JupiterOne provides cloud native cyber asset collection, monitoring, security and governance. Automate the continuous collection of cyber asset infrastructure and security configuration data to provide an always up to date, easy to query, system of record for your cyber asset universe.
JupiterOne is a cyber asset analysis platform every modern security team needs to collect and transform asset data into actionable insights to secure their attack surface. JupiterOne makes security as simple as asking a question and getting the right answer back, to make context driven decisions. With JupiterOne, organizations are able to see all asset data in a single place, improve confidence in choosing their priorities, and optimize their infrastructure and policies.
The main use-cases that the JupiterOne platform provides are:
Asset Management and analysis through relationship mapping
Vulnerability Prioritization by introducing business context
Attack surface and security posture management
Automated evidence collection and continuous monitoring across industry benchmarks such as PCI-DSS, SOC2, FedRamp, ISO 27001, CIS and more
Visualize blast radius of a compromised user endpoint or workload speeding up remediation of incidents
JupiterOne provides custom pricing for customers via Private Offer. Please contact aws-jupiterone-marketplace@jupiterone.com for a better understanding of our pricing model and platform.
Highlights
Complete asset visibility with agentless discovery - pull in all assets (both IP based and software defined) via read-only APIs for more than 80+ AWS native services and 200+ 3rd party applications
Visualize relationships between assets and reduce your attack surface by discovering complex attack paths across clouds and platforms
Interrogate your assets through natural language queries to answer questions that take hours in seconds and set up automated alerts
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You buy this platform on a 12-month contract, and pricing scales with the number of data points in your environment. Three fixed tiers each include a set data point capacity: Small-Market covers up to 200,000, Mid-Market up to 400,000, and Enterprise up to 1,000,000. Pick the tier that matches your environment today and move up as it grows. If you need more than 1,000,000 data points or a tailored arrangement, the AWS Marketplace Private Offer lets you contact the JupiterOne sales team for a custom quote.
Top-of-mind questions for buyers
What counts as one data point for billing purposes?
A data point is a unit of cyber asset data ingested from your environment. This includes cloud infrastructure, devices, identities, and their relationships collected across your connected tools. Your tier's capacity reflects the total volume of asset data pulled in during the subscription term.
What happens if my environment grows past my tier's data point capacity?
Each tier includes a set data point capacity for the term. Small-Market covers up to 200,000, Mid-Market up to 400,000, and Enterprise up to 1,000,000. If your environment outgrows your tier, you move up to the next one. Above 1,000,000 data points, you request a custom quote through the Private Offer.
Does the tier price cover all product modules or just asset visibility?
The tier price is based on data point volume for the asset visibility foundation. Some modules meter on other metrics, such as vulnerability findings. Continuous controls monitoring uses your existing data points with no added input. Confirm which modules your quote includes with the JupiterOne sales team.
jupiterone.com
Helpful?
Vendor refund policy
JupiterOne does not offer refund. All purchases are final.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
JupiterOne offers email, slack, and ticket submission based support. All support options are included with your purchase. We encourage all customers to join our community slack channel and submit questions and support requests through that system or via email. support@jupiterone.com
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Pull in all assets via read-only APIs for more than 80 AWS native services and 200+ third-party applications without requiring agent deployment
Asset Relationship Mapping
Visualize relationships between assets and discover complex attack paths across clouds and platforms to reduce attack surface
Natural Language Query Interface
Interrogate assets through natural language queries to retrieve information and set up automated alerts
Continuous Compliance Monitoring
Automated evidence collection and continuous monitoring across industry benchmarks including PCI-DSS, SOC2, FedRamp, ISO 27001, and CIS
Incident Blast Radius Analysis
Visualize blast radius of compromised user endpoints or workloads to accelerate incident remediation
Cloud Access Security Broker
Unified cloud access security broker (CASB) functionality providing conditional and granular policy controls over employee access to managed and unmanaged cloud services.
Secure Web Gateway
Next generation secure web gateway (SWG) capabilities delivering comprehensive threat protection for cloud and web services with cloud-native architecture.
Data Loss Prevention
Data-at-rest and data-in-motion inspection with DLP violation detection, malware scanning in cloud storage, and capabilities to block, quarantine, encrypt, or apply legal holds to prevent data exfiltration.
Cloud Security Posture Management
Continuous security assessment monitoring of cloud infrastructure for risky misconfigurations, data exposure detection, and vulnerability remediation with pre-defined compliance profiles aligned to CIS, PCI, and NIST standards.
API-Driven Security Operations
Enterprise workflows including advanced role-based access control (RBAC), scheduled reports, alert notifications, exception handling, and automated remediation accessible via REST APIs.
Attack Surface Management
Aggregates comprehensive attack surface visibility across hybrid environments with external attack surface scans to provide 360-degree view of entire attack surface
Vulnerability Management
Delivers complete visibility across on-premise and remote endpoints to identify, communicate, and remediate vulnerabilities, misconfigurations, and risks
Cloud Security
Provides code-to-cloud protection for cloud-native applications with CI/CD pipeline integration and agentless risk assessment based on reachability, exploitability, and potential impact
Next-Generation SIEM and XDR
Delivers accelerated detection and response with SaaS deployment, out-of-the-box detections informed by MDR SOC, and built-in automation capabilities
Threat Intelligence
Delivers high-fidelity actionable threat intelligence infused with proprietary threat and vulnerability research from Rapid7 Labs and community-driven tools
Asset governance has become centralized and reveals naming gaps and user experience issues
Reviewed on Sep 06, 2026
Review from a verified AWS customer
What is our primary use case?
Currently, my main use case for JupiterOne is integrating it with AWS and other different resources, mostly AWS and Azure, at the end of the life cycle. JupiterOne is used for asset management as well as for security governance.
For governance, I use JupiterOne to see if it follows compliance, and I use it to find out if there are gaps within the organization for any of the assets that we have. As asset management, we have integrated several other components within the organization that give us all the details about each of the assets that we have. We count those assets, keeping them secure while also checking if we are under the license with JupiterOne to maintain those numbers.
What is most valuable?
JupiterOne's asset management is great, and recently they introduced JupiterOne MCP that we have downloaded, which is currently very handy for people who are new to JupiterOne. The ease of using queries as well as the impeccable customer care has a significant impact on my learning of JupiterOne.
Recently, the ease of using queries and the new MCP feature has helped me because sometimes I would have difficulty writing the queries, but the AI within the query field in JupiterOne suggests if the query is incorrect and proposes a new query. MCP does almost the same thing, and we use our terminal to download MCP approved by our company, which helps us learn JupiterOne and how to find out different assets. We basically do what we used to ask JupiterOne using MCP.
Within our team, JupiterOne is our source of truth. Having a source of truth means that when it comes to compliance, we can easily count how many assets we have or identify spikes caused by automation creating a tremendous amount of assets on AWS, for example. If there is a spike we are unaware of, we can find it using JupiterOne. We have created alerts for any unusual spikes, making it easy to find issues with our assets within the organization.
What needs improvement?
I find that sometimes it is difficult to find out the individual queries for asset types or names, such as AWS_creds or AWS_credentials. The naming part is something the AI or JupiterOne AI or MCP is not very good at yet, and it should learn the entity names when we are trying to find a specific type of integration.
I have been using JupiterOne for a while and I am familiarized with it, and it has kept up with technology by adding MCP for us to use. However, I think there are still many improvements to make, especially regarding user experience because finding the number of entities can be complicated; it is often buried deep in the interface. Additionally, I struggle with identifying the names of each entity type, which complicates finding specific items, an AWS EC2 instance name, as it does not prepopulate when I type the query.
Regarding JupiterOne's AI capabilities concerning accuracy and reliability of output, I think it has good reliability, but I have found that while doing governance, the data can sometimes be outdated, necessitating reruns to achieve updated accuracy.
I have seen areas where JupiterOne could improve, particularly with asset naming conventions, as it would be helpful to have a list of asset names.
For how long have I used the solution?
I have been using JupiterOne for the last two years.
What do I think about the stability of the solution?
JupiterOne is very stable and has been performing well for us.
What do I think about the scalability of the solution?
JupiterOne's scalability is high, as it mentions in the contract that I can scale as much as I want and then pay a higher price for going overboard. However, I believe it would be nice to have better scalability regarding the number of assets, which is tied to the pricing model during the contract. Currently, if we go overboard with the number of assets, we need to create our own alerts to notify us, and it would be helpful if JupiterOne provided us with such notifications beforehand.
How are customer service and support?
Customer support is responsive, typically answering within less than twenty-four hours of when I ask a question. I am happy with the customer support.
Which solution did I use previously and why did I switch?
We have always been using JupiterOne and did not previously use any different solution.
How was the initial setup?
I am not sure about the setup cost, pricing, and licensing, but I have heard from senior individuals in my organization that it was extremely expensive while being widely used across many teams. It is a bit expensive for us.
What was our ROI?
As for return on investment, JupiterOne has been widely used and is one of the sought-after applications for asset management for us, creating alerts and featuring automation with a dashboard, making it a one-in-all solution. However, since we use it so vastly, I cannot clearly indicate a return on investment, even though I have heard it is pretty expensive.
Which other solutions did I evaluate?
We explored open-source asset management options before choosing JupiterOne, but I do not think we could match JupiterOne's functionality. We decided to stick with it.
What other advice do I have?
My advice to others looking into using JupiterOne is that it is a great product for asset management, though it is a bit pricey. Nevertheless, it offers all-in-one integration for most of the products we use to manage our assets. I give it a thumbs up. I would rate this product a seven out of ten.
Shbhaves Sherman
Centralized cloud asset visibility has improved security monitoring and compliance workflows
Reviewed on Aug 17, 2026
Review from a verified AWS customer
What is our primary use case?
My main use case for JupiterOne is as a cybersecurity platform that I use for cyber asset management, security operations, and compliance.
For example, I use JupiterOne for cloud asset visibility and security monitoring. Whenever a new resource like an EC2 instance and a delegated IAM role is created, JupiterOne automatically discovers it and maps its relationship. I use this to identify misconfigurations such as publicly accessible S3 buckets or overly permissive IAM roles and then remediate them through our DevOps and IaC pipelines.
How has it helped my organization?
JupiterOne positively impacts our organization by giving us centralized visibility into our cloud assets, identities, vulnerabilities, and their relationships. It helps us quickly identify security gaps such as excessive IAM permissions and publicly exposed resources, prioritize risk based on their business impact, and automate remediation. This improves our security posture, reduces manual compliance efforts, and provides the DevOps and security teams with better visibility across the environment.
What is most valuable?
The best features JupiterOne offers include automatic discovery and maintenance of a centralized inventory for cloud users, applications, and devices, supporting more than 200 integrations. Another feature is the querying ability; I use J1QL to query the entire environment to answer questions like which AWS resources are publicly exposed or which users have provisional access. JupiterOne also supports natural language queries, and it has continuous compliance features that check security controls against frameworks such as SOC 2, ISO 27001, and HIPAA while aiding in audit evidence collection. The last feature is alerts and automation; I can create rules and alerts for security changes and automate workflows such as sending findings to Jira for remediation.
The key feature I rely on most in my daily work is the graph-based asset relationship mapping JupiterOne provides. It does not just show me that an EC2 instance or an IAM role exists; it shows how that asset is connected to users, applications, vulnerabilities, and security controls. This allows me to quickly understand the risk associated with a resource if it becomes publicly exposed and to trigger the necessary remediation.
What needs improvement?
One improvement I would suggest for JupiterOne is to make the platform's remediation workflow more tightly integrated with DevOps pipelines. For example, when JupiterOne identifies a critical misconfiguration, it could automatically create a Jira ticket or trigger a Terraform or IaC pipeline with the required remediation while maintaining approval controls for sensitive changes. This would reduce the gap between security detection and actual remediation.
I can implement better real-time notifications for critical asset changes, more customizable dashboards for DevOps, security, and management separately, and deeper Terraform and IaC integration to detect issues before infrastructure is deployed.
For how long have I used the solution?
I have almost six years of experience in my current field.
What do I think about the stability of the solution?
JupiterOne is stable.
What do I think about the scalability of the solution?
Scalability of JupiterOne is effective.
JupiterOne scales well because it is a SaaS, API-driven platform. Our organization has grown from a few cloud resource accounts to hundreds of accounts and thousands of resources without needing to deploy additional JupiterOne infrastructure. I simply onboard additional AWS, GCP, SaaS, and security tool integrations, and JupiterOne continuously ingests and normalizes the asset data into its graph.
How are customer service and support?
Customer support for JupiterOne is good, and I find it quite strong, especially for enterprise use. Apart from standardized documentation support, I have access to the customer success team for integration, query, and workflow-related issues. They are also helpful when I need assistance creating and improving J1QL queries and onboarding new integrations. JupiterOne provides documentation, a support channel, community resources, and customer success support.
Which solution did I use previously and why did I switch?
I did not use any previous solution before JupiterOne.
How was the initial setup?
I use all three cloud providers, AWS, GCP, and Azure, mostly with JupiterOne.
What about the implementation team?
I use JupiterOne exclusively without evaluating other options.
What was our ROI?
I cannot share specifics from the team's perspective or the company perspective, but personally, using JupiterOne has helped me reduce my total time by almost twenty percent.
What's my experience with pricing, setup cost, and licensing?
My organization manages pricing, setup costs, and licensing, so I am not certain about those specifics.
Which other solutions did I evaluate?
I use JupiterOne exclusively without evaluating other options.
What other advice do I have?
My advice for others looking into using JupiterOne is to utilize it as it helps in monitoring cloud resources and is better for security and compliance purposes. I would rate this review a ten out of ten.
Rajesh Podishetty
Automated compliance has reduced audit work and improves fraud detection in global banking
Reviewed on Jun 22, 2026
Review from a verified AWS customer
What is our primary use case?
My main use case for JupiterOne is related to banking, specifically global retail banking. I use JupiterOne to unify cloud, SaaS, and on-prem assets to achieve visibility. I have achieved 99.9% uptime and reduced audit preparation time by 40%. Continuous monitoring is another aspect I generally conduct through JupiterOne, which flags misconfigurations in payment gateways before they impact customers.
One example in my project is with the European Investment Bank, where JupiterOne has leveraged continuous controls monitoring (CCM) to help stay compliant with different SOX and PCI DSS regulations. This has reduced manual compliance efforts by 80-90%. The system improved fraud detection by accurately correlating data during critical business operations. JupiterOne also integrates with AWS and Azure cloud workloads, detecting IAM role misconfigurations in real-time, thus preventing unauthorized access to sensitive financial data. Overall, it has also reduced mean time to incident resolution from hours to minutes.
What is most valuable?
Earlier, my audit preparation was a manual compliance task where I assigned tasks to different associates based on manual work. After using JupiterOne, I transitioned to an automated approach for audit readiness, enabling limited users access to assigned tasks and streamlining everything. This automation reduced manual work by 40-70% and significantly improved my audit readiness.
Fraud detection stands out as a key feature of JupiterOne. It prioritizes data, especially AI-driven data, and the accuracy of fraud detection is at 95%.
One of the best features JupiterOne offers is its graph-native asset model, which illustrates the relationships between users, workloads, and permissions, particularly in the banking sector. This helps me understand who logs in daily, identifies authorized users versus unauthorized ones, and monitors legal transactions versus improper ones. It provides clarity on transaction types, whether online payments, manual withdrawals, or ATM use. Another excellent feature is continuous controls monitoring, which constantly tracks access systems. Unified Vulnerability Management (UVM) is also a standout feature, along with AI-powered natural language queries that allow querying databases for transaction metrics and user profits, giving an overview of operations.
What needs improvement?
JupiterOne could improve regarding the cost, as enterprise deployment can be costly. The challenge of high costs, particularly with the integration of third-party applications to access banking systems, should be addressed.
Skills development is another important area that needs attention, as teams require training in graph-based query language to effectively handle large transaction datasets. Additionally, addressing integration complexity across diverse SaaS and on-prem systems is essential.
For how long have I used the solution?
I have been working in my current field for the last six years.
What do I think about the stability of the solution?
JupiterOne is stable.
What do I think about the scalability of the solution?
JupiterOne's scalability is impressive, particularly compared to other tools in the market. It handles diverse daily data, supports multi-cloud environments, and accommodates thousands of users and applications. Given my use of AWS cloud, it integrates with over 200 operations across different models.
How are customer service and support?
I would rate customer support eight out of ten, as it is very good.
Which solution did I use previously and why did I switch?
I did not use any different solution. I started with JupiterOne from the outset.
What was our ROI?
With JupiterOne, I have reduced the number of employees needed due to increased automation, which has also led to significant cost savings. Earlier, costs were about $10,000 per quarter, which has now decreased to $2,000. I have saved approximately $8,000.
Which other solutions did I evaluate?
I think some other tools were considered, but none of them met my standards. The only one mentioned was ServiceNow GRC, which my team evaluated prior to choosing JupiterOne.
What other advice do I have?
Using JupiterOne, I have observed an increase in transaction success rates to 99% without improper data, translating to 99% time saved. Audit readiness has improved due to a 40-70% reduction in manual work, shifting towards automation. Incident response time has improved significantly, going from over one hour to just minutes.
JupiterOne has benefited my organization through continuous compliance, allowing valid user access and maintaining audit trails that minimize regulatory risk. I conduct quarterly audits to ensure continuous compliance by understanding system interactions and roles of access, including customer and third-party interactions. Governance automation is another benefit, enabling the mapping and control of multiple frameworks simultaneously. Real-time monitoring has reduced downtime and financial risk, contributing to overall operational resilience. AI-driven prioritization has lessened false positives, enhancing transaction accuracy, ensuring reliability.
Regarding governance and security, JupiterOne offers robust capabilities. It features an AI attack surface management (ASM) option that maps risks across cloud and SaaS systems and integrates AI effectively. AI-driven queries enhance compliance and risk reporting accuracy, allowing for valid data extraction from substantial datasets. The predictive risk modeling identifies attack paths linked to third-party vendor access and enforces policy adherence.
In terms of output accuracy and reliability, JupiterOne delivers trustworthy results. Using AI queries, it processes large data sets efficiently, managing thousands of transactions with precision. In just seconds, it provides accurate counts and results. The governance and security aspects are stable, with restricted access to ensure unauthorized users cannot interfere.
I would advise that JupiterOne is a stable and scalable cybersecurity and governance platform, particularly in financial services and banking sectors. It provides real-time visibility, continuous compliance, monitoring, AI-driven risk prioritization, and governance automation. These features enhance audit readiness and improve fraud prevention. I rate JupiterOne nine out of ten because it is scalable, stable, and well-suited for retail, investment, and banking sectors. It excels in graphical asset management and includes useful AI features, making it superior to other market tools.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Tarun Goswami_
Unified cloud visibility has simplified compliance reporting and improved incident response
Reviewed on Jun 11, 2026
Review from a verified AWS customer
What is our primary use case?
I have been using JupiterOne for four to five months. I explored JupiterOne during my cybersecurity studies, and it serves as a cloud asset management and security solution for my company.
I use JupiterOne to address issues that my company faces with rating limits to deliver strong values, visibility, and compliance for all of my clients' terms.
The main use cases with JupiterOne involve personalized voice scripts for company assets, including tracking compliance and checks and cloud monitoring.
The best use case for JupiterOne is primarily its privacy capabilities, such as how it operates in private zones.
When S3 buckets are publicly exposed by mistake, JupiterOne flags it immediately through its graph relationship without manual checking of each asset. The compilation reporting is handled automatically instead of manually collecting evidence for SOC 2 or ISO audits. JupiterOne continuously maps infrastructures against compliance frameworks, which helps my company significantly.
Regarding automation with JupiterOne, I added some automations that directly contact clients or utilize the graph of the clients. They can see the live graphs of whatever is behind that situation, and it automatically finds the catalogs of every digital asset like cloud instances, user apps, and devices without manual inputs. The graph-based visualizations handle compliance mapping and policy management effectively.
What is most valuable?
JupiterOne affects my organization from many perspectives, particularly from a security viewpoint. Organizations gain a complete picture of their entire digital infrastructure with no blind spots, every asset, and every connection in one place. This reduces manual work and enables faster incident response, making compliance easier for standards like ISO and HIPAA. Evidence is automatically collected, which is the main cause of cost savings.
Fewer security breaches result from less manual effort, leading to better risk management. That is why my company uses JupiterOne extensively.
Time saved and money saved are both significant benefits that I have experienced.
What needs improvement?
Regarding performance and speed scenarios for JupiterOne, queries sometimes take too long, especially when dealing with large datasets or complex graph relationships that can slow down significantly. There is also a steep learning curve, as J1QL, their query language, is powerful but requires time to learn. New users struggle initially, and better onboarding tutorials are needed.
Rate limiting issues can be frustrating, as API rate limits sometimes cause problems.
Price transparency for JupiterOne is an area for improvement. The price is not publicly listed, so you have to contact sales for smaller teams or startups, which becomes a barrier. Another issue is alert noise, as sometimes too many alerts are generated. Better filtering and prioritization are needed so that critical issues do not get lost.
JupiterOne is very good when compared to other cloud asset platforms overall.
For how long have I used the solution?
I have been working with this solution for seventeen months.
What do I think about the stability of the solution?
JupiterOne is stable.
What do I think about the scalability of the solution?
The scalability of JupiterOne is quite good. It is built to handle enterprise-scale infrastructures with thousands of assets across multiple cloud environments. As our AWS infrastructure grew with more EC2 instances, more IAM roles, and more S3 buckets, JupiterOne automatically discovered and added them to the graph without any manual interventions. Horizontal scaling was seamless.
The graph database architecture is a smart choice for scalability. As we had more assets and relationships, the graph expanded naturally without restructuring. It is suitable for most mid-sized to large organizations. Only at very large enterprise scale do we feel those performance pressures.
How are customer service and support?
Our experience with JupiterOne's customer support was generally positive. During onboarding, support was strong. When we initially set up the platform, their team provided dedicated assistance for connecting integrations like AWS and GitHub, which made the first two to three weeks much smoother than expected.
JupiterOne has a documentation portal that is quite comprehensive. Most common questions and integration guides are well covered there, and our team relied on it heavily during initial configurations.
For ticket-based support, response time was reasonable for standard issues, usually within twenty-four to forty-eight hours. For critical issues, we sometimes received faster responses.
I would rate the customer service nine out of ten.
Which solution did I use previously and why did I switch?
Before JupiterOne, we were using a combination of tools including primarily AWS Security Hub for cloud security monitoring, spreadsheets for access tracking and compliance evidence collection, and a separate tool for vulnerability scanning. The problem was that those tools did not communicate with each other, resulting in three separate dashboards, no unified view, and a lot of manual work stretching data together for reporting.
This consolidation issue was the main reason we switched to JupiterOne. We wanted one single platform that could replace all three and give us a connected graph view instead of isolated data silos. That is why we chose JupiterOne, and it was the best decision ever.
I did not evaluate other options and directly switched to JupiterOne.
How was the initial setup?
My overall experience is good. JupiterOne follows a subscription-based pricing model that is not publicly listed, so you have to go through their sales team for actual numbers. In our case, the pricing was based on the number of assets monitored, with more assets resulting in higher costs. For a mid-sized organization like mine, it was a premium price but justified given the value.
The initial configurations took some effort, connecting all integrations like AWS and GitHub. It took about two to three weeks to fully set up and fine-tune. The licensing was a straightforward annual enterprise license.
Overall, it is not cheap, but for what it does, it is a good value.
What was our ROI?
I have definitely seen a positive return on investment from JupiterOne in a few concrete ways. The first is time savings. Before JupiterOne, our security team spent roughly fifteen to twenty hours per week manually tracking assets and preparing compliance reports. After implementation, that dropped to about three to four hours, saving nearly eighty percent of manual effort in that area.
The second area is audit preparation for SOC 2. Previously, it took four to six weeks of intensive work, but with JupiterOne continuously collecting evidence, that came down to roughly one week. This alone saved significant consultant and employee hours.
The third area is incident response.
What's my experience with pricing, setup cost, and licensing?
JupiterOne follows a subscription-based pricing model that is not publicly listed, so you have to go through their sales team for actual numbers. In our case, the pricing was based on the number of assets monitored, with more assets resulting in higher costs. For a mid-sized organization like mine, it was a premium price but justified given the value.
The initial configurations took some effort, connecting all integrations like AWS and GitHub. It took about two to three weeks to fully set up and fine-tune. The licensing was a straightforward annual enterprise license.
Overall, it is not cheap, but for what it does, it is a good value.
Which other solutions did I evaluate?
I did not evaluate other options and directly switched to JupiterOne.
What other advice do I have?
I have several practical pieces of advice for anyone looking into JupiterOne. The first is to start with clear asset inventory goals. Before you even set up the tools, know what you want to track, such as cloud assets or user applications. Going in without clarity makes the setup overwhelming.
The second is to invest time in learning J1QL early, as it is the key to unlocking JupiterOne's full power. The third is to connect your most critical integrations first, such as AWS and GitHub, and get those running before expanding to others. Do not try to connect everything at once as it becomes messy.
The fourth is to involve your compliance team from day one. JupiterOne's biggest ROI is in audit preparation, but only if compliance requirements are mapped correctly from the start. Finally, use the trial period seriously. Do not just click around; actually run real queries against your infrastructure and see if the insights match your expectations before committing to enterprise pricing.
My overall advice is that if you are a mid-sized or large organization dealing with multi-cloud complexity, JupiterOne is absolutely worth evaluating seriously. I gave this review an overall rating of eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Chijioke Okoye
Unified asset visibility has improved investigations and now simplifies tracking security assets
Reviewed on Feb 16, 2026
Review from a verified AWS customer
What is our primary use case?
Our main use case for JupiterOne is as an asset catalog tool where we document all our assets that are integrated from different platforms such as Device42, Qualys, Microsoft M365, and Defender. We are aggregating all our assets from different tools into JupiterOne.
A specific example of how we use JupiterOne day-to-day is being able to draw a network flow of how network traffic travels through the network, starting from the edge devices to the internal devices. We are also using JupiterOne to track assets that are being brought in and assets that are leaving the environment. Additionally, we are using JupiterOne as the source of truth for many other things that we are doing. Some of my other teammates in areas such as data are tapping into it for asset categorization.
How has it helped my organization?
JupiterOne has had a significant impact on our organization. Previously, when looking at security alerts, we would need to examine different tools separately. Now, we often take the IP address or the FQDN and input it into JupiterOne, which usually tells us what that asset is. We are ingesting data from places such as AWS, Azure, Device42, Qualys, Defender, and Trend Micro. These are different tools that, on a good day without JupiterOne, we would have to look at separately to determine where a particular asset is. JupiterOne helps us aggregate all those things on one single platform, allowing us to quickly identify what environment that asset lives in and what type of asset it is.
One feature we also value is the ability to enter custom tags so we can create asset types or asset locations and detail who owns the asset. These features have positively impacted us at Landmark Information Group.
What is most valuable?
I think one of the best features JupiterOne offers is blast radius, being able to see assets that could be directly or indirectly affected by any cyber incident or to see how some assets communicate with other assets and some do not communicate with other assets. I also think it is easy to query assets and find assets using queries and build out graphs that often make it easy for us to drill down on certain types of assets or categories of assets.
The blast radius feature has helped our team because, in security operations, one of the first places we look when investigating an alert is JupiterOne. We might enter the IP address or the FQDN of the server to find out where it is, who owns it, and what it does. At that point in time, we identify other assets that might be in the same environment or the same place where that asset lives, which helps us when we are doing security operations and investigating alerts.
What needs improvement?
There are some features that I have shared with our customer service manager. One of them that is relevant to us at this time is the need for better determination of unified devices. Currently, JupiterOne uses hostname weights, MAC addresses, or IP addresses to tie devices together, but we have actually requested a way for us to make those determinations ourselves. For example, when externally scanning a device using Qualys, internally it gives an IP address or FQDN, while externally it might be different. We want to be able to decide ourselves that these two devices are the same device even when they have different names and IP addresses for external and internal use. The unified devices feature is valuable and did not used to exist, and it has been fantastic. However, I believe more can be done regarding unified devices, and giving users the privilege to tie them together would be a good addition to the platform.
One of the other things that interest us in JupiterOne and why we really wanted to use the tool is the compliance feature. We wanted to use it to track our compliance since we are ISO 27001 certified. However, the compliance module has not worked well, and we have had to continue tracking our compliance manually with the tools we use. Although there are some works in progress to improve the compliance part of the tool, I think if they can get it up to speed, that would be a really good improvement.
For how long have I used the solution?
I have been using JupiterOne for three years. I was initially recruited with Landmark Group to be a subject matter expert for JupiterOne.
What other advice do I have?
JupiterOne has many features. Although none comes to mind almost immediately, I know it often depends on how we are able to write or craft the queries. JupiterOne has been very instrumental to me in my work. Being the subject matter expert for JupiterOne at Landmark, I think it has been very beneficial for me.
JupiterOne has been quite helpful to us, especially in information security. One of the things it helps us with is housekeeping, allowing us to see where there are duplicates and address those.
I would rate JupiterOne an eight. JupiterOne is a strong tool, and there are some issues that need to be addressed, but overall, I think it is a good tool. The reason I am giving it an eight is that there are features that are not its strengths, which is understandable, but it performs very well in the aggregation of assets from different platforms.
I would definitely recommend JupiterOne because some of the features I have mentioned here are part of what makes it strong. The aggregation of tools from different platforms into one single repository allows you to easily query assets by typing their IP address, hostname, or FQDN. I believe that is JupiterOne's greatest strength. Additionally, you can create dashboards or widgets for a high-level overview, and JupiterOne can track trends over time, telling you if something is increasing, decreasing, or remaining stable. Those are part of the great features that JupiterOne has, and I would recommend it to anyone needing a single cyber asset tool.