked, vendor evidence unchanged
  4. re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  5. re-checked, vendor evidence unchanged
  6. re-checked, vendor evidence unchanged

Showing the 6 most recent of 17 verification passes.

Free to cite with attribution — this page re-verifies continuously.

Hidden costs & gotchas

What the public pricing page doesn't put in bold. Captured from pricing-page footnotes, contract terms, and recurring complaints.

  • Lacework does not publish per-workload pricing, so you may need to commit to an annual contract to get a reasonable quote, which can surprise buyers expecting a usage-based model.
  • Agent-based deployment adds operational overhead: you must install and maintain agents on each workload, which consumes resources and requires patching.

Where the pricing makes sense

The company stage and team size where Lacework's pricing actually pencils out — and where peers do it cheaper.

Lacework pricing is enterprise-oriented, typically requiring a sales conversation and annual commitment. If you are a small team, consider open-source tools like Falco or Cloud Custodian, or lighter paid options like Wiz for more transparent pricing.

Setup time & first value

How long it actually takes to get something useful out of Lacework — broken out by persona, not the marketing-page minute.

For a DevOps engineer, initial setup to connect AWS and enable agentless scanning can take a few hours; the Polygraph learning period typically observes baseline behavior for 24–72 hours before alerts are meaningful.

Switching to or from Lacework

How to bring data in from common predecessors and how to get it back out — written for the switcher, not the buyer.

Migrating in
  • From manual security tooling: Enable Lacework agentless scanning to get immediate visibility, then onboard agents gradually for runtime protection.
Migrating out
  • To Wiz: Export your current findings and compliance reports, then scope your Wiz deployment by replicating your account structure.

Integrations

AWSGoogle CloudAzureKubernetesDockerTerraformJenkinsGitLab CISlackPagerDutyJiraSplunkServiceNowDatadogSysdig

Resources & Guides

Tutorials & Learning

Tools that pair well with Lacework

Common stack mates teams adopt alongside Lacework, with the specific reason each pairing earns its keep.

Alternatives to Lacework

View all
Orca Security

Orca Security

Agentless CNAPP for multi-cloud security with AI-driven risk prioritization.

Contact SalesTry
Securiti

Securiti

Unified data security, privacy, and AI governance platform for hybrid multicloud enterprises

Contact SalesTry
Lumana

Lumana

Turn existing IP cameras into self-learning AI agents for enterprise video security.

Contact SalesTry

Frequently Asked Questions

Used Lacework? Help shape our editorial sentiment research.