Expel
Expel is a privately held US-based managed detection and response (MDR) provider delivering 24x7 human-led, AI-accelerated security operations across cloud, endpoint, identity, and SaaS for enterprise and mid-market customers in financial services, transportation, retail, healthcare, and technology.
- Company typePrivate
- Founded2016
- HeadquartersHerndon, United States
- Headcount251–500
- GTM typeB2B
- OfferingSoftware
What Expel does
Expel is a privately held, US-based managed detection and response (MDR) provider founded in 2016 and headquartered in Herndon, Virginia. The company delivers 24×7, human-led, AI-accelerated security operations across cloud, endpoint, identity, email, network, and SaaS attack surfaces, serving enterprise and mid-market customers in financial services, transportation, retail, healthcare, legal, and technology — including named logos such as Visa, Uber, United Airlines, Affirm, Markel, Carter's, and Skechers.
The core technology stack centers on two proprietary assets: the Workbench™ operations platform, which ingests and orchestrates alerts from customer security tools and provides transparency into Expel's triage and remediation actions, and Ruxie AI, a proprietary agentic AI capability built on ten years of live SOC production data that the company cites as the basis for a 14-minute mean time to remediate. The product portfolio includes Expel MDR (flagship), Expel Managed SIEM (co-managed service for Microsoft Sentinel and Splunk Enterprise Security, launched March 2026), Expel Phishing, Expel Threat Hunting, Expel Auto Remediation, Expel Intel threat intelligence, and a Security Data Lake for cost-optimized retention. Expel integrates with hyperscaler ecosystems including AWS (Cloud Partner of the Year 2026), Microsoft, Google Cloud/Google SecOps, and Splunk, and holds SOC 2 Type 2, ISO 27001, ISO 27701, GDPR, EU-U.S. DPF, NIST CSF/PF, and NIST 800-171 / CMMC Level 3-aligned certifications.
Expel's business model is a subscription-based MDR service billed annually in advance with auto-renewing one-year terms, supplemented by a freemium trial (up to 45 days), paid Managed SIEM add-on subscriptions priced by attack surface and log volume, and a formal channel/reseller program across North America/Latin America/APAC and EMEA. Go-to-market is primarily sales-led direct enterprise motion, supported by a content-led marketing engine (annual threat report, webinars, RSAC presence) and a partner ecosystem (GuidePoint Security NA Partner of the Year, Babble Cloud EMEA Partner of the Year). The company has raised over $140M in disclosed funding across multiple rounds from 2016 to 2022, reaching unicorn status (over $1B valuation) at its November 2021 Series E led by CapitalG and Paladin Capital Group.
Expel firmographics
Firmographics- Name
- Expel
- Legal name
- Expel, Inc.
- Website
- https://expel.com
- Company type
- Private
- Founded year
- 2016
- Operating status
- Operating
- Headcount range
- 251–500 employees
- Short description
- Expel is a privately held US-based managed detection and response (MDR) provider delivering 24x7 human-led, AI-accelerated security operations across cloud, endpoint, identity, and SaaS for enterprise and mid-market customers in financial services, transportation, retail, healthcare, and technology.
- Ownership category
- akta.pro rank
Expel industry classification
Industry- Product category
- Managed Detection and Response Services
- NAICS
- Security Systems Services (except Locksmiths) (561621), Security Systems Services (56162), Computer Facilities Management Services (541513)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370), Services-Prepackaged Software (7372)
- akta.pro primary industry
- Managed Detection & Response (MDR) (BPAEADAA)
- akta.pro secondary industries
- Security Operations Center (SOC) as a Service (BPAEADAB), Attack Detection & Response for Cloud/SaaS (SOC for Cloud) (HDADAGAJ), Email & Collaboration Threat Detection/Response (ICR/CTDR) (HDADAKAI), Endpoint Security Managed Services (EDR/XDR) (BPAEADAH)
Keywords
Where Expel is headquartered
LocationHeadquarters
- HQ city
- Herndon
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Expel business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Subscription MDR Services: Expel charges annual subscription fees in advance (net 30 days from invoice) for its proprietary cloud-based security operations management platform and related MDR services, with automatic renewal for successive one-year terms unless 90 days' notice is given. Customers can be billed for Overages if service usage exceeds purchased quantities by 10% for more than one month in any rolling six-month period.
- Free Trial Services: Expel offers short-term no-cost usage of its services for IT setup/configuring or time-limited free trials, typically up to 45 days from initiation, providing a land-and-expand entry point to convert prospects into paying subscription customers.
- Managed SIEM Add-on Subscriptions: Expel Managed SIEM is offered as a paid add-on subscription to Expel MDR, priced based on attack surfaces and log sources, with two tiers (Detection Engineering and Performance Engineering).
- Channel / Reseller Revenue: Expel sells through authorized Reseller Partners in North America/Latin America/APAC and EMEA, with reseller-specific terms and conditions governing service delivery and billing arrangements.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | MDR annual subscription with annual billing in advance, net 30 days from invoice; auto-renews in one-year terms unless 90 days' notice given; overages apply if usage exceeds purchased quantity by 10% for more than one month in any rolling six-month period. |
| Freemium | Pay-as-you-go | Free Trial Services available up to 45 days for setup/configuration or time-limited trial of Expel's services. |
| Unit Pricing | Annual | Expel Managed SIEM add-on priced based on attack surfaces and log sources, with Detection Engineering and Performance Engineering subscription tiers. |
Go-to-market motion1 record
Distribution channels4 records
Marketing channels11 records
Expel product offering
Product offeringCore offering
Expel provides 24x7 human-led, AI-accelerated managed detection and response (MDR) services through its proprietary Workbench™ cloud operations platform and Ruxie AI engine, monitoring cloud, endpoint, identity, email, SaaS, and network attack surfaces. Core offerings include the MDR service, co-managed SIEM for Microsoft Sentinel and Splunk, phishing investigation, threat hunting, security data lake, and Expel Intel threat intelligence, sold as annual subscriptions with a 45-day free trial and add-on modules.
Product overview
Expel offers a single integrated platform-plus-modules architecture: the Expel Workbench™ operations platform serves as the digital command center that powers all offerings, with Ruxie AI providing AI and agentic automation across the threat lifecycle on top of it. The flagship offering is Expel Managed Detection and Response (MDR), a 24×7 human-led, AI-accelerated service that monitors cloud, endpoint, identity, network, email, and SaaS environments. Add-on modules include Expel Managed SIEM (co-managed detection engineering for Microsoft Sentinel and Splunk Enterprise Security), Phishing investigation and response, and Threat hunting. Adjacent solutions include a Security Data Lake (for lower-cost long-term retention), Expel Intel (threat intelligence), Auto Remediation, and Expel MDR packages/Plans & Packages. Customers keep their existing tools and gain transparency into Expel's work via Workbench.
Differentiator
Problem solved
Functional benefit
Brands
- Expel Managed SIEM: Co-managed SIEM service integrating with Microsoft Sentinel and Splunk Enterprise Security to handle detection strategy, custom detection logic, and SIEM cost optimization.
- Expel MDR
- Ruxie AI
- Workbench
Products and services
- Expel Managed Detection and Response (MDR) 24x7 human-led, AI-accelerated managed detection and response service that monitors customers' existing security tools across cloud, endpoint, identity, email, network, and SaaS attack surfaces. Delivered through the Workbench™ platform and Ruxie AI with 14-minute mean time to remediate. Sold as an annual subscription with a 45-day free trial.
- Expel Managed SIEM Co-managed SIEM service integrating with Microsoft Sentinel and Splunk Enterprise Security that embeds Expel detection engineers to handle detection strategy, custom detection logic, rule review, automation, and SIEM cost optimization. Available in two subscription tiers (Detection Engineering and Performance Engineering). Customers retain full ownership of the detection rules created, and Expel does not profit from data volume.
- Expel Workbench™ Operations Platform Expel's proprietary cloud-based operations platform that serves as the SOC's digital command center. Workbench™ aggregates signals from customer security tools via APIs, orchestrates Expel's 24x7 human-led analyst response, and provides real-time visibility and transparency into investigations and remediation actions.
- Ruxie AI AI and agentic capability layer powering Expel's "agentic MDR" across the full threat lifecycle. Built on ten years of live SOC production data, Ruxie AI accelerates analyst decisions across alert triage, investigation, and response, and is delivered as a capability within Expel MDR.
- Expel Security Data Lake Solution that lowers long-term security storage costs while keeping telemetry available for threat detection, investigation, and compliance. Complements the primary MDR service for organizations seeking cost-efficient retention of security data.
- Expel Phishing Investigation and response service for phishing inboxes. Provides triage and remediation of user-reported phishing emails, integrated with Expel's broader 24x7 MDR service.
- Expel Threat Hunting Hypothesis-based threat hunting service that proactively searches customer environments for activity that evades automated detection. Delivered by Expel's SOC analysts as part of the broader MDR service.
- Expel Intel Threat intelligence offering that combines Expel's research, threat data, and the Annual Threat Report (which analyzed over 1 million security alerts in 2025). Delivered as part of Expel's broader security operations capability to inform customer defenses.
Quantifiable outcome
- 14-minute mean time to remediate (MTTR)
- +6 more outcomes
Companies that use Expel
Customer profileNamed customers18 records
Segments5 records
Ideal customer profiles3 records
Expel technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration3 records
AI capability9 records
Feature5 records
Expel partnerships and signals
Strategic signalPartnerships
Six partnerships are on record, tiered core - top north american channel partner., core - top emea channel partner., core - designated cloud partner of the year and dedicated aws cloud security solution., strategic - major cloud platform integration. and core - foundational siem integration underpinning managed siem service..
- GuidePoint Securitycore - top north american channel partner.GuidePoint Security was named Expel's North American Partner of the Year at Expel's second annual Partner of the Year Awards (February 2026), recognizing excellence in delivering transparent, outcomes-based security operations to customers.
- Babble Cloudcore - top emea channel partner.Babble Cloud was named Expel's EMEA Partner of the Year at Expel's second annual Partner of the Year Awards (February 2026), recognizing excellence in delivering transparent, outcomes-based security operations across the EMEA region.
- Amazon Web Services (AWS)core - designated cloud partner of the year and dedicated aws cloud security solution.AWS was named Expel's Cloud Partner of the Year at Expel's second annual Partner of the Year Awards (February 2026). Expel offers dedicated AWS Cloud Security MDR services integrated with AWS environments, evidencing a deep cloud partnership.
- Google Cloud (Google SecOps)strategic - major cloud platform integration.In October 2025, Expel announced an integration with Google SecOps to deliver managed detection and response for Google Cloud customers. The integration enables Expel to leverage Google SecOps' advanced capabilities to provide faster detection and response without additional operational overhead for customers.
- Microsoft (Microsoft Sentinel)core - foundational siem integration underpinning managed siem service.Expel Managed SIEM integrates with Microsoft Sentinel as part of its co-managed SIEM offering (launched at RSAC 2026). Expel handles detection strategy, custom detection logic development, and SIEM administration for Sentinel customers.
- Splunk (Splunk Enterprise Security)core - foundational siem integration underpinning managed siem service.Expel Managed SIEM integrates with Splunk Enterprise Security as part of its co-managed SIEM offering (launched at RSAC 2026). Expel handles detection strategy, custom detection logic development, and SIEM administration for Splunk customers.
Scale indicators10 records
Recent moves6 records
Expansion highlights6 records
Expel competitors and assessment
Company assessmentDirect peers
- Arctic Wolf: Closely comparable pure-play MDR provider offering 24x7 managed detection and response across endpoint, cloud, identity, and network, with a security operations platform and concierge delivery model. Directly competes with Expel for mid-market and enterprise MDR deals.
- eSentire: Long-standing pure-play MDR vendor with 24x7 SOC, threat hunting, and managed detection across endpoint, network, cloud, and log, sold to mid-market and enterprise. Direct head-to-head competitor to Expel in the MDR category.
- ReliaQuest: Enterprise-focused MDR and security operations platform (GreyMatter) vendor with similar 24x7 SOC, detection engineering, and threat-hunting offerings. Competes with Expel for large enterprise MDR budgets and now expanding into co-managed SIEM.
- Critical Start: Pure-play MDR and MDR-for-MSP vendor with a Zero-Trust Analytics Platform and 24x7 SOC. Direct competitor to Expel in mid-market and enterprise MDR, with comparable SLAs and SOC-as-a-service positioning.
Broad incumbents
- Sophos MDR: Incumbent endpoint-plus-MDR vendor offering 24x7 managed detection and response as part of a broader Sophos security portfolio. Competes with Expel by bundling MDR with endpoint products, particularly in the mid-market.
- CrowdStrike (Falcon Complete): Endpoint platform incumbent that bundles managed detection and response (Falcon Complete) on top of its Falcon platform. Directly competes with Expel for endpoint-centric MDR, with massive scale and an expanding AI-driven SOC story.
- Rapid7 MDR: Public security analytics company offering managed detection and response alongside its InsightIDR/InsightConnect platform. Competes with Expel in enterprise MDR, particularly where customers already use Rapid7 SIEM/XDR products.
- Secureworks: Incumbent MSSP-turned-MDR with Taegis XDR platform and global SOC. Competes with Expel in enterprise and mid-market MDR, with broader portfolio including incident response and compliance services.
- SentinelOne (Vigilance MDR): Endpoint and AI-native security platform incumbent offering Vigilance MDR service on top of its Singularity XDR platform. Competes with Expel in AI-driven managed detection and response, particularly for endpoint-centric buyers.
Emerging players
- Huntress: Fast-growing MDR provider with strong focus on SMB and mid-market, particularly through MSP/MSSP channels. Overlaps with Expel in managed detection and 24x7 SOC delivery but skews downmarket.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Expel social profiles
Digital presenceExpel compliance and trust
Trust signalCompliance10 records
Expel financial estimates
Financial estimateRevenue estimate
Valuation estimate
Expel leadership team
Management profileNumber of profiles
Profiles11 records
Expel funding detail
Funding detailFunding overview
Funding rounds6 records
Investors11 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Expel M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Expel
What does Expel do?
Expel provides 24x7 human-led, AI-accelerated managed detection and response (MDR) services through its proprietary Workbench™ cloud operations platform and Ruxie AI engine, monitoring cloud, endpoint, identity, email, SaaS, and network attack surfaces. Core offerings include the MDR service, co-managed SIEM for Microsoft Sentinel and Splunk, phishing investigation, threat hunting, security data lake, and Expel Intel threat intelligence, sold as annual subscriptions with a 45-day free trial and add-on modules.
Is Expel a public or private company?
Expel is a private company. It is classified as venture growth investor backed and is currently operating.
When was Expel founded?
Expel was founded in 2016. It employs 251 to 500 people.
Where is Expel based?
Expel is headquartered in Herndon, United States, in the North America region.
How does Expel make money?
Four revenue lines are on record. Subscription MDR Services are the primary driver. The others are free Trial Services, managed SIEM Add-on Subscriptions and channel / Reseller Revenue.
Who are Expel's main competitors?
Direct peers on record are Arctic Wolf, eSentire, ReliaQuest and Critical Start. Broad incumbents are Sophos MDR, CrowdStrike (Falcon Complete), Rapid7 MDR, Secureworks and SentinelOne (Vigilance MDR). Huntress is listed as an emerging player.
Does Expel have an API?
No public API is recorded for Expel.
What industry is Expel in?
Expel's product category is Managed Detection and Response Services. Its primary akta.pro industry code is BPAEADAA, Managed Detection & Response (MDR), with a secondary code of BPAEADAB, Security Operations Center (SOC) as a Service. Its NAICS code is 561621 and its SIC code is 7370.