Chronicle
Chronicle, rebranded as Google Security Operations, is Google Cloud's cloud-native platform unifying SIEM, SOAR, and applied threat intelligence for enterprise security operations teams, government agencies, and organizations migrating from legacy SIEM.
- Company typePrivate
- Founded2017
- HeadquartersMountain View, United States
- Headcount5,001–10,000
- GTM typeB2B
- OfferingSoftware
What Chronicle does
Chronicle, now marketed as Google Security Operations (Google SecOps), is a cloud-native, intelligence-driven security operations platform that unifies SIEM, SOAR, and applied threat intelligence into a single product. The platform was originally founded in 2017 as an independent cybersecurity startup, was acquired by Google (Alphabet Inc.) in 2020, and was subsequently rebranded as Google Security Operations around 2023–2024. It serves enterprise security operations teams, government agencies, and organizations migrating from legacy SIEM platforms, with named enterprise customers spanning financial services (Charles Schwab, BBVA, Jack Henry, Apex FinTech Solutions), pharmaceuticals (Pfizer), telecommunications (Telefonica), retail (Kroger, Groupon), and infrastructure (Vertiv, Morgan Sindall).
The underlying technology combines Google-scale data infrastructure for security telemetry ingestion, the proprietary YARA-L 2.0 detection authoring language, 700+ data parsers, and 300+ SOAR integrations, and integrates Google's Gemini generative AI for natural language search, investigation assistance, AI-generated case summaries, and automated playbook/detection creation. Threat intelligence is delivered through bundled access to Mandiant frontline research, VirusTotal, and Google Safe Browsing, with ML-based prioritization of IoC matches. The product is sold in three tiered subscription packages (Standard, Enterprise, Enterprise Plus) priced by ingestion volume with 12 months of hot data retention included; all pricing is quote-based through Google Cloud's direct enterprise sales organization. The platform was recognized as a Leader in the 2025 Gartner Magic Quadrant for SIEM and the 2024 IDC MarketScape for SIEM.
Chronicle firmographics
Firmographics- Name
- Chronicle
- Legal name
- Chronicle
- Website
- https://chronicle.security
- Company type
- Private
- Founded year
- 2017
- Operating status
- Acquired
- Headcount range
- 5,001–10,000 employees
- Short description
- Chronicle, rebranded as Google Security Operations, is Google Cloud's cloud-native platform unifying SIEM, SOAR, and applied threat intelligence for enterprise security operations teams, government agencies, and organizations migrating from legacy SIEM.
- Ownership category
- akta.pro rank
Chronicle industry classification
Industry- Product category
- Cloud Security Operations / SIEM
- NAICS
- Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (5182)
- SIC
- Services-Computer Integrated Systems Design (7373), Services-Computer Programming, Data Processing, Etc. (7370), Services-Computer Processing & Data Preparation (7374)
- akta.pro primary industry
- Attack Detection & Response for Cloud/SaaS (SOC for Cloud) (HDADAGAJ)
- akta.pro secondary industries
- Security Operations Center (SOC) as a Service (BPAEADAB), Threat Intelligence Services (BPAEADAC)
Keywords
Where Chronicle is headquartered
LocationHeadquarters
- HQ city
- Mountain View
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Chronicle business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Infrastructure, Marketing or Sales, Operations
Revenue model
- Subscription-based SaaS (Security Operations Platform): Cloud-native security operations platform available in tiered packages (Standard, Enterprise, Enterprise Plus) based on ingestion volume. Includes one year of security telemetry retention at no additional cost. Revenue generated through annual or multi-year subscriptions with contact sales for enterprise pricing.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Standard - Base SIEM and SOAR capabilities with core detection and investigation features |
| Subscription | Annual | Enterprise - Includes Standard plus UEBA, curated detections, and Gemini AI capabilities |
| Subscription | Annual | Enterprise Plus - Full threat intelligence with Mandiant, VirusTotal, and advanced capabilities |
Go-to-market motion1 record
Distribution channels2 records
Marketing channels6 records
Chronicle product offering
Product offeringCore offering
Chronicle (now Google Security Operations) provides a cloud-native, intelligence-driven security operations platform that unifies SIEM, SOAR, and applied threat intelligence for enterprise security teams. The platform ingests and analyzes security telemetry at Google scale, applies Mandiant/VirusTotal-derived threat intelligence, and uses Gemini AI to accelerate detection, investigation, and response. It is sold in tiered subscriptions (Standard, Enterprise, Enterprise Plus) with 12 months of hot data retention included.
Product overview
Google Security Operations (formerly Chronicle) is a unified intelligence-driven security operations platform that combines SIEM, SOAR, and applied threat intelligence capabilities. The platform offers three tiered packages: Standard (base SIEM and SOAR with 700+ parsers and 300+ SOAR integrations), Enterprise (adds UEBA, enriched threat intelligence including Google Safe Browsing, curated detections, and Gemini AI), and Enterprise Plus (adds full Google Threat Intelligence including Mandiant and VirusTotal, advanced data pipeline management, and BigQuery storage). The platform leverages Gemini AI for natural language search, investigation assistance, and automated detection/playbook creation.
Differentiator
Problem solved
Functional benefit
Brands
- Google Security Operations: The unified security operations platform combining SIEM, SOAR, and threat intelligence capabilities, formerly known as Chronicle Security Operations.
Products and services
- Google Security Operations (SecOps) Intelligence-driven and AI-powered cloud-native security operations platform that empowers enterprise security teams to detect, investigate, and respond to cybersecurity threats by unifying SIEM, SOAR, and applied threat intelligence.
- SIEM (Security Information and Event Management)
Quantifiable outcome
- 240% ROI according to Forrester Consulting Total Economic Impact study
- +3 more outcomes
Companies that use Chronicle
Customer profileNamed customers11 records
Segments3 records
Ideal customer profiles3 records
Chronicle technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration5 records
AI capability4 records
Feature8 records
Chronicle partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered core.
- MandiantcoreMandiant experts deliver personalized guidance and program management tailored to customer needs for cyber defense transformation with Google SecOps. Mandiant's frontline threat intelligence from active incident response engagements is integrated into the Enterprise Plus tier. Mandiant Managed Defense, Incident Response, and Consulting services are offered alongside Google SecOps.
- VirusTotalcoreVirusTotal malware scanning and threat intelligence data is integrated as part of Google Threat Intelligence in the Enterprise Plus tier. VirusTotal provides community-driven verification features and malware scanning against multiple antivirus engines.
Scale indicators7 records
Recent moves6 records
Expansion highlights5 records
Chronicle competitors and assessment
Company assessmentDirect peers
- Palo Alto Networks Cortex XSIAM: Cortex XSIAM is Palo Alto Networks' AI-driven SOC platform combining SIEM, XDR, and SOAR. It targets the same cloud-native, AI-first SOC modernization segment as Google SecOps and benefits from Palo Alto's installed base of NGFW and Cortex customers.
- Microsoft Sentinel: Microsoft Sentinel is a cloud-native SIEM/SOAR built on Azure, deeply integrated with Microsoft Defender and Copilot for Security. It is Chronicle's most direct cloud-native SIEM competitor, especially in Microsoft-heavy enterprise environments.
- Splunk: Splunk is the historical SIEM market leader, offering SIEM, SOAR, and observability on a unified data platform. Now part of Cisco, it competes head-to-head with Google SecOps for enterprise SOC modernization deals and SIEM migration workloads.
Emerging players
- Elastic Security: Elastic Security delivers SIEM, endpoint security, and observability on the Elasticsearch platform, with strong search-driven analytics. It competes with Google SecOps in cloud-native SIEM use cases, particularly for cost-sensitive deployments.
- Datadog Cloud SIEM: Datadog Cloud SIEM combines log management, security monitoring, and observability on one platform. It competes with Google SecOps for cloud-first enterprises already using Datadog for observability who want consolidated security and monitoring.
- Rapid7 InsightIDR: Rapid7 InsightIDR is a cloud-native SIEM/XDR focused on behavior analytics and rapid deployment. It is a comparable mid-market and enterprise SIEM alternative to Chronicle, particularly for organizations seeking unified detection and response.
- CrowdStrike Falcon LogScale: CrowdStrike Falcon LogScale (formerly Humio) provides high-performance log management and SIEM capabilities tightly integrated with CrowdStrike's endpoint and identity protection. It is a comparable next-gen SIEM alternative, especially for CrowdStrike-anchored environments.
- Sumo Logic: Sumo Logic is a cloud-native SaaS log analytics and SIEM platform. It competes with Chronicle in mid-market and cloud-first enterprises that prioritize log analytics breadth alongside SIEM functionality.
- Exabeam: Exabeam offers an AI-driven SIEM and XDR platform with strong UEBA heritage. It targets the same AI-driven SOC modernization narrative as Chronicle and competes for security operations transformation deals.
Broad incumbents
- IBM QRadar: IBM QRadar is a long-established enterprise SIEM, now positioned alongside Randori for attack surface management. It competes with Chronicle for traditional enterprise SOCs and large regulated-industry deployments.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
Chronicle social profiles
Digital presenceChronicle financial estimates
Financial estimateRevenue estimate
Valuation estimate
Chronicle leadership team
Management profileNumber of profiles
Profiles2 records
Chronicle funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Chronicle M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Chronicle
What does Chronicle do?
Chronicle (now Google Security Operations) provides a cloud-native, intelligence-driven security operations platform that unifies SIEM, SOAR, and applied threat intelligence for enterprise security teams. The platform ingests and analyzes security telemetry at Google scale, applies Mandiant/VirusTotal-derived threat intelligence, and uses Gemini AI to accelerate detection, investigation, and response. It is sold in tiered subscriptions (Standard, Enterprise, Enterprise Plus) with 12 months of hot data retention included.
Is Chronicle a public or private company?
Chronicle is a private company. It is classified as corporate owned and is currently acquired.
When was Chronicle founded?
Chronicle was founded in 2017. It employs 5,001 to 10,000 people.
Where is Chronicle based?
Chronicle is headquartered in Mountain View, United States, in the North America region.
How does Chronicle make money?
One revenue line is on record: subscription-based SaaS (Security Operations Platform).
Who are Chronicle's main competitors?
Direct peers on record are Palo Alto Networks Cortex XSIAM, Microsoft Sentinel and Splunk. Emerging players are Elastic Security, Datadog Cloud SIEM, Rapid7 InsightIDR, CrowdStrike Falcon LogScale, Sumo Logic and Exabeam. IBM QRadar is listed as a broad incumbent.
Does Chronicle have an API?
No public API is recorded for Chronicle.
What industry is Chronicle in?
Chronicle's product category is Cloud Security Operations / SIEM. Its primary akta.pro industry code is HDADAGAJ, Attack Detection & Response for Cloud/SaaS (SOC for Cloud), with a secondary code of BPAEADAB, Security Operations Center (SOC) as a Service. Its NAICS code is 5182 and its SIC code is 7373.