We believe modern security platforms need to enable security for the way your team actually works. In practice, that means two things.

  1. The platform’s data needs to work with whatever AI tools your teams already use. That means the IDEs your developers live in, the chat interfaces your analysts prompt from, and the coding agents shipping features every day. Security data belongs where the work happens, not trapped in a console.
  2. The platform must have AI agents with real domain expertise, so the work that used to require a senior analyst runs at machine speed. Driving the right agentic action requires correlating context consistently with domain knowledge, not just raw data.

That’s the bar. This post walks through how Orca AI delivers on both, including how you can shape agents of your own.

AI Agents With Domain Expertise

Orca’s Core Agents are specialized AI teammates, grouped into pods that work together within a security discipline. Expertise alone isn’t the differentiator. Every Core Agent runs on the same Unified Data Model behind Orca’s risk prioritization and attack path analysis. That means every agent reasons over cloud, identities, code, data, and AI systems with reachability, blast radius, and business impact already factored in.

That combination is the point. Domain expertise is the knowledge that powers the agent. The Unified Data Model is what makes its actions trustworthy. Agents that reason from stitched-together sources at query time return fragmented conclusions. Agents that reason from correlated context before the question was asked return answers you can act on.

The pods split the work by the shape of the problem: attack and validate, investigate and triage, remediate.

Red Pod: The Attacker’s Perspective

Red Pod agents work from the attacker’s side, testing what’s exposed on the outside and what’s exploitable in your code. They validate before they report, so what reaches you is what an attacker could actually use.

Attack Surface. On-demand AI-driven DAST and AI penetration testing that probes your public-facing assets. Each test starts with reconnaissance context already assembled from Orca’s live graph, so an endpoint sitting in front of a workload with an open critical misconfiguration gets treated very differently from the same endpoint in front of an isolated test environment. Findings arrive with real risk context, not raw scan output.

Code Security Auditor. Full-repository scanning that protects apps against the AI-powered attacks Mythos-class frontier models make possible. It traces cross-file data flows across your repository to reconstruct the attack chains an attacker would take. That’s how it catches the classes pattern-matching SAST cannot see: broken authorization, privilege escalation, and business-logic flaws. These are the vulnerabilities that don’t look like a signature because they aren’t a pattern at all. They’re logic. Reasoning over the graph is how you catch them.

Blue Pod: The Defender’s Verdict

Blue Pod agents investigate alerts and findings end to end, gathering evidence across your environment to reach a verdict: malicious or benign, real risk or false positive. What’s proven gets escalated. What isn’t gets out of your way. They handle the day-to-day triage so your team can focus on what matters most.

AppSec Triage. Analyzes SAST and secrets findings using code context, data flow, and sanitization patterns to separate true positives from likely false positives, then adjusts risk scores accordingly. The AppSec noise problem doesn’t get solved by more scanners. It gets solved by an agent that reasons about whether a finding is actually exploitable in the code as it stands.

Threat Investigator. Runs an alert’s full investigation lifecycle, correlating signals, validating facts, and producing a transparent report with recommended containment actions. The transparency matters as much as the verdict. Analysts see the reasoning at every step, so what reaches them is a case they can validate, not a black box they have to trust.

Green Pod: The Path to Resolution

Green Pod agents pick up where a finding ends. They work out who owns it, what stands in the way, and what the fix actually is, then hand it over ready to apply. Findings become work that gets done, so your risk goes down and you stay compliant. This is where the loop closes: a validated finding from Red or Blue Pod doesn’t sit in a queue waiting for someone to translate it into engineering work. It arrives with the fix already drafted, in the format the team already uses.

The pattern across all three pods is the same. Specialized reasoning for the discipline, grounded in the Unified Data Model that Orca already maintains, delivered as work your team can act on rather than another alert queue to clear.

Custom Agents: Shape One Around Your Environment

Agents also need to cover your unique workflows. Which applications are your crown jewels. Which controls have the shortest audit window. Which handoffs between security and engineering repeat every week. That knowledge lives in senior team members’ heads today, and it decides how the work actually flows.

Custom Agents let you automate security workflows with your own instructions, data, and triggers. Start from an Orca template and adapt it, or build one from scratch. Either way, the agent inherits the same Unified Data Model and reasoning fabric every Core Agent uses. You personalize it to your company’s way of working.

Orca ships templates for the shapes of work most teams end up automating. For example:

  • SLA Watcher monitors in-scope alerts and classifies them as Within SLA, At Risk, or Breached, then sends a daily digest of the top ten per classification.
  • Attack Path Optimizer analyzes active attack paths and finds the minimum set of fixes that severs the most of them.
  • Crown Jewel Assignment runs on a schedule to discover newly created assets, evaluates each against classification rules, and marks the qualifying ones.
  • Compliance Gap Analysis analyzes failing controls across enabled frameworks (or a specified one like PCI DSS, CIS AWS, or HIPAA) and ranks them by blast radius.
  • Trending Threat Response investigates emerging security news (CVEs, zero-days, supply chain attacks, malware campaigns) and maps them back to your environment.

Others cover ticket routing, remediation effort estimation, financial exposure quantification, Dockerfile risk scoring, dependency vulnerability triage, and full vulnerability reporting. Each template ships with a pre-built prompt you can keep as-is or adjust to fit your workflow. Each is scoped to a specific trigger: manual, scheduled (Daily, Weekly, Monthly, Quarterly), or fired by an alert automation.

When no template fits, you can still create one from scratch. You define the prompt, the trigger, and the tools the agent can use, and it’s best suited for team-specific work. It’s the encoded judgment no template will ever cover, because it’s yours.

Orca MCP Server: Security for the Way You Work

Orca also delivers three things that make Orca context AI compatible.

The Orca MCP Server extends Orca’s reasoning into Claude, Codex, Cursor, VS Code, and any MCP-compatible client. A developer working a ticket in their IDE can ask Claude to pull the alert details, generate the remediation code, and prep a diff for review, without switching to a separate security tool. Read about how the MCP Server shifts security left →

The AI Skills Hub sits on top of the MCP Server. It’s a set of open-source, pre-built cloud security skills with the specialized security logic already written. Teams can fork, modify, and extend any skill. Read about the AI Skills Hub →

The MCP App experience is the interactive layer on top of both. When an agent’s response is more than a paragraph can communicate, Orca’s MCP App returns a live, interactive card right in the conversation. Read about our MCP App and the interactive layer →

Together, these make Orca 100% AI compatible. Orca data goes to the tool your team is already using, instead of forcing them to come to Orca. And what flows through isn’t raw data. It’s correlated context: every asset, alert, identity, and dependency already stitched together in Orca’s Unified Data Model, so whenever an AI tool asks a question, the response factors in reachability, blast radius, and business impact from the start.

Security for the Companies that Build

Orca Security delivers security for the companies that build. As cloud, AI, and app generation expand the attack surface, the Orca Platform provides complete visibility, correlates risk, and prioritizes what matters most. Trusted by SAP, Autodesk, Gannett, Lemonade, and Digital Turbine. Backed by Temasek, CapitalG, ICONIQ Capital, and Redpoint Ventures.

Learn More

Interested in seeing how Orca’s AI Agents and the Orca Platform can help your team work the way it actually wants to? Schedule a personalized 1:1 demo.