Investment memo / Battle
Investment memo · scheduled battle

Wiz — cloud security platform, fastest-growing software company ever by some accounts

September 14 at 04:41 · $0.129 total

grok-4.6 wins
judged by claude-fable-5 · both position-swapped passes agree
“B is more factually current ($32B Google acquisition), broader named competitor set, cleaner fact/unknown separation, and a conditional verdict with a testable question.”
gemini-3.1-pro
$0.02523s2096 tokens

Investment Memo: Wiz

Thesis Wiz has the potential to be a generational, fund-returning cybersecurity company because it fundamentally solves the most acute pain point in modern enterprise IT: securing dynamic, multi-cloud environments without slowing down engineering. The transition to the cloud broke traditional perimeter security, and early cloud security tools relied on deploying "agents" (software installed on every server), which caused massive friction, blind spots, and operational overhead.

Wiz’s thesis is built on an architectural breakthrough: an agentless, graph-based approach. By connecting directly to cloud APIs, Wiz provides 100% visibility in minutes, correlating toxic combinations of risks (e.g., a vulnerability + excessive permissions + public exposure) rather than generating thousands of siloed alerts. Backed by a repeat-founder team (Assaf Rappaport and co-founders, who previously sold Adallom to Microsoft and led Microsoft’s Cloud Security Group), Wiz possesses the ultimate combination of deep domain expertise, a massive TAM, and a product architecture that perfectly aligns with how modern DevOps teams operate.

Product & Wedge Wiz’s wedge is frictionless time-to-value via agentless scanning. Instead of begging DevOps teams to install agents on every workload, security teams can grant Wiz an IAM role, and within 15 minutes, the platform scans the entire cloud estate (AWS, Azure, GCP) via APIs.

The core product is a Cloud Native Application Protection Platform (CNAPP). Once plugged in, Wiz builds a "Security Graph" that maps the relationships between cloud identities, network exposures, vulnerabilities, and secrets. The wedge is visibility and Cloud Security Posture Management (CSPM)—showing the CISO exactly where their critical risks are. From there, Wiz expands into vulnerability management, container security, and identity and access management (CIEM), becoming the single pane of glass for cloud risk.

Market & Competition The cloud security market is vast, growing at a double-digit CAGR, and highly fragmented. Wiz is competing in the CNAPP category, which is rapidly consolidating point solutions.

Real competitors include:

  • Palo Alto Networks (Prisma Cloud): The 800lb gorilla. Prisma was built largely through acquisitions (RedLock, Twistlock, Bridgecrew). It is feature-rich but often criticized for being heavy, disjointed, and difficult to deploy.
  • Orca Security: The closest architectural competitor. Orca pioneered the "SideScanning" agentless approach and is currently locked in patent litigation with Wiz.
  • CrowdStrike & SentinelOne: Endpoint giants moving aggressively into cloud workloads. They have a massive distribution advantage but are historically rooted in agent-based architectures.
  • Native Cloud Providers (Microsoft Defender for Cloud, AWS Security Hub): "Good enough" native tools that are heavily bundled but struggle with multi-cloud visibility.

Traction & Business Signal Wiz’s growth is historically unprecedented in enterprise software.

  • ARR: Reached $100M ARR in just 18 months. Surpassed $350M ARR in 2023.
  • Customer Base: Secures over 40% of the Fortune 100.
  • Valuation: Most recently valued at $12B (publicly known).
  • Net Retention Rate (NRR): Unknown precisely, but widely reported to be top-quartile (likely 130%+ given their rapid land-and-expand motion).
  • Burn Rate / CAC: Unknown. While growth is explosive, the capital efficiency of this growth (how much cash was burned to acquire these logos) remains a closely guarded secret.

Risks To underwrite this deal, we must accept three potential deal-killers:

  1. The "Agentless Ceiling" (Remediation vs. Visibility): Agentless scanning is incredible for finding problems, but it cannot block an active runtime attack in real-time. If the market shifts from demanding visibility to demanding active runtime prevention, Wiz will be forced to deploy agents (which they are beginning to do with their runtime sensor). Building and managing agents is a completely different, highly commoditized, and operationally heavy business that could erode their frictionless wedge.
  2. Incumbent Bundling and Price Wars: Palo Alto and CrowdStrike view CNAPP as an existential battleground. As IT budgets tighten, these incumbents can offer cloud security modules for free or at steep discounts to protect their core endpoint/firewall renewals. Wiz must prove its standalone platform is so vastly superior that CISOs will justify a separate, premium line item.
  3. Commoditization of the Security Graph: The "agentless graph" was a novel breakthrough in 2020. Today, every competitor—from Orca to Palo Alto to open-source tools—is building a graph. If the underlying technology becomes table stakes, Wiz’s moat will rely entirely on GTM execution rather than product differentiation, which is a dangerous game at their valuation expectations.

Verdict: INVEST At a hypothetical Series A, this is a table-pounding INVEST. The founder-market fit is top 1% globally, the architectural shift (agentless) is a true paradigm breaker, and the time-to-value creates a viral sales motion rarely seen in enterprise security. You back this team to win the category.

The One Question to Answer First: “How do you plan to bridge the gap between identifying a risk (visibility) and actually fixing it (remediation) without forcing DevOps teams to change their workflows or requiring heavy runtime agents?” If they have a scalable, automated answer to remediation, they won't just be a great security tool—they will become the system of record for cloud infrastructure.

grok-4.6 · winner
$0.01136s1783 tokens

Investment Memo: Wiz (hypothetical Series A)

Thesis. Multi-cloud adoption created a structural security gap: enterprises needed a unified, agentless view of risk across AWS, Azure, and GCP without the operational tax of agents or point tools. Wiz’s founding team (Assaf Rappaport et al., prior Adallom exit to Microsoft) had already proven they could sell security into large enterprises and execute at speed. If they could turn a graph-based, agentless CNAPP into the default control plane for cloud risk, the company could become the category leader in a market expanding with every workload that left the data center. That combination of timing, team, and a technically differentiated wedge is what makes a fund-returner possible: winner-take-most dynamics in a high-ACV, expanding TAM.

Product & wedge. Wiz’s core is an agentless scanner that ingests cloud metadata, configurations, identities, and vulnerabilities, then builds a security graph that surfaces attack paths (e.g., public bucket + over-privileged identity + unpatched CVE). The wedge was speed-to-value: connect via API, get a prioritized risk picture in hours rather than months of agent rollout. This bypassed the classic CSPM/CWPP friction and let security teams show immediate reduction in toxic combinations. Later expansion into DSPM, CIEM, and runtime was a natural graph extension, not a bolt-on. The product is not “better scanning”; it is a queryable model of the entire cloud attack surface.

Market & competition. Cloud security spend (CSPM, CWPP, CNAPP, identity, data) was already a multi-billion-dollar category and growing with cloud itself. Real competitors at the time included Palo Alto Prisma Cloud (broad platform, heavy), Check Point CloudGuard, CrowdStrike (endpoint-first expanding into cloud), Microsoft Defender for Cloud (bundled, Azure-centric), Orca Security (also agentless, similar graph thesis), Aqua Security (container-native), and Lacework (data-driven, later acquired). Hyperscalers themselves (AWS Security Hub, Azure Security Center, GCP Security Command Center) offered native, cheaper, but shallower alternatives. The market was crowded; differentiation had to be in time-to-insight, graph quality, and multi-cloud neutrality.

Traction & business signal. Publicly known: founded 2020; rapid early customer logos among large enterprises and cloud-native companies; subsequent rounds showed extreme velocity ($100 M ARR in roughly 18 months is the most-cited figure). Exact Series A ARR, NRR, logo count, ACV, and burn at the hypothetical Series A round are unknown. Later public signals (multiple $100 M+ rounds, $10 B+ valuations, eventual $32 B Google acquisition) confirm the growth was real, but those are post-Series A facts. Customer concentration, exact win rates versus Orca/Prisma, and sales-cycle length at Series A remain unknown.

Risks (the three that actually kill the deal).

  1. Hyperscaler bundling and “good enough” native tools. AWS/Azure/GCP can give away 70 % of the value inside the console. If enterprises decide native + a thin overlay is sufficient, Wiz’s premium pricing and multi-cloud story collapse. This is not theoretical; it has killed or compressed many pure-play cloud security companies.
  2. Category commoditization and sales-cycle elongation. Once every vendor has a graph and agentless scan, differentiation shrinks to brand, integrations, and GTM. Large deals then become bake-offs won by the incumbent platform (Palo Alto, CrowdStrike, Microsoft). High growth can mask this until the first down-quarter.
  3. Founder/team execution risk at scale. The same speed that produced record ARR can produce cultural and operational debt. Retention of the original Israeli engineering core, ability to build a world-class enterprise sales machine in the US, and avoidance of over-hiring against unsustainable growth rates are all unknown at Series A and have derailed otherwise strong security companies.

Verdict: Invest at a hypothetical Series A, provided one question is answered first: “Show me the first 15–20 paying customers, their ACV, time-to-value, and whether they expanded within 6 months—without the founders in the room.” If the product is already pulling enterprise dollars with short cycles and expansion, the team’s prior exit plus the multi-cloud timing outweigh the three risks above. If the early logos are mostly design partners or low-ACV, pass; the competitive set was already too strong to bet on unproven GTM. (Word count: 712)