Sekoia.io
Sekoia.io is a French cybersecurity company that provides an agentic AI SOC platform combining SIEM, CTI, CAASM, and AI SOC agents to enterprises, governments, and MSSPs for automated threat detection, investigation, and response.
- Company typePrivate
- Founded2022
- HeadquartersRennes, France
- Headcount101–250
- GTM typeB2B
- OfferingSoftware
What Sekoia.io does
Sekoia.io is a France-based (Paris, with a Rennes presence) cybersecurity software company that sells an agentic AI Security Operations Center (SOC) platform to enterprises, government agencies, and managed security service providers (MSSPs). The platform bundles four product modules — Sekoia Defend (a cloud-native SIEM replacement), Sekoia Intelligence (cyber threat intelligence), Sekoia Reveal (CAASM, or cyber asset attack surface management), and Sekoia Elevate (AI SOC agents for autonomous triage, investigation, and response) — under a single AI engine that correlates logs, signals, threat intel, and behavioral analytics into high-context alerts and a one-click course of action. The platform is differentiated by an in-house Threat Detection & Research (TDR) team whose original adversary research feeds the detection rules and is cited in major outlets (The Hacker News, SecurityWeek, ZDNet, Le Monde), and by a 'Made in EU' positioning targeted at organizations subject to NIS2 and DORA.
The company generates revenue primarily through annual recurring subscriptions sold via two motions: a direct enterprise sales-led motion (a prominent 'Get a demo' / 'Speak to a Sekoia expert' CTA on the website, with quote-based pricing and named logos including NATO and URSSAF) and a channel partner program aimed at MSSPs and resellers (Sekoia University, partner portal, and a 'Become a partner' funnel). Additional revenue comes from professional services and training delivered through Sekoia University. Customer segments span government, healthcare, technology, energy & utilities, and manufacturing, with MSSP identified as the primary segment.
Sekoia has raised €60 million cumulatively — a €35 million Series A (May 2023, co-led by Banque des Territoires and Bright Pixel) and a €26 million Series B (April 2025, led by Revaia) — and is operating with 101-250 employees. Its go-to-market has expanded beyond France into multiple European countries, the United States, Asia, and the Middle East, accelerated by a strategic partnership with Thales (October 2025) and reinforced by an ESET PROTECT integration (May 2026) that is jointly marketed as European sovereign technology. The company is recognized by Frost & Sullivan (Frost Radar XDR 2024 Leader), Gartner (2025), and Forrester (XDR Landscape Q1 2026).
Sekoia.io firmographics
Firmographics- Name
- Sekoia.io
- Legal name
- Sekoia
- Website
- https://sekoia.io
- Company type
- Private
- Founded year
- 2022
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Short description
- Sekoia.io is a French cybersecurity company that provides an agentic AI SOC platform combining SIEM, CTI, CAASM, and AI SOC agents to enterprises, governments, and MSSPs for automated threat detection, investigation, and response.
- Ownership category
- akta.pro rank
Sekoia.io industry classification
Industry- Product category
- Extended Detection and Response (XDR) / Security Operations Platform
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Security Operations Center (SOC) as a Service (BPAEADAB)
- akta.pro secondary industry
- Threat Intelligence Services (BPAEADAC)
Keywords
Where Sekoia.io is headquartered
LocationHeadquarters
- HQ city
- Rennes
- HQ country
- France
- HQ region
- Europe
Offices6 records
Markets served
Sekoia.io business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Infrastructure, Operations
Revenue model
- Security-as-a-Service Subscription: Recurring subscription to Sekoia's XDR/SIEM platform that monitors threats and integrates with existing cybersecurity solutions. Delivered as a cloud-native service.
- Managed SOC / MSSP Channel Revenue: Revenue distributed through a partner network of MSSPs and resellers (e.g., ConnectProtect) who deliver Sekoia's platform as part of their managed detection and response services.
- Professional Services and Training: Revenue from training courses, Sekoia University, and partner enablement programs supporting deployment and ongoing use of the platform.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Quote-based subscription for the Sekoia AI SOC Platform (Defend, Intelligence, Reveal, Elevate) |
Go-to-market motion4 records
Distribution channels4 records
Marketing channels8 records
Sekoia.io product offering
Product offeringCore offering
Sekoia.io provides an autonomous, agentic AI SOC platform that combines four integrated products — Sekoia Defend (SIEM), Sekoia Intelligence (CTI), Sekoia Reveal (CAASM), and Sekoia Elevate (AI SOC agents) — to detect, investigate, and respond to cyber threats in real time. The platform is fueled by Sekoia's in-house Threat Detection & Research (TDR) team and is sold to enterprise security teams and MSSPs across Europe, the US, Asia, and the Middle East.
Product overview
Sekoia.io offers a unified, agentic Security Operations (SOC) platform, sold as a core AI SOC Platform that bundles four named modules: Sekoia Defend (SIEM), Sekoia Intelligence (CTI), Sekoia Reveal (CAASM), and Sekoia Elevate (AI SOC agents). The platform is augmented by services from the in-house Sekoia Threat Detection & Research (TDR) team, Sekoia University training courses, and a Partner Portal for MSSPs and resellers, with bi-directional integrations across the customer's existing security and IT stack.
Differentiator
Problem solved
Functional benefit
Brands
- Sekoia Defend: SIEM product within the Sekoia unified SOC platform.
- Sekoia Intelligence
- Sekoia Reveal
- Sekoia Elevate
Products and services
- Sekoia AI SOC Platform Unified, agentic Security Operations platform that combines detection, hunting, investigation, and response into a single workflow driven by autonomous AI agents. It funnels logs, signals, and threat intelligence through one AI engine that correlates activity and presents analysts with high-context alerts and a one-click course of action. Sold to enterprise SOC teams and MSSPs.
- Sekoia Threat Detection & Research (TDR) Team In-house threat intelligence research service that produces original adversary research, FLINT reports, and continuously updated detection content that fuels Sekoia's platform and is available to customers as part of the intelligence subscription.
- Sekoia University / Training Courses Formal paid training portal and courses that partners and customers can purchase to build skills on the Sekoia platform and the MSSP partner program.
Quantifiable outcome
- Goal of protecting more than 3.5 million employees across Europe within two years (stated at Series A).
- +3 more outcomes
Companies that use Sekoia.io
Customer profileNamed customers4 records
Segments6 records
Ideal customer profiles3 records
Sekoia.io technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration22 records
AI capability11 records
Feature8 records
Sekoia.io partnerships and signals
Strategic signalPartnerships
18 partnerships are on record, tiered core technology partner, flagship strategic partner for international expansion, strategic european cybersecurity partner and flagship mssp partner (cited testimonial).
- ESETcore technology partnerESET and Sekoia announced an integration of the ESET PROTECT platform with Sekoia Defend to enhance AI-driven threat detection and response for SOC teams. Endpoint telemetry and alerts from ESET PROTECT are forwarded into Sekoia Defend, where they are enriched with threat intelligence, processed via detection rules, and correlated into full-context alerts. Both companies market the joint offering as trusted 'Made in EU' technology.
- Thalesflagship strategic partner for international expansionThales and Sekoia announced a partnership to expand Sekoia's international presence, including distribution of Sekoia's XDR platform through Thales's channels and joint cybersecurity solutions for organizations with high data-protection needs in France and abroad. The collaboration emphasizes AI-powered threat intelligence.
- Cloudflarecore technology partnerCloudflare is featured as a primary technology integration within Sekoia's integration framework, enabling bi-directional exchange of signals, alerts, and context across the security stack.
- Microsoft (Entra ID / Azure)core technology partnerMicrosoft Entra ID and Azure Windows integrations are featured prominently in Sekoia's integrations catalog, allowing identity and cloud telemetry to flow into Sekoia's detection and response workflows.
- AWS (CloudTrail)core technology partnerAWS CloudTrail is featured in Sekoia's integrations catalog for cloud-audit telemetry ingestion into the Sekoia platform.
- Cisco (Secure Firewall, Meraki MX)core technology partnerCisco Secure Firewall and Cisco Meraki MX integrations enable network telemetry to feed Sekoia's SOC platform for detection and response.
- Fortinet (FortiGate)core technology partnerFortinet FortiGate integration is featured in Sekoia's integrations catalog, ingesting firewall telemetry for threat detection.
- Palo Alto Networks (NGFW)core technology partnerPalo Alto NGFW integration is featured in Sekoia's integrations catalog for network and firewall telemetry.
- Sophos (Firewall)core technology partnerSophos Firewall is listed in Sekoia's integrations catalog for ingesting firewall telemetry.
- Stormshield (SNS)strategic european cybersecurity partnerStormshield SNS integration is featured in Sekoia's integrations catalog, aligning two European cybersecurity vendors for joint sovereign offerings.
- HarfangLab (EDR)core technology partnerHarfangLab EDR integration is featured in Sekoia's integrations catalog for endpoint detection telemetry.
- ConnectProtectflagship mssp partner (cited testimonial)ConnectProtect is an MSSP that re-architected its managed XDR platform around Sekoia, citing Sekoia's AI capabilities and commercial fit (testimonial from founder & CEO Rob Gupta on the Sekoia homepage).
- WALLIX (Bastion)core technology partnerWALLIX Bastion is featured in Sekoia's integrations catalog for privileged-access telemetry ingestion.
- Veeam (Backup)core technology partnerVeeam Backup is listed in Sekoia's integrations catalog for backup and recovery telemetry.
- Varonis (Data Security)core technology partnerVaronis Data Security is featured in Sekoia's integrations catalog for data-security telemetry.
- Anomali (ThreatStream)core technology partnerAnomali ThreatStream is featured in Sekoia's integrations catalog, enabling threat-intelligence platform interoperability.
- Google (Workspace)core technology partnerGoogle Workspace is listed in Sekoia's integrations catalog for productivity/identity telemetry ingestion.
- VMware (ESXi)core technology partnerVMware ESXi is listed in Sekoia's integrations catalog for virtualization infrastructure telemetry.
Scale indicators8 records
Recent moves7 records
Expansion highlights6 records
Sekoia.io competitors and assessment
Company assessmentDirect peers
- CrowdStrike: CrowdStrike Falcon XDR is a direct competitor to Sekoia's AI SOC platform, offering endpoint, identity, cloud, and threat intelligence in a unified agent-based architecture for enterprise SOC teams.
- SentinelOne: SentinelOne's Singularity XDR platform competes head-on with Sekoia in autonomous, AI-driven detection and response, targeting the same enterprise SOC consolidation narrative.
- Elastic Security: Elastic Security offers SIEM and XDR capabilities built on the Elastic Search platform and competes with Sekoia in the cloud-native SIEM replacement market.
- Exabeam: Exabeam is a direct competitor in AI-driven SIEM and security analytics, targeting the same SOC analyst-efficiency and threat-detection use cases as Sekoia Defend.
- Devo Technology: Devo is a cloud-native SIEM/XDR platform targeting enterprise SOC modernization, directly competing with Sekoia Defend in high-volume, AI-assisted detection and analytics.
Broad incumbents
- Palo Alto Networks: Palo Alto's Cortex XDR is a direct XDR/SIEM competitor and Palo Alto also integrates with Sekoia's platform, illustrating overlapping detection-and-response capabilities at much larger scale.
- Microsoft: Microsoft Sentinel is a leading cloud-native SIEM/XDR and a primary 'SIEM replacement' competitor to Sekoia Defend, benefiting from bundling with the broader Microsoft security and Azure stack.
- Splunk: Splunk (now part of Cisco) is a category-defining SIEM that Sekoia explicitly targets for replacement; its enterprise scale and Cisco distribution make it a key incumbent competitor.
- Trellix: Trellix (formed from FireEye and McAfee Enterprise) offers a broad XDR platform that overlaps with Sekoia's detection, intelligence, and response capabilities for enterprise SOC buyers.
Emerging players
- Arctic Wolf: Arctic Wolf provides managed detection and response built on a proprietary cloud-native platform, competing with Sekoia both directly (platform) and via its own MSSP-like delivery model.
Market position
Strengths5 records
Weaknesses4 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
Sekoia.io social profiles
Digital presenceSekoia.io compliance and trust
Trust signalCompliance1 record
Sekoia.io financial estimates
Financial estimateRevenue estimate
Valuation estimate
Sekoia.io leadership team
Management profileNumber of profiles
Profiles1 record
Sekoia.io funding detail
Funding detailFunding overview
Funding rounds4 records
Investors10 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Sekoia.io M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Sekoia.io
What does Sekoia.io do?
Sekoia.io provides an autonomous, agentic AI SOC platform that combines four integrated products — Sekoia Defend (SIEM), Sekoia Intelligence (CTI), Sekoia Reveal (CAASM), and Sekoia Elevate (AI SOC agents) — to detect, investigate, and respond to cyber threats in real time. The platform is fueled by Sekoia's in-house Threat Detection & Research (TDR) team and is sold to enterprise security teams and MSSPs across Europe, the US, Asia, and the Middle East.
Is Sekoia.io a public or private company?
Sekoia.io is a private company. It is classified as venture growth investor backed and is currently operating.
When was Sekoia.io founded?
Sekoia.io was founded in 2022. It employs 101 to 250 people.
Where is Sekoia.io based?
Sekoia.io is headquartered in Rennes, France, in the Europe region.
How does Sekoia.io make money?
Three revenue lines are on record. Security-as-a-Service Subscription is the primary driver. The others are managed SOC / MSSP Channel Revenue and professional Services and Training.
Who are Sekoia.io's main competitors?
Direct peers on record are CrowdStrike, SentinelOne, Elastic Security, Exabeam and Devo Technology. Broad incumbents are Palo Alto Networks, Microsoft, Splunk and Trellix. Arctic Wolf is listed as an emerging player.
Does Sekoia.io have an API?
No public API is recorded for Sekoia.io.
What industry is Sekoia.io in?
Sekoia.io's product category is Extended Detection and Response (XDR) / Security Operations Platform. Its primary akta.pro industry code is BPAEADAB, Security Operations Center (SOC) as a Service, with a secondary code of BPAEADAC, Threat Intelligence Services. Its NAICS code is 54151 and its SIC code is 7373.