Dazz Unified Remediation Platform logo

    Dazz Unified Remediation Platform

    Sold by
    The Dazz Unified Remediation Platform is a SaaS platform that accelerates remediation and risk reduction for security and development teams. Dazz automates the manual, time-consuming remediation process, allowing organizations to quickly uncover blind spots, shrink vulnerability backlog into root causes, and streamline fixes in existing customer workflows.

    Ratings and reviews

    4.3
    61 ratings
    3 star
    2 star
    1 star
    56%
    44%
    0%
    0%
    0%
    40 AWS reviews
    |
    21 external reviews
    External reviews are from PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (61)
    PrashantGupta2

    Automated scanning has safeguarded our pipelines and continuously improves cloud security

    Reviewed on Sep 19, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Wiz is to scan the vulnerabilities related to our system.

    We are planning to introduce Wiz into our CI/CD, scanning the Docker image whenever it gets built, so if there is any vulnerability, we can refer to the Wiz report and resolve it before pushing the code.

    The cloud security democratization aspect of Wiz is crucial, as our company offers various services and must ensure data security and product quality while managing threats from older dependencies or JARs.

    What is most valuable?

    I feel that the automated scanning system of images and accounts offered by Wiz is amazing, and the best part is that they provide solutions as well, allowing us to solve the problems without looking elsewhere.

    The automated scanning stands out for me because when our security team raises a ticket, the solutions provided in the Wiz report help us debug those issues, and I rely 100% on the Wiz solutions.

    Wiz has positively impacted our organization by solving many issues, such as ensuring we do not have vulnerable code in our production environment, protecting our customer data, and helping us maintain system security from potential threats.

    I notice that whenever the scans are completed, we consistently upgrade our system, and Wiz scans for any unused infrastructure that we are not using or maintaining, pointing out vulnerable files that can be upgraded or deleted.

    Wiz does allow us to consolidate tools, providing abundant infrastructure information before billing is affected and recommending solutions for any public-facing vulnerabilities, which enables us to rely on Wiz to address critical infrastructure issues.

    I feel that Wiz has reduced alert fatigue in our organization by approximately 70%.

    What needs improvement?

    I believe Wiz is 100% correct in what it does, and if there is any improvement needed, it would be more mature reporting and solutions, as Wiz detects threats only when they have a solution available.

    I think speed is important; Wiz waits for approval before suggesting a new vulnerability solution, so a faster cycle would help developers prepare before an attack occurs.

    For how long have I used the solution?

    I have been using Wiz for two years.

    What do I think about the stability of the solution?

    Wiz is stable.

    What do I think about the scalability of the solution?

    For my use case, I do not experience any issues with Wiz's scalability, and I see that it can handle various services, making it highly scalable and reliable.

    How are customer service and support?

    Customer support was helpful in resolving issues caused by a mistake on our part during configuration.

    Which solution did I use previously and why did I switch?

    I do not have prior experience with any solutions besides Wiz, so I feel that Wiz does the job perfectly in identifying active threats.

    Which other solutions did I evaluate?

    We have only used Wiz, and when I joined my company, Wiz was the ultimate choice for us.

    What other advice do I have?

    I find Wiz's AI capabilities to be very capable, as we sometimes chat with the AI and review reports for better understanding.

    The accuracy and reliability of Wiz's output are quite good, and the AI helps clarify any doubts I have regarding the reports.

    I advise others looking into using Wiz to rely on it smartly and trust the solutions it provides.

    I rate this review as 9 out of 10.

    Sonaansha Aneja

    Centralized cloud risk visibility has transformed how our team prioritizes and remediates issues

    Reviewed on Sep 11, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I have been using Wiz for around six months. My main use case for Wiz is cloud security visibility and risk management, as I use it to identify misconfigurations, vulnerabilities, and potentially security risks across a cloud environment. Having this information in one place makes it easier for the security team to prioritize issues and focus on the risks that need attention first.

    An example of how my team uses Wiz for risk management or visibility is identifying a cloud resource with a security misconfiguration and prioritizing it based on the associated risk. Instead of manually checking every resource, the team can quickly see the issue, understand its potential impact, and route it to the right team for remediation, making the review process much more efficient.

    I also use Wiz as a central point for getting an overall view of the cloud security posture. It helps us bring different security findings together, prioritize the important risks, and give us a clear picture of where attention is needed. The centralized visibility is probably the biggest benefit for all of us.

    Wiz is primarily used in our public cloud environment, having integrated with a cloud account so the team can get centralized visibility into configurations, vulnerabilities, and security risks across the environment without managing separate tools for each account.

    Wiz has helped us consolidate some of our cloud security workflows into a single platform, making it easier to prioritize critical risks because we can see the related findings and context together instead of switching between multiple tools. It reduces the noise and helps the team focus on issues that have the greatest potential impact.

    The runtime sensor has improved our visibility into active threats by providing more context around what is happening in the environment, making it easier to distinguish active threats from lower findings and focus the team's attention on threats that require immediate investigation compared to previous solutions.

    What is most valuable?

    The best features Wiz offers include centralized cloud visibility, risk prioritization, and the identification of misconfigurations and vulnerabilities. I also appreciate how Wiz connects different findings and provides context around the potential impact, making it easier to focus on the issues that actually matter instead of treating every alert the same way.

    The feature that has made the biggest difference for our team is centralized cloud visibility, as it gives us a much clearer view of our overall security posture and helps us quickly identify which sources have the highest priority risks. This saves time compared to manually referring to different cloud environments and security findings separately.

    I appreciate that the features work together rather than operating as completely separate tools, as the combination of visibility, risk context, and prioritization makes it easier for the team to understand what needs attention first. It keeps the security workflow relatively simple while still providing a good level of detail.

    Overall, Wiz has a positive impact on our organization by improving our visibility into the cloud environment and making it easier to identify and prioritize security risks. The centralized view has also helped the team spend less time manually viewing findings and focus more on addressing the issues that have the greatest potential impact.

    What needs improvement?

    Wiz is already quite strong, but the platform could be made even easier for new users with more guided workflows and simpler explanations of some of the more advanced findings. I would also like to see further improvements in reporting and customization so the team can tailor dashboards and reports more closely to their specific needs.

    One area I would like to see improved is the user experience around complex findings, as having more contextual guidance on why an issue is important and the recommended remediation steps would make it easier for newer team members to act on findings. More flexible reporting and dashboard options would also be useful.

    What do I think about the stability of the solution?

    Overall, I have found Wiz to be stable and reliable in day-to-day use, consistently providing visibility across our cloud environment without experiencing major stability issues. The platform has been dependable for monitoring security posture and keeping track of risks over time.

    What do I think about the scalability of the solution?

    I rate Wiz's scalability quite positively, as it works well as the cloud environment grows and makes it possible to maintain visibility across multiple accounts and resources from a centralized platform, making it easier for the security team to scale monitoring and risk management without significantly increasing the manual effort.

    How are customer service and support?

    Overall, I have had a positive experience with Wiz customer support, as the team has been responsive when I needed help with configuration or understanding specific findings. Their guidance has helped me resolve questions faster, although the response time on more complex issues could sometimes be improved.

    Which solution did I use previously and why did I switch?

    I previously used CrowdStrike as a cloud security solution, but I was not finding it working according to my needs, so I needed to switch. I chose Wiz, which has been more efficient and has been working very well.

    How was the initial setup?

    My experience with pricing, setup cost, and licensing for Wiz has been fairly straightforward, as the setup was relatively smooth once the cloud environment and integrations were configured. The licensing model was easy for me to understand, with the overall cost feeling reasonable considering the visibility and security coverage Wiz provides across the cloud environments.

    What was our ROI?

    While I have not calculated a formal ROI with specific financial figures, the overall impact of Wiz has been positive, as it saves time by bringing cloud security findings and context into one place and reduces manual investigation and prioritization. It also helps the existing team work more efficiently without needing additional resources just to manage cloud security visibility.

    Which other solutions did I evaluate?

    I evaluated a few other cloud security platforms before choosing Wiz, mainly comparing them on cloud visibility, risk prioritization, ease of deployment, integrations, and overall usability. Wiz stood out because it provided a more centralized view of our cloud environment and made it easier to understand and prioritize the risks I was seeing.

    What other advice do I have?

    While I have not formally measured the impact with specific numbers, the time savings from using Wiz are noticeable, as it reduces the amount of manual effort needed to view cloud resources and prioritize findings. The team can get context around the risks much faster, helping us respond to important issues most efficiently.

    Wiz has reduced alert fatigue for the team, mainly by providing better context and helping prioritize the findings that matter most. While I have not formally measured the reduction over a specific period, the team spends noticeably less time sorting through low findings and can focus more quickly on critical risks.

    I use Wiz post-sale support services when needed, which have been helpful for resolving configuration questions and getting guidance on more complex security findings. Having that support available helps our team troubleshoot issues faster, using the time I could otherwise spend figuring out certain problems on my own.

    Wiz has helped us reduce and prioritize critical issues, although we have not consistently reached zero criticals in the issue queue. Its prioritization and contextual information make it easier to identify the most important issues and get them assigned for remediation, which has improved our overall response process.

    I recommend Wiz to organizations looking for better visibility and centralized management for cloud security risks, advising that they clearly define their cloud accounts and security priorities before deploying it. The platform can surface a lot of information, so taking time to understand its prioritization features will help the team get the most value from it. I rate this product nine out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    reviewer2866275

    Unified cloud visibility has improved risk mapping and reduces code-level vulnerabilities quickly

    Reviewed on Sep 03, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Wiz is being tested to compare against Checkmarx, examining scanning capabilities, native visibility, ease of deployment, and code-level analysis. The proof of concept has completed, and we had interaction with the user interface, gaining the ability to use some of the features and functionality of Wiz. The scanning process was very easy, with a single pane of glass making it simple to move from one feature to another. There is significant customization involved, allowing for bespoke configuration to meet specific requirements. Wiz provided many advantages, and the proof of concept was very impressive. The interface was simple to use and quick to become familiar with.

    We were able to examine risks and vulnerabilities very easily, which was the main focus of the initiative—to identify exactly where the vulnerabilities, risks, and threats were located and to detect and identify those immediately within the framework provided. Multi-cloud risk mapping proved very useful because we could see everything with no hidden elements. Everything was visible and transparent. In terms of prioritization, we could identify which specific area of the cloud or container contained vulnerabilities. When critical issues appeared, we could develop metrics to understand where specific problems lay. If a certain area had multiple critical vulnerabilities, we looked deeper into that area to find underlying causes. There was immediate information available, as well as information that could be gleaned after conducting root cause analysis. Trends and trend analysis have improved, helping us build a clearer picture of what is happening, where it is happening, and why. Robust static application security testing (SAST) and SCA analysis at the code level proved very useful. Catching vulnerabilities early was a key highlight and takeaway from the proof of concept.

    What is most valuable?

    The best feature Wiz offers is the ability to identify different threats, weaknesses, and vulnerabilities, with vulnerabilities being the main focus because that is what we have to communicate to our coders and developers. We were able to see what specific vulnerabilities contained in terms of root cause analysis, such as whether libraries needed updating, whether certain CVEs were related to those vulnerabilities, and how common those vulnerabilities were, including whether patches or fixes were available. Significant information was available that could help remediate numerous issues. Vulnerabilities identification and detection were very important; we were immediately able to see through drilling down exactly what was available in terms of remediation, whether it was possible immediately or what could be done afterward.

    In terms of posture management, it was fantastic because we could see how risks were mapped across multi-cloud infrastructure seamlessly. The threat detection algorithms and mapping prioritized vulnerabilities based on actual exposure, allowing us to see critical, high, medium, or low priorities instantly. The deployment was also very easy.

    Wiz has positively impacted our organization with improved remediation speed and efficiencies in terms of time saved, as well as reducing false positives. We are currently conducting deep code scanning alongside posture management, and we have seen improvements and efficiencies in both areas. Final metrics have not been established, and I am certain that will be completed in October once analysis is finished. However, the initial findings and recommendations are very positive, indicating benefits in time saved and efficiency, as well as economies of scale in performing tasks more easily and quickly while eradicating false positives and achieving a clearer picture of real vulnerabilities.

    Wiz has met my expectations in terms of accuracy and reliability of output, with the co-pilot functionality being very good. The assistant services from AI exceeded what I had anticipated. Although the full range has not been tested, my experiences, along with my colleagues', have been very impressive regarding the outputs generated by AI.

    What needs improvement?

    While Checkmarx may perform better in some deep code scanning aspects, Wiz is considerably easier to use, has a better user interface, and offers a more compelling argument for its use. It is more robust and stable, making these positive points quite clear. The only slight negative is its scanning capability compared to Checkmarx, but it is still very good. Additional comments regarding needed improvements around scanning capabilities or any other area where Wiz could catch up to Checkmarx are not necessary.

    For how long have I used the solution?

    Wiz has been used for a proof of concept over the course of a few weeks. A decision regarding adoption will be made by our company based on the findings and recommendations from the participants in the proof of concept initiative.

    What do I think about the stability of the solution?

    Wiz is stable based on proof of concept experience, and it is certainly much more stable than Checkmarx.

    What do I think about the scalability of the solution?

    I am very impressed with Wiz's scalability. We began with 50 licenses and quickly increased that number to 200. It was efficient in scaling up. While we anticipate needing in excess of 200 licenses moving forward, we are confident Wiz can handle that demand.

    How are customer service and support?

    Customer support receives a rating of 10 because we had a few initial questions, and they responded quickly and professionally, resolving all our issues regarding identity and access management in a short period.

    Which solution did I use previously and why did I switch?

    The main solution currently in use is Checkmarx. We considered switching because Checkmarx experienced several outages and failures in service delivery, prompting us to explore other options in the marketplace.

    How was the initial setup?

    During the proof of concept, there was minimal interaction with other applications. There was a link to Jira and Confluence for ticket creation, but since it was a proof of concept, much of the information was dummy data. Wiz was used primarily in isolation to see how the product would function on its own, without integration with other products.

    What about the implementation team?

    Post-sale support services were not used during the proof of concept. The next step will be to collect all findings and make recommendations to senior management, who will decide whether to implement Wiz within the company.

    What was our ROI?

    A return on investment has not been technically realized yet, but efficiencies have been achieved in terms of fewer false positives and reduced analyst time on resolving vulnerabilities. These metrics will become clearer in October after assessing how Wiz performed against Checkmarx. The initial findings are encouraging, and we are optimistic about future assessments.

    What's my experience with pricing, setup cost, and licensing?

    No involvement occurred with pricing, setup cost, and licensing for Wiz since it was a free proof of concept. Approximately 200 licenses were provided for the initiative, but pricing moving forward is unknown. It is expected to be more expensive than Checkmarx; however, the overall feeling is that Wiz is the more stable and user-friendly product, strong with features and functionality, potentially favoring the decision to move forward.

    Which other solutions did I evaluate?

    The recommendations provided by Wiz were valuable. This functionality is not available with Checkmarx currently. The concept of using the co-pilot and large language models, along with agentic AI, is refreshing and potentially very beneficial for future operations, particularly in troubleshooting and root cause analysis.

    What other advice do I have?

    Multi-cloud risk mapping was very useful because we could see everything with no hidden elements. Everything was visible and transparent. In terms of prioritization, we could identify which specific area of the cloud or container contained vulnerabilities. When critical issues appeared, we could develop metrics to understand where specific problems lay. If a certain area had multiple critical vulnerabilities, we looked deeper into that area to find underlying causes. Significant immediate information was available, as well as information that could be gleaned after conducting root cause analysis. Trends and trend analysis have improved, helping us build a clearer picture of what is happening, where it is happening, and why. Robust static application security testing (SAST) and SCA analysis at the code level proved very useful. Catching vulnerabilities early was a key highlight and takeaway from the proof of concept.

    The recommendations provided by Wiz were valuable. This functionality is not available with Checkmarx currently. The concept of using the co-pilot and large language models, along with agentic AI, is refreshing and potentially very beneficial for future operations, particularly in troubleshooting and root cause analysis.

    My overall rating for this review is 9.

    Jagdish Mandaramariq

    Cloud security has improved as I manage multi-cloud risks and streamline compliance audits

    Reviewed on Jul 27, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I have been using Wiz for approximately three to four weeks, and I find that Wiz is an amazing cloud security platform that helps the organization identify, prioritize, and remediate security issues across cloud environments such as AWS, Azure, and various types of clouds, Kubernetes, and containers.

    My main use cases for Wiz include cloud security posture management, or CSPM, because admins continuously monitor the cloud environment for misconfigurations and if any misconfiguration is found, Wiz will correct them. Additionally, there is the Vulnerability Management feature because it prioritizes vulnerabilities based on real-world risks and exploitability, also identifying vulnerabilities that could impact real-world risk within organizations. The Identity security feature also detects excessive permissions and identifies related risk, along with Kubernetes security which scans the Kubernetes clusters and workloads. These are my use cases of Wiz in my role.

    We use Wiz in a cloud risk assessment because we scan client cloud environments to identify exposed resources and misconfigurations, generate security assessment reports, and perform vulnerability management and compliance audits which validate adherence to industry frameworks and produce audit-related reports for customers. This eases their workload, and it is also used for incident response to investigate attack paths, identify compromised resources, and reduce investigation time with centralized visibility. These are my use cases in my work.

    What is most valuable?

    The best feature of Wiz is its multi-cloud support which encompasses AWS, Microsoft Azure, Google Cloud Platform, and Kubernetes. This multi-cloud support is one of the main features that stands out, along with path analysis that matches how attackers could navigate through the environment.

    Wiz has impacted our organization very positively because it includes various advanced features such as compliance audits, continuous security monitoring, and vulnerability management, along with cloud assistance and DevSecOps integration. All these features empower Wiz, significantly aiding our organization's growth.

    I have seen major changes since implementing Wiz because it greatly enhances visibility into our cloud infrastructure; the onboarding became simpler and the dashboard provides clear insights into vulnerabilities, misconfigurations, and attack paths, contributing positively to our organization's security and growth.

    Wiz provides governance as it implements all necessary policies correctly, validating compliance with industry frameworks rather than just standard frameworks. It adheres to frameworks created by the CB or RBAC which gets validated here, providing Audit Ready Reports for customers; this is an excellent point for both customers and co-owners.

    The accuracy and reliability of Wiz are impressive; all the inputs fit perfectly with no extra adjustments needed. Reliability exists in various features, especially when creating policies, allowing us to execute incident response tasks effectively; hence, accuracy and reliability are strong components of Wiz.

    Wiz's Runtime Sensor integrates seamlessly with DevSecOps, providing CI/CD pipelines and integrating with various tools and use cases, helping to effectively identify actively running threats, making it a strong solution compared to previous ones.

    Wiz has great scalability; I find it one of its strong features, helping organizations grow due to its capabilities.

    What needs improvement?

    I believe a little more documentation could help users follow step by step. That is the extent of the improvements needed.

    I feel there is a bit of noise in the initial setup and quality cleaning that may take time in larger environments. Additionally, advanced features might require security expertise; hence, improvements in documentation would be beneficial. Otherwise, all aspects are very good and easy to use.

    For how long have I used the solution?

    I have been using Wiz for approximately three to four weeks.

    How are customer service and support?

    Customer support is good; whenever we need assistance, the business support team is readily available to help us. It is reassuring to know we can rely on good customer support.

    What other advice do I have?

    All of the ways I use Wiz are amazing, as it can be used anywhere it is suitable, and it is especially great for large organizations.

    I find myself relying most on multi-cloud support because it is very useful, especially since we do not have a single cloud but rather use different clouds such as AWS, Azure, and Google Cloud Platform along with Kubernetes. Wiz allows us to coordinate efficiently across these different teams and groups, which is why our organization relies heavily on this feature.

    Wiz does not allow for tool consolidation in our environment; even though it has features for that, there is not a need to consolidate different tools because it functions very well with existing tools in our organization.

    We have reduced alert fatigue in our organization due to Wiz's accuracy in managing alerts. I can approximate a reduction of approximately three to four hours in alert handling since Wiz provides alerts with minimal latency between the alerts and real-time notifications.

    I advise others to choose Wiz because it stands out as an awesome tool that offers various benefits to organizations, and trying Wiz will undoubtedly benefit you. I have given this product a review rating of 9.5 out of 10.

    jay-savaliya

    Contextual risk insights have transformed cloud posture management and now streamline audits

    Reviewed on Jul 27, 2026
    Review from a verified AWS customer

    What is our primary use case?

    Our primary use case for Wiz is Cloud Security Posture Management and Cloud Native Application Protection.

    One of our clients was preparing for a security assessment, so Wiz identified an internet-facing EC2 instance with excessive IAM permissions and outdated software containing critical vulnerabilities. Instead of reviewing multiple security tools separately, Wiz correlated the exposure, vulnerability, and privilege information into a single risk finding. That allowed us to remediate the issue quickly before the audit.

    We use Wiz daily to monitor cloud resources, investigate security findings, and prioritize remediation based on actual business risk instead of simply focusing on CVE severity.

    What is most valuable?

    The best features offered by Wiz are the Attack Path Analysis and the risk prioritization and agentless cloud security scanning.

    The Security Graph and Attack Path Analysis have been the most valuable in our organization because rather than generating thousands of alerts, Wiz helps us to understand which findings represent real risk and should be addressed first.

    Wiz has improved our visibility into cloud risk, reduced manual security assessments, and helped us prioritize remediation efforts more effectively.

    It reduced the time spent investigating cloud security findings by around 40% and also accelerates the process of identification of critical cloud risk.

    The findings from Wiz are generally accurate and well prioritized, and I appreciate that Wiz focuses on contextual risk rather than overwhelming us with every possible vulnerability.

    What needs improvement?

    More customizable executive dashboards can be created, and better reporting for non-technical stakeholders can also be improved in Wiz platform.

    Overall, it is a mature platform and most enhancements I would like are around reporting automation and simplifying executive level reporting.

    For how long have I used the solution?

    I have been using Wiz for approximately one and a half years.

    What do I think about the stability of the solution?

    Our companies are currently processing terabytes of data, and Wiz is very stable.

    What do I think about the scalability of the solution?

    Wiz is very scalable, so there is no problem in that regard.

    How are customer service and support?

    We have used the support services after purchase, and they are very good. Their teams are very knowledgeable and very supportive, and their team can handle all issues.

    Customer support is very good, and they are very knowledgeable and always ready to help you out from any difficult situation or if you face any complexity in Wiz platform.

    Which solution did I use previously and why did I switch?

    Before using Wiz, we relied on multiple tools for vulnerability scanning, cloud configuration checks, and cloud native security services. Each tool generated its own findings, so correlating risks required manual effort, but with Wiz, we get a unified view of combined vulnerabilities, misconfigurations, exposed assets, IAM permissions, and runtime context all in a single platform.

    Previously, we were using multiple tools for cloud security, cloud native application management, AWS monitoring, and similar tasks, but we wanted a single platform that encompasses all these capabilities, so we switched to Wiz.

    How was the initial setup?

    Setup is very easy, and if you feel any difficulty while setting up anything, their support team is ready to help you out with that.

    What about the implementation team?

    We have used the support services after purchase, and they are very good. Their teams are very knowledgeable and very supportive, and their team can handle all issues.

    Customer support is very good, and they are very knowledgeable and always ready to help you out from any difficult situation or if you face any complexity in Wiz platform.

    What was our ROI?

    We have seen the ROI from this because it reduced our engineer's time by 50% and also saved time on addressing false positives, allowing us to be very confident in our posture.

    What's my experience with pricing, setup cost, and licensing?

    The pricing is a bit higher than the market rate, but the value it provides is more valuable than the pricing. Setup is very easy, and if you feel any difficulty while setting up anything, their support team is ready to help you out with that. We are running it on a monthly license basis, so we have not purchased the enterprise version.

    Which other solutions did I evaluate?

    We have not evaluated any other option.

    What other advice do I have?

    AI security posture management in the cloud is very important because risks are increasing, and to reduce the manual effort of every department, AI agents can be deployed in cloud security posture to directly find AI security as connected within the organization.

    Wiz has reduced the alert fatigue in our organization, and if you are fully migrated with Wiz, within a week you can see the difference.

    Before Wiz, we used Falcon as a runtime sensor, and after using Wiz, we are now 100% sure that Wiz's Runtime Sensor is very accurate and helped us to identify active threats more effectively compared to our previous solution.

    Teams currently using multiple platforms for security assessments, compliance monitoring, cloud native application posture management, and cloud security posture management can directly switch to Wiz without any hassle, and it will be a very valuable decision for their teams.

    Wiz is very scalable, so there is no problem in that regard.

    Wiz is a very mature platform that we use daily as an end-to-end cloud management tool. It is great as it reduces your company's security risk and actively monitors your entire cloud infrastructure, so you do not need to worry about any cloud risks affecting your organization. I would rate this product a 9 out of 10.

    reviewer2860563

    Improved code security posture and visibility but still needs stronger secret scanning protections

    Reviewed on Jun 23, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Our AppSec journey focuses specifically on secret scanning to SCA, and we have been using Wiz Code IAC lately to perform Terraform and IAC code scannings for security posture before deployment to the cloud. Wiz Code has another feature where we ingest AppSec findings from Semgrep, Snyk, and Gosec.

    When developers write microservices with containers, Azure Functions, or any sort of microservice or monolithic applications, they use a default branch focused towards production and feature branches. Approximately 30 to 40% of code comes via AI agentic development. When engineers develop new features, their code is scanned as part of the feature branch using Wiz Code. Wiz Code supports first-party and third-party code scanning along with secrets and IAC, and provides constructive feedback for security hygiene and code posture. Engineers or agents receive this feedback, act upon it, and fix findings before merging to the default branch, which may be main or any release branch we have. Our CD pipeline then kicks in. Wiz Code fits into our Application Security Posture Management and gives us thorough insights.

    What is most valuable?

    I prefer Wiz Code specifically because it creates less friction and the intuitive UI helps me significantly. Wiz Code has a rules policy that is not noisy for the engineering team, which is quite important. Less false positives with Wiz Code is the key USP that I love.

    The UI is everything in the AppSec world and dashboards. If results are not constructively presented and showcased with prioritizations and metrics, they will be misguided. Wiz Code helps us show results in the best way, and this has been consumed by the engineering team with good prioritization metrics. Wiz Code has a UI dashboard and performance metrics that help us triage vulnerabilities quicker.

    People are writing secure code with good visibility about how the code is performing and the posture is becoming visible. Wiz Code has helped us have better visibility across our source code and gives us thorough insights.

    What needs improvement?

    Wiz Code could be better in secret scanning where no push protections are enabled at the GitHub or GitLab level to prevent pushing secrets on GitHub itself. There appear to be limitations in terms of Wiz Code as an external party to SCM source code management systems, which makes this somewhat problematic. Otherwise, it still seems to be good.

    For how long have I used the solution?

    I have been using Wiz Code for around 15 months.

    What other advice do I have?

    Approximately 30 to 40% of vulnerabilities are being remediated quicker and easily because Wiz Code has an auto-fixing PR feature available for IAC code, which helps us fix issues quickly. We also use it for containers. Using Wiz OS, we were able to resolve many vulnerabilities, and Wiz Code scans those and gives assurance that these particular images are not vulnerable anymore. Secure coding practices are improving.

    Wiz Code is used to develop our AppSec dashboards. We have our internal CMDB tied up to Wiz. Wiz Code is used as an inventory to see our application security postures. It is used across our engineering teams, product teams, vulnerability management team, GRC, architecture teams, CISO, head of engineering, head of cybersecurity, and SecEng teams, all of whom use Wiz Code for checking the posture of our applications.

    Wiz Code has mature ways of handling AI, which seems to be good. The efficacy seems to be very good. The review rating for this product is 7.

    Nicholas Louisma

    Unified cloud views have simplified finding infrastructure vulnerabilities and identity risks

    Reviewed on Jun 23, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I have been working with Wiz for about two years. I use Wiz for vulnerability management, specifically finding infrastructure-related security bugs, particularly with Windows. I have also used it for a couple of months for identity-related purposes.

    What is most valuable?

    The UI is what I appreciate most about Wiz; the interface is really easy and not clunky. You can create many dashboards and a personal page for all the vulnerabilities you are trying to find. When it comes to your systems, users, and applications, having all of those attachments to your different platforms and being able to have the scans go throughout the platforms while pulling those vulnerabilities is really helpful with a nice user interface.

    Wiz brings great integration into GCP resources, which is crucial for my previous organizations that were very heavily GCP-based. Wiz has seamless integration into GCP, AWS, Azure, Okta, and other large cloud platforms and SaaS platforms.

    Wiz allows you to consolidate tools, but not all tools. It does not handle the nuanced type of tools, but the major tools it does allow you to consolidate from my experience.

    The main advantage of Wiz is its user interface. A good interface makes it easy for engineers to not get fatigued from working with so much data and ensures it is not clunky-looking, as it is hard to identify issues. You want something that is visually appealing to identify risk, and having a good UI presents a huge benefit.

    What needs improvement?

    I would want to see Wiz improve by connecting to other major platforms agnostically, with the ability to connect to other platforms without needing to do too much integration. It requires a lot of alignment with different platforms for it to function properly.

    I am not sure if Wiz has reduced alert fatigue in my organization, as I have not really looked into that aspect.

    Wiz is not agnostic compared to other competitors in the market. If you want to add a new integration to another platform, it does not have an easy plug-and-play option for whatever platform. It requires integration to the proper tooling, and that is only from my experience with it.

    For how long have I used the solution?

    My experience with Wiz began six months ago.

    What do I think about the stability of the solution?

    I have not had any crashes, downtimes, or performance issues with Wiz.

    What do I think about the scalability of the solution?

    I find Wiz scalable and have tried to scale it up and out.

    How are customer service and support?

    I evaluate the customer service and technical support of Wiz as pretty useful. At my last company, we were able to have weekly calls with Wiz to talk about new updates and remediate any issues that we had. I would rate the technical support an eight on a scale of one to ten.

    Which solution did I use previously and why did I switch?

    I have used Exonius, but that is not a cloud posture platform; it is more of a logging platform or monitoring platform. I probably have used others, but I do not remember their names.

    How was the initial setup?

    Onboarding with Wiz is straightforward. I find it easy to teach myself how to use it, and I was able to figure it out within a week or two of just exploring it inside of Wiz.

    What about the implementation team?

    I was not involved in the setup deployment of Wiz.

    What other advice do I have?

    I have not utilized Wiz Defend. I do not use Wiz Code in my operations. I have not used the AI Posture Management in Wiz, but I have used Posture Management, though I only used it for a few weeks in the beginning.

    I find Wiz Posture Management pretty beneficial in my overall cloud security strategy, as everything is in the cloud. Many companies use cloud resources, so I think it is pretty beneficial.

    I have not utilized Wiz Runtime Sensor, as I am more infrastructure, networking, and compute-related, so I have not been involved in application risk and have not really used the runtime features for Wiz.

    Wiz has not helped my organization achieve zero criticals in its issue queues. There are many critical issues that come up regularly, and having to tackle them means sometimes those critical issues cannot be resolved because of architectural issues. If you resolve it, there will be an issue within the architecture, so I do not think I have ever seen the critical issues get down to zero.

    Regarding the cloud security democratization aspect of Wiz, I have only used it here and there for infrastructure-related items and touched some other cloud-related items, but from my scope, I do not think I have seen the actual impact it has on our entire team or organization. When I used it, I was a level one engineer, so I did not get to see the entire scope of its impact.

    I have not used Wiz recently, but from my memory of using it, I did appreciate the identity platform and think that they should expand more into the identity area and make it more seamless for items such as RBAC or non-human identities.

    I am not entirely sure how my latest company purchased Wiz, but my first company that I used it with bought it through Google's Marketplace.

    I was not using Wiz post-sales support services.

    My overall rating for Wiz is an eight out of ten.

    reviewer2860389

    Cloud security has strengthened and vulnerability exposure reduces across multi-cloud environments

    Reviewed on Jun 23, 2026
    Review from a verified AWS customer

    What is our primary use case?

    We are using Wiz Code for cloud security across AWS, Google Cloud Platform, and Azure. We utilize Wiz Code for vulnerability scanning and misconfiguration issue detection across all three cloud platforms.

    For vulnerability management with Wiz Code, we perform daily checks for vulnerabilities and receive CVEs, which we then provide to appropriate teams for remediation guidance. Regarding misconfigurations, we primarily focus on IAMs. If any extra privileges exist with any users, we work with the team to fix these issues.

    Wiz Code is very useful for us because it is agentless, so it does not require attention for storage issues on VMs or Kubernetes. It is very useful and supports cloud environments such as Amazon Web Services, Microsoft Azure, and Google Cloud. We use this for identity management, misconfiguration issues, and CSPM security posture management.

    What is most valuable?

    CSPM is a cloud security posture management feature in Wiz Code. We review the percentage metrics in Wiz Code, and when we identify anomalies or vulnerabilities and fix them, we follow the score on Wiz Code.

    Previously, we identified over 500,000 vulnerabilities before Wiz Code. After implementing Wiz Code, we identified more vulnerabilities and misconfiguration issues but reduced the score significantly. Now we identify only 200,000 vulnerabilities, which means Wiz Code helped us reduce 300,000 vulnerabilities in our organization.

    First of all, Wiz Code has given us more accurate results. When we identify vulnerabilities, we review that vulnerability and CVE, check publicly affected vulnerabilities in our organization, and determine which VMs are affected. We segregate the data based on CVE codes and work with other teams to remediate these vulnerabilities or address OS upgrades and end-of-life issues.

    The AI capabilities in Wiz Code are a very good feature. Employees working on this will get more remediations and detailed remediation guidance. If some tools provide a vulnerability list without remediation guidance, Wiz Code reduces the load of searching for remediation information. For governance and security, Wiz Code is very helpful. It scans everything and provides really deep scans, identifying more vulnerabilities than other tools can find. Vulnerability management is my primary focus, and Wiz Code is a very good tool for this.

    What needs improvement?

    There are many improvements that could be made to Wiz Code, but I would point out that sometimes it gives false results, though not every time. We know that Wiz Code scans our environment once a day. If it scanned twice a day, that would be more accurate. This is a suggestion from my side.

    For how long have I used the solution?

    I have been using Wiz Code for the past two and a half years.

    What do I think about the stability of the solution?

    I did not participate in the integration part as my senior handled those tasks, but I heard that the integration was very easy for any organization.

    What do I think about the scalability of the solution?

    It is very easy to use, especially the dashboards and everything. We have created many dashboards in Wiz Code for our utilization. We use Wiz Code dashboards and queries daily to identify vulnerabilities.

    How are customer service and support?

    I would say that they are very responsive. When we initiate a case for Wiz Code customer support, they immediately respond and contact us to help reduce that issue and address any possibilities. It is very good.

    Which solution did I use previously and why did I switch?

    Previously we used Rapid7, and now we are using Defender. Wiz Code is better than both Defender and Rapid7 and gives more accurate results.

    What other advice do I have?

    It is very easy to pick up on this new tool, and Wiz Code is very useful and easy to learn and apply in our day-to-day work. We plan to keep Wiz Code for a long time with our subscription through 2030. Wiz Code is a good tool that gives accurate results for our environment and is very useful and user-friendly for employees. Overall, Wiz Code is a very good tool to use in any organization, whether mid-level or high-level. Wiz Code fits any organization. I have given this tool a rating of nine out of ten.

    reviewer2860287

    Comprehensive cloud security has improved visibility and enabled precise threat response

    Reviewed on Jun 22, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Wiz is cloud security, infrastructure as code, threat detection and response, and application security.

    For example, if we have a cloud resource that has an Amazon GuardDuty alert, we will use Wiz to ingest the log, and we review it for security reasons and use that information in our alerting pipeline. Wiz is where we ingest all the information and logs.

    My main use case is to scan cloud infrastructure for misconfigurations, issues, security threat intelligence, and more.

    What is most valuable?

    The best features Wiz offers include the scanning, the ability to map vulnerabilities to specific resources, the ability for GraphQL API integration, and their security graph when it comes to querying information, finding specific detections, and responding to them, and much more.

    For example, we use many other automation tools that need to integrate with Wiz, and through the graph API or GraphQL API, we are able to call Wiz in a very specific way where if we want to automate anything, it is possible via their API.

    There is a variety of features per team, such as cloud security, AI security, security operations center, and more.

    Wiz has positively impacted my organization by stopping security incidents, giving us full visibility in our cloud environments, and providing us with the confidence that we can use the tool not just for security but also for operations tooling, DevOps, code scanning, and all of the above.

    We have seen specific outcomes and information improve as a result, and we have definitely narrowed down more incidents that we might need to take care of with the tooling, which has given us wider visibility compared to when we did not have it.

    Wiz allowed us to consolidate tools, and on the issues it gives us from the top level down—critical to informational—we are able to fully prioritize the things that are most important due to that capability.

    What needs improvement?

    Wiz's pricing model is very poor.

    The pricing is out of control, but when it comes to the actual functionality of the tool, the tool is great.

    On a scale of one to ten, I would rate Wiz an eight. I rate it an eight because internally, they have specific people who want to bulldoze you when it comes to signing agreements that are much higher priced than the value that you get. Wiz is great. Some people are great and some are not, so they are a little bit less willing to work with customers on their specific needs regarding things such as pricing versus other tools.

    For how long have I used the solution?

    I have been using Wiz for over four years.

    What do I think about the stability of the solution?

    Wiz is stable.

    What do I think about the scalability of the solution?

    Wiz's scalability is very good, and I have not had any issues yet.

    How are customer service and support?

    The customer support is fair; they are not great, nor bad.

    Which solution did I use previously and why did I switch?

    We started to use Wiz since their inception.

    How was the initial setup?

    Everything is very well set up; the UI is easy to use, and their API is great.

    What about the implementation team?

    We are just a customer without a business relationship with this vendor other than that.

    What was our ROI?

    I have definitely saved time, but money saved is still up in the air; there have been things that make us feel that is not the case. We also need fewer employees, partially.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing has been very poor.

    Which other solutions did I evaluate?

    Before choosing Wiz, I evaluated other options such as Orca and Upwind.

    What other advice do I have?

    The extent to which the Wiz runtime sensor has helped in identifying active threats more effectively compared to previous solutions is pretty minimal.

    My impression of the cloud security democratization aspect of the product is that it is one of the best sources of truth we have. It is extremely impactful on the organization, so it is definitely a tool we are going to use if the pricing is right.

    We have gone through three technical account managers and have decided not to renew.

    My advice to others looking into using Wiz is to make sure that you are working with the right account team, set up all of your integrations correctly, and take your time during your proof of value.

    Wiz is a great tool, and we will continue to use it over time. I rate Wiz an eight out of ten overall.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Karunesh Tripathi

    Cloud security has become more prioritized and consolidated but still needs better context and bundling

    Reviewed on Jun 17, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I am using Wiz for CNAPP and DSPM, primarily for vulnerability and exposure management. These are the key areas I am focusing on, and over the last five years, I have been actively working with Wiz. Prior to that, I used it for a specific customer deployment in my previous organizations.

    What is most valuable?

    There are several resources deployed on the cloud, and we are monitoring those assets. Wiz has a very strong AI engine that can correlate these findings, and I believe that is the clearer differentiator from other products in the market. We are using Wiz to define the correlation, and it works perfectly by defining priority based on impact and likelihood. I feel this saves considerable rework from security engineers and the team, helping us to immediately act on these exposure issues and address high and critical vulnerabilities.

    All other security tools I have seen mainly focus on impact and try to map directly with the CVSS. I think that context is outdated now because threats have changed and patterns have evolved. It clearly requires a different approach so that we can use it enterprise-wide, and security leaders should get clear visibility on the likelihood of these incidents and decide whether to spend resources on them.

    Wiz is performing quite well with the existing CNAPP capability. However, Wiz has additional functionalities under Wiz Code, and there are other modules coming for AI security. That is definitely new, which Wiz offers, and it is completely different from existing solutions.

    From a security tooling perspective, every enterprise is bombarded with thousands of tools and nobody knows how to consolidate them and what those different data points should be used for. That has been one of the nightmares, where most people simply spend their resources managing those tools and remediating the same issues on different platforms. Using Wiz Code and the other matching capability helps me eliminate the redundancy of tools in my infrastructure. That is a significant win, as I can see everything in a single pane of glass.

    The response time has drastically increased, and the data we are getting is more focused. That is something truly required in security, as you need to respond as quickly as possible to breaches because they occur in fractions of seconds. Therefore, quick responsiveness is something Wiz has truly achieved.

    What needs improvement?

    As an extensive user of Wiz, I have noticed that one critical area Wiz is missing is context. It is performing well in terms of reporting issues and mapping to the environment, but many false positives are generated because it lacks context. I would appreciate Wiz ingesting customer context, understanding how I am using it and what my infrastructure looks like, so it can determine whether something is truly an issue for me. I do not want to keep dealing with thousands of vulnerabilities and marking them under ignore rules or wasting time assessing everything only to find they are false positives. This is an area where Wiz really needs to focus.

    Secondly, regarding remediation, Wiz has playbooks, but it is not adding anything new. If I wanted to use Wiz with AI infrastructure, it could provide more guidance on best practices and how to implement them.

    Currently, Wiz has three modules: Wiz, Wiz Code, and CNAPP. At some point, Wiz needs to rethink this and consider a bundled offering for more benefit to customers and product owners. If I buy CNAPP and later move to Wiz Code, there may be conflicting or overlapping features. People could be confused about why to use Wiz Code and what is different. It should look like a simple bundle, indicating what you are getting and when to use each. Currently, when to use what is missing, and while it is documented, as an enterprise decision maker, I do not want to spend time repeatedly on the same tools. I want a single comprehensive solution. Wiz Code should be the default offering as a simple, pay-as-you-go model without requiring separate deployments.

    The lack of context is an issue. The tool is performing well, but without context, it generates many false positives, which every organization using Wiz struggles with. Secondly, the multiple offerings lead to confusion, as people may hesitate to use the next solution, such as Wiz Code. These two aspects are holding me back from giving a higher rating.

    For how long have I used the solution?

    I have been using Wiz for almost five years.

    What other advice do I have?

    As a security product manager and extensive user, I recommend that people explore Wiz. It simplifies their lives with many new features and capabilities. It allows for easy adoption in defining benchmarks and a minimum security baseline for organizations, something that is harder with other tools. Some solutions claim to have specific capabilities, but they do not deliver. Based on my hands-on experience, I can say that Wiz is a clear differentiator, and people should definitely consider it.

    Wiz helped consolidate tools, but there were overlapping capabilities, and we still are not getting a complete view. To a certain extent, it helped with consolidation, but there is still room for improvement. I provided feedback suggesting that Wiz Code and other capabilities should be under the same bundle with a pay-as-you-go model, as it can be time-consuming to enable these capabilities later.

    Overall, I believe Wiz is doing a great job, simplifying many aspects for security professionals and enterprises. The dashboard is quite nice, and with the introduction of the MCP, I am only concerned about remediation, context defining, and bundling of offerings. These are three areas I want Wiz to focus on to make their product even better. I would rate this product a seven out of ten.