Back to vendors
D

Darktrace

Also known as: Darktrace ActiveAI Security Platform, ActiveAI, Cyber AI Analyst, Antigena, Autonomous Response, Darktrace PREVENT, Darktrace DETECT, Darktrace RESPOND, Darktrace HEAL, Enterprise Immune System, Cado Security, Cybersprint

Visit site
Entry priceContact salesFull pricing detail

The oldest autonomous response vendor in the index: self learning AI models each customer's own patterns of life rather than a global corpus, with Cyber AI Analyst investigating and prioritising incidents across six domains.

Darktrace has been running autonomous response in production since long before agentic AI was a category, and that history is the point of the record. Founded in Cambridge in 2013, it built its business on self learning AI that models the unique patterns of life of each individual customer in real time, then flags and acts on deviations from that learned normal.

That architecture is what separates it from every other security incumbent in this index. Palo Alto grounds its agents in 1.2 billion historical playbook executions; SentinelOne tunes across trillions of security data points with a global expert feedback loop. Darktrace has no global corpus in that sense. It learns what normal looks like inside one organisation and treats departure from it as the signal, which means it can act on threats nobody has seen before but also that every deployment starts from scratch.

The ActiveAI Security Platform, launched in 2024, organises this into a full lifecycle: PREVENT for attack path analysis and breach simulation, DETECT for anomaly detection across network, cloud, email, identity, endpoint and operational technology, RESPOND for autonomous response descended from the original Antigena product, and HEAL for guided and automated recovery and readiness exercises. Cyber AI Analyst sits across it, investigating alerts, correlating across domains, prioritising incidents and producing written narratives so analysts inherit a conclusion rather than a queue.

Thoma Bravo took the company private in October 2024 for roughly 5.3 billion dollars. Under private ownership it has become more acquisitive, buying Cado Security for cloud forensics and Cybersprint for attack surface management.

The honest limits are model flexibility, which does not exist by design, and its own security and deployment documentation, which was not retrievable in this pass.

Vendor details

Canonical URL

https://www.darktrace.com

Category

Security / SOC agent

Subcategory

Self learning autonomous detection and response

Funding status

Acquired by Thoma Bravo in an all cash take private valued at approximately 5.3 billion USD, completed October 2024, delisting from London. CEO Jill Popelka, formerly COO; co-founder Poppy Gustafsson stepped down in 2024. Roughly 2,400 employees protecting nearly 10,000 customers, with over 200 patent applications filed. Reported to be investing more than 200 million USD in US operations in 2026 including a Dallas deployment centre, targeting 1 billion USD revenue around 2027.

Company status

acquired

Use cases & customers

Primary use cases

autonomous threat detection and response across the digital estateAI led alert investigation and incident prioritisationemail and Microsoft Teams threat detectionoperational technology and network anomaly detectionattack path analysis and breach simulation

Target customers

large enterprisemid-marketoperational technology and industrial environmentsorganisations with unknown threat exposure

Deployment options

deployed across network, cloud, email, identity, endpoint and operational technology environments

Integrations

Covers network, cloud, email, identity, endpoint and operational technology as one platform with cross domain correlation, rather than integrating a set of point products. Cado Security added cloud forensics and investigation depth, and Cybersprint added external attack surface visibility. Email coverage extends to Microsoft Teams messaging with behavioural and natural language analysis across both channels.

In practice

A security team faces a threat with no known signature, and the platform acts on it anyway because it deviates from that organisation's own learned normal rather than matching a global indicator.

An analyst opens Cyber AI Analyst to find alerts already correlated across network, cloud and email into a written incident narrative with a priority attached.

An industrial operator extends the same anomaly detection into operational technology environments where signature based tooling has poor coverage.

Agentic Index coverage score

9.0 / 14 capabilities · 64%

Integrations & Tool CallingCovers network, cloud, email, identity, endpoint and operational technology as one platform with cross domain correlation rather than a set of integrated point products, extended by the Cado Security acquisition for cloud forensics and Cybersprint for external attack surface, with email coverage reaching into Microsoft Teams messaging. Darktrace and Thoma Bravo announcements 2026-08-08 Full
Workflow OrchestrationThe ActiveAI Security Platform runs a full lifecycle - PREVENT for attack path analysis and simulation, DETECT for anomaly detection, RESPOND for autonomous response, HEAL for guided and automated recovery - with Cyber AI Analyst orchestrating investigations across domains, correlating evidence and prioritising incidents end to end. Darktrace platform materials and independent analysis 2026-08-08 Full
Knowledge Grounding & RAGARCHITECTURALLY DISTINCT FROM EVERY PEER: proprietary self learning AI models THE UNIQUE PATTERNS OF LIFE FOR EACH INDIVIDUAL CUSTOMER IN REAL TIME and treats deviation from that learned normal as the signal, rather than grounding in a global corpus as palo-alto (1.2 billion playbook executions) and sentinelone (trillions of global data points) do. The trade off is explicit: it can act on threats never seen before, but every deployment starts cold. Darktrace platform description 2026-08-08 Full
Human Oversight & GuardrailsCyber AI Analyst produces written incident narratives for human review and HEAL provides GUIDED as well as automated recovery, implying human decision points, but the configuration governing when autonomous response acts alone versus awaiting human confirmation was not retrieved in this pass. Possible undergrade worth re checking. Darktrace platform materials 2026-08-08 Partial
Security, Identity & GovernanceNOT RETRIEVED AND LIKELY AN UNDERGRADE - FLAGGED FOR CORRECTION. Darktrace protects nearly 10,000 customers across regulated industries and holds over 200 patent applications, so attestations certainly exist, but none were retrieved in this pass. Consistent with the Sec paradox pattern now seven instances deep. Check darktrace.com trust or compliance pages and correct. Darktrace public sources 2026-08-08 Partial
Observability & AuditabilityCyber AI Analyst investigates alerts and produces WRITTEN NARRATIVES explaining each incident, correlating across domains and prioritising, so analysts inherit a reasoned conclusion rather than raw alerts; PREVENT adds attack path visibility across the estate. Reported to cut phishing investigation false positives by up to 60 percent. Darktrace platform materials and Cado acquisition release 2026-08-08 Full
Memory & State PersistenceThe per customer pattern of life baseline is durable learned state that accumulates and changes system behaviour over time, which is closer to aera's decision memory than to the data store shapes seen elsewhere, but it is a DETECTION MODEL rather than agent memory and is graded as such. No conversation or task context persistence is documented. Darktrace platform description 2026-08-08 Partial
Deployment & Data ResidencyDeploys across network, cloud, email, identity, endpoint and operational technology environments including on premise and industrial estates, which implies substantial deployment flexibility, but specific self hosted, sensor and data residency options were not retrieved in this pass. Likely an undergrade given the OT and network heritage. Darktrace platform description 2026-08-08 Partial
Prebuilt Agents, Templates & PacksShips as four packaged lifecycle products (PREVENT, DETECT, RESPOND, HEAL) across six environments, plus named capabilities including Cyber AI Analyst and a Mailbox Security Assistant, all working out of the box rather than requiring customer assembly. Darktrace platform materials 2026-08-08 Full
Triggers & Channel CoverageOperates continuously in real time across six environments and is stated to autonomously spot and respond to in progress threats WITHIN SECONDS, with detection driven by deviation from learned behaviour rather than by scheduled scans. Darktrace platform description 2026-08-08 Full
Model Flexibility & RoutingRuns proprietary self learning AI by design, with the per customer learned model being the core intellectual property; no model selection, provider choice or bring your own model capability exists or would be architecturally coherent. Honest absence rather than a gap. Darktrace platform description 2026-08-08 Unable to verify
APIs, SDKs & MCP ExtensibilityCross domain coverage and the absorption of Cado Security integrations imply a substantial integration and API surface, but no public API reference, SDK family or MCP support was retrieved in this pass. Notable that MCP support was not found where palo-alto and sentinelone both ship it. Darktrace public sources 2026-08-08 Partial
Testing, Debugging & OptimizationPREVENT provides attack path analysis and SIMULATION OF POTENTIAL BREACHES, and HEAL includes READINESS EXERCISES, both of which test the environment and the response plan before a real incident - but these test the customer's posture rather than evaluating the agent's own behaviour, so this is not agent evaluation in the sense the axis measures. Darktrace platform lifecycle description 2026-08-08 Partial
Browser & Computer UseOperates on network traffic, email, cloud and endpoint telemetry through sensors and integrations; no browser control, page navigation or computer use capability is documented. Darktrace product documentation 2026-08-08 Unable to verify

The Agentic Index coverage score grades every vendor Full, Partial or Unable to verify against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Pricing

Contact sales

coverage area and estate size, not disclosed

Included quota

Not disclosed.

What is public

Nothing on price. Ownership and acquisition terms are public because the take private was a listed company transaction.

Billing mechanics

Not publicly disclosed. Direct enterprise sales and channel, licensed by coverage area across the platform modules.

Cost watchouts

The platform is modular across six environments and four lifecycle products, so the cost driver is how much of the estate is covered rather than a headline licence. **A DEPLOYMENT SPECIFIC CONSIDERATION FOLLOWS FROM THE ARCHITECTURE: because the AI learns each customer's own patterns of life from scratch, there is a learning period before the system is fully effective, and that ramp is a real cost in analyst time even though it does not appear on an invoice.** Operational technology and network coverage historically involve sensor deployment, which carries its own installation effort.

Variable cost rationale

Graded medium rather than high because the licence is scoped to coverage areas and estate size, which is a stable and forecastable basis, and Darktrace runs its own models rather than passing through third party token consumption - so there is no opaque agent consumption unit of the kind seen across the BPM and agent builder pockets. The offsetting unknowns are that no rates are published at all and that adding coverage areas later is a negotiated expansion.

Additional watchouts

Scope the coverage areas deliberately. The platform's value case rests on cross domain correlation, so partial coverage weakens the core mechanism while still carrying the licence.

Overage / add-ons

Not disclosed.

Sales call required

Yes, required for paid access

Free / trial

Proof of value deployments historically offered; not confirmed in this pass

Commercial notes

Taken private by Thoma Bravo for approximately 5.3 billion USD in October 2024, delisting from London, so the historical financial transparency of a listed company no longer applies. Reported to be investing more than 200 million USD in US operations in 2026 and targeting 1 billion USD revenue around 2027, with US revenue rising from roughly 35 percent to 50 percent of total - which suggests commercial pressure toward larger US enterprise deals.

Key ambiguities

All commercial terms. Private equity ownership removes the public filings that previously gave some visibility into revenue and pricing structure while Darktrace was listed in London.

Missing data

All pricing, module rates, and how the four lifecycle products are packaged relative to the six coverage environments.

Agentic Index verified 2026-08-08

Alternatives to Darktrace

The closest documented capability profiles to Darktrace among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • Abnormal AI9.0 / 14Matches Darktrace across all 14 documented capabilities
  • Vanta8.5 / 14A lighter documented profile than Darktrace
  • Arctic Wolf9.0 / 14Fuller documented coverage on Human Oversight & Guardrails
  • Crogl10.0 / 14Fuller documented coverage on Human Oversight & Guardrails and Deployment & Data Residency
  • Magnitude9.0 / 14Fuller documented coverage on Security, Identity & Governance
  • Mycroft9.0 / 14Fuller documented coverage on Security, Identity & Governance

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.