{
 "categories": [
  "enterprise",
  "observability"
 ],
 "deployment": "saas",
 "evidence": [
  {
   "date": "2026-09-04",
   "fact": "homepage",
   "note": "Wiz presents a commercial cloud and AI security platform that connects code, cloud, and runtime into a single security graph, with a get-a-demo path.",
   "source": "https://www.wiz.io/",
   "tier": "declared"
  },
  {
   "date": "2026-09-04",
   "fact": "license",
   "note": "Wiz pricing is a custom quote for modular Cloud, Code, Defend, Sensor, and SMB bundle licenses. No public self-serve free plan is published.",
   "source": "https://www.wiz.io/pricing",
   "tier": "declared"
  },
  {
   "date": "2026-09-04",
   "fact": "modalities.api.exists",
   "note": "Wiz states that customers can build custom integrations that use the Wiz API, and that all programmatic interaction with the Wiz SaaS platform occurs through an authenticated GraphQL endpoint.",
   "source": "https://www.wiz.io/blog/how-wiz-meets-cisa-secure-by-design-objectives",
   "tier": "declared"
  },
  {
   "date": "2026-09-04",
   "fact": "modalities.api.kinds[0]",
   "note": "The same page states the GraphQL API is strongly typed, accepts only POST requests, and is the programmatic interface to the Wiz SaaS platform. No public REST catalog was opened.",
   "source": "https://www.wiz.io/blog/how-wiz-meets-cisa-secure-by-design-objectives",
   "tier": "declared"
  },
  {
   "date": "2026-09-04",
   "fact": "modalities.api.auth[0]",
   "note": "Wiz documents Service Accounts for custom integrations, using a per-request API token flow with short-lived tokens, granular permissions, and custom expiry dates. Public pages do not name request headers or token-mint URLs.",
   "source": "https://www.wiz.io/blog/how-wiz-meets-cisa-secure-by-design-objectives",
   "tier": "declared"
  },
  {
   "date": "2026-09-04",
   "fact": "modalities.api.coverage",
   "note": "The public page establishes that a GraphQL API exists for custom integrations. It does not publish a schema, resource list, or write-versus-read matrix. Coverage stays unknown.",
   "source": "https://www.wiz.io/blog/how-wiz-meets-cisa-secure-by-design-objectives",
   "tier": "declared"
  },
  {
   "date": "2026-09-04",
   "fact": "modalities.mcp.first_party",
   "note": "Wiz announces general availability of Wiz MCP as a Wiz-owned way to connect assistants and custom agents to the Security Graph, Wiz AI Agents, and Wiz AI Skills.",
   "source": "https://www.wiz.io/blog/introducing-wiz-mcp",
   "tier": "declared"
  },
  {
   "date": "2026-09-04",
   "fact": "modalities.agent_docs.llms_txt",
   "note": "Wiz publishes https://www.wiz.io/llms.txt as a first-party index of academy, blog, platform, and solution pages. It is not a developer API catalog.",
   "source": "https://www.wiz.io/llms.txt",
   "tier": "declared"
  },
  {
   "date": "2026-09-04",
   "fact": "verdict.scores.api",
   "note": "A production GraphQL API with Service Accounts is declared, but public pages omit the endpoint, schema, and auth headers. That is useful production work with a material public-documentation gate.",
   "source": "https://www.wiz.io/blog/how-wiz-meets-cisa-secure-by-design-objectives",
   "tier": "declared"
  },
  {
   "date": "2026-09-04",
   "fact": "verdict.scores.mcp",
   "note": "Wiz MCP is first-party and marked generally available, with described Security Graph, Issues, threat, and Skills workflows. Public pages still omit the tool catalog and auth contract, so the official path is limited (5-6), not a fully documented production MCP (7-8).",
   "source": "https://www.wiz.io/blog/introducing-wiz-mcp",
   "tier": "declared"
  },
  {
   "date": "2026-09-04",
   "fact": "freshness.watch[0].url",
   "note": "Opened and verified as Wiz's July 2026 GA announcement for Wiz MCP, including Security Graph, AI Agents, and AI Skills. No public tool table on this page.",
   "source": "https://www.wiz.io/blog/introducing-wiz-mcp",
   "tier": "declared"
  },
  {
   "date": "2026-09-04",
   "fact": "freshness.watch[1].url",
   "note": "Opened and verified as the earlier preview post. It states Wiz built the MCP server and that setup details live in customer documentation.",
   "source": "https://www.wiz.io/blog/introducing-mcp-server-for-wiz",
   "tier": "declared"
  },
  {
   "date": "2026-09-04",
   "fact": "freshness.watch[2].url",
   "note": "Opened and verified as the public Wiz page that declares the GraphQL API and Service Account short-lived token flow.",
   "source": "https://www.wiz.io/blog/how-wiz-meets-cisa-secure-by-design-objectives",
   "tier": "declared"
  },
  {
   "date": "2026-09-04",
   "fact": "freshness.watch[3].url",
   "note": "Opened and verified as Wiz's current public llms.txt index.",
   "source": "https://www.wiz.io/llms.txt",
   "tier": "declared"
  },
  {
   "date": "2026-09-04",
   "fact": "freshness.watch[4].url",
   "note": "Opened and verified as the current Wiz product homepage for the Security Graph platform.",
   "source": "https://www.wiz.io/",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-09-04",
  "volatility": "high",
  "watch": [
   {
    "type": "mcp",
    "url": "https://www.wiz.io/blog/introducing-wiz-mcp"
   },
   {
    "type": "mcp",
    "url": "https://www.wiz.io/blog/introducing-mcp-server-for-wiz"
   },
   {
    "type": "docs",
    "url": "https://www.wiz.io/blog/how-wiz-meets-cisa-secure-by-design-objectives"
   },
   {
    "type": "docs",
    "url": "https://www.wiz.io/llms.txt"
   },
   {
    "type": "docs",
    "url": "https://www.wiz.io/"
   }
  ]
 },
 "homepage": "https://www.wiz.io/",
 "id": "wiz",
 "license": "commercial",
 "modalities": {
  "agent_docs": {
   "llms_txt": true
  },
  "api": {
   "auth": [
    "service-account-short-lived-token"
   ],
   "coverage": "unknown",
   "docs": null,
   "exists": true,
   "kinds": [
    "graphql"
   ]
  },
  "cli": {
   "exists": "unknown"
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [],
   "import": []
  },
  "extensibility": {
   "scripting": [],
   "webhooks": "unknown"
  },
  "integrations": {
   "make": "unknown",
   "n8n": "unknown",
   "power_automate": "unknown",
   "zapier": "unknown"
  },
  "mcp": {
   "first_party": true,
   "third_party": [],
   "verdict": "official"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No repeatable UI probe was run. Public pages establish a first-party Wiz MCP and a GraphQL API used through Service Accounts. Browser automation remains unassessed.\n",
   "ui_stack": [
    "web-dom"
   ],
   "vendor_support": []
  },
  "sdk": {
   "exists": "unknown",
   "languages": [],
   "official": "unknown"
  }
 },
 "name": "Wiz",
 "platforms": [
  "web"
 ],
 "related": {
  "alternatives": [
   "crowdstrike-falcon",
   "snyk"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "Wiz",
 "verdict": {
  "best_path": "mcp",
  "scores": {
   "api": 5,
   "cli": null,
   "computer_use": null,
   "integrations": null,
   "mcp": 6,
   "overall": 6,
   "rpa": null
  },
  "summary": "Wiz is automatable today through a vendor-declared first-party MCP server. This record is the Wiz CNAPP / Security Graph platform, including Issues, threats, Wiz AI Agents, and Wiz AI Skills reachable through Wiz MCP. It is not CrowdStrike Falcon or Snyk. A July 2026 Wiz blog announces general availability of Wiz MCP for AI assistants, custom agents, and AI-powered applications, grounded in the Security Graph and reusable Wiz AI Skills. The earlier April 2025 preview post says Wiz built the server and that it translates natural-language queries into Wiz operations such as listing critical issues, examining an issue, and inventory search. Public blogs do not publish a tool table, transport URL, or authentication contract. Customer documentation at docs.wiz.io returned a bot checkpoint on this pass and was not used. A public Wiz CISA Secure-by-Design page states that all programmatic interaction with the Wiz SaaS platform uses an authenticated GraphQL endpoint and that custom integrations use Service Accounts with a per-request short-lived API token flow. That page does not publish the GraphQL URL, header names, or schema. No official CLI or language SDK was established from the opened pages. iPaaS catalogs were not opened. Computer-use viability is unassessed. MCP scores 6 because it is official and generally available but the public-doc gap on tools and auth keeps it in the limited-official band. The GraphQL API scores 5 for the same public-contract gap.\n"
 }
}