Panther
Panther Labs is a San Francisco-based security operations company that sells an AI-native SIEM platform built on a security data lake architecture. It serves enterprise and mid-market security teams migrating from legacy SIEMs, using Python detection-as-code and autonomous AI agents for alert investigation.
- Company typePrivate
- Founded2018
- HeadquartersSan Francisco, United States
- Headcount101–250
- GTM typeB2B
- OfferingSoftware
What Panther does
Panther Labs Inc. is a San Francisco-based security operations company that sells a modern, AI-native SIEM platform to enterprise and mid-market security teams. The platform is built on a security data lake architecture that stores normalized telemetry in open, SQL-queryable formats inside the customer's own Snowflake or Databricks environment, eliminating vendor lock-in and the volume-based ingestion pricing that constrains legacy SIEMs. Its core product, the Complete AI SOC Platform, combines a Data Pipeline for petabyte-scale log ingestion, a Detection Engine in Python with version control and CI/CD, an AI SOC Agent that autonomously investigates alerts and auto-resolves benign ones, AI-powered alerting and triage automation, and analytics/reporting that maps detections to MITRE ATT&CK and generates audit evidence for SOC 2, PCI-DSS, ISO 27001, and HIPAA. The differentiator is a closed-loop architecture in which every triage outcome improves the underlying detection code via GitHub pull requests, so alert volume decreases over time rather than remaining static.
Panther operates a horizontal, enterprise-led go-to-market motion with direct field sales targeting organizations migrating from Splunk, Elastic, and Sumo Logic, complemented by MSSP/MDR channel partners (including Arctic Wolf and Cloocus for APAC) and a content-first demand generation engine spanning blog, webinars, podcasts, G2 reviews (4.7/5), and developer documentation. Pricing is quote-based and not publicly disclosed; the subscription model is decoupled from daily ingest volume, which the company positions as the primary cost advantage over incumbents (customers such as Cockroach Labs and Zapier publicly report $200K–$400K in annual savings while ingesting 3.5x–5x more data). Named customers include Docker, Zapier, Dropbox, Snyk, GitGuardian, Tealium, Cockroach Labs, Varo Bank, Spring Health, HealthEquity, LaunchDarkly, GoFundMe, Wolt, Benchling, JupiterOne, Cresta, and Infoblox.
The company was founded in 2018 and raised approximately $140.5M across four rounds, including a $120M Series B in December 2021 led by Coatue Management with Snowflake Ventures participation at a $1.4B unicorn valuation. In October 2025, Panther acquired Datable. In June 2026, Databricks announced an agreement to acquire Panther to establish the 'security lakehouse' category — Databricks' third cybersecurity acquisition following Antimatter and SiftD.ai — subject to customary closing conditions and regulatory clearances. As of the announcement, Panther continues to operate as a separate entity pending deal completion.
Panther firmographics
Firmographics- Name
- Panther
- Legal name
- Panther Labs Inc.
- Website
- https://panther.com
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Short description
- Panther Labs is a San Francisco-based security operations company that sells an AI-native SIEM platform built on a security data lake architecture. It serves enterprise and mid-market security teams migrating from legacy SIEMs, using Python detection-as-code and autonomous AI agents for alert investigation.
- Ownership category
- akta.pro rank
Panther industry classification
Industry- Product category
- Security Information and Event Management (SIEM) / AI SOC Platform
- NAICS
- Software Publishers (513210), Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (518)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- End-to-End Enterprise AI Platforms (MLOps & Model Lifecycle Management) (HDAEANAA)
- akta.pro secondary industries
- Enterprise AI Data & Knowledge Platforms (Vector Databases, Knowledge Graphs) (HDAEANAH), Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII) (HDAEANAG)
Keywords
Where Panther is headquartered
LocationHeadquarters
- HQ city
- San Francisco
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Panther business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Infrastructure, Operations
Revenue model
- SaaS Subscription (Platform + Ingestion + AI): Panther charges a subscription fee for platform access, log ingestion, and AI capabilities. Pricing is not publicly disclosed and is quote-based / negotiated per customer, consistent with enterprise SaaS go-to-market motion targeting organizations migrating from volume-priced legacy SIEMs.
- Managed Cloud (Hosted Deployment): Panther offers a fully managed hosted deployment model where Panther operates the platform and ingests customer data into a dedicated, isolated environment, providing the fastest path to value when there is no internal data warehouse mandate or single-vendor operations requirement.
- Partner/Channel (MSSP/MDR): Managed service providers and MDR partners deploy Panther on behalf of their customers, creating recurring subscription revenue through channel partnerships. Partners benefit from the open architecture to build differentiated managed security service offerings.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise subscription with volume-based log ingestion and AI capabilities |
Go-to-market motion3 records
Distribution channels3 records
Marketing channels10 records
Panther product offering
Product offeringCore offering
Panther sells a Complete AI SOC Platform that operates as a modern SIEM on a security data lake, ingesting petabyte-scale logs from cloud, SaaS, identity, endpoint, and network sources into a normalized, SQL-queryable schema stored in customer-owned Snowflake or Databricks. It ships 300+ pre-built Python detections that are version-controlled in GitHub, an autonomous AI SOC Agent that investigates and auto-resolves alerts, AI-powered detection building from natural language, and a remote MCP server that exposes the platform to external AI agents.
Product overview
Panther is a unified AI SOC platform consisting of multiple integrated modules: Data Pipeline for log ingestion and normalization, AI SOC Agent for autonomous investigation and threat hunting, Detection Engine for detection-as-code with Python, Alerting and Triage Automation for AI-powered triage, and Analytics and Reporting for dashboards and compliance. The platform operates on a security data lake architecture where data stays in customer-owned Snowflake or Databricks instances. Solutions include AI SOC Transformation, Detection Engineering, Threat Hunting, Compliance Reporting, Managed Detection and Response, and Cloud Security Posture. Key differentiators include detection-as-code in Python, closed-loop detection improvement from triage outcomes, natural language interfaces, and MCP server for AI agent integration.
Differentiator
Problem solved
Functional benefit
Products and services
- Complete AI SOC Platform Unified SaaS security operations platform combining SIEM capabilities with AI-powered autonomous agents for alert investigation, threat detection, and incident response, sold to enterprise security teams.
- Data Pipeline Security data ingestion and normalization layer that ingests logs at petabyte scale from cloud platforms, SaaS tools, endpoints, and network devices, with automatic schema normalization at ingestion for enterprise security teams.
- AI SOC Agent Autonomous AI agent that investigates alerts, runs scheduled threat hunts, responds to natural-language queries, and automatically improves detection logic through closed-loop triage feedback, for security operations teams.
- Detection Engine Detection-as-code platform using Python with version control, CI/CD, and GitHub workflows, including AI Detection Builder for natural-language rule generation and closed-loop tuning, for detection engineering teams.
- Alerting and Triage Automation AI-powered alert triage that autonomously investigates every alert with full context, provides definitive risk classification, and auto-resolves benign alerts with full audit trails, for security operations analysts.
- Analytics and Reporting Built-in SOC performance dashboards, MITRE ATT&CK coverage mapping, natural-language search, and compliance reporting for SOC 2, PCI-DSS, ISO 27001, and HIPAA, for security leadership and auditors.
- Cloud Security Posture Cloud security posture management offering with daily AWS scanning, policy-as-code, CSPM integrations (Wiz, Orca, Upwind), and correlation with log data, for cloud security teams.
- Managed Detection and Response (MSSP/MDR offering) Channel offering enabling MSSP/MDR partners to deliver enterprise SOC coverage with AI-powered investigation and dedicated customer instances, sold to managed security service providers.
- Compliance Reporting Continuous compliance offering that generates audit evidence, maintains complete audit trails for AI decisions, and supports SOC 2, PCI-DSS, ISO 27001, and HIPAA frameworks, for compliance-focused security programs.
Quantifiable outcome
- Up to 90% reduction in investigation time, with context and narrative assembled autonomously
- +9 more outcomes
Companies that use Panther
Customer profileNamed customers18 records
Segments6 records
Ideal customer profiles3 records
Panther technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration22 records
AI capability6 records
Feature10 records
Panther partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered flagship and regional.
- DatabricksflagshipDatabricks announced an agreement to acquire Panther in June 2026, subject to customary closing conditions and regulatory clearances. The acquisition aims to establish the 'security lakehouse' category and compete with CrowdStrike and Cisco's Splunk. Panther's 100+ pre-built integrations, detection-as-code capabilities, and agentic SOC workflows will be integrated into Databricks' data lakehouse architecture. This is Databricks' third cybersecurity acquisition following Antimatter and SiftD.ai. CEO Ali Ghodsi stated that traditional SIEM is obsolete and AI agents must counter AI-powered attackers.
- CloocusregionalCloocus, a South Korean cloud services company specializing in data and AI, signed a cooperation agreement with Panther on May 27, 2026 to provide South Korean enterprises with an AI-based SOC operations model for cloud security. The partnership combines Panther's integrated AI SOC platform with Cloocus's cloud and AI expertise to advance security operations in the APAC region.
Scale indicators6 records
Recent moves6 records
Expansion highlights6 records
Panther competitors and assessment
Company assessmentDirect peers
- Securonix: Securonix is a next-generation SIEM built on a security data lake (Snowflake) with UEBA and AI-driven detection, making it a close architectural peer to Panther. Both companies use open data lakehouse backends, target enterprise SOCs migrating from legacy SIEMs, and emphasize AI-augmented threat detection.
- Elastic: Elastic Security is a direct SIEM/log analytics competitor that Panther targets among legacy incumbents. Both companies serve enterprise security operations with log search, detection rules, and analytics, and Panther's open SQL-queryable data lake is positioned against Elastic's proprietary indexed store.
- Exabeam: Exabeam is an AI-driven SIEM competitor that merged with LogRhythm, offering security analytics, automated investigations, and threat detection for enterprise SOCs. Both companies target legacy SIEM displacement with AI-augmented triage and detection engineering, and overlap in enterprise security operations buyers.
- Splunk: Splunk is the dominant legacy SIEM platform, now owned by Cisco, and Panther explicitly positions itself as a modern alternative for organizations migrating off Splunk. Both compete for enterprise security operations spend, ingest logs, and run detections, but Panther differentiates via a security data lake and detection-as-code rather than Splunk's proprietary SPL.
- Sumo Logic: Sumo Logic is a cloud-native SIEM and log analytics platform named by Panther as a primary displacement target at renewal. Both serve enterprise security operations with log ingestion at scale, detection rules, and analytics workflows, and both compete on cost-per-GB economics.
Emerging players
- Hunters Security: Hunters is an AI-driven SOC platform that ingests telemetry from multiple sources and applies AI for detection, triage, and investigation. Like Panther, it targets enterprise security teams seeking to replace legacy SIEMs with AI-augmented workflows and offers broad third-party integrations.
- Tines: Tines is a security automation and workflow orchestration platform used by SOCs for alert triage, enrichment, and response. It is adjacent rather than directly competitive with Panther's SIEM, but converges on the same AI-driven SOC automation buyer and increasingly overlaps with Panther's alert triage and runbook capabilities.
Broad incumbents
- CrowdStrike: CrowdStrike's Falcon platform includes LogScale SIEM and adjacent security modules and is cited by Databricks as a primary competitor in Panther's acquisition rationale. Both serve enterprise SOCs with endpoint, log, and AI-driven detection capabilities, and CrowdStrike's Charlotte AI overlaps with Panther's AI SOC agent.
- Microsoft Sentinel: Microsoft Sentinel is a cloud-native SIEM bundled into the Microsoft security and E5 ecosystem, competing for the same enterprise SOC budgets as Panther. Both ingest cloud and SaaS telemetry and offer AI-assisted detection, but Sentinel benefits from native Azure integration and Microsoft licensing bundles that Panther must displace.
Peers
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights6 records
Customer concentration
Panther social profiles
Digital presencePanther compliance and trust
Trust signalCompliance6 records
Panther financial estimates
Financial estimateRevenue estimate
Valuation estimate
Panther leadership team
Management profileNumber of profiles
Profiles5 records
Panther funding detail
Funding detailFunding overview
Funding rounds4 records
Investors10 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Panther M&A and investment
M&A and investmentM&A1 record
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Panther
What does Panther do?
Panther sells a Complete AI SOC Platform that operates as a modern SIEM on a security data lake, ingesting petabyte-scale logs from cloud, SaaS, identity, endpoint, and network sources into a normalized, SQL-queryable schema stored in customer-owned Snowflake or Databricks. It ships 300+ pre-built Python detections that are version-controlled in GitHub, an autonomous AI SOC Agent that investigates and auto-resolves alerts, AI-powered detection building from natural language, and a remote MCP server that exposes the platform to external AI agents.
Is Panther a public or private company?
Panther is a private company. It is classified as venture growth investor backed and is currently operating.
When was Panther founded?
Panther was founded in 2018. It employs 101 to 250 people.
Where is Panther based?
Panther is headquartered in San Francisco, United States, in the North America region.
How does Panther make money?
Three revenue lines are on record. SaaS Subscription (Platform + Ingestion + AI) is the primary driver. The others are managed Cloud (Hosted Deployment) and partner/Channel (MSSP/MDR).
Who are Panther's main competitors?
Direct peers on record are Securonix, Elastic, Exabeam, Splunk and Sumo Logic. Emerging players are Hunters Security and Tines. Broad incumbents are CrowdStrike and Microsoft Sentinel. Devo Technology is listed as a peer.
Does Panther have an API?
Yes. Panther provides a REST API and Terraform provider for managing AWS accounts, log sources, and cloud security scanning configurations. The API allows teams to programmatically manage the platform, including log source drop-off alarms, cloud account configurations, and detection workflows. Developer documentation is at docs.panther.com.
What industry is Panther in?
Panther's product category is Security Information and Event Management (SIEM) / AI SOC Platform. Its primary akta.pro industry code is HDAEANAA, End-to-End Enterprise AI Platforms (MLOps & Model Lifecycle Management), with a secondary code of HDAEANAH, Enterprise AI Data & Knowledge Platforms (Vector Databases, Knowledge Graphs). Its NAICS code is 513210 and its SIC code is 7372.