Developer docs
API playgroundTry for free, no card

Search company profiles

Panther

Full company profile

uuid00003qi

Namestring
Panther
Legal namestring
Panther Labs Inc.
Websiteurl
panther.com
Company typeenum
Private
Founded yearint
2018
Descriptiontext

Panther Labs Inc. is a San Francisco-based security operations company that sells a modern, AI-native SIEM platform to enterprise and mid-market security teams. The platform is built on a security data lake architecture that stores normalized telemetry in open, SQL-queryable formats inside the customer's own Snowflake or Databricks environment, eliminating vendor lock-in and the volume-based ingestion pricing that constrains legacy SIEMs. Its core product, the Complete AI SOC Platform, combines a Data Pipeline for petabyte-scale log ingestion, a Detection Engine in Python with version control and CI/CD, an AI SOC Agent that autonomously investigates alerts and auto-resolves benign ones, AI-powered alerting and triage automation, and analytics/reporting that maps detections to MITRE ATT&CK and generates audit evidence for SOC 2, PCI-DSS, ISO 27001, and HIPAA. The differentiator is a closed-loop architecture in which every triage outcome improves the underlying detection code via GitHub pull requests, so alert volume decreases over time rather than remaining static.

Panther operates a horizontal, enterprise-led go-to-market motion with direct field sales targeting organizations migrating from Splunk, Elastic, and Sumo Logic, complemented by MSSP/MDR channel partners (including Arctic Wolf and Cloocus for APAC) and a content-first demand generation engine spanning blog, webinars, podcasts, G2 reviews (4.7/5), and developer documentation. Pricing is quote-based and not publicly disclosed; the subscription model is decoupled from daily ingest volume, which the company positions as the primary cost advantage over incumbents (customers such as Cockroach Labs and Zapier publicly report $200K–$400K in annual savings while ingesting 3.5x–5x more data). Named customers include Docker, Zapier, Dropbox, Snyk, GitGuardian, Tealium, Cockroach Labs, Varo Bank, Spring Health, HealthEquity, LaunchDarkly, GoFundMe, Wolt, Benchling, JupiterOne, Cresta, and Infoblox.

The company was founded in 2018 and raised approximately $140.5M across four rounds, including a $120M Series B in December 2021 led by Coatue Management with Snowflake Ventures participation at a $1.4B unicorn valuation. In October 2025, Panther acquired Datable. In June 2026, Databricks announced an agreement to acquire Panther to establish the 'security lakehouse' category — Databricks' third cybersecurity acquisition following Antimatter and SiftD.ai — subject to customary closing conditions and regulatory clearances. As of the announcement, Panther continues to operate as a separate entity pending deal completion.

Short descriptiontext

Panther Labs is a San Francisco-based security operations company that sells an AI-native SIEM platform built on a security data lake architecture. It serves enterprise and mid-market security teams migrating from legacy SIEMs, using Python detection-as-code and autonomous AI agents for alert investigation.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
101–250
akta.pro rankint
HeadquartersSan Francisco, United States
HQ citystring
San Francisco
HQ countrystring
United States
HQ regionstring
North America
Markets served

Serves global market

Offices1 record

Each record includes

City, Country, Type, Description, Source

Keyword5 values
cloud-native SIEM, AI SOC platform, detection-as-code, security data lake, threat detection and response
Industry3 codes
1End-to-End Enterprise AI Platforms (MLOps & Model Lifecycle Management)
CodeHDAEANAAPrimaryYes
2Enterprise AI Data & Knowledge Platforms (Vector Databases, Knowledge Graphs)
CodeHDAEANAHPrimaryNo
3Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII)
CodeHDAEANAGPrimaryNo
NAICS code2 codes
  • Software Publishers513210
  • Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services518
SIC code2 codes
  • Services-Prepackaged Software7372
  • Services-Computer Integrated Systems Design7373
Product category
Security Information and Event Management (SIEM) / AI SOC Platform
GTM motion3 records

Each record includes

Type, Description, Source

Revenue model3 records
1SaaS Subscription (Platform + Ingestion + AI)
TypeSubscription Recurring
Description

Panther charges a subscription fee for platform access, log ingestion, and AI capabilities. Pricing is not publicly disclosed and is quote-based / negotiated per customer, consistent with enterprise SaaS go-to-market motion targeting organizations migrating from volume-priced legacy SIEMs.

panther.com
2Managed Cloud (Hosted Deployment)
TypeSubscription Recurring
Description

Panther offers a fully managed hosted deployment model where Panther operates the platform and ingests customer data into a dedicated, isolated environment, providing the fastest path to value when there is no internal data warehouse mandate or single-vendor operations requirement.

panther.com
3Partner/Channel (MSSP/MDR)
TypeSubscription Recurring
Description

Managed service providers and MDR partners deploy Panther on behalf of their customers, creating recurring subscription revenue through channel partnerships. Partners benefit from the open architecture to build differentiated managed security service offerings.

panther.com
Marketing channels10 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels3 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components5 values
Technology or R&D, Personnel, Marketing or Sales, Infrastructure, Operations
Pricing details1 tier
1Enterprise subscription with volume-based log ingestion and AI capabilities
ModelSubscriptionBilling cadenceAnnual
Notes

Pricing is quote-based and not publicly disclosed. The platform does not charge based on daily ingest volume like legacy SIEMs, eliminating tradeoffs between coverage breadth and budget.

panther.com
GTM typeB2B
B2B
Offering typeSoftware
Software
Core offering1 text field

Panther sells a Complete AI SOC Platform that operates as a modern SIEM on a security data lake, ingesting petabyte-scale logs from cloud, SaaS, identity, endpoint, and network sources into a normalized, SQL-queryable schema stored in customer-owned Snowflake or Databricks. It ships 300+ pre-built Python detections that are version-controlled in GitHub, an autonomous AI SOC Agent that investigates and auto-resolves alerts, AI-powered detection building from natural language, and a remote MCP server that exposes the platform to external AI agents.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 10 values shown
  • Up to 90% reduction in investigation time, with context and narrative assembled autonomously
+9 more records
Product overview1 text field

Panther is a unified AI SOC platform consisting of multiple integrated modules: Data Pipeline for log ingestion and normalization, AI SOC Agent for autonomous investigation and threat hunting, Detection Engine for detection-as-code with Python, Alerting and Triage Automation for AI-powered triage, and Analytics and Reporting for dashboards and compliance. The platform operates on a security data lake architecture where data stays in customer-owned Snowflake or Databricks instances. Solutions include AI SOC Transformation, Detection Engineering, Threat Hunting, Compliance Reporting, Managed Detection and Response, and Cloud Security Posture. Key differentiators include detection-as-code in Python, closed-loop detection improvement from triage outcomes, natural language interfaces, and MCP server for AI agent integration.

Product and service9 records
1Complete AI SOC Platform
CategorySIEM / AI SOC Platform
Description

Unified SaaS security operations platform combining SIEM capabilities with AI-powered autonomous agents for alert investigation, threat detection, and incident response, sold to enterprise security teams.

2Data Pipeline
CategoryData ingestion and normalization
Description

Security data ingestion and normalization layer that ingests logs at petabyte scale from cloud platforms, SaaS tools, endpoints, and network devices, with automatic schema normalization at ingestion for enterprise security teams.

3AI SOC Agent
CategoryAI security operations
Description

Autonomous AI agent that investigates alerts, runs scheduled threat hunts, responds to natural-language queries, and automatically improves detection logic through closed-loop triage feedback, for security operations teams.

4Detection Engine
CategoryDetection authoring and management
Description

Detection-as-code platform using Python with version control, CI/CD, and GitHub workflows, including AI Detection Builder for natural-language rule generation and closed-loop tuning, for detection engineering teams.

5Alerting and Triage Automation
CategoryAlert triage and automation
Description

AI-powered alert triage that autonomously investigates every alert with full context, provides definitive risk classification, and auto-resolves benign alerts with full audit trails, for security operations analysts.

6Analytics and Reporting
CategorySecurity analytics and compliance reporting
Description

Built-in SOC performance dashboards, MITRE ATT&CK coverage mapping, natural-language search, and compliance reporting for SOC 2, PCI-DSS, ISO 27001, and HIPAA, for security leadership and auditors.

7Cloud Security Posture
CategoryCloud security posture management
Description

Cloud security posture management offering with daily AWS scanning, policy-as-code, CSPM integrations (Wiz, Orca, Upwind), and correlation with log data, for cloud security teams.

8Managed Detection and Response (MSSP/MDR offering)
CategoryManaged security services
Description

Channel offering enabling MSSP/MDR partners to deliver enterprise SOC coverage with AI-powered investigation and dedicated customer instances, sold to managed security service providers.

9Compliance Reporting
CategoryCompliance reporting and audit
Description

Continuous compliance offering that generates audit evidence, maintains complete audit trails for AI decisions, and supports SOC 2, PCI-DSS, ISO 27001, and HIPAA frameworks, for compliance-focused security programs.

Scale indicator6 records

Each record includes

Type, Value, Description, Source

Partnership2 partners
Strategic tierFlagshipTypeStrategic or Co-development PartnerAnnounced on2026-06-16
Description

Databricks announced an agreement to acquire Panther in June 2026, subject to customary closing conditions and regulatory clearances. The acquisition aims to establish the 'security lakehouse' category and compete with CrowdStrike and Cisco's Splunk. Panther's 100+ pre-built integrations, detection-as-code capabilities, and agentic SOC workflows will be integrated into Databricks' data lakehouse architecture. This is Databricks' third cybersecurity acquisition following Antimatter and SiftD.ai. CEO Ali Ghodsi stated that traditional SIEM is obsolete and AI agents must counter AI-powered attackers.

Strategic tierRegionalTypeChannel Partner/ Reseller/ DistributorAnnounced on2026-05-27
Description

Cloocus, a South Korean cloud services company specializing in data and AI, signed a cooperation agreement with Panther on May 27, 2026 to provide South Korean enterprises with an AI-based SOC operations model for cloud security. The partnership combines Panther's integrated AI SOC platform with Cloocus's cloud and AI expertise to advance security operations in the APAC region.

Recent move6 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight6 records

Each record includes

Type, Description

Peers10 records
TypeDirect peer
Description

Securonix is a next-generation SIEM built on a security data lake (Snowflake) with UEBA and AI-driven detection, making it a close architectural peer to Panther. Both companies use open data lakehouse backends, target enterprise SOCs migrating from legacy SIEMs, and emphasize AI-augmented threat detection.

TypeEmerging player
Description

Hunters is an AI-driven SOC platform that ingests telemetry from multiple sources and applies AI for detection, triage, and investigation. Like Panther, it targets enterprise security teams seeking to replace legacy SIEMs with AI-augmented workflows and offers broad third-party integrations.

TypeBroad incumbent
Description

CrowdStrike's Falcon platform includes LogScale SIEM and adjacent security modules and is cited by Databricks as a primary competitor in Panther's acquisition rationale. Both serve enterprise SOCs with endpoint, log, and AI-driven detection capabilities, and CrowdStrike's Charlotte AI overlaps with Panther's AI SOC agent.

TypeDirect peer
Description

Elastic Security is a direct SIEM/log analytics competitor that Panther targets among legacy incumbents. Both companies serve enterprise security operations with log search, detection rules, and analytics, and Panther's open SQL-queryable data lake is positioned against Elastic's proprietary indexed store.

TypeDirect peer
Description

Exabeam is an AI-driven SIEM competitor that merged with LogRhythm, offering security analytics, automated investigations, and threat detection for enterprise SOCs. Both companies target legacy SIEM displacement with AI-augmented triage and detection engineering, and overlap in enterprise security operations buyers.

TypeDirect peer
Description

Splunk is the dominant legacy SIEM platform, now owned by Cisco, and Panther explicitly positions itself as a modern alternative for organizations migrating off Splunk. Both compete for enterprise security operations spend, ingest logs, and run detections, but Panther differentiates via a security data lake and detection-as-code rather than Splunk's proprietary SPL.

TypeEmerging player
Description

Tines is a security automation and workflow orchestration platform used by SOCs for alert triage, enrichment, and response. It is adjacent rather than directly competitive with Panther's SIEM, but converges on the same AI-driven SOC automation buyer and increasingly overlaps with Panther's alert triage and runbook capabilities.

TypeDirect peer
Description

Sumo Logic is a cloud-native SIEM and log analytics platform named by Panther as a primary displacement target at renewal. Both serve enterprise security operations with log ingestion at scale, detection rules, and analytics workflows, and both compete on cost-per-GB economics.

TypeBroad incumbent
Description

Microsoft Sentinel is a cloud-native SIEM bundled into the Microsoft security and E5 ecosystem, competing for the same enterprise SOC budgets as Panther. Both ingest cloud and SaaS telemetry and offer AI-assisted detection, but Sentinel benefits from native Azure integration and Microsoft licensing bundles that Panther must displace.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat5 records

Each record includes

Type, Details

Key risks6 records

Each record includes

Headline, Details, Source

Key highlights6 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers18 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment6 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile3 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
Yes

Docs URL, Description

Integration22 records

Each record includes

Title, Type, Description, Source

AI capability6 records

Each record includes

Type, Description, Source

AI maturity
App detail

Has app

Feature10 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles5 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

No data
Compliance6 records

Each record includes

Name, Class, Description

Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds4 records

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors10 records

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A1 record

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Panther

Security Information and Event Management (SIEM) / AI SOC Platformpanther.com

Panther Labs is a San Francisco-based security operations company that sells an AI-native SIEM platform built on a security data lake architecture. It serves enterprise and mid-market security teams migrating from legacy SIEMs, using Python detection-as-code and autonomous AI agents for alert investigation.

What Panther does

Panther Labs Inc. is a San Francisco-based security operations company that sells a modern, AI-native SIEM platform to enterprise and mid-market security teams. The platform is built on a security data lake architecture that stores normalized telemetry in open, SQL-queryable formats inside the customer's own Snowflake or Databricks environment, eliminating vendor lock-in and the volume-based ingestion pricing that constrains legacy SIEMs. Its core product, the Complete AI SOC Platform, combines a Data Pipeline for petabyte-scale log ingestion, a Detection Engine in Python with version control and CI/CD, an AI SOC Agent that autonomously investigates alerts and auto-resolves benign ones, AI-powered alerting and triage automation, and analytics/reporting that maps detections to MITRE ATT&CK and generates audit evidence for SOC 2, PCI-DSS, ISO 27001, and HIPAA. The differentiator is a closed-loop architecture in which every triage outcome improves the underlying detection code via GitHub pull requests, so alert volume decreases over time rather than remaining static.

Panther operates a horizontal, enterprise-led go-to-market motion with direct field sales targeting organizations migrating from Splunk, Elastic, and Sumo Logic, complemented by MSSP/MDR channel partners (including Arctic Wolf and Cloocus for APAC) and a content-first demand generation engine spanning blog, webinars, podcasts, G2 reviews (4.7/5), and developer documentation. Pricing is quote-based and not publicly disclosed; the subscription model is decoupled from daily ingest volume, which the company positions as the primary cost advantage over incumbents (customers such as Cockroach Labs and Zapier publicly report $200K–$400K in annual savings while ingesting 3.5x–5x more data). Named customers include Docker, Zapier, Dropbox, Snyk, GitGuardian, Tealium, Cockroach Labs, Varo Bank, Spring Health, HealthEquity, LaunchDarkly, GoFundMe, Wolt, Benchling, JupiterOne, Cresta, and Infoblox.

The company was founded in 2018 and raised approximately $140.5M across four rounds, including a $120M Series B in December 2021 led by Coatue Management with Snowflake Ventures participation at a $1.4B unicorn valuation. In October 2025, Panther acquired Datable. In June 2026, Databricks announced an agreement to acquire Panther to establish the 'security lakehouse' category — Databricks' third cybersecurity acquisition following Antimatter and SiftD.ai — subject to customary closing conditions and regulatory clearances. As of the announcement, Panther continues to operate as a separate entity pending deal completion.

Panther firmographics

Firmographics
Name
Panther
Legal name
Panther Labs Inc.
Website
https://panther.com
Company type
Private
Founded year
2018
Operating status
Operating
Headcount range
101–250 employees
Short description
Panther Labs is a San Francisco-based security operations company that sells an AI-native SIEM platform built on a security data lake architecture. It serves enterprise and mid-market security teams migrating from legacy SIEMs, using Python detection-as-code and autonomous AI agents for alert investigation.
Ownership category
akta.pro rank

Panther industry classification

Industry
Product category
Security Information and Event Management (SIEM) / AI SOC Platform
NAICS
Software Publishers (513210), Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (518)
SIC
Services-Prepackaged Software (7372), Services-Computer Integrated Systems Design (7373)
akta.pro primary industry
End-to-End Enterprise AI Platforms (MLOps & Model Lifecycle Management) (HDAEANAA)
akta.pro secondary industries
Enterprise AI Data & Knowledge Platforms (Vector Databases, Knowledge Graphs) (HDAEANAH), Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII) (HDAEANAG)

Keywords

  • Cloud-native SIEM
  • AI SOC platform
  • Detection-as-code
  • Security data lake
  • Threat detection and response

Where Panther is headquartered

Location

Headquarters

HQ city
San Francisco
HQ country
United States
HQ region
North America

Offices1 record

Markets served

Panther business model

Business model
GTM type
B2B
Offering type
Software
Cost components
Technology or R&D, Personnel, Marketing or Sales, Infrastructure, Operations

Revenue model

  1. SaaS Subscription (Platform + Ingestion + AI): Panther charges a subscription fee for platform access, log ingestion, and AI capabilities. Pricing is not publicly disclosed and is quote-based / negotiated per customer, consistent with enterprise SaaS go-to-market motion targeting organizations migrating from volume-priced legacy SIEMs.
  2. Managed Cloud (Hosted Deployment): Panther offers a fully managed hosted deployment model where Panther operates the platform and ingests customer data into a dedicated, isolated environment, providing the fastest path to value when there is no internal data warehouse mandate or single-vendor operations requirement.
  3. Partner/Channel (MSSP/MDR): Managed service providers and MDR partners deploy Panther on behalf of their customers, creating recurring subscription revenue through channel partnerships. Partners benefit from the open architecture to build differentiated managed security service offerings.

Pricing tiers

ModelBillingPrice
SubscriptionAnnualEnterprise subscription with volume-based log ingestion and AI capabilities

Go-to-market motion3 records

Distribution channels3 records

Marketing channels10 records

Panther product offering

Product offering

Core offering

Panther sells a Complete AI SOC Platform that operates as a modern SIEM on a security data lake, ingesting petabyte-scale logs from cloud, SaaS, identity, endpoint, and network sources into a normalized, SQL-queryable schema stored in customer-owned Snowflake or Databricks. It ships 300+ pre-built Python detections that are version-controlled in GitHub, an autonomous AI SOC Agent that investigates and auto-resolves alerts, AI-powered detection building from natural language, and a remote MCP server that exposes the platform to external AI agents.

Product overview

Panther is a unified AI SOC platform consisting of multiple integrated modules: Data Pipeline for log ingestion and normalization, AI SOC Agent for autonomous investigation and threat hunting, Detection Engine for detection-as-code with Python, Alerting and Triage Automation for AI-powered triage, and Analytics and Reporting for dashboards and compliance. The platform operates on a security data lake architecture where data stays in customer-owned Snowflake or Databricks instances. Solutions include AI SOC Transformation, Detection Engineering, Threat Hunting, Compliance Reporting, Managed Detection and Response, and Cloud Security Posture. Key differentiators include detection-as-code in Python, closed-loop detection improvement from triage outcomes, natural language interfaces, and MCP server for AI agent integration.

Differentiator

Problem solved

Functional benefit

Products and services

  • Complete AI SOC Platform Unified SaaS security operations platform combining SIEM capabilities with AI-powered autonomous agents for alert investigation, threat detection, and incident response, sold to enterprise security teams.
  • Data Pipeline Security data ingestion and normalization layer that ingests logs at petabyte scale from cloud platforms, SaaS tools, endpoints, and network devices, with automatic schema normalization at ingestion for enterprise security teams.
  • AI SOC Agent Autonomous AI agent that investigates alerts, runs scheduled threat hunts, responds to natural-language queries, and automatically improves detection logic through closed-loop triage feedback, for security operations teams.
  • Detection Engine Detection-as-code platform using Python with version control, CI/CD, and GitHub workflows, including AI Detection Builder for natural-language rule generation and closed-loop tuning, for detection engineering teams.
  • Alerting and Triage Automation AI-powered alert triage that autonomously investigates every alert with full context, provides definitive risk classification, and auto-resolves benign alerts with full audit trails, for security operations analysts.
  • Analytics and Reporting Built-in SOC performance dashboards, MITRE ATT&CK coverage mapping, natural-language search, and compliance reporting for SOC 2, PCI-DSS, ISO 27001, and HIPAA, for security leadership and auditors.
  • Cloud Security Posture Cloud security posture management offering with daily AWS scanning, policy-as-code, CSPM integrations (Wiz, Orca, Upwind), and correlation with log data, for cloud security teams.
  • Managed Detection and Response (MSSP/MDR offering) Channel offering enabling MSSP/MDR partners to deliver enterprise SOC coverage with AI-powered investigation and dedicated customer instances, sold to managed security service providers.
  • Compliance Reporting Continuous compliance offering that generates audit evidence, maintains complete audit trails for AI decisions, and supports SOC 2, PCI-DSS, ISO 27001, and HIPAA frameworks, for compliance-focused security programs.

Quantifiable outcome

  • Up to 90% reduction in investigation time, with context and narrative assembled autonomously
  • +9 more outcomes

Companies that use Panther

Customer profile

Named customers18 records

Segments6 records

Ideal customer profiles3 records

Panther technology and API

Technology

Technology focussed Yes

API detail

Has API
Yes
API docs
API detail

Core technology

AI maturity

App detail

Integration22 records

AI capability6 records

Feature10 records

Panther partnerships and signals

Strategic signal

Partnerships

Two partnerships are on record, tiered flagship and regional.

  • DatabricksflagshipStrategic or Co-development Partner · 16 June 2026Databricks announced an agreement to acquire Panther in June 2026, subject to customary closing conditions and regulatory clearances. The acquisition aims to establish the 'security lakehouse' category and compete with CrowdStrike and Cisco's Splunk. Panther's 100+ pre-built integrations, detection-as-code capabilities, and agentic SOC workflows will be integrated into Databricks' data lakehouse architecture. This is Databricks' third cybersecurity acquisition following Antimatter and SiftD.ai. CEO Ali Ghodsi stated that traditional SIEM is obsolete and AI agents must counter AI-powered attackers.
  • CloocusregionalChannel Partner/ Reseller/ Distributor · 27 May 2026Cloocus, a South Korean cloud services company specializing in data and AI, signed a cooperation agreement with Panther on May 27, 2026 to provide South Korean enterprises with an AI-based SOC operations model for cloud security. The partnership combines Panther's integrated AI SOC platform with Cloocus's cloud and AI expertise to advance security operations in the APAC region.

Scale indicators6 records

Recent moves6 records

Expansion highlights6 records

Panther competitors and assessment

Company assessment

Direct peers

  • Securonix: Securonix is a next-generation SIEM built on a security data lake (Snowflake) with UEBA and AI-driven detection, making it a close architectural peer to Panther. Both companies use open data lakehouse backends, target enterprise SOCs migrating from legacy SIEMs, and emphasize AI-augmented threat detection.
  • Elastic: Elastic Security is a direct SIEM/log analytics competitor that Panther targets among legacy incumbents. Both companies serve enterprise security operations with log search, detection rules, and analytics, and Panther's open SQL-queryable data lake is positioned against Elastic's proprietary indexed store.
  • Exabeam: Exabeam is an AI-driven SIEM competitor that merged with LogRhythm, offering security analytics, automated investigations, and threat detection for enterprise SOCs. Both companies target legacy SIEM displacement with AI-augmented triage and detection engineering, and overlap in enterprise security operations buyers.
  • Splunk: Splunk is the dominant legacy SIEM platform, now owned by Cisco, and Panther explicitly positions itself as a modern alternative for organizations migrating off Splunk. Both compete for enterprise security operations spend, ingest logs, and run detections, but Panther differentiates via a security data lake and detection-as-code rather than Splunk's proprietary SPL.
  • Sumo Logic: Sumo Logic is a cloud-native SIEM and log analytics platform named by Panther as a primary displacement target at renewal. Both serve enterprise security operations with log ingestion at scale, detection rules, and analytics workflows, and both compete on cost-per-GB economics.

Emerging players

  • Hunters Security: Hunters is an AI-driven SOC platform that ingests telemetry from multiple sources and applies AI for detection, triage, and investigation. Like Panther, it targets enterprise security teams seeking to replace legacy SIEMs with AI-augmented workflows and offers broad third-party integrations.
  • Tines: Tines is a security automation and workflow orchestration platform used by SOCs for alert triage, enrichment, and response. It is adjacent rather than directly competitive with Panther's SIEM, but converges on the same AI-driven SOC automation buyer and increasingly overlaps with Panther's alert triage and runbook capabilities.

Broad incumbents

  • CrowdStrike: CrowdStrike's Falcon platform includes LogScale SIEM and adjacent security modules and is cited by Databricks as a primary competitor in Panther's acquisition rationale. Both serve enterprise SOCs with endpoint, log, and AI-driven detection capabilities, and CrowdStrike's Charlotte AI overlaps with Panther's AI SOC agent.
  • Microsoft Sentinel: Microsoft Sentinel is a cloud-native SIEM bundled into the Microsoft security and E5 ecosystem, competing for the same enterprise SOC budgets as Panther. Both ingest cloud and SaaS telemetry and offer AI-assisted detection, but Sentinel benefits from native Azure integration and Microsoft licensing bundles that Panther must displace.

Peers

Market position

Strengths5 records

Weaknesses5 records

Competitive moat5 records

Key risks6 records

Key highlights6 records

Customer concentration

Panther social profiles

Digital presence

Panther compliance and trust

Trust signal

Compliance6 records

Panther financial estimates

Financial estimate

Revenue estimate

Valuation estimate

Panther leadership team

Management profile

Number of profiles

Profiles5 records

Panther funding detail

Funding detail

Funding overview

Funding rounds4 records

Investors10 records

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

Panther M&A and investment

M&A and investment

M&A1 record

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about Panther

What does Panther do?

Panther sells a Complete AI SOC Platform that operates as a modern SIEM on a security data lake, ingesting petabyte-scale logs from cloud, SaaS, identity, endpoint, and network sources into a normalized, SQL-queryable schema stored in customer-owned Snowflake or Databricks. It ships 300+ pre-built Python detections that are version-controlled in GitHub, an autonomous AI SOC Agent that investigates and auto-resolves alerts, AI-powered detection building from natural language, and a remote MCP server that exposes the platform to external AI agents.

Is Panther a public or private company?

Panther is a private company. It is classified as venture growth investor backed and is currently operating.

When was Panther founded?

Panther was founded in 2018. It employs 101 to 250 people.

Where is Panther based?

Panther is headquartered in San Francisco, United States, in the North America region.

How does Panther make money?

Three revenue lines are on record. SaaS Subscription (Platform + Ingestion + AI) is the primary driver. The others are managed Cloud (Hosted Deployment) and partner/Channel (MSSP/MDR).

Who are Panther's main competitors?

Direct peers on record are Securonix, Elastic, Exabeam, Splunk and Sumo Logic. Emerging players are Hunters Security and Tines. Broad incumbents are CrowdStrike and Microsoft Sentinel. Devo Technology is listed as a peer.

Does Panther have an API?

Yes. Panther provides a REST API and Terraform provider for managing AWS accounts, log sources, and cloud security scanning configurations. The API allows teams to programmatically manage the platform, including log source drop-off alarms, cloud account configurations, and detection workflows. Developer documentation is at docs.panther.com.

What industry is Panther in?

Panther's product category is Security Information and Event Management (SIEM) / AI SOC Platform. Its primary akta.pro industry code is HDAEANAA, End-to-End Enterprise AI Platforms (MLOps & Model Lifecycle Management), with a secondary code of HDAEANAH, Enterprise AI Data & Knowledge Platforms (Vector Databases, Knowledge Graphs). Its NAICS code is 513210 and its SIC code is 7372.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
VerdictDatabricks lands $5bn funding, valuation climbs to $190bnDatabricks closed a $5bn strategic funding round at a $190bn valuation, led by Coatue, and reported passing a $7bn revenue run-rate in Q2. Its Lakehouse product exceeded a $1.5bn run-rate, and proceeds will fund Lakebase, Genie, and Unity AI Gateway. The company also extended its partnership with Microsoft into the 2030s.BenzingaQUICK SPARK: Databricks Finalizes Panther Acquisition to Bolster AI Cybersecurity PushDatabricks has finalized its acquisition of Panther, an AI-powered security operations platform, to strengthen its cybersecurity offerings. The deal combines Panther's security operations center workflows, detection engine, and automation capabilities with Databricks' security lakehouse platform, addressing challenges facing traditional SIEM systems including rising data costs and fragmented tools. Databricks envisions an "agentic" security operations model where AI systems help teams identify threats, investigate incidents, and improve detection in real time.StartupHub.aiDatabricks Buys PantherDatabricks has officially completed its acquisition of Panther, an AI-powered Security Operations Center (SOC) platform, to merge its capabilities with Databricks' security lakehouse architecture. This strategic move aims to enhance threat detection and data retention by combining Panther's SOC workflows with Databricks' Lakewatch foundation, addressing the limitations of legacy SIEM systems. The integration positions Databricks to compete more effectively in the evolving cybersecurity market against rivals like Snowflake and Palantir.DatabricksDatabricks Completes Acquisition of Panther: Accelerating the Security Lakehouse EraDatabricks has officially completed its acquisition of Panther, an AI SOC platform, integrating Panther's mature security operations workflows and detection engine with Databricks' Lakewatch open security lakehouse foundation. The combined platform enables security teams to retain petabyte-scale telemetry in open formats, deploy autonomous AI agents for real-time alert triage, and execute detections-as-code through CI/CD pipelines. Databricks expects the acquisition to accelerate its security lakehouse vision by providing over 100 out-of-the-box integrations across major cloud providers, identity systems, and SaaS applications.BiggoDatabricks Acquires AI Security Platform Panther to Reshape SIEM Around AI Agents — BigGo FinanceDatabricks is acquiring Panther, an AI-native security operations platform, as part of its strategy to reshape the traditional SIEM (Security Information and Event Management) ecosystem around AI agents. Databricks plans to combine Panther with its Lakewatch security lakehouse platform to automate core SOC workflows including alert triage, context gathering, and response recommendations, significantly reducing the response burden on security teams. This marks Databricks' third security acquisition following Antimatter and SiftD.ai, signaling a broader expansion from data analytics into cybersecurity as enterprises face increasingly sophisticated AI-powered threats.DigitaltodayAI-focused M&A gains pace as big cloud firms step up security expansionDatabricks is acquiring Panther Labs, an AI-based cyberattack detection platform, marking its third cybersecurity acquisition this year following purchases of Antimatter and SiftD, as AI-focused M&A activity intensifies in the security industry. SailPoint Technologies is also acquiring AI agent security startup Entro Security, while major cloud providers AWS and Google Cloud are expanding their AI security offerings with new platforms. The roundup also covers a large-scale breach of Fortinet firewalls exploiting leaked passwords, and South Korean government initiatives supporting adoption of the national network security framework.Pulse 2.0Databricks To Acquire Panther To Expand Security Lakehouse PlatformDatabricks announced it has agreed to acquire Panther, an AI SOC platform that helps security teams unify data sources, detect threats, and investigate alerts using agentic workflows, in a deal designed to advance Databricks' security lakehouse strategy. The combined offering is expected to embed AI agents directly into security operations center workflows, automate alert triage, and improve detection and response capabilities across cloud, SaaS, and AI systems. The proposed acquisition remains subject to customary closing conditions, including required regulatory clearances.Analytics InsightBest AI-Powered SOC Providers for Cybersecurity in 2026AI-powered Security Operations Center (SOC) platforms are rapidly replacing traditional cybersecurity approaches in 2026, with global spending expected to exceed $300 billion as enterprises seek faster threat detection and automated response capabilities. The article profiles leading providers including CrowdStrike, Palo Alto Networks, Microsoft, Google, SentinelOne, and Arctic Wolf, detailing their AI-driven platforms and market positioning. Notable industry developments include SoftBank's launch of an AI cybersecurity product developed with OpenAI, and Databricks' acquisition of Panther Labs to enhance its security offerings.DigitaltodayDatabricks to acquire attack-detection platform Panther LabsDatabricks announced on June 16 that it will acquire Panther Labs, a startup offering an AI-based cyberattack detection platform, with the deal value remaining undisclosed. Panther's technology filters and organizes system log data to identify threats and can generate natural-language descriptions of vulnerabilities, which Databricks plans to integrate with its Lakewatch cybersecurity product launched in March. This acquisition marks Databricks' third cybersecurity startup purchase this year, following its acquisitions of Antimatter and SiftD.ItnewsDatabricks strikes deal to buy Panther LabsDatabricks has agreed to acquire cybersecurity startup Panther Labs, marking the data analytics software provider's third acquisition in the security space as it seeks to compete with established players like CrowdStrike and Cisco's Splunk. Panther Labs, valued at US$1.4 billion after raising US$120 million in Series B funding in 2021, offers a unified security data platform that enables AI agents to respond to emerging threats in the AI era. Databricks CEO Ali Ghodsi argued that traditional security information and alert management is outdated, stating that organizations must now use AI agents to defend against AI-powered attacks.