Deepwatch
Deepwatch is a private cybersecurity company that delivers AI-native Managed Detection and Response (MDR) services through its Guardian MDR Platform and NEXA Agentic AI Ecosystem, sold 100% via channel partners to enterprise customers across financial services, healthcare, technology, and other verticals.
- Company typePrivate
- Founded2019
- HeadquartersTampa, United States
- Headcount101–250
- GTM typeB2B
- OfferingServices
What Deepwatch does
Deepwatch is a private, venture-backed cybersecurity company founded in 2019 and headquartered in Palo Alto, California, with additional offices in Tampa, Florida and a Global Capability Center in Bengaluru, India. The company delivers an AI-native Managed Detection and Response (MDR) platform that combines automated threat detection, investigation, and response with 24/7/365 human expert governance. Its core offering is the Deepwatch Guardian MDR Platform, powered by the NEXA Agentic AI Ecosystem, which comprises six coordinated AI agents (CTEM, Detection Advisor, Ticket Analyzer, Investigative, Narrative, Response) that collaborate with named security analysts. The platform is SIEM-agnostic, supporting more than 800 telemetry sources and integrating natively with Splunk, Google SecOps, Microsoft Sentinel, Securonix, CrowdStrike Next-Gen SIEM, Palo Alto, and others, allowing customers to retain their existing security investments without rip-and-replace deployments.
Deepwatch monetizes primarily through annual subscription-based managed services (MDR, Managed EDR, Vulnerability Management, Managed Firewall) augmented by add-on modules including Active Response, Continuous Threat Exposure Management (CTEM), and Dark Web Monitoring and Response. Pricing is quote-based and tailored to customer environment complexity. The company operates a 100% channel-driven go-to-market model, selling exclusively through resellers, distributors, and solution providers, supplemented by co-sell motions with technology partners such as AWS, Splunk, Google Cloud, and CrowdStrike. Its customer base spans financial services, healthcare, technology, telecom/REIT, and industrial distribution verticals, with named enterprise logos including City National Bank of Florida, Informatica, Xactly, SBA Communications, Fulton Bank, AARP, Benjamin Moore, and Premise Health.
As of 2026, Deepwatch has raised approximately $256M across three funding rounds led primarily by Goldman Sachs, with the most recent $180M round in February 2023 led by Springcoast Capital Partners, Splunk Ventures, and Vista Credit Partners. The company made one acquisition (Dassana, February 2025) to strengthen its CTEM and AI capabilities. In May 2026, Brian Dhatt was appointed CEO succeeding John DiLullo, while Anand Ramanathan was promoted to President. The company underwent a workforce reduction of approximately 60-80 employees in November 2025 to accelerate AI investment, and achieved ISO/IEC 42001:2023 certification for NEXA in May 2026.
Deepwatch firmographics
Firmographics- Name
- Deepwatch
- Legal name
- Deepwatch, Inc.
- Website
- https://deepwatch.com
- Company type
- Private
- Founded year
- 2019
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Short description
- Deepwatch is a private cybersecurity company that delivers AI-native Managed Detection and Response (MDR) services through its Guardian MDR Platform and NEXA Agentic AI Ecosystem, sold 100% via channel partners to enterprise customers across financial services, healthcare, technology, and other verticals.
- Ownership category
- akta.pro rank
Deepwatch industry classification
Industry- Product category
- Managed Detection and Response Services
- NAICS
- Security Systems Services (except Locksmiths) (561621), Computer Systems Design and Related Services (54151)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370), Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Managed Detection & Response (MDR) (BPAEADAA)
- akta.pro secondary industries
- Endpoint Security Managed Services (EDR/XDR) (BPAEADAH), Attack Surface Management (EASM/CAASM) (HDADAHAC)
Keywords
Where Deepwatch is headquartered
LocationHeadquarters
- HQ city
- Tampa
- HQ country
- United States
- HQ region
- North America
Offices4 records
Markets served
Deepwatch business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Infrastructure, Marketing or Sales, Operations
Revenue model
- Managed Detection and Response (MDR) Services: Core subscription-based managed security services providing 24/7/365 monitoring, threat detection, investigation, and response. Delivered as a platform combining AI automation with human expert governance. Services include MDR, Managed EDR, Vulnerability Management, Managed Firewall, Dark Web Monitoring, and CTEM.
- Active Response Add-on: Precision containment capabilities across identities and endpoints, offered as an add-on to core MDR services. Includes automated response actions governed by customer-defined intent matrices and human analyst oversight.
- Continuous Threat Exposure Management (CTEM): Add-on service that transforms organizations from reactive to preemptive security posture by prioritizing vulnerabilities, streamlining compliance, and accelerating threat detection. Two-way integration with core MDR platform.
- Dark Web Monitoring and Response (DWMR): Add-on service delivering actionable visibility into cybercriminal activity across open, deep, and dark web, including private forums and encrypted messaging apps. Enhanced with takedown services.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise MDR with full platform capabilities |
| Subscription | Annual | Add-on modules for specialized capabilities |
Go-to-market motion3 records
Distribution channels3 records
Marketing channels10 records
Deepwatch product offering
Product offeringCore offering
Deepwatch is an AI-native Managed Detection and Response (MDR) cybersecurity company that delivers 24/7/365 threat detection, investigation, and response by combining AI-driven automation with human expert governance. Its flagship Deepwatch Guardian MDR Platform integrates with customers' existing security tools (Splunk, Google SecOps, Microsoft Sentinel, Securonix, CrowdStrike) and is augmented by a suite of add-on modules including Continuous Threat Exposure Management (CTEM), Active Response, Dark Web Monitoring and Response, Managed Endpoint Detection and Response, Vulnerability Management, and Managed Firewall services.
Product overview
Deepwatch offers a platform-plus-modules architecture built around its AI-native Deepwatch Guardian MDR Platform. The core platform combines technology, people, and processes for 24/7/365 managed detection and response governed by expert human oversight. The platform integrates with customers' existing security tools (SIEMs, EDR, cloud, identity, network) through specialized MDR modules for Splunk, Google SecOps, Microsoft Sentinel, Securonix, and CrowdStrike Next-Gen SIEM. Add-on modules include Active Response (automated containment), CTEM (continuous threat exposure management), Dark Web Monitoring and Response, Managed Endpoint Detection and Response, Vulnerability Management, and Managed Firewall services. The offering is powered by the NEXA Agentic AI Ecosystem, Deepwatch's proprietary collaborative AI platform featuring six autonomous agents for investigation, detection, response, and narrative generation. Supporting services include the Security Center dashboard interface and Adversary Tactics and Intelligence (ATI) threat hunting unit. Deepwatch operates as a 100% channel-driven company, selling exclusively through technology and reseller partners.
Differentiator
Problem solved
Functional benefit
Brands
- Deepwatch Guardian MDR Platform™: The company's core managed detection and response platform providing AI-native security operations
- Deepwatch NEXA™ Agentic AI Ecosystem
- Deepwatch CTEM (Continuous Threat Exposure Management)
- Deepwatch Dark Web Monitoring and Response (DWMR)
Products and services
- Deepwatch Guardian MDR Platform AI-native managed detection and response platform combining technology, people, and processes to provide 24/7/365 expert-led threat detection, investigation, and response across customer environments. Connects industry-leading security tools with Deepwatch's security teams and ticketing systems through the Security Center interface.
- NEXA Agentic AI Ecosystem The MDR industry's first collaborative AI agentic ecosystem featuring six intelligent agents (CTEM Agent, Detection Advisor Agent, Ticket Analyzer Agent, Investigative Agent, Narrative Agent, Response Agent) that work with humans to deliver real-time security insight and action. Powers the Deepwatch Guardian MDR Platform with generative AI, data unification, and human expertise.
- MDR for Splunk Managed Detection and Response service specifically designed for Splunk environments. Connects directly to customer's Splunk instance (on-premises or cloud) with 24/7/365 monitoring, curated detection engineering, proactive threat hunting, and Dynamic Risk Scoring integration native to Splunk dashboards.
- MDR for Google SecOps Joint MDR solution combining Deepwatch's Precision MDR with Google Security Operations (SecOps) platform for end-to-end visibility, AI-powered automation, and expert analysis across cloud, hybrid, and on-premises environments. Leverages Google's SIEM, SOAR, and threat intelligence including Mandiant and VirusTotal.
- MDR for Microsoft Sentinel Managed Detection and Response integration with Microsoft Sentinel providing bi-directional data flow, expert triage and guided remediation, custom detection rules, and SOAR playbook integration for automated incident response. Integrates with Microsoft 365 Defender, Azure AD, and endpoints.
- MDR for Securonix Managed Detection and Response service operationalizing Securonix Unified Defense SIEM with continuous monitoring, AI-enhanced investigations, structured triage workflows, and expert-led response. Enables Securonix customers to bypass 6-12 months of SIEM tuning.
- MDR for CrowdStrike Next-Gen SIEM Managed Detection and Response service turning CrowdStrike Next-Gen SIEM detections into action with 24/7 expert monitoring, AI-driven investigations, alert enrichment, normalization, and consistent case management through ServiceNow or Deepwatch Security Center.
- Active Response Precision containment capability across identities and endpoints delivered as part of the Guardian MDR Platform. Provides automated response actions based on customer-defined Response Intent Matrix with options for monitor-only, analyst-approved, or autonomous execution modes for Identity (session revocation, password reset) and Endpoint (process kill, host isolation) responses.
- Continuous Threat Exposure Management (CTEM) Preemptive cybersecurity and unified threat response capability that transforms organizations from reactive to proactive security posture by prioritizing vulnerabilities, quantifying enterprise risks, and prioritizing threats based on business impact. Integrates bidirectionally with the Guardian MDR Platform for continuous risk metric updates.
- Dark Web Monitoring and Response Actionable visibility into cybercriminal activity across open, deep, and dark web including private forums and encrypted messaging apps. Detects leaked credentials, stolen data, and threat actor chatter with optional takedown services for swift removal of harmful or unauthorized content.
- Managed Endpoint Detection and Response (MEDR) Next-generation endpoint protection service providing coordinated investigation and response workflows for endpoint threats. Includes sub-minute machine-speed response, comprehensive endpoint reaction capabilities, and correlation with enterprise telemetry for holistic security perspective.
- Vulnerability Management Fully-managed end-to-end vulnerability management program including asset identification, risk-based remediation prioritization, configuration baseline assessments, continuous scanning, zero-day alerting, vulnerability hunting, and remediation verification and planning.
- Managed Firewall Collaborative firewall management service providing 24/7/365 monitoring and management from U.S.-based security experts. Includes governance review, device monitoring, configuration updates, rule set changes, and connectivity troubleshooting with the patented Deepwatch Security Index methodology.
Quantifiable outcome
- 98% reduction in low and medium severity alerts
- +7 more outcomes
Companies that use Deepwatch
Customer profileNamed customers10 records
Segments5 records
Ideal customer profiles4 records
Deepwatch technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration23 records
AI capability9 records
Feature7 records
Deepwatch partnerships and signals
Strategic signalPartnerships
17 partnerships are on record, tiered core and minor.
- Google Cloud / Google SecOpscoreDeepwatch MDR integrates with Google Security Operations platform providing end-to-end visibility, AI-powered automation, and expert analysis across all environments. Deepwatch joined Google Cloud Managed Security Services Provider Initiative in July 2025.
- SecuronixcoreDeepwatch expanded its SIEM-agnostic Guardian MDR Platform to include native support for Securonix Unified Defense SIEM. Integration enables Securonix customers to bypass 6-12 months of SIEM tuning with immediate access to Deepwatch detection platform, automated alert investigations, and AI-enhanced threat analysis.
- Microsoft (Azure, Microsoft Sentinel, Microsoft Defender, Microsoft Entra)coreDeepwatch Guardian MDR Platform integrates with Microsoft security ecosystem including Microsoft Sentinel (SIEM), Microsoft Defender (endpoint), and Microsoft Entra (identity). Bi-directional integration enriches Microsoft security capabilities with 24/7 Deepwatch monitoring and response.
- SplunkcoreDeepwatch MDR for Splunk provides 24/7/365 monitoring using Splunk Enterprise and Cloud. Deepwatch is a Splunk Authorized Reseller and received Splunk's AMER Marketing Partner of the Year award in 2023. Also received Splunk Partner Award for AMER Marketing Partner of the Year.
- CrowdStrikecoreStrategic partnership announced May 2024 to transform traditional managed security operations with the CrowdStrike Falcon Platform. Deepwatch operationalizes CrowdStrike Next-Gen SIEM detections with 24/7 expert monitoring, AI-driven investigations, and faster response.
- AWScoreDeepwatch achieved AWS Level 1 MSSP Competency status and Modern Compute Specialization distinction. Listed in AWS Marketplace. Announced AWS Built-In Solution in June 2023. Named AWS Partner of the Year Finalist (Rising Star ISV Partners).
- Trace3coreChannel partner delivering Managed Detection and Response service powered by Deepwatch. Strategic partnership for enterprise customer acquisition.
- ePluscoreChannel partner delivering security solutions with enhanced managed detection and response powered by Deepwatch. Partnership announced November 2022.
- Palo Alto Networks (Cortex XDR, Prisma Cloud)coreDeepwatch integrates with Palo Alto Networks ecosystem including Cortex XDR for endpoint and Prisma Cloud for cloud security, supporting comprehensive security operations.
- TenablecoreTechnology partner providing vulnerability management capabilities integrated with Deepwatch MDR platform for comprehensive security coverage.
- ServiceNowcoreIntegration partner for case management. Deepwatch cases are routed through ServiceNow providing real-time visibility, reporting, and documented response workflows.
- SentinelOnecoreEndpoint security partner integrated with Deepwatch MDR for comprehensive endpoint detection and response.
- QualyscoreVulnerability assessment partner providing scanning capabilities integrated with Deepwatch vulnerability management services.
- CybereasonminorStrategic partnership to help enterprises stop advanced cyber attacks, combining Deepwatch MDR with Cybereason's endpoint protection.
- TevoraminorConsulting partner driving growth and advanced cybersecurity services. Partnership announced March 2020.
- Red8minorPartnership to drive secure and responsible customer transition to the cloud. Announced September 2020.
- DassanacoreDeepwatch acquired Dassana in February 2025 to integrate AI-powered risk and threat management technology into its cybersecurity platform. Leverages Dassana's expertise in AI-driven security data processing to empower security leaders with real-time posture insights.
Scale indicators15 records
Recent moves8 records
Expansion highlights6 records
Deepwatch competitors and assessment
Company assessmentDirect peers
- Arctic Wolf: Arctic Wolf is one of the largest pure-play MDR providers offering 24/7 monitoring, managed detection and response, and security operations solutions to mid-market and enterprise customers. They compete directly with Deepwatch on the channel-driven, AI-augmented MDR delivery model.
- Rapid7: Rapid7 offers MDR services alongside its SIEM and vulnerability management platform (InsightIDR/InsightConnect), serving mid-market and enterprise customers. Competes with Deepwatch as both a SIEM-agnostic MDR provider and integrated security analytics platform.
- eSentire: eSentire is a pure-play MDR specialist providing 24/7 threat detection, investigation, and response services to mid-market organizations across financial services, healthcare, and technology. Directly competes with Deepwatch on the MDR-as-primary-service positioning.
- Expel: Expel provides MDR and cloud detection and response services with a transparent, SaaS-based delivery model targeting mid-market and enterprise customers. Direct competitor to Deepwatch's transparency-focused, AI-augmented MDR offering.
- Sophos (Secureworks): Sophos acquired Secureworks in 2025 to combine its MDR services (Secureworks Taegis) with Sophos endpoint and network security products. Competes directly with Deepwatch on enterprise MDR and brings bundled platform economics.
- ReliaQuest: ReliaQuest provides enterprise-grade MDR and security operations through its GreyMatter platform, focusing on large enterprises and Fortune 500 customers. Directly competes with Deepwatch for enterprise MDR contracts with a similar SIEM-agnostic, platform-plus-services approach.
Broad incumbents
- CrowdStrike (Falcon Complete): CrowdStrike's Falcon Complete is a fully managed MDR service built on its Falcon endpoint and Next-Gen SIEM platform. While Deepwatch partners with CrowdStrike, Falcon Complete is also a direct competitor offering bundled MDR to enterprises globally.
- Palo Alto Networks (Unit 42 MDR): Palo Alto Networks offers Unit 42 MDR services alongside Cortex XDR and Prisma Cloud. Competes with Deepwatch as a broad platform incumbent with integrated MDR capabilities across endpoint, network, and cloud.
- Microsoft Defender Experts for Hunting: Microsoft's Defender Experts and Security Copilot-powered managed services compete with Deepwatch for Microsoft Sentinel and Defender customers. While Deepwatch integrates with Sentinel, Microsoft is also building competing in-house MDR capabilities.
- SentinelOne (Watchtower): SentinelOne's Watchtower MDR services leverage the Singularity XDR platform to provide managed detection and response. Both a technology integration partner and a competitive incumbent with bundled platform economics.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks5 records
Customer concentration
Deepwatch social profiles
Digital presenceDeepwatch compliance and trust
Trust signalCompliance5 records
Deepwatch financial estimates
Financial estimateRevenue estimate
Valuation estimate
Deepwatch leadership team
Management profileNumber of profiles
Profiles13 records
Deepwatch subsidiaries and ownership
Company hierarchySubsidiaries1 record
Deepwatch funding detail
Funding detailFunding overview
Funding rounds3 records
Investors7 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Deepwatch M&A and investment
M&A and investmentM&A1 record
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Deepwatch
What does Deepwatch do?
Deepwatch is an AI-native Managed Detection and Response (MDR) cybersecurity company that delivers 24/7/365 threat detection, investigation, and response by combining AI-driven automation with human expert governance. Its flagship Deepwatch Guardian MDR Platform integrates with customers' existing security tools (Splunk, Google SecOps, Microsoft Sentinel, Securonix, CrowdStrike) and is augmented by a suite of add-on modules including Continuous Threat Exposure Management (CTEM), Active Response, Dark Web Monitoring and Response, Managed Endpoint Detection and Response, Vulnerability Management, and Managed Firewall services.
Is Deepwatch a public or private company?
Deepwatch is a private company. It is classified as venture growth investor backed and is currently operating.
When was Deepwatch founded?
Deepwatch was founded in 2019. It employs 101 to 250 people.
Where is Deepwatch based?
Deepwatch is headquartered in Tampa, United States, in the North America region.
How does Deepwatch make money?
Four revenue lines are on record. Managed Detection and Response (MDR) Services are the primary driver. The others are active Response Add-on, continuous Threat Exposure Management (CTEM) and dark Web Monitoring and Response (DWMR).
Who are Deepwatch's main competitors?
Direct peers on record are Arctic Wolf, Rapid7, eSentire, Expel, Sophos (Secureworks) and ReliaQuest. Broad incumbents are CrowdStrike (Falcon Complete), Palo Alto Networks (Unit 42 MDR), Microsoft Defender Experts for Hunting and SentinelOne (Watchtower).
Does Deepwatch have an API?
No public API is recorded for Deepwatch.
What industry is Deepwatch in?
Deepwatch's product category is Managed Detection and Response Services. Its primary akta.pro industry code is BPAEADAA, Managed Detection & Response (MDR), with a secondary code of BPAEADAH, Endpoint Security Managed Services (EDR/XDR). Its NAICS code is 561621 and its SIC code is 7370.