How Cybersecurity companies build with AI — which foundational models they run and how directly, ranked by proximity to the model. Avg Foundation Proximity Score 55/100.
Cybersecurity · AWS · Native (own / self-hosted weights)
Abnormal runs a cloud-native, API-first behavioral AI platform that integrates with cloud email and collaboration suites (e.g., Microsoft 365, Google Workspace) outside the mail flow, ingesting user, email, and identity telemetry into proprietary behavioral models and a data lake to drive detection, response, and human-risk scoring.[1][5][7][8][9] Its core is a proprietary behavioral foundation model and related ML pipelines hosted in its own cloud environment, exposed through its SaaS console and APIs rather than via public/open-source model distribution.[7][9]
Cybersecurity · Hybrid · Native (own / self-hosted weights)
Self-Learning AI built in-house; models the network rather than calling an LLM.
Cybersecurity · Multi-Cloud · Native (own / self-hosted weights)
Palo Alto Networks runs a multi-cloud SaaS architecture with AWS as the primary runtime for major platforms like Prisma Cloud, using services such as RDS, Redshift, Neptune, OpenSearch, Redis, and S3 alongside Kubernetes-based microservices for data ingestion, analytics, and Infinity Graph. GCP (including Vertex AI) and Azure are used selectively for AI/ML workloads and cloud-native firewall offerings, with proprietary security engines and data stores layered on top of these managed services.
Cybersecurity · AWS · Native (own / self-hosted weights)
Purple AI combines SentinelOne’s own Ultraviolet models with Anthropic Claude + OpenAI GPT over its Singularity data lake; exposes a Purple MCP server for agentic SOC investigation.
Cybersecurity · GCP · Native (own / self-hosted weights)
Developer-security platform on GCP/AWS scanning code and dependencies; DeepCode AI combines symbolic analysis with ML for fix suggestions. Backed by a curated open-source vulnerability database.
Cybersecurity · AWS · Cloud-hosted (Bedrock/Vertex/Azure)
The Falcon platform is a cloud-native, single lightweight-agent architecture built on AWS that streams endpoint and cloud telemetry into CrowdStrike’s distributed NoSQL and object stores, processed by large-scale analytics and ML pipelines (e.g., EMR, SageMaker) to power detections, Threat Graph, and higher-level services like Next-Gen SIEM and Charlotte AI.[2][4][5][6][13][15] It operates as a multi-tenant SaaS service hosted on AWS regions, integrating deeply with AWS-native services and APIs while protecting workloads across on-prem, AWS, GCP, Azure, and other environments.[2][4][6][7][8][11][12][15]
Cybersecurity · AWS · Middleware / wrapper
AWS-native identity cloud (workforce + Auth0 customer identity) on MySQL/DynamoDB with a multi-tenant cell architecture. AI is in-house threat-detection ML plus assistant LLMs.
Cybersecurity · AWS · Middleware / wrapper
Security hyperautomation; routes partner LLMs through its SOC workflow engine.
Cybersecurity · Hybrid · Off the LLM map (in-house non-LLM ML)
1Password’s production architecture is centered on a zero-knowledge, end-to-end encrypted vault service, where plaintext is encrypted on the client before reaching 1Password’s servers. Publicly available sources confirm hybrid cloud deployment patterns for components such as the SCIM bridge, but they do not reliably expose the company’s full internal database stack or all backend infrastructure details.
Cybersecurity · Multi-Cloud · Off the LLM map (in-house non-LLM ML)
Wiz operates as a SaaS platform with an agentless, multi-cloud security architecture that ingests cloud, workload, identity, and data metadata into a unified Security Graph. Its production environment is described as immutable infrastructure managed through infrastructure-as-code, with isolated production databases and cloud-native encryption, but the exact underlying database vendors are not publicly disclosed.
Cybersecurity · On-Prem · Off the LLM map (in-house non-LLM ML)
Own global proxy cloud + in-house ML; off the LLM map at the core.