Comparisec
Cloud Security Posture ManagementJupiterOne
StrongStrongStrongStrong
4.4

VendorsCloud Security Posture ManagementJupiterOne

JupiterOne logo

JupiterOne

JupiterOne

Founded 2018·US·VC-backed
4.4

Combined score

G2
4.661
Gartner
4.342

Editorial verdict

JupiterOne takes a genuinely broader approach to cloud security posture than most CSPM vendors, building a comprehensive relationship graph that spans not just cloud infrastructure but SaaS applications, identity providers, and code repositories in a single queryable model. For security teams that want to ask custom risk questions spanning multiple asset types, such as which SaaS applications a departed employee's still-active credentials could reach, this graph database approach provides flexibility that dashboard-first CSPM tools built purely around cloud infrastructure cannot easily replicate. The fully agentless and API-driven architecture reflects a platform built for security engineers comfortable working with data programmatically rather than exclusively through pre-built visualisations.

The honest trade-off is specialisation. This breadth comes at some cost to pure cloud infrastructure attack path analysis depth, where Wiz and Orca's singular cloud-first focus produces more refined results, and extracting full value from JupiterOne's graph approach requires more security engineering sophistication than a turnkey dashboard product.

The verdict: JupiterOne is right for security teams wanting a comprehensive asset graph spanning cloud, SaaS, identity, and code with the flexibility for custom risk queries. Organisations wanting the deepest pure cloud infrastructure analysis should evaluate Wiz or Orca Security instead.

Last reviewed: September 2026

G2

4.661 reviews

Gartner

4.342 reviews
Gartner MQ: Not in MQ

Cloud Security Posture Management assessment

PROTECTIONStrong
Cloud platform coverage
5 / 5
Risk prioritisation
4 / 5
OPERATIONSStrong
Remediation workflows
4 / 5
ANALYTICSStrong
Compliance reporting
4 / 5
TRUST & ECOSYSTEMStrong
Multi-cloud scale
4 / 5

Strongest: Cloud platform coverage

Watch out for: Multi-cloud scale

Strengths & limitations

Strengths

The broadest asset coverage in this comparison, extending beyond pure cloud infrastructure to include SaaS applications, identity providers, and code repositories in a single queryable graph
Fully agentless and API based architecture that security teams can query programmatically for custom risk questions beyond pre-built dashboards
Strong G2 rating of 4.6 from 61 reviews with particular praise for the flexibility of the underlying graph database approach

Watch out for

The graph database approach requires more security engineering sophistication to extract full value from compared to pre-built dashboard-first competitors
Cloud-specific attack path analysis depth for pure infrastructure risk is less specialised than Wiz or Orca's cloud-first focus
No Gartner Magic Quadrant presence, and market visibility is narrower than the established CSPM category leaders

Best for

Security teams wanting a comprehensive asset relationship graph spanning cloud, SaaS, identity, and code repositories, with the flexibility to query custom risk questions beyond pre-built dashboards.

Not suitable for: Organisations wanting the deepest pure cloud infrastructure attack path analysis specifically, or teams without security engineering capacity to leverage a graph query approach.

Compliance coverage

SOC 2
NIST CSF
GDPR
Essential Eight
AU Privacy Act
HIPAA
PCI-DSS
CMMC
NIS2
DORA
ISO 27001
CIS Benchmarks

Switching intelligence

Switching from

Common migration paths based on review data

  • Spreadsheet asset inventory
  • Siloed cloud and SaaS tools

Also considering

Vendors typically shortlisted alongside

← Back to Cloud Security Posture ManagementCompare with other Cloud Security Posture Management vendors ➲

Quick facts

Pricing modelPer asset, annual
Pricing rangeQuote-based, mid-market to enterprise
Free trialYes - 14 days
Min seatsNo minimum
Deployment time< 1 week
Complexity2 / 5
Pricing transparency2 / 5
AU presenceNo
IRAP assessedNo
Open sourceProprietary

Deployment

ModelsSaaS
OS support
CloudAWS, Azure, GCP
SupportEmail, Chat, Dedicated CSM
Data residencyUS

Company

JupiterOne

Founded 2018 · 50-200 employees · VC-backed

HQ: US

Not publicly disclosed

Certifications

SOC 2 Type II

Integrations

OktaGitHubGoogle WorkspaceSlackJira