AI-powered cloud-native application protection platform providing behavioral threat detection, compliance monitoring, and vulnerability management across multi-cloud environments
AI-powered cloud-native application protection platform providing behavioral threat detection, compliance monitoring, and vulnerability management across multi-cloud environments
Lacework, now rebranded as FortiCNAPP, is an enterprise-grade AI-powered Cloud-Native Application Protection Platform (CNAPP) in the cloud security category that provides behavioral threat detection, compliance automation, and vulnerability management, with custom pricing typically starting in the mid-five-figure annual range for mid-market deployments. Originally founded in 2015 and acquired by Fortinet in 2024 for an undisclosed sum following $1.3 billion in total venture funding, the platform pioneered the use of machine learning and behavioral analytics to automatically baseline normal cloud activity and detect anomalies indicative of threats. The Polygraph Data Platform ingests over 750 billion cloud events daily across customer environments, building behavioral models for every entity — users, processes, containers, and network flows — to surface deviations that rule-based systems miss entirely.
The platform consolidates five core cloud security disciplines into a single solution: Cloud Security Posture Management (CSPM), Cloud Workload Protection (CWPP), Cloud Infrastructure Entitlement Management (CIEM), Kubernetes security, and vulnerability management. This unified approach replaces an average of 3–5 point security tools for enterprise customers, reducing tool sprawl and the associated licensing and integration overhead. FortiCNAPP supports over 150 prebuilt compliance frameworks and policy packs — including PCI DSS 4.0, HIPAA, SOC 2 Type II, NIST 800-53, and CIS Benchmarks — enabling continuous compliance evidence collection that organizations report cuts audit preparation effort by more than half compared to manual processes.
FortiCNAPP provides both agentless scanning via cloud API integrations across AWS, Azure, GCP, and Oracle Cloud Infrastructure, and optional lightweight eBPF-based agents for deeper runtime workload visibility. The agentless approach enables deployment across hundreds of cloud accounts within hours rather than weeks, while the agent-based option delivers sub-second runtime threat detection for critical workloads. The platform's attack path analysis engine correlates vulnerabilities, misconfigurations, overprivileged identities, and network exposure to identify the approximately 2–4% of issues that form genuinely exploitable attack chains, allowing security teams to focus remediation on the exposures that matter most.
Following Fortinet's 2024 acquisition, the platform has been integrated into the Fortinet Security Fabric, enabling correlation of cloud workload telemetry with network and endpoint security data from FortiGate (deployed by over 700,000 customers globally), FortiEDR, and FortiAnalyzer. This integration provides unified visibility from network edge to cloud workload, a capability unique among CNAPP vendors. Fortinet, publicly traded on NASDAQ as FTNT with over 10,000 employees, reported $5.3 billion in annual revenue in fiscal 2023, providing long-term product stability and R&D investment backing for the FortiCNAPP platform.
Was this helpful?
Lacework (FortiCNAPP) is well-regarded by enterprise security teams for its AI-driven behavioral detection that significantly reduces alert fatigue compared to rule-based alternatives. Users praise the Polygraph engine's ability to surface genuine threats with minimal tuning, though note that initial baseline calibration takes several weeks. The platform's breadth as a unified CNAPP is valued, but some reviewers find the UI less intuitive than newer entrants like Wiz. The Fortinet acquisition has introduced uncertainty for some customers but is viewed positively by existing Fortinet shops seeking unified cloud-to-network visibility.
Advanced machine learning algorithms create dynamic baselines for cloud workloads and automatically detect anomalous behaviors that indicate potential security threats, including zero-day attacks and insider threats
Use Case:
Essential for detecting sophisticated attacks that bypass traditional signature-based security tools, particularly useful for identifying lateral movement and data exfiltration attempts
Automatically discovers and maps all cloud resources, containers, and their interconnections across multi-cloud environments to provide comprehensive visibility and context for security events
Use Case:
Perfect for organizations with complex cloud architectures needing to understand attack paths and blast radius of potential security incidents
Provides comprehensive threat detection and compliance monitoring without requiring agent installation, using cloud-native APIs and integrations for minimal performance impact
Use Case:
Ideal for organizations seeking rapid deployment and broad coverage across dynamic cloud environments without operational overhead
Continuous assessment of cloud configurations against major compliance frameworks with automated report generation and remediation guidance
Use Case:
Critical for enterprises needing to maintain compliance with SOC 2, PCI DSS, HIPAA, and other regulatory requirements while scaling cloud operations
Custom
Ready to get started with Lacework (now FortiCNAPP)?
View Pricing Options →We believe in transparent reviews. Here's what Lacework (now FortiCNAPP) doesn't handle well:
Weekly insights on the latest AI tools, features, and trends delivered to your inbox.
Lacework now operates under the FortiCNAPP brand as part of Fortinet's cloud security portfolio. Recent focus areas include deeper integration with the Fortinet Security Fabric (FortiGate, FortiEDR, FortiSIEM, FortiSOAR) for cross-domain detection and response, expanded agentless coverage and attack path analysis, enhanced AI-assisted investigation and triage in the Polygraph data platform, and broader Kubernetes and IaC security coverage aligned with modern DevSecOps workflows.
Enterprise Agents
AI-powered agentless cloud security platform that provides comprehensive vulnerability management and compliance monitoring across multi-cloud environments
Enterprise Agents
Self-learning AI cybersecurity platform that creates an Enterprise Immune System, autonomously detecting and responding to sophisticated cyber threats without signatures or rules.
No reviews yet. Be the first to share your experience!
Get started with Lacework (now FortiCNAPP) and see if it's the right fit for your needs.
Get Started →Take our 60-second quiz to get personalized tool recommendations
Find Your Perfect AI Stack →Explore 20 ready-to-deploy AI agent templates for sales, support, dev, research, and operations.
Browse Agent Templates →