What is our primary use case?
My main use case for Sweet Security as a distributor is to distribute to our partners within the UK channel, and they then take it to their customers who are looking for a cloud-native platform that offers advanced threat detection and incident response capabilities to provide deep runtime context to security teams, enabling them to quickly extract actual attack narratives. Sweet Security is designed to protect sensitive data in cloud environments, understand the environment, and respond to any threats as they occur. The platform leverages runtime insights to deliver comprehensive protection across all layers of the security stack.
I can provide a specific example of how one of my partners' customers has used Sweet Security in practice. Organizations primarily utilize Sweet Security for VM vulnerability management on cloud assets, particularly with AWS, which enhances runtime visibility and enables effective threat detection. Sweet Security is integrated for runtime protection and has evolved to support broader security ranges. It allows users to visualize cloud relationships, understand dependencies, and manage vulnerabilities from a code perspective. Sweet Security provides real-time security event response for security teams.
What is most valuable?
What stands out about my main use case and how my partners use Sweet Security is the deep runtime visibility and application layer security, particularly for APIs and microservices. This is where most traditional CNAPP solutions are weakest, and this is where Sweet Security performs exceptionally well. Additionally, in production environments, Sweet Security is focused on detecting and responding to real-life effects in live production environments. It correlates signals across cloud, apps, identity, and data into a single attack story. The way it contextualizes information in story form is another real positive, which I found mentioned by other reviewers as well.
Before Sweet Security, partners and customers needed to conduct extensive investigations when they found detection of activity across all different platforms and security logs until they could identify what was actually wrong in the bigger picture. Sweet Security enabled teams to see each detection of activity upon every request made from the application level towards the infrastructure, making it much easier and reducing the time for an analyst to understand what is really happening. It provides real-time visibility in the cloud environment, which is a massive differentiator because teams are seeing events as they happen, live in real time.
Sweet Security's capabilities in runtime coverage impact my overall security strategy and the strategies of my partners by allowing us to capture threats as they occur in the live production environment in real time. We are capturing code-level events because we have shifted right in our approach. This is a key point to add: we are not traditional tools on the left side of the shift. We shift right, which means we operate in production and in real time. We are not pre-code or pre-cloud. We have shifted right, and this is a massive positive for time efficiency, workload efficiency, and more importantly, being proactive rather than reactive across the cyber landscape.
What needs improvement?
Sweet Security can be improved in terms of product maturity and ecosystem. It has a smaller market presence, so we do not have as many large enterprise deployments. Sweet Security is less mature than competitors such as Wiz or Palo Alto Networks. Some competitors provide better integrations and workflow tooling. Additionally, as a new vendor, there is a new market perception and higher perceived risk, which relates to trust of the product. Some competitors are seen as safer and more established choices. Since Sweet Security operates in the production live environment, there have been a couple of problems reported where issues occurred in production environments. However, these have been resolved within about an hour or two. Having that risk is always going to be a negative.
As a cloud-native platform solution, Sweet Security is really good overall. There are only a couple of areas for improvement, such as not being fully 100% production safe, and the reality that its competitors are global, well-known companies such as Palo Alto and Wiz.
For how long have I used the solution?
I have been working in my current field for about 18 months. I have been using Sweet Security for about 18 months, as long as I have been working within cyber. Sweet Security, as a cloud-native platform, has been part of my experience for approximately 18 months.
What do I think about the stability of the solution?
From my observations, Sweet Security is stable, as I find that user experience does not tend to reveal many production problems, and when they do occur, they are resolved quickly. Users have reported that they are very satisfied and Sweet Security garners praise while maintaining a stable environment across diverse scenarios. It is extremely stable, and I would give it a nine out of ten because if a problem does occur, it is resolved quickly.
What do I think about the scalability of the solution?
Regarding scalability, I find that deployment is quite straightforward across multiple different infrastructures. However, regarding performance with large-scale infrastructures, particularly those of enterprises across cloud assets, it sometimes struggles. Smaller to medium-sized enterprises or organizations represent the sweet spot for Sweet Security. There may be a couple of issues with scalability at the top level of enterprise and large organizations. While many find the scalability is good, it could be rated a bit lower if it was trying to cater exclusively to enterprise organizations. The best sweet spot is small to medium organizations, and there have been some issues with scalability across large enterprise organizations.
How are customer service and support?
Sweet Security excels in customer support, as they provide on-hand, prompt, hands-on assistance. Their customer service and CSM team address issues, and users get a line to a specialist who are the right experts and are involved in technical support. They are quick to resolve any issues that are encountered. This is why, even if the price is a bit higher, users get ROI from the price they pay because of the constant user help provided by customer service and support.
I would rate customer support a nine out of ten because they maintain a competitive price, offer trial periods, provide follow-up, are very responsive, and are effectively hands-on in assisting and offering prompt service and support.
How was the initial setup?
Sweet Security is deployed in my organization in a straightforward manner for multiple users across our partners and customers. While some experienced a few challenges, including a couple of bug log connections, the process was mostly easy and quick to implement. Generally, across variant sizes of teams, the setup was effective and took a couple of days depending on the approach from the security teams.
What was our ROI?
Sweet Security has positively impacted my organization by providing faster incident response in minutes versus hours, reducing alert fatigue through significant noise reduction because of the prioritization feature, giving better prioritization of exploitable risk, and providing better coverage for both traditional and AI-based apps. Sweet Security also improves visibility across multi-cloud environments and provides a unified visible platform. Most of the cyber landscape is moving toward platform plays, so Sweet Security is well-positioned in this direction. Most importantly, it moves from finding misconfigurations to detecting and stopping threats in real time in the environment.
Alert fatigue is always happening because at the end of the day, what we look for is not swimming through noise. Therefore, time is saved by the analyst or security team. The ROI is that we are not waiting for a breach but being proactive rather than reactive. Most people in that proactive phase find that it gives them the ability to find their infrastructure's breach attack paths and understand where they are most vulnerable to exposure. Sweet Security really does provide that proactive rather than reactive mentality within the cyber landscape.
Sweet Security has helped my team and my partners prioritize risks and threats more effectively because everything that comes out represents real-life detects and threats. Every time we see a threat, we push it through to our first-line support team so they can action it. Everything we see on Sweet Security then gets pushed and actioned because it represents real-time threats, and we are getting ahead of the curve. We can then over time as an ROI see where we are best suited and where we are finding most risks. From there, in our security stack or platform, we can assess whether we need to invest in a new tool, giving us ROI to take through the board to explain that this is where we are getting breached most and that having a tool like X will help with Y.
I have seen a return on investment where time saved is the best benefit because we are not working through hundreds of vulnerabilities. Sweet Security condenses it down, contextualizes it, and allows us to identify what is really going to breach us in real time. That is the best ROI. Additionally, we can spend less time worrying about where we will not get breached with vulnerabilities that might not be anywhere near breachable. However, if we find that certain cloud vulnerabilities come up time and time again, we can look into a tool that will help that as well. We can invest in that tool and go to the board or executive level explaining that we need this tool because Sweet Security has pinpointed specific issues, and we need to have this to prevent that from happening because we are seeing that as an ongoing problem we keep finding using Sweet Security.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing has been that Sweet Security's pricing is quite fair and cost-effective by many users. It is not the cheapest option, but it offers competitive rates compared to its competitors. It shows better value through ROIs by reducing reliance on other tools because you can have Sweet Security as a platform across many different cloud tools. Obviously, the pricing depends on the specific company and what they are actually using it for, but overall, it highlights great value. Sweet Security works well for enterprise-level businesses, which many startups or newer companies struggle with. Overall, it is a fair and cost-effective solution because of the platform play and how it integrates and works.
Which other solutions did I evaluate?
I evaluated other options before choosing Sweet Security, including Wiz and Palo Alto. I also work with Tenable as a CNAPP platform, as they have released a new cloud component as part of their Tenable One platform.
What other advice do I have?
I would describe the effectiveness of Sweet Security's Layer-7 network traffic inspection in understanding application requests and responses as very important. Sweet Security monitors real-time API and service-to-service traffic in production while building context around normal versus abnormal application behavior. What Layer 7 detects in Sweet Security is essential because many modern attacks do not break infrastructure; they abuse applications. Traditional CNAPP tools often just look at misconfigurations and CVEs, whereas Sweet Security adds depth by focusing on runtime behavior. Sweet Security's Layer 7 capability means real-time visibility into API and application behavior to detect attacks that bypass infrastructure-level defenses.
I would assess the integration of LLMs in Sweet Security's vulnerability management as beneficial because they can summarize complex runtime security events in plain English. This gives faster alert triage and investigation and reduces alert noise. CNAPP tools can normally generate many alerts, but LLMs filter duplicates, group related issues, and prioritize real threats. This is why we are experiencing better time efficiency because we are prioritizing real threats and taking away alert fatigue. LLMs help interpret API and application layer behavior, which is useful for understanding normal API flows and authentication abuse, providing strong Layer 7 contextual analysis. Additionally, LLMs enable executive-ready reporting by converting technical incidents into summaries, impact analysis, and business risk explanations, making it much easier to communicate with leadership. The LLM integration with Sweet Security improves detection, reduces noise, and turns complex runtime cloud security data into clear, actionable intelligence.
My advice to others looking into Sweet Security is to examine whatever cloud-native platform they have, run a free trial, and attempt a proof of value or proof of concept. Learn about it, use it, and compare it to what you currently have. Although it may not be as well-known as Wiz, Palo Alto, or Tenable CNAPP, Sweet Security definitely stands the test of time and is a great product. Everything I have mentioned is truly excellent. Sweet Security represents the next generation of CNAPP that differentiates through a runtime-first approach and focuses on detecting and responding to real attacks in environments. For me, that provides correlating signals across cloud, app, and identity. What stands out against traditional tools is that we are shifting right in our approach. If you want to be proactive rather than reactive, Sweet Security is a strong CNAPP enterprise vendor that any organization should consider.
As a shifting-right technology in the production environment responding to real-time threats with Layer 7 integration and LLMs to help contextualize risk and show where breaches will occur rather than providing a long list of vulnerabilities, Sweet Security offers competitive pricing and great customer service. I would highly recommend that people research Sweet Security, trial it, and definitely compare it to their current CNAPP platform. I would rate this review an eight out of ten overall.