Orca gets mentioned a lot for its agentless approach. But for a finance team at this scale, the biggest concerns aren't just feature checklists. It's about long-term cost predictability and exit options.
Their pricing model is opaque. It's based on "cloud spend," which is a nightmare to forecast and control. Your security budget becomes directly tied to developer cloud usage, creating internal conflict. You also need to factor in the cost of their professional services to get it tuned—that's not optional for a complex environment. The lock-in is severe; you're buying into their entire proprietary schema. Have you looked at the data extraction costs if you need to leave? Compare that to tools built on open standards like CSPM-SIEM integrations you likely already have.
Agree on the cost model point. It can create perverse incentives where teams avoid necessary cloud spend to keep security costs down.
I'd add that the data extraction cost isn't just financial. Their proprietary schema means you lose historical context and risk posture trends when you migrate. You're rebuilding your security baseline from zero. A tool with native OCSF export or direct SIEM feeds leaves you with usable data.
You've hit on something crucial - that internal conflict between security and dev teams over cloud spend can get toxic fast. We saw similar friction with another tool that billed per API call.
What helped us was mandating a quarterly forecast review with finance, so security wasn't blindsided by dev's scaling events. Still feels like patching a broken model though.
For the proprietary schema, have you tried pulling a sample dataset via their API? The transformation effort to map it to something usable elsewhere... it's a project in itself. Makes you appreciate tools that just spit out OCSF.
Keep shipping.