Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
Automatic evidence collection triggered on detection is materially stronger than manual initiation, since cloud logs often have short retention/rotation windows that can destroy evidence before a human gets to it.
Ask specifically which response actions are automatable versus which always require human approval, and for a real incident example where automated response measurably reduced dwell time.
Automated cross-service, cross-account timeline correlation is the core value proposition of this category over manually querying each cloud service's logs separately during a live incident.
Strong answers are candid about coverage gaps between cloud providers; a customer with a genuinely multi-cloud environment needs to know where the real depth is, not just that all three are nominally 'supported.'
Ephemeral resource evidence capture is a genuinely hard, category-defining problem; ask specifically how the platform handles investigation of a resource that's already gone, since this is common in auto-scaling cloud environments.
Automatic case creation with full context in the existing SOC tooling avoids duplicate work and lost context; a standalone tool requiring manual re-entry into the primary incident-tracking system is a real workflow friction point.
Look for transparent, predictable scaling economics; telemetry-volume-based pricing that spikes when the customer expands logging coverage (otherwise good security practice) creates a perverse cost incentive to under-log.
Native compliance-evidence generation is materially more valuable than raw investigation logs requiring manual compilation for every audit cycle.
Trend-over-time reporting is a distinct capability from individual investigation reports — confirm this exists as a maintained, exportable report.
Investigation evidence can have real legal consequences and reveal sensitive operational details — role-based access control over this specific asset is an often-overlooked consideration.
A false positive with automated containment can cause real production disruption — ask for a real, customer-validated false-positive figure and explicit safety guardrails against incorrect automated actions.
This is a real, common buyer question given the functional overlap with CDR and CNAPP's own response capabilities — a vendor should give an honest answer about the boundary and complementarity.
Strong answers give a concrete, customer-validated timeline for a realistic existing-footprint scenario (not a small greenfield deployment) and are honest about the customer-side configuration effort required.
Investigation records may have ongoing legal/compliance retention value — a vendor with no clear data-portability answer creates real vendor lock-in risk for historically significant forensic records.
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).