Logpoint
Logpoint (now Guardsix) is a Copenhagen-based cybersecurity vendor selling a sovereign SIEM/SOAR/NDR platform — the Guardsix Command Centre — to European critical infrastructure, healthcare, and municipal organizations that require NIS2/GDPR/CADA-compliant security operations with full data sovereignty.
- Company typePrivate
- Founded2001
- HeadquartersCopenhagen, Denmark
- Headcount101–250
- GTM typeB2B
- OfferingSoftware
What Logpoint does
Logpoint, operating under the Guardsix brand since a March 2026 rebrand, is a Copenhagen-based cybersecurity vendor that sells a sovereign security operations platform — the Guardsix Command Centre — to European organizations protecting critical national infrastructure, public services, and sensitive data. The platform integrates five product pillars: SIEM (log management, threat detection, compliance reporting), NDR (network detection and response, inherited from the October 2024 Muninn acquisition), SOAR (orchestration and automation, inherited from the September 2021 SecBI acquisition), Governance (access governance and audit trails), and Fleet (endpoint visibility), with 100+ third-party integrations. Distribution is hybrid: direct enterprise field sales for large CNI, healthcare, and government accounts; MSSP and reseller channels for mid-market reach across Europe; and self-serve PLG tools (SIEM sizing calculator, Academy training) for smaller organizations. Pricing is a predictable node-based subscription model explicitly designed as an alternative to ingestion-based pricing, supporting lean security teams without specialist dependencies.
The company serves more than 8,000 customers across healthcare (NHS), energy and utilities (Energinet, Sachsen Energie), municipalities (City of Copenhagen, Göteborgs Stad), industrial/OT (Secomea), and broader enterprise/technology accounts (Siemens, KMD, Metcloud), with European MSSPs (8COM, Sun Management) as a key go-to-market multiplier. Go-to-market is anchored on European data sovereignty, EU jurisdiction control, and compliance with NIS2, GDPR, and CADA regulations, with deployment flexibility spanning on-premises and cloud. The company has raised approximately $40M in disclosed equity funding (notably a $30M round led by Yttrium in September 2020 with participation from DICO and Evolution Equity Partners) and has grown headcount to 251-500 employees, with engineering/R&D presence in Copenhagen, Aarhus (Muninn team), and Tel Aviv (former SecBI operations, branded as LogPoint Israel). Leadership includes CEO Mikkel Drucker, founder and chairman Søren Laustrup, CFO John Little, CTO Christian Have, and CPO Sean Muirhead.
Logpoint firmographics
Firmographics- Name
- Logpoint
- Legal name
- Guardsix
- Website
- https://logpoint.com
- Company type
- Private
- Founded year
- 2001
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Short description
- Logpoint (now Guardsix) is a Copenhagen-based cybersecurity vendor selling a sovereign SIEM/SOAR/NDR platform — the Guardsix Command Centre — to European critical infrastructure, healthcare, and municipal organizations that require NIS2/GDPR/CADA-compliant security operations with full data sovereignty.
- Ownership category
- akta.pro rank
Logpoint industry classification
Industry- Product category
- Cybersecurity Operations Platform (SIEM/SOAR/NDR)
- NAICS
- Computer Systems Design Services (541512), Computer Systems Design and Related Services (54151), Security Systems Services (56162)
- SIC
- Services-Computer Programming Services (7371), Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- SIEM Platforms & Log Management (HDADAGAA)
- akta.pro secondary industries
- Cloud Security Logging, SIEM/SOAR & Threat Detection (HDABAHAL), Log Management & Analytics (HDABAJAC), Grid Cyber Risk Management, Governance, Compliance & Audit (NERC CIP/IEC 62443) (EUADANAC), Vulnerability & Patch Management for OT Assets (EUADANAF), Security Systems Monitoring & Dispatch (SOC/Remote Guarding) (IMAIAEAF)
Keywords
Where Logpoint is headquartered
LocationHeadquarters
- HQ city
- Copenhagen
- HQ country
- Denmark
- HQ region
- Europe
Offices3 records
Markets served
Logpoint business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- SIEM Platform Subscription: Node-based subscription model for SIEM platform providing predictable, scalable pricing based on nodes/logical units rather than data ingestion volume.
- MSSP Services: Multi-customer visibility and control offerings for managed security service providers with exclusive pricing and collaboration tools.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Node-based SIEM pricing for public sector |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels6 records
Logpoint product offering
Product offeringCore offering
Logpoint (now operating as Guardsix) sells a sovereign cybersecurity platform called the Guardsix Command Centre that integrates SIEM, NDR, SOAR, Governance, and Fleet capabilities into a single offering. The platform provides log management, threat detection, automated incident response, access governance, and audit-ready compliance evidence for European organizations protecting critical infrastructure, deployable on-premises or under EU jurisdiction.
Product overview
Logpoint (now rebranded as Guardsix) offers a unified cybersecurity platform called the Guardsix Command Centre, combining SIEM, NDR, SOAR, Governance, and Fleet products into a single sovereign security platform designed for European critical infrastructure operators. The platform architecture integrates network detection (Muninn NDR), security orchestration and automation (SecBI SOAR), log management, endpoint visibility, and access governance to enable organizations to detect, respond to, and investigate threats while maintaining full data sovereignty and control. The offering emphasizes deployment flexibility, predictable pricing, and compliance with EU regulations including NIS2 and GDPR.
Differentiator
Problem solved
Functional benefit
Products and services
- Guardsix Command Centre The sovereign security platform serving as the unified umbrella for all Logpoint/Guardsix products, integrating SIEM, NDR, SOAR, Governance, and Fleet capabilities in a single platform designed for European organizations protecting critical infrastructure.
- Guardsix SIEM Security Information and Event Management platform providing log management, threat detection, and compliance reporting capabilities with predictable node-based pricing and audit-ready evidence for lean security teams.
- Guardsix NDR Network Detection and Response capability providing advanced network monitoring and AI-driven threat detection, inherited from the Muninn acquisition, offering visibility into network traffic patterns and anomalies.
- Guardsix SOAR Security Orchestration, Automation and Response platform inherited from the SecBI acquisition, enabling automated security workflows, case management, and coordinated incident response across integrated security tools.
- Guardsix Governance Access governance and compliance module providing patient-record access governance, audit trails, and regulatory compliance support for organizations maintaining control over who accesses sensitive data and why.
- Guardsix Fleet Endpoint security management capability providing visibility and control across endpoint devices, combining endpoint, network, and log-based detection in the integrated security platform.
- Guardsix Academy Training and education service offering on-demand and instructor-led courses to help security analysts develop skills from day one, supporting career development and platform adoption.
Quantifiable outcome
- Organizations integrating SIEM, NDR, and endpoint detection respond to incidents 50% faster (Gartner research)
- +2 more outcomes
Companies that use Logpoint
Customer profileNamed customers10 records
Segments5 records
Ideal customer profiles5 records
Logpoint technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability3 records
Feature4 records
Logpoint partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered core and flagship.
- NXLogcorePartnership to promote European digital sovereignty and enhance data control for organizations in regulated environments. Collaboration allows better control over security data collection, processing, and enrichment, particularly supporting compliance with EU regulations like NIS2.
- Sun ManagementcoreCollaboration to provide public-sector IT departments with scalable SIEM solution focused on predictable, node-based pricing. Model allows organizations to retain control while receiving expert support, addressing needs of smaller agencies with limited resources.
- Muninn (Acquired)flagshipAcquisition of Denmark-based AI-driven network detection and response provider to enhance SIEM-based Cyber Defense Platform with AI detection capabilities. Brings entire Muninn team including CEO/founder Andreas Wehowsky into Logpoint.
- SecBI (Acquired - now LogPoint Israel)flagshipAcquisition of Israeli cybersecurity firm to enhance automation capabilities in threat detection and response. Integration of SecBI's SOAR and XDR platform into LogPoint operations; SecBI remaining in Tel Aviv as LogPoint Israel.
Scale indicators3 records
Recent moves6 records
Expansion highlights6 records
Logpoint competitors and assessment
Company assessmentDirect peers
- Splunk: The dominant enterprise SIEM platform, now owned by Cisco. Splunk directly competes with Logpoint's Command Centre SIEM for log management, threat detection, and SOAR workloads across enterprise and public-sector buyers globally.
- Securonix: Cloud-native SIEM with UEBA and SOAR focused on enterprise and MSSP segments. Recently merged with Securonix and operates a comparable partner-led, multi-tenant MSSP model.
- IBM QRadar: Long-standing enterprise SIEM with strong installed base in regulated industries. Competes head-to-head with Logpoint for large CNI operators and government SIEM deployments across Europe.
- Exabeam: AI-driven SIEM and security analytics platform with UEBA and SOAR capabilities. Directly comparable in product scope (SIEM + analytics + automation) and enterprise-focused GTM motion.
- Elastic Security: Open-source-anchored SIEM and observability platform competing on log analytics and detection. Targets similar cost-conscious enterprise buyers with flexible deployment models, overlapping Logpoint's node-based value proposition.
- Microsoft Sentinel: Cloud-native SIEM bundled with Microsoft E5 licences, the most direct pricing threat to Logpoint's mid-market positioning. Competes on ingestion-based analytics, SOAR, and tight integration with the Microsoft security stack.
- Sumo Logic: Cloud-native log management and SIEM platform competing on analytics, observability, and threat detection. Targets similar enterprise and MSSP use cases with subscription-based pricing.
Broad incumbents
- Rapid7 (InsightIDR / InsightConnect): Broader security platform offering SIEM/XDR (InsightIDR) and SOAR (InsightConnect) alongside vulnerability management. Overlaps with Logpoint's Command Centre for mid-market and enterprise security operations buyers.
- Palo Alto Networks (Cortex XSIAM / XSOAR): Hyperscaler-adjacent security platform with XSIAM (modern SIEM) and XSOAR (SOAR). Competes broadly with Logpoint in converged SOC platforms, especially where buyers want a single vendor for SIEM, EDR, and SOAR.
Emerging players
- Devo Technology: Cloud-native SIEM focused on enterprise SOC modernisation with native SOAR. A more direct emerging competitor in the converged SIEM/SOAR niche that Logpoint occupies, particularly in Europe and with MSSPs.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Logpoint compliance and trust
Trust signalCompliance2 records
Logpoint financial estimates
Financial estimateRevenue estimate
Valuation estimate
Logpoint leadership team
Management profileNumber of profiles
Profiles10 records
Logpoint subsidiaries and ownership
Company hierarchySubsidiaries2 records
Logpoint funding detail
Funding detailFunding overview
Funding rounds3 records
Investors3 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Logpoint M&A and investment
M&A and investmentM&A3 records
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Logpoint
What does Logpoint do?
Logpoint (now operating as Guardsix) sells a sovereign cybersecurity platform called the Guardsix Command Centre that integrates SIEM, NDR, SOAR, Governance, and Fleet capabilities into a single offering. The platform provides log management, threat detection, automated incident response, access governance, and audit-ready compliance evidence for European organizations protecting critical infrastructure, deployable on-premises or under EU jurisdiction.
Is Logpoint a public or private company?
Logpoint is a private company. It is classified as venture growth investor backed and is currently operating.
When was Logpoint founded?
Logpoint was founded in 2001. It employs 101 to 250 people.
Where is Logpoint based?
Logpoint is headquartered in Copenhagen, Denmark, in the Europe region.
How does Logpoint make money?
Two revenue lines are on record. SIEM Platform Subscription is the primary driver. The others are MSSP Services.
Who are Logpoint's main competitors?
Direct peers on record are Splunk, Securonix, IBM QRadar, Exabeam, Elastic Security, Microsoft Sentinel and Sumo Logic. Broad incumbents are Rapid7 (InsightIDR / InsightConnect) and Palo Alto Networks (Cortex XSIAM / XSOAR). Devo Technology is listed as an emerging player.
Does Logpoint have an API?
No public API is recorded for Logpoint.
What industry is Logpoint in?
Logpoint's product category is Cybersecurity Operations Platform (SIEM/SOAR/NDR). Its primary akta.pro industry code is HDADAGAA, SIEM Platforms & Log Management, with a secondary code of HDABAHAL, Cloud Security Logging, SIEM/SOAR & Threat Detection. Its NAICS code is 541512 and its SIC code is 7371.