Executive Summary
AI-generated analysis for Wiz
Wiz (wiz.io) is a cloud security software vendor that has recently been acquired by Google in a $32 billion transaction (completed March 2026). At the time of this assessment, Wiz presents a Moderate Risk (Tier 3) posture, driven primarily by two factors: the operational uncertainty inherent in a major corporate acquisition and the absence of a publicly discoverable AI data usage policy. Wiz demonstrates a strong overall security and compliance posture across multiple dimensions:
Key Findings
- Infrastructure footprint is minimal: only 2 open ports (80 and 443) detected, with zero known CVEs — this is significantly below the SaaS industry average of 8–12 open ports and represents a well-controlled external attack surface.
- Domain reputation is clean across all active blacklist and malware databases (SURBL, Spamhaus DBL, URLhaus, Malware detection service).
- HTTP security headers earned a B+ grade (80/100), with 9 of 10 tests passing.
- TLS configuration uses TLSv1.3 with a strong cipher suite and HSTS is enforced.
- The vendor maintains a published trust center (https://wiz.io/trust-center and https://trust.wiz.io) claiming an extensive compliance portfolio including SOC 2 Type II, ISO 27001/27017/27018, PCI DSS v4.0.1, HIPAA, FedRAMP (Wiz4Gov platform), and CSA STAR Level 1.
- The vendor's published subprocessor list identifies Amazon Web Services and A-LIGN, neither of which triggered sanctions or safety concerns.
- No sanctions matches, adverse media, or regulatory enforcement actions were identified. Two areas require attention before this vendor can be approved without conditions. First, all eight compliance certifications are vendor-attested only — independent registry verification could not be confirmed for any of them during this assessment, including FedRAMP authorization. Compliance teams should request the full SOC 2 Type II report, ISO 27001 certificate, and FedRAMP authorization package directly from the vendor. Second, no publicly accessible AI data usage policy was discoverable, which is a meaningful gap for a cloud security platform that may incorporate AI-driven analysis features. Buyers should request the vendor's Data Protection Addendum (DPA) and any AI-specific product terms to understand training commitments and data retention practices. Overall, Wiz is a well-established, operationally mature cloud security vendor with a strong technical security posture. The Moderate Risk rating reflects the active acquisition transition and unresolved certification verification requirements rather than any identified security unavailability. Conditional approval is appropriate pending receipt of key compliance documentation.
Independence Statement
All evidence in this report was independently sourced from external data providers, public registries, and open-source intelligence without any participation, disclosure, or input from the vendor under investigation.