Sandfly Security
Sandfly Security is a Christchurch, New Zealand-based cybersecurity company founded in 2017 that delivers agentless Linux endpoint detection and response (EDR) to enterprise customers in critical infrastructure, telecom, government, and education.
- Company typePrivate
- Founded2017
- HeadquartersChristchurch, New Zealand
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Sandfly Security does
Sandfly Security is a Christchurch, New Zealand-based cybersecurity company founded in 2017 that provides agentless endpoint detection and response (EDR) for Linux environments. The company's core technology monitors Linux-based systems without requiring software agents to be deployed on individual endpoints, addressing a deployment and performance gap in traditional EDR products that historically prioritize Windows. The product portfolio has expanded from Linux server monitoring to include network device support (Cisco and Juniper in Sandfly 5.4, April 2025) and a generative AI-powered security analyst for alert investigation (Sandfly 5.5, July 2025), with integrations into enterprise SIEM platforms such as Microsoft Sentinel.
The company serves enterprise customers in critical infrastructure, telecommunications, government, and education sectors. Notable deployments include an automotive manufacturer running 1,600 Linux servers. Sandfly operates a quote-based enterprise pricing model and reaches the market through three principal channels: direct enterprise sales, the Ericsson partnership for telecom XDR integration, the Carahsoft partnership (March 2026) for US public sector distribution, and the DigitalOcean cloud marketplace for SMB and developer-led self-serve adoption. The team remains small at 1–10 employees, supported by a March 2024 seed round from Gula Tech Adventures, Sorenson Capital, and Alt Ventures, with product momentum validated by a 2025 Gold Cybersecurity Excellence Award.
Sandfly Security firmographics
Firmographics- Name
- Sandfly Security
- Legal name
- Sandfly Security Limited
- Website
- https://sandflysecurity.com
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Sandfly Security is a Christchurch, New Zealand-based cybersecurity company founded in 2017 that delivers agentless Linux endpoint detection and response (EDR) to enterprise customers in critical infrastructure, telecom, government, and education.
- Ownership category
- akta.pro rank
Sandfly Security industry classification
Industry- Product category
- Linux Endpoint Detection and Response (EDR) / Linux Security
- NAICS
- Other Computer Related Services (541519)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Endpoint Security for End Users (EDR/XDR, Patch/Vuln, Zero Trust Endpoint) (BPAEAIAG)
- akta.pro secondary industry
- Endpoint Deception & Anti-Ransomware (HDADAEAL)
Keywords
Where Sandfly Security is headquartered
LocationHeadquarters
- HQ city
- Christchurch
- HQ country
- New Zealand
- HQ region
- Oceania
Offices1 record
Markets served
Sandfly Security business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Software Subscription Licenses: Annual or monthly subscription licenses for the Sandfly agentless Linux EDR platform, sold per host or enterprise-wide. Fees are quoted based on customer requirements and scope.
- Support Services: Telephone and email support included with paid licenses, with optional enhanced support terms. Updates and new versions provided as part of subscription.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Pay-as-you-go | Free Trial - 30 days |
| Subscription | Annual | Paid Subscription |
Go-to-market motion3 records
Distribution channels3 records
Marketing channels6 records
Sandfly Security product offering
Product offeringCore offering
Sandfly Security develops and sells an agentless endpoint detection and response (EDR) platform purpose-built for Linux systems. The platform connects over SSH to deliver threat detection, SSH key monitoring, password auditing, drift detection, AI-powered alert investigation, and active response without installing endpoint agents, making it suitable for production servers, legacy Linux, and embedded devices. Revenue is generated primarily through annual or monthly per-host subscription licenses with optional enhanced support, supplemented by a free 30-day incident response license for organizations under active attack.
Product overview
Sandfly Security offers a unified agentless Linux security platform consisting of the core Sandfly EDR product plus modular capabilities including Threat Detection, SSH Key Monitoring, Password Auditing, Drift Detection, and Incident Response. The platform operates agentlessly, connecting via SSH to scan and monitor Linux systems without installing endpoint agents. Key differentiators include no performance impact on production systems, compatibility with legacy and embedded Linux, and AI-powered analysis for expert-level threat investigation. The company also provides a free incident response license for active security incidents and maintains an open source file entropy scanner tool.
Differentiator
Problem solved
Functional benefit
Products and services
- Sandfly Agentless Linux EDR Platform Agentless endpoint detection and response platform for Linux systems that connects over SSH to provide threat detection, SSH key monitoring, password auditing, drift detection, AI-powered alert investigation, and active response without installing software on protected hosts. Designed for security operations teams at enterprises, government agencies, telecommunications providers, manufacturers, cloud platforms, and educational institutions running production, embedded, or legacy Linux.
- Free Emergency Incident Response License Complimentary 30-day license of the Sandfly agentless Linux EDR platform provided to organizations (and their incident response partners) that are actively responding to a cyber attack, covering up to 500 Linux hosts, intended to enable rapid deployment and threat containment without procurement delay.
- Sandfly Filescan (Open Source) Open source Linux file entropy scanner that identifies potentially malicious files by analyzing entropy patterns, used for malware detection and forensic analysis on Linux systems.
Quantifiable outcome
- 16x expansion in Linux security coverage for enterprise customer
- +1 more outcomes
Companies that use Sandfly Security
Customer profileNamed customers8 records
Segments4 records
Ideal customer profiles4 records
Sandfly Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration1 record
AI capability3 records
Feature8 records
Sandfly Security partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered core and minor.
- Carahsoft Technology Corp.coreCarahsoft serves as Sandfly's Master Government Aggregator, making the agentless Linux EDR platform available to U.S. Public Sector. Distribution through multiple government contract vehicles including NASA SEWP V, ITES-SW2, TIPS, OMNIA Partners, E&I Cooperative Services, and The Quilt.
- EricssoncoreEricsson partners with Sandfly to deliver agentless Linux security for telecommunications providers worldwide. Sandfly's EDR is integrated into the Ericsson Security Manager XDR solution, enhancing detection capability and security visibility for telecommunications customers where traditional endpoint agents are unsuitable.
- DigitalOceancoreSandfly available through DigitalOcean Marketplace, enabling customers to deploy agentless Linux security for DigitalOcean cloud deployments. Partnership allows joint solution offering to DigitalOcean's customer base.
- VayminorVay, an innovative remote-driving technology company, implemented Sandfly's agentless security to maintain critical performance standards while ensuring fleet-wide safety. Case study customer demonstrating technology deployment.
Scale indicators3 records
Recent moves6 records
Expansion highlights6 records
Sandfly Security competitors and assessment
Company assessmentDirect peers
- Tripwire (Fortra):
- Wazuh: Wazuh is an open-source SIEM and XDR platform with deep Linux endpoint monitoring, file integrity, and intrusion detection capabilities. It directly overlaps with Sandfly's Linux detection and forensics use cases at a free price point, making it the closest open-source competitive threat.
- TuxCare: TuxCare provides Linux security and compliance services including live patching, vulnerability scanning, and extended lifecycle support for enterprise Linux distributions. It targets a similar Linux-focused buyer and competes for the same Linux security budget.
Broad incumbents
- SentinelOne: SentinelOne Singularity is an AI-driven EDR/XDR platform with Linux endpoint support and active response capabilities that overlap with Sandfly's core offering. It is a broad incumbent competing for the same Linux security budget.
- CrowdStrike: CrowdStrike Falcon is the leading cloud-native EDR/XDR platform with growing Linux coverage. Comparable as a direct endpoint security competitor, though much broader in scope than Sandfly's Linux-only focus and a significant incumbent threat.
- Trend Micro: Trend Micro offers endpoint and server security with Linux coverage as part of its broader portfolio. It is a long-established incumbent competing for the same Linux server security buyers, particularly in regulated and government sectors.
- Microsoft Defender for Endpoint: Microsoft Defender for Endpoint now includes Linux server support and is often bundled with enterprise agreements at no incremental cost. It competes directly with Sandfly in the Linux server detection space, especially for Microsoft-heavy enterprises.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks1 record
Key highlights6 records
Customer concentration
Sandfly Security social profiles
Digital presenceSandfly Security compliance and trust
Trust signalCompliance1 record
Sandfly Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Sandfly Security leadership team
Management profileNumber of profiles
Profiles2 records
Sandfly Security funding detail
Funding detailFunding overview
Funding rounds1 record
Investors3 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Sandfly Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Sandfly Security
What does Sandfly Security do?
Sandfly Security develops and sells an agentless endpoint detection and response (EDR) platform purpose-built for Linux systems. The platform connects over SSH to deliver threat detection, SSH key monitoring, password auditing, drift detection, AI-powered alert investigation, and active response without installing endpoint agents, making it suitable for production servers, legacy Linux, and embedded devices. Revenue is generated primarily through annual or monthly per-host subscription licenses with optional enhanced support, supplemented by a free 30-day incident response license for organizations under active attack.
Is Sandfly Security a public or private company?
Sandfly Security is a private company. It is classified as venture growth investor backed and is currently operating.
When was Sandfly Security founded?
Sandfly Security was founded in 2017. It employs 1 to 10 people.
Where is Sandfly Security based?
Sandfly Security is headquartered in Christchurch, New Zealand, in the Oceania region.
How does Sandfly Security make money?
Two revenue lines are on record. Software Subscription Licenses are the primary driver. The others are support Services.
Who are Sandfly Security's main competitors?
Direct peers on record are Tripwire (Fortra), Wazuh and TuxCare. Broad incumbents are SentinelOne, CrowdStrike, Trend Micro and Microsoft Defender for Endpoint.
Does Sandfly Security have an API?
No public API is recorded for Sandfly Security.
What industry is Sandfly Security in?
Sandfly Security's product category is Linux Endpoint Detection and Response (EDR) / Linux Security. Its primary akta.pro industry code is BPAEAIAG, Endpoint Security for End Users (EDR/XDR, Patch/Vuln, Zero Trust Endpoint), with a secondary code of HDADAEAL, Endpoint Deception & Anti-Ransomware. Its NAICS code is 541519 and its SIC code is 7372.