◆ Gentoo Logic · Modeling Warehouse

Architecture comparison

Palo Alto Networks vs SentinelOne

Palo Alto Networks runs closer to the foundational model (Native (own / self-hosted weights)) than SentinelOne (Native (own / self-hosted weights)). Shared foundation: proprietary / self-built models, Anthropic · Claude (highlighted).

Palo Alto Networks

Cybersecurity

Proximity
Native (own / self-hosted weights)
Models
proprietary / self-built modelsAnthropic · Claude
Cloud · datastore
Multi-CloudAmazon RDSAmazon RedshiftAmazon NeptuneAmazon OpenSearch ServiceRedisS3 (data lake / cold storage)Proprietary PAN-OS / Cortex / Prisma data stores
Compliance
SOC 2ISO 27001FedRAMPHIPAAPCI-DSS
Architecture

Palo Alto Networks runs a multi-cloud SaaS architecture with AWS as the primary runtime for major platforms like Prisma Cloud, using services such as RDS, Redshift, Neptune, OpenSearch, Redis, and S3 alongside Kubernetes-based microservices for data ingestion, analytics, and Infinity Graph. GCP (including Vertex AI) and Azure are used selectively for AI/ML workloads and cloud-native firewall offerings, with proprietary security engines and data stores layered on top of these managed services.

SentinelOne

Cybersecurity

Proximity
Native (own / self-hosted weights)
Models
proprietary / self-built modelsAnthropic · ClaudeOpenAI · GPT
Cloud · datastore
AWSownSnowflake
Compliance
SOC 2FedRAMP
Architecture

Purple AI combines SentinelOne’s own Ultraviolet models with Anthropic Claude + OpenAI GPT over its Singularity data lake; exposes a Purple MCP server for agentic SOC investigation.

← Full orbit map · Score your own stack →