Prisma Cloud
A code-to-cloud CNAPP securing applications across their entire lifecycle.
Palo Alto Networks Prisma Cloud is a comprehensive Cloud-Native Application Protection Platform (CNAPP) that secures applications from code to cloud — spanning posture management, workload protection, identity, data, web-app, and infrastructure-as-code security in one platform. It replaces a patchwork of point tools with unified, lifecycle-wide cloud security. Faltrox operates it as the CNAPP layer of managed cloud defence.
Overview
What Prisma Cloud is
Cloud security is fragmented across dozens of point tools — one for posture, another for workloads, another for identity — and the gaps between them are where breaches happen. Prisma Cloud consolidates them into one Cloud-Native Application Protection Platform that secures the entire application lifecycle, from the code and pipeline where risk is introduced to the running cloud workloads where it is exploited.
It brings together Cloud Security Posture Management (CSPM), Cloud Workload Protection (CWPP) for hosts, containers, and serverless, Cloud Infrastructure Entitlement Management (CIEM), data security, web-application and API security, and infrastructure-as-code scanning — across AWS, Azure, GCP, and more. Shifting security left into the pipeline while protecting runtime, it gives one view of cloud risk. Faltrox operates Prisma Cloud — tuning policy, triaging findings, and driving remediation as managed cloud defence.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Multi-Cloud
Secures workloads and posture across AWS, Azure, Google Cloud, and more.
Code & Pipeline
Shifts security left with infrastructure-as-code scanning and pipeline security.
Workloads
Protects hosts, containers, and serverless functions at runtime.
Cloud Identities
Cloud Infrastructure Entitlement Management right-sizes permissions and finds over-privilege.
Cloud Data
Discovers and protects sensitive data across cloud services.
Posture & Compliance
Cloud Security Posture Management enforces configuration and compliance.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Shift Left
Infrastructure-as-code and pipeline scanning catch misconfiguration and vulnerabilities before deployment.
- 02
Assess Posture
CSPM continuously assesses cloud configuration and compliance across every account.
- 03
Protect Runtime
CWPP protects running hosts, containers, and serverless workloads from threats.
- 04
Right-Size Access
CIEM analyses cloud entitlements to find and remediate over-privilege.
- 05
Operate
Faltrox tunes policy, triages findings across the lifecycle, and drives remediation as managed cloud defence.
Capabilities
Key capabilities
Code-to-Cloud CNAPP
One platform securing the full application lifecycle from code to running cloud workload.
Posture Management (CSPM)
Continuously assesses cloud configuration and compliance across every account and cloud.
Workload Protection (CWPP)
Protects hosts, containers, and serverless functions at runtime.
Entitlement Management (CIEM)
Right-sizes cloud permissions and finds over-privileged identities.
Data Security
Discovers and protects sensitive data across cloud services.
Web-App & API Security
Protects cloud-hosted web applications and APIs.
IaC Scanning
Shifts security left by scanning infrastructure-as-code and the pipeline before deployment.
Unified Risk View
Consolidates point tools into one view of cloud risk across the lifecycle.
Works with
Part of the platform
Palo Alto Networks products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Palo Alto Networks Prisma Cloud for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01What is a CNAPP and why consolidate tools?
A Cloud-Native Application Protection Platform consolidates the many separate cloud security tools — posture, workload, identity, data, code — into one platform. Consolidation matters because breaches happen in the gaps between point tools; a CNAPP secures the whole application lifecycle with one connected view of risk.
02What does "code to cloud" mean?
It means securing the application from where risk is introduced (the code and infrastructure-as-code in the pipeline) through to where it is exploited (the running cloud workload). Shifting security left into the pipeline while protecting runtime catches issues earlier and cheaper.
03Which clouds does it cover?
It secures workloads and posture across AWS, Azure, Google Cloud, and other clouds from one platform, so a multi-cloud estate has consistent security and one view of risk rather than per-cloud native tools.
04How does it relate to Cortex Cloud?
Cortex Cloud is Palo Alto Networks’ next-generation cloud security offering that brings real-time cloud detection and response together with CNAPP capabilities under the Cortex platform. Faltrox scopes which fits your maturity and detection-and-response needs.
05How does Faltrox operate it?
We deploy Prisma Cloud across your clouds, tune the posture, workload, and entitlement policies, triage findings across the lifecycle, and drive remediation with your teams — delivering CNAPP as managed cloud defence.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us