Cybersecurity · AWS
CrowdStrike
The Falcon platform is a cloud-native, single lightweight-agent architecture built on AWS that streams endpoint and cloud telemetry into CrowdStrike’s distributed NoSQL and object stores, processed by large-scale analytics and ML pipelines (e.g., EMR, SageMaker) to power detections, Threat Graph, and higher-level services like Next-Gen SIEM and Charlotte AI.[2][4][5][6][13][15] It operates as a multi-tenant SaaS service hosted on AWS regions, integrating deeply with AWS-native services and APIs while protecting workloads across on-prem, AWS, GCP, Azure, and other environments.[2][4][6][7][8][11][12][15]
Foundation proximity: Cloud-hosted (Bedrock/Vertex/Azure)
Foundational models & how they consume them
PrimaryCharlotte AI (CrowdStrike internal orchestration layer over multiple fine-tuned LLMs)· CrowdStrike on AWS · Cloud-hosted (Bedrock/Vertex/Azure)
SecondaryMultiple fine-tuned LLMs for security use cases (names not publicly disclosed)· Hosted and fine-tuned via Amazon SageMaker Large Model Inference (LMI) · Cloud-hosted (Bedrock/Vertex/Azure)
TertiaryEmbedding models for semantic search over Falcon data· Amazon SageMaker LMI + Amazon OpenSearch Service vector store · Cloud-hosted (Bedrock/Vertex/Azure)
Cloud & datastore
AWSDistributed NoSQL store for Threat Graph and telemetry (proprietary, AWS-hosted)[5]Amazon S3 for large-scale object storage of security telemetry and detections[5]Amazon OpenSearch Service (including vector store for embeddings)[5]Amazon EMR (data processing over scalable storage, likely HDFS/S3-backed)[5]Streaming/ETL pipelines for telemetry ingestion (precise tech not publicly confirmed; Kafka/Kinesis inferred by architecture)[5]Compliance
SOC 2 Type I[3][14]SOC 2 Type II[3][14]ISO/IEC 27001:2022[3][14]ISO/IEC 27017[3]ISO/IEC 42001:2023 (AI management system)[3][14]ISO 22301:2019[3]PCI DSS v4.0.1[3][10]FedRAMP High authorization for Falcon Platform for Government[3][14]GovRAMP (CrowdStrike public-sector program)[3]HIPAA (for applicable offerings)[10]CSA STAR Level 2[3][10]GDPR-aligned controls and attestations[10]NIST-aligned controls (including TX-RAMP listing)[10]Similar companies
OktaTorqAbnormal SecurityDarktracePalo Alto NetworksSentinelOneOthers that build on proprietary / self-built models
Abnormal SecurityAbridgeAdobeAI21 LabsAleph AlphaAmbienceExplore
FAQ
Does CrowdStrike use a foundational AI model?
CrowdStrike uses Charlotte AI (CrowdStrike internal orchestration layer over multiple fine-tuned LLMs), Multiple fine-tuned LLMs for security use cases (names not publicly disclosed), Embedding models for semantic search over Falcon data (Cloud-hosted (Bedrock/Vertex/Azure)).
What cloud does CrowdStrike run on?
CrowdStrike runs on AWS.
What database does CrowdStrike use?
CrowdStrike uses Distributed NoSQL store for Threat Graph and telemetry (proprietary, AWS-hosted)[5], Amazon S3 for large-scale object storage of security telemetry and detections[5], Amazon OpenSearch Service (including vector store for embeddings)[5], Amazon EMR (data processing over scalable storage, likely HDFS/S3-backed)[5], Streaming/ETL pipelines for telemetry ingestion (precise tech not publicly confirmed; Kafka/Kinesis inferred by architecture)[5].
How close does CrowdStrike run to the foundational model?
CrowdStrike is Cloud-hosted (Bedrock/Vertex/Azure) — further out, trading control for convenience.
Sources
crowdstrike.com ↗Also on the map
← Full orbit map (260 companies) · Score your own stack →
Architecture inferred from public sources · confidence medium · verify before betting on a detail.