Léargas Security
Léargas Security is a US-based private cybersecurity company that sells an AI-powered unified XDR/SIEM platform with strong ICS/OT and critical-infrastructure specialization, targeting enterprises, government agencies, MSSPs, and electric membership corporations via annual enterprise subscriptions.
- Company typePrivate
- Founded2018
- HeadquartersCanton, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Léargas Security does
Léargas Security is a privately held US cybersecurity company, founded in 2018 and headquartered in Canton, United States, that builds an AI-powered Security Operations Platform positioned as a unified XDR (Extended Detection and Response) product. The platform consolidates SIEM, UEBA, NDR, vulnerability assessment, deception technology, and threat intelligence into a single subscription, using cloud-to-core correlation across AWS, Azure, Google Cloud, Microsoft 365, Google Workspace, Okta, Duo, and major EDR/network vendors alongside Zeek and Suricata full-traffic capture deployed via SPAN. A defining differentiator is deep ICS/OT security capability, with native protocol support for Siemens, SCADA, PROFINET, Modbus, OPC UA, EtherCAT, EtherNet/IP, DNP3, BACnet, and CIP, and alignment with NERC CIP, NIST, and SOC 2 compliance frameworks for critical-infrastructure operators.
The platform embeds generative AI (built-in large language models and local vLLM processing) for AI-assisted investigations, plain-language analyst guidance, executive summaries, and automated SOC workflows, layered on top of anomaly detection, predictive analytics, and six years of threat-intelligence engineering that evolved from standalone CIRCL AIL to local LLM processing. The company sells through an enterprise field-sales motion with quote-based annual subscriptions, demo-driven CTAs, and no public pricing; its go-to-market is segmented across four named verticals — Enterprise, Government, MSSPs, and Electric Membership Corporations (EMCs) — with active 2025 presence at utility-sector conferences such as Co-op Cyber Tech 2025.
The company is founder-controlled (CEO Patrick Kelley and CTO Glenn Holzmacher, both previously at Critical Path Security), operates with 11–50 employees, has no disclosed institutional funding or revenue figures, and markets itself primarily through a content-driven blog covering AI, critical infrastructure, IT/OT, and threat intelligence. The product is positioned around three economic promises: one-day deployment eliminating 100+ hours of professional services, high-fidelity detection through multi-source correlation, and unified IT/OT visibility from cloud to core switch.
Léargas Security firmographics
Firmographics- Name
- Léargas Security
- Legal name
- Léargas Security Inc.
- Website
- https://leargassecurity.com
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Léargas Security is a US-based private cybersecurity company that sells an AI-powered unified XDR/SIEM platform with strong ICS/OT and critical-infrastructure specialization, targeting enterprises, government agencies, MSSPs, and electric membership corporations via annual enterprise subscriptions.
- Ownership category
- akta.pro rank
Léargas Security industry classification
Industry- Product category
- Security Operations Platform (XDR/SIEM)
- NAICS
- Computer Systems Design and Related Services (54151), Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (5182)
- SIC
- Services-Computer Programming Services (7371), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Extended Detection & Response (XDR) (HDADAEAB)
- akta.pro secondary industries
- Security Operations Center (SOC) as a Service (BPAEADAB), Revenue Protection, Theft Detection & Meter Analytics (EUADAFAG)
Keywords
Where Léargas Security is headquartered
LocationHeadquarters
- HQ city
- Canton
- HQ country
- United States
- HQ region
- North America
Markets served
Léargas Security business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Infrastructure, Operations
Revenue model
- Security Platform Subscription: All-in-one security platform sold as a unified subscription covering prevention, detection, response, and prediction across network, cloud, and endpoints. Includes multi-layered protection with AI algorithms, threat intelligence, and machine learning. Pricing appears to be quote-based requiring demo/sales consultation.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise platform pricing - quote-based |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels6 records
Léargas Security product offering
Product offeringCore offering
Léargas Security provides an AI-powered unified Security Operations Platform (XDR) that consolidates SIEM, network detection and response (NDR), threat intelligence, and ICS/OT security into a single subscription-based solution. The platform correlates signals from cloud (AWS, Azure, Google Cloud), identity (Okta, Duo, Microsoft 365, Google Workspace), endpoint (CrowdStrike, SentinelOne, Carbon Black, Trend Micro), and network (Zeek, Suricata) sources, augmented by built-in large language models for AI-assisted investigations and executive-readable summaries. It is sold to enterprises, government agencies, MSSPs, and electric utilities through a direct enterprise sales motion with quote-based annual subscriptions.
Product overview
Léargas Security offers a unified cybersecurity platform called the Léargas Security Operations Platform with Generative AI, which integrates multiple protection tools into a single solution. The core platform unifies SIEM, XDR (Extended Detection and Response), NDR (Network Detection and Response), and vulnerability assessment with advanced AI capabilities. The portfolio includes the main Security Operations Platform with Generative AI, complemented by specialized modules: ICS & OT Security for industrial control system protection, Deception Technology for threat detection via decoys, Network Traffic Analysis for full-traffic visibility including lateral movement detection, Threat Intelligence powered by AI and local vLLM processing, and Léargas Cloud for unified multi-cloud and SaaS correlation. The platform combines cloud, identity, endpoint, and network signals with AI-powered correlation to detect, prevent, and respond to threats in real time.
Differentiator
Problem solved
Functional benefit
Products and services
- Léargas Security Operations Platform Unified cybersecurity platform that integrates SIEM, XDR, NDR, and vulnerability assessment into a single solution. Combines prevention, detection, response, and prediction across network, cloud, and endpoints with AI-powered correlation and analysis. Sold to enterprise SOCs, government agencies, MSSPs, and electric utilities via annual subscription.
- Léargas Security Operations Platform with Generative AI Enhanced version of the core Léargas platform that incorporates built-in large language models to deliver AI-assisted investigations, plain-language analyst guidance, executive summaries, and automated SOC workflows. Enables faster triage and more consistent incident response for security operations teams.
- ICS & OT Security Industrial Control Systems and Operational Technology security module providing deep packet inspection and real-time visibility into ICS/OT networks. Detects lateral movement across SCADA, PLCs, and IoT devices with support for NERC CIP compliance frameworks. For utilities, electric co-operatives, manufacturing, and other critical-infrastructure operators.
- Deception Technology Deception capabilities that create realistic decoys and traps to detect and divert attackers, identifying threats early in the attack lifecycle and enhancing overall defense strategy.
- Network Traffic Analysis (NDR) Network Detection and Response providing full-traffic visibility including north-south and east-west traffic analysis. Deployed at core switches via SPAN to expose lateral movement and suspicious internal communications that cloud-only log analysis cannot detect.
- Threat Intelligence AI-driven threat intelligence platform leveraging OSINT, XDR integration, and local vLLM processing to provide advanced threat detection and situational awareness. For security teams needing curated, AI-augmented intelligence on emerging threats.
- Léargas Cloud Cloud security module providing unified cloud-to-core correlation across AWS, Azure, Google Cloud, Microsoft 365, Google Workspace, Okta, Duo, and leading EDR solutions. Correlates cloud signals with Zeek and Suricata data for comprehensive visibility.
Quantifiable outcome
- Time to detect threats significantly reduced through AI-powered analytics and unified correlation
- +3 more outcomes
Companies that use Léargas Security
Customer profileSegments4 records
Ideal customer profiles3 records
Léargas Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration27 records
AI capability8 records
Feature7 records
Léargas Security partnerships and signals
Strategic signalPartnerships
18 partnerships are on record, tiered core.
- AWS (Amazon Web Services)coreCloud platform integration for unified security monitoring and correlation of AWS cloud workloads alongside on-premises and other cloud environments.
- Microsoft AzurecoreAzure cloud integration for security telemetry correlation and unified visibility across Azure-hosted workloads.
- Google CloudcoreGoogle Cloud platform integration for security monitoring and correlation of GCP workloads.
- Microsoft 365coreIntegration with Microsoft 365 for identity and productivity security telemetry correlation.
- Google WorkspacecoreIntegration with Google Workspace for security telemetry correlation and visibility.
- OktacoreIdentity provider integration for authentication and identity security monitoring correlation.
- Duo SecuritycoreMFA/identity security integration for enhanced authentication monitoring.
- CrowdStrikecoreEDR integration with CrowdStrike for endpoint detection and response telemetry correlation.
- SentinelOnecoreEDR integration with SentinelOne for endpoint detection and response telemetry correlation.
- VMware Carbon BlackcoreEDR integration with VMware Carbon Black for endpoint security telemetry correlation.
- SonicWallcoreNetwork security integration with SonicWall for firewall and network security telemetry.
- Trend MicrocoreIntegration with Trend Micro for extended security monitoring and correlation.
- CIRCL AILcoreCIRCL AIL (Analysis Information Leak) platform used for threat intelligence and external leak detection, part of the six-year threat intelligence development journey.
- ZeekcoreNetwork security monitoring tool integration for deep packet analysis and network traffic analysis.
- SuricatacoreIDS/IPS integration with Suricata for network threat detection and security monitoring.
- Siemens (ICS/OT)coreICS/OT security integration supporting Siemens industrial control systems and automation equipment.
- SCADA SystemscoreSCADA/HMI integration for operational technology security monitoring.
- OPC Foundation (OPC UA)coreOPC UA protocol support for industrial automation interoperability and security.
Scale indicators2 records
Recent moves6 records
Expansion highlights5 records
Léargas Security competitors and assessment
Company assessmentDirect peers
- Dragos: OT cybersecurity specialist focused on industrial control systems, with NERC CIP expertise and incident response services. Comparable to Léargas' ICS & OT positioning for utilities and critical infrastructure.
- Exabeam: AI-driven SIEM/XDR platform combining security analytics, UEBA, and automated investigations. Closest direct peer to Léargas in converged SIEM/XDR/UEBA positioning and enterprise go-to-market motion.
- Claroty: Industrial cybersecurity platform for OT, IoT, and IIoT environments with broad protocol coverage and asset discovery. Strong direct peer for Léargas' EMC and critical infrastructure use cases.
- Nozomi Networks: OT/ICS network visibility and security specialist with deep industrial protocol support. Directly comparable to Léargas' ICS & OT Security module in serving utilities, manufacturing, and critical infrastructure.
- LogRhythm: SIEM and XDR platform targeting mid-market and enterprise security operations. Comparable in converging log management, analytics, and case management into a single platform.
- Devo Technology: Cloud-native SIEM and security analytics platform with autonomous SOC capabilities. Comparable in modernizing SOC operations with AI-driven analytics and cloud-native architecture.
- Securonix: Cloud-native SIEM with UEBA and XDR capabilities, often competing in the same enterprise SOC modernization deals. Similar AI-augmented analytics and MSSP-friendly multi-tenant architecture.
Broad incumbents
- SentinelOne: Endpoint-led XDR platform extending into cloud, identity, and SIEM-adjacent capabilities (Purple AI). Broad incumbent competing for enterprise XDR consolidation budgets.
- Microsoft (Sentinel): Microsoft Sentinel is a cloud-native SIEM/XDR with deep integration across Azure, M365, and Defender. Major incumbent in the same converged SOC platform category with strong distribution advantages.
- CrowdStrike: Dominant endpoint security vendor whose Falcon platform now extends into XDR, SIEM (Falcon LogScale), and IT/OT modules. Broad incumbent competing for the same converged-platform RFPs Léargas targets.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
Léargas Security social profiles
Digital presenceLéargas Security compliance and trust
Trust signalCompliance3 records
Léargas Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Léargas Security leadership team
Management profileNumber of profiles
Profiles4 records
Léargas Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Léargas Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Léargas Security
What does Léargas Security do?
Léargas Security provides an AI-powered unified Security Operations Platform (XDR) that consolidates SIEM, network detection and response (NDR), threat intelligence, and ICS/OT security into a single subscription-based solution. The platform correlates signals from cloud (AWS, Azure, Google Cloud), identity (Okta, Duo, Microsoft 365, Google Workspace), endpoint (CrowdStrike, SentinelOne, Carbon Black, Trend Micro), and network (Zeek, Suricata) sources, augmented by built-in large language models for AI-assisted investigations and executive-readable summaries. It is sold to enterprises, government agencies, MSSPs, and electric utilities through a direct enterprise sales motion with quote-based annual subscriptions.
Is Léargas Security a public or private company?
Léargas Security is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Léargas Security founded?
Léargas Security was founded in 2018. It employs 11 to 50 people.
Where is Léargas Security based?
Léargas Security is headquartered in Canton, United States, in the North America region.
How does Léargas Security make money?
One revenue line is on record: security Platform Subscription.
Who are Léargas Security's main competitors?
Direct peers on record are Dragos, Exabeam, Claroty, Nozomi Networks, LogRhythm, Devo Technology and Securonix. Broad incumbents are SentinelOne, Microsoft (Sentinel) and CrowdStrike.
Does Léargas Security have an API?
No public API is recorded for Léargas Security.
What industry is Léargas Security in?
Léargas Security's product category is Security Operations Platform (XDR/SIEM). Its primary akta.pro industry code is HDADAEAB, Extended Detection & Response (XDR), with a secondary code of BPAEADAB, Security Operations Center (SOC) as a Service. Its NAICS code is 54151 and its SIC code is 7371.