Stop threats before they strike with TrendAI Vision One™ - the AI-powered enterprise cybersecurity platform built to predict, prevent, and respond to threats across AWS, hybrid, and multi-cloud environments. Gain unified visibility, streamline cloud risk management, accelerate cloud investigations, and empower your security teams with proactive, layered protection that works at cloud speed. Proactive security starts here.
TrendAI Vision One™ gives enterprises and security leaders the power to see, secure, and control their entire multi-cloud and hybrid environments from a single, unified platform. Gain complete visibility with real-time risk scoring, threat exposure mapping, and centralized monitoring all from one intuitive dashboard.
Backed by AI, machine learning, and predictive analytics, TrendAI Vision One™ empowers proactive cloud security by automating threat detection, risk mitigation, and response. Streamline operations, reduce security complexity, and offload the pressure on your teams with modern CNAPP capabilities so you can stay ahead of every attack.
Trusted by industry leaders and recognized as a 2024 Gartner Peer Insights™ Customers' Choice for CNAPP, Trend Vision One is proven to reduce operational costs by up to 79% and accelerate detection and response times by 70%. It's also a Leader in the 2025 Gartner® Magic Quadrant for Endpoint Protection Platforms, delivered a 100% detection rate in MITRE evaluations, and was named a Leader in the IDC MarketScape for Cloud-Native Application Protection Platforms 2025, solidifying its position as the most trusted platform for securing the cloud.
Confidently secure your cloud transformation with a platform built for the modern enterprise. From hybrid to multi-cloud, TrendAI Vision One™ delivers unmatched protection, visibility, and control - wherever your workloads live.
Trend provides custom pricing via Private Offer. Please contact us if you're interested in personalized pricing options.
Highlights
Identify and eliminate hidden cloud risks with unified Cyber Risk Exposure Management - discover assets, prioritize vulnerabilities, and manage posture and attack surface all from one place.
Stay steps ahead of threats with XDR for Cloud, which extends visibility into cloud environments and streamlines SOC investigations through powerful correlation and alerting.
Secure every application and workflow - from containers and code to S3 files and cloud workloads - with holistic protection via the integrated stack: Container Security, File Security, Workload Security, and Code Security.
Get personalized pricing in minutes - New
If qualified, an express private offer gets you custom pricing and terms. Finalize your purchase in the AWS Marketplace console.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor, and additional usage. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. Usage-based pricing is in effect for overages or additional usage not covered in the contract. These charges are applied on top of the contract price. If you choose not to renew or replace your contract before the contract end date, access to your entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You buy this platform through a contract and mix independent security modules based on what you protect. Cloud Risk Management bills per 500 resources per cloud account per hour. Container Security bills per node, instance, pod, or task per hour. Endpoint Security scales by workload type and size, from Essentials through Small, Medium, Large, and Non-Cloud units. File Security bills per file scan or per storage per hour across several deployment options. XDR for Cloud bills per gigabyte ingested. TrendAI Flex uses credits, letting you purchase and allocate across solutions flexibly.
Top-of-mind questions for buyers
What counts as one unit for Endpoint Security billing across the Small, Medium, and Large sizes?
Each protected instance counts as one unit. Small covers EC2 instances from micro to medium, WorkSpaces, or other cloud with 1 vCPU. Medium covers large EC2 or 2 vCPU instances. Large covers XL EC2 or 4 vCPU instances. Essentials covers a workload with anti-malware, web reputation, and XDR only.
How does Container Security cost change between a Kubernetes node and a serverless container pod?
You are billed separately for each type. Protected Kubernetes nodes or Amazon ECS instances meter per node or instance per hour. Serverless container pods or tasks meter per pod or task per hour. The two rates run independently, so your bill reflects the mix of container types you actually run.
How do File Security dimensions differ, and which metric drives the cost?
File Security SDK, Storage, Virtual Appliance, and Containerized Scanner all meter per file scan, so scan volume drives cost. Storage also offers per cloud storage per hour billing. Appliance and Containerized Scanner options add a per-scanner charge. You pick the deployment that matches where your files live.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Your purchase also includes 24x7 support from Trend Micro. You can log a support ticket for any issues directly from your TrendAI Vision One™ console. If you experience any issues or have questions, please contact our AWS Security experts by email at aws.marketplace@trendmicro.com.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Centralized cyber risk exposure management with asset discovery, vulnerability prioritization, and attack surface management from a single dashboard
Extended Detection and Response for Cloud
XDR capabilities that extend visibility into cloud environments with correlation and alerting to streamline security operations center investigations
AI-Powered Threat Detection
Machine learning and predictive analytics for automated threat detection, risk mitigation, and response across multi-cloud and hybrid environments
Comprehensive Application Security
Integrated security stack covering container security, file security, workload security, and code security for end-to-end application protection
Real-Time Risk Scoring and Monitoring
Real-time risk scoring and threat exposure mapping with centralized monitoring capabilities across AWS, hybrid, and multi-cloud environments
Attack Surface Management
Aggregates comprehensive attack surface visibility across hybrid environments with external attack surface scans to provide 360-degree view of entire attack surface
Vulnerability Management
Delivers complete visibility across on-premise and remote endpoints to identify, communicate, and remediate vulnerabilities, misconfigurations, and risks
Cloud Security
Provides code-to-cloud protection for cloud-native applications with CI/CD pipeline integration and agentless risk assessment based on reachability, exploitability, and potential impact
Next-Generation SIEM and XDR
Delivers accelerated detection and response with SaaS deployment, out-of-the-box detections informed by MDR SOC, and built-in automation capabilities
Threat Intelligence
Delivers high-fidelity actionable threat intelligence infused with proprietary threat and vulnerability research from Rapid7 Labs and community-driven tools
Offensive Security Engine
Simulates external exploits to produce Verified Exploit Paths for prioritizing exposures that are truly reachable by outside attackers, reducing cloud attack surface.
Cloud Security Posture Management
Continuously monitors and manages security of AWS configurations to prevent public exposure and ensure compliance.
Secrets Scanning
Identifies more than 750 types of secrets across public and private repositories.
Cloud Infrastructure Entitlements Management
Detects and manages excessive or unused permissions to mitigate the risk of privilege escalation.
Real-Time Malware Detection
Detects malware including zero-days in milliseconds with scanning performed directly in cloud environment for object storage services like Amazon S3 and file storage services.
Unified security platform has reduced risk exposure and simplified threat detection and response
Reviewed on Sep 24, 2026
Review from a verified AWS customer
What is our primary use case?
TrendAI Vision One provides multiple security solutions including email security, endpoint security, XDR, and identity security, as well as cyber risk exposure management.
For a Sri Lanka organization requesting a tender related to endpoint detection and response (EDR) solutions for their workstations and servers, I proposed TrendAI Vision One Standard Endpoint Protection.
I also use TrendAI Vision One email security for customer requirements, such as securing their email traffic from attackers, and I have proposed an email security solution as well.
What is most valuable?
The best feature that is trending is cyber risk exposure management, which can be used to identify the risk score of the whole organization's security threat landscape.
In customer environments where separate solutions exist to secure the environment, I integrate those third-party solutions with TrendAI Vision One, which analyzes the whole logs and shows a detailed view of the risk related to misconfigurations, vulnerabilities, and incidents captured from those third-party logs.
When a customer comes with security solutions for their security landscape, including endpoint security, email security, and network security, I can propose a single solution to cater to all those requirements.
The single solution approach allows me to avoid a siloed architecture. When I log into the solutions, I can use a single dashboard to navigate all security solutions, including endpoint security, email security, and cyber risk exposure management. Customers can identify their organization's risk and minimize that risk by following the remediation actions shown in TrendAI Vision One platform.
What needs improvement?
When it comes to challenges, I am using the Singapore region tenant, and I suggest adding more regions that come with the solution in the future.
Regarding improvements, I believe they need to develop some dashboards with correlations; that would be better.
For how long have I used the solution?
I have been using TrendAI Vision One for nearly three-plus years.
What do I think about the stability of the solution?
TrendAI Vision One is stable.
What do I think about the scalability of the solution?
TrendAI Vision One now uses credits to manage the licensing part, so if I have free credits, I can utilize them for additional security requirements in TrendAI Vision One.
How are customer service and support?
Customer support is reliable. I have access to a support portal where I can raise support tickets according to severity levels, which are responded to quickly based on that severity.
Which solution did I use previously and why did I switch?
I started with TrendAI Vision One solution and have exclusively used that.
What was our ROI?
After deploying our solutions for customers, I find that there is no need for multiple admins to configure and monitor, as everything works independently from the configuration policies.
Which other solutions did I evaluate?
In the market, there are solutions such as Microsoft clouds or SentinelOne. As we are distributors for Trend Micro, I considered Trend Micro for our company domain.
What other advice do I have?
They are looking for new solutions with AI involvement while improving their policy levels and dashboards. They are also integrating their AI Chat companion into TrendAI Vision One console.
Coverage is very critical for my organization's network because the threat landscape is increasing today, and attackers are using new techniques to compromise organizations. This is very critical for security solutions, and TrendAI provides security solutions to minimize the threat landscape.
When it comes to remote code executions, I can use endpoint detection and response solutions. For spam and phishing mails, I can utilize TrendAI Vision One email security solution.
These solutions are fully cloud-based, allowing access to the console from anywhere in the world using secure communications through the HTTPS protocol. If deployed as on-premise, I can use secure web gateways to communicate with that cloud console.
TrendAI Vision One helps consolidate my use of security vendors and reduces silos since it provides multiple security solutions through one single dashboard, including email security, endpoint security, network security, and identity security.
In today's threat landscape, it is important that TrendAI Vision One has AI built into its platform because I cannot rely solely on signatures, especially with attacks such as fileless attacks. I need AI and ML techniques to identify the behavior of these attacks.
I use TrendAI Vision One in my hybrid environments to address security requirements, including Azure VMs where I have deployed TrendAI Vision One Server security agents, as well as on-premise deployments such as fingerprint and file servers to secure critical assets.
TrendAI Vision One helps reduce my time to detect and respond to threats significantly due to its massive threat intelligence and the Zero-Day Initiatives team focusing on zero-day attacks and providing the best possible mitigation actions.
When it comes to attacks, the solution carries out response actions quickly. I have not heard of any breaches from TrendAI Vision One platform.
After analyzing logs from third-party solutions, TrendAI Vision One maps the risks and provides mitigation actions to reduce those risks. By following those steps, I can minimize risks.
I use the cyber risk exposure management capabilities, which show me, for instance, what vulnerable software is installed on endpoints, helping me to identify versions, vulnerabilities, and risk scores. From there, I can determine necessary actions such as patching or protecting with endpoint security solutions.
I rate this product nine out of ten based on my overall experience.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
reviewer2649927
Unified security console has simplified endpoint protection and improved user awareness
Reviewed on Sep 23, 2026
Review provided by PeerSpot
What is our primary use case?
TrendAI Vision One is used primarily in endpoint security, email security, mobile security, cyber risk exposure management, and XDR.
For mobile security, TrendAI Vision One is used for mobile threat detection as an MTD solution, and it allows enrollment of both BYOD devices and company-owned devices while providing protection for mobile devices. The solution supports Android, iOS, and similar platforms.
My main use case for TrendAI Vision One is endpoint security, and I am also familiar with mobile security. TrendAI Vision One functions as a full-fledged next-generational antivirus solution for users, and it prevents malware, viruses, and similar threats. The solution has many machine learning features as well.
What is most valuable?
The best feature in my experience with TrendAI Vision One is that when implementing endpoint security and email security for an organization, there is no need to use multiple consoles. With TrendAI Vision One, a single console provides access to all these solutions, making it a comprehensive platform that includes all of the solutions. This consolidated approach is the main usefulness for users.
TrendAI Vision One can integrate with third-party solutions as well. Regarding usability, I credit TrendAI Vision One since it uses a credit-based model. Additionally, the licensing for TrendAI Vision One is very flexible for users and organizations.
TrendAI Vision One is a full-fledged platform for combining multiple solutions, making it easy for administrators to navigate and configure the console. It provides comprehensive security for devices and users, and the flexible licensing is very useful for organizations.
Regarding the platform's ability to provide centralized visibility and management across protection layers, the centralized visibility is really helpful for administrators to configure settings without having to navigate multiple consoles. This streamlines issue resolution and ensures that protection is covered from multiple aspects within the same console.
TrendAI Vision One has helped consolidate the use of security vendors and reduced silos significantly.
What needs improvement?
TrendAI Vision One has recently added updates and new features, which can be a bit confusing. However, those features are helpful but not organized clearly. When an administrator logs into the console, it can be difficult to find some features because of the organization.
Regarding documentation improvements for TrendAI Vision One, it would be easier with the TrendAI companion. Most of the documentation and answers can be found, but it would be helpful if the company could provide more data sheets or whitepapers as well as configuration support.
Additional improvements needed for TrendAI Vision One include issues where the console sometimes indicates that services are not available. I believe these issues are being improved, but they do not constantly display as expected.
For how long have I used the solution?
I have been using TrendAI Vision One for more than one and a half years.
What other advice do I have?
TrendAI Vision One provides more security for users regarding detections and security incidents, such as warnings on unsecured websites and detecting viruses. The solution has really reduced the number of detections over time while providing full protection for users.
The top security challenge in the industry is user awareness since users are often unaware of the dangers posed by certain applications and websites. TrendAI Vision One helps address this issue by providing user awareness training, such as phishing campaigns that inform users to avoid threats.
My main advice for others considering TrendAI Vision One is that it provides both basic and advanced protection for every user, while the licensing is very flexible compared to other solutions. With TrendAI Vision One, most features are included in basic licensing, unlike other solutions that require payment for simple features.
TrendAI Vision One is a great solution for users requiring advanced protection. Over the past 20 years, it has provided as many features as possible for every user, so I can confidently recommend it for organizations. I would rate this solution an 8 out of 10.
YFT
Centralized threat visibility has improved response times and simplifies incident investigations
Reviewed on Sep 23, 2026
Review provided by PeerSpot
What is our primary use case?
The main use case for TrendAI Vision One in my organization is that we manage client assets such as endpoints, servers, and email.
What is most valuable?
TrendAI Vision One has positively impacted my organization. TrendAI Vision One has helped us reduce the time to detect and respond to threats, as with the correlation of events across various security layers, I benefit from a complete view of incidents from a single platform without the need to jump around.
The investigation and alert prioritization tools expedite analysis significantly, automating many detection and containment tasks even before the analyst reviews the event viewer.
What needs improvement?
I think there are quite a few things that could improve TrendAI Vision One. The console or the graphical interface of the console is a bit complex, with several sections for each module where information is spread out among them and some is repeated across sections. Console updates change the layout of sections and modules significantly, without any notice or alert informing me of these changes. The APIs section is also a bit confusing, as I understand there is a general API, but then each module has its own, and it is not very well explained when to use one or the other.
Vendor support can feel random; depending on who you get, resolving an incident can be easy or very difficult. Some support members do not have sufficient knowledge about the platform or the relevant concepts, and response times can be very variable—sometimes they can respond the next day or it can take a week. If it is a serious incident, you might be stuck for the entire week. Report generation is a bit basic; the reports are simple and I cannot customize them effectively. Licensing is also confusing because we seem to have the same license duplicated with similar functionality for different teams, which is not clearly reflected.
At the Endpoint Security level, the agents being used in TrendAI Vision One have several problems; we frequently encounter incidents where the agent consumes resources uncontrollably. Many servers or endpoints can manage this easily, but some have limited resources and processing power. It often interferes with the company's internal processes, creating delays, communication issues, and data loss, forcing us to disable modules on machines. Furthermore, support for different operating systems is limited; many clients use devices with older, unsupported operating systems, resulting in fewer modules being available.
At the Cloud level, I also experience several issues with Cloud Email Gateway Protection in TrendAI Vision One, such as problems with DKIM validation where the platform often fails to provide clear information on whether the cause is a poorly made signature or DNS resolution failures; sometimes the header indicates the absence of a DKIM signature when there actually is one. Additionally, the API for Cloud Email Gateway Protection has limitations, such as a 72-hour log retrieval limit that feels excessive. I also cannot filter mail traffic by user or specific address and must retrieve the entire domain's data. This means pulling in around 300,000 emails for a 24-hour period only to filter it myself, which consumes resources and time. Certain functions are available in the console but not through the API, which I find critical. Lastly, we have faced issues where emails that should bypass Inbound Protection based on our defined rules still get blocked, which does not make much sense.
For how long have I used the solution?
I have been using TrendAI Vision One for one year and five months.
What do I think about the stability of the solution?
Overall, it has proven to be a pretty stable platform. The main services, dashboards, APIs, and security modules generally provide consistent availability and performance. Of course the are some occasional issues, specially during maintenance, service updates, or when processing a high volume of data, but these don't significantly affected the overall reliability of the platform in our experience.
What do I think about the scalability of the solution?
It offers a very strong scalability, particularly for enterprise environments with a large number of users, endpoints, and security events. The platform also provides a centralized visibility of the security layers and products, which makes it really easy to manage a growin environment without increasing the operational complexity.
How are customer service and support?
4
Which solution did I use previously and why did I switch?
No
How was the initial setup?
I didn't took part on that process
What about the implementation team?
I didn't took part on that process
What was our ROI?
We have, but I can't share any data
What's my experience with pricing, setup cost, and licensing?
I didn't took part on that process
Which other solutions did I evaluate?
I didn't took part on that process
What other advice do I have?
The features of TrendAI Vision One are really useful and have improved my work. The main security challenges in my sector include managing diverse threats. I have covered everything I had to say and do not remember anything else important that I have left out. My review rating for TrendAI Vision One is 8.
AhmedEl-Tayeb
Centralized security visibility has improved threat response while kernel-level impact needs work
Reviewed on Sep 08, 2026
Review provided by PeerSpot
What is our primary use case?
TrendAI Vision One has helped my customers consolidate their use of security vendors and reduce silos. If you purchase multiple technologies or products provided by TrendAI, that unified visibility console gives you full visibility across all the products provided by TrendAI across the network. This facilitates management and policy deployment for customers.
My customers do not purchase TrendAI Vision One directly from TrendAI or from any third party. TrendAI is not considering selling directly to end users unless it is a big corporate arrangement or an OEM agreement. Usually, sales should occur through a reseller, then a distributor, or directly through a distributor to TrendAI.
What is most valuable?
User behavior analysis is the most important feature of TrendAI Vision One, in addition to the zero-day feature within that application. When customers upsell or add an XDR license, the product becomes a closed, solid endpoint protection solution that wins against the competition.
TrendAI Vision One has helped my customers consolidate their use of security vendors and reduce silos. If you purchase multiple technologies or products provided by TrendAI, that unified visibility console gives you full visibility across all the products provided by TrendAI across the network. This facilitates management and policy deployment for customers.
What needs improvement?
TrendAI Vision One should learn from its competitors that having everything managed in one single platform gives strength to the product itself. However, instead of focusing on easing access for administrators, they should pay more attention to development itself and staying up to date. There was an initiative in the early days called Zero-Day, which means that before a threat is announced, they would hire specialists who immediately learn about threats and push updates directly to the product.
Customers are protected even before the threat is announced. Currently, the Zero-Day initiative is not as active as it once was.
Additional features I expect from TrendAI Vision One in the future to make it more competitive could be more technical in nature. A product working on the kernel level of a PC, machine, or server consumes significantly more resources than other products that work on runtime memory. If an application is attached to the operating system of the machine itself, it consumes more resources from the PC or server than running that product on the memory level. Memory-level products read all running activities across the memory when the machine is on, and when they detect malicious activity, they cut or end the session, which is lighter on the operating system and does not consume many resources.
For how long have I used the solution?
I have been working with TrendAI Vision One for around five years.
How are customer service and support?
TrendAI Vision One's technical support is adequate because they recently implemented a good methodology of supporting their customers. They initiated a Major Service Center divided across the globe, with a dedicated support center for the Middle East, another for Europe, a third one in the American market, and a final one in Singapore dedicated to supporting Far East customers. This has enhanced their support.
What gives more strength to their products is that they enable business partners, distributors, resellers, and others with sufficient tools to identify problems and provide first and second level support themselves. When an engineering intervention is needed, the case can be escalated to their support team, which is more effective than the old model. They initiated this Major Service Center two or three years ago, which makes it easier for customers and enhances support.
What other advice do I have?
My impressions of TrendAI's ability to provide centralized visibility and management across protection layers are positive. They had, in the early beginning, a unified management console called Apex One. The commercial name has changed over time, and it is now called Apex Central. TrendAI Vision One Apex Central gives full visibility across the customer network, including all solutions provided by TrendAI, with unified visibility, policy deployment, and plug-in extensibility.
TrendAI Vision One has helped my customers reduce their time to detect and respond to threats. There have been a few incidents where intruders could get into the network even while the product was deployed. TrendAI ranks third globally as an endpoint or EDR solution. There are pros and cons to the product. I would rate TrendAI Vision One between seven and eight out of ten.
My customers may use the Cyber Risk Exposure Management capabilities of TrendAI Vision One. However, I do not think they are using or activating that feature because it can conflict with other products. Most banking customers prefer not to activate EDR and endpoint protection from the same vendor, as a compromise could become a significant issue. Therefore, I did not use this feature.
SANDEEP S.
Centralized Console That Saves Time with Strong Threat Detection
Reviewed on Sep 08, 2026
Review provided by G2
What do you like best about the product?
A single, centralized console for endpoints and servers with threat detection and remediation. It saves a lot of time and effort.
What do you dislike about the product?
Sometimes the endpoints are not synchronized with the console.
What problems is the product solving and how is that benefiting you?
Single console avoids eliminating false positives and avoid multiple visits to individual endpoint locations