Cybersecurity
Proximity
Native (own / self-hosted weights)
Models
proprietary / self-built models
Cloud · datastore
AWSPostgreSQLAmazon S3 (data lake/object storage)Elasticsearch/OpenSearch (log/search, inferred)
Compliance
SOC 2 (inferred from enterprise email security norm)ISO 27001 (inferred)GDPR-aligned data processing (inferred)
Architecture
Abnormal runs a cloud-native, API-first behavioral AI platform that integrates with cloud email and collaboration suites (e.g., Microsoft 365, Google Workspace) outside the mail flow, ingesting user, email, and identity telemetry into proprietary behavioral models and a data lake to drive detection, response, and human-risk scoring.[1][5][7][8][9] Its core is a proprietary behavioral foundation model and related ML pipelines hosted in its own cloud environment, exposed through its SaaS console and APIs rather than via public/open-source model distribution.[7][9]
Cybersecurity
Proximity
Cloud-hosted (Bedrock/Vertex/Azure)
Models
proprietary / self-built modelsmiddleware / wrappers
Cloud · datastore
AWSDistributed NoSQL store for Threat Graph and telemetry (proprietary, AWS-hosted)[5]Amazon S3 for large-scale object storage of security telemetry and detections[5]Amazon OpenSearch Service (including vector store for embeddings)[5]Amazon EMR (data processing over scalable storage, likely HDFS/S3-backed)[5]Streaming/ETL pipelines for telemetry ingestion (precise tech not publicly confirmed; Kafka/Kinesis inferred by architecture)[5]
Compliance
SOC 2 Type I[3][14]SOC 2 Type II[3][14]ISO/IEC 27001:2022[3][14]ISO/IEC 27017[3]ISO/IEC 42001:2023 (AI management system)[3][14]ISO 22301:2019[3]PCI DSS v4.0.1[3][10]FedRAMP High authorization for Falcon Platform for Government[3][14]GovRAMP (CrowdStrike public-sector program)[3]HIPAA (for applicable offerings)[10]CSA STAR Level 2[3][10]GDPR-aligned controls and attestations[10]NIST-aligned controls (including TX-RAMP listing)[10]
Architecture
The Falcon platform is a cloud-native, single lightweight-agent architecture built on AWS that streams endpoint and cloud telemetry into CrowdStrike’s distributed NoSQL and object stores, processed by large-scale analytics and ML pipelines (e.g., EMR, SageMaker) to power detections, Threat Graph, and higher-level services like Next-Gen SIEM and Charlotte AI.[2][4][5][6][13][15] It operates as a multi-tenant SaaS service hosted on AWS regions, integrating deeply with AWS-native services and APIs while protecting workloads across on-prem, AWS, GCP, Azure, and other environments.[2][4][6][7][8][11][12][15]