Deepwatch
A managed detection and response provider using a named-analyst "Squad" delivery model and deep Splunk-ecosystem ties, backed by $256M in total funding including a Splunk Ventures-led 2023 round.
Visit Website ↗ + Add to CompareOverview
Deepwatch is a managed detection and response (MDR) provider that layers its own analytics platform and a 24/7 security operations center staffed by in-house analysts on top of a customer’s existing security stack — SIEM, EDR, and cloud logs — aimed at organizations that want continuous threat detection and response without building a full internal SOC.
Founded in 2019 and originally headquartered in Tampa, Florida, Deepwatch relocated its headquarters to Palo Alto, California in 2025 as part of a broader push upmarket. The company has raised roughly $256M to date, including a $180M round in February 2023 backed by Splunk Ventures, Vista Credit Partners, and ABS Capital, alongside earlier investment from Goldman Sachs — a notably deep and strategic investor base for an MDR vendor, given Splunk’s position as a leading SIEM platform.
Deepwatch operates in the crowded MDR market alongside providers like Arctic Wolf, Expel, and Red Canary. Its differentiation is a “Squad” delivery model — a small, consistent, named team of analysts assigned per customer rather than a rotating shift-based SOC — combined with close integration into the Splunk ecosystem via Splunk Ventures’ strategic stake.
The scale of Deepwatch’s institutional backing implies real investor diligence, but the company has not published independent, third-party-validated detection or response performance metrics (of the kind found in, for example, MITRE ATT&CK Evaluations) that would substantiate its efficacy claims beyond its own marketing.
Innovation Matrix Assessment
Continued platform investment (its analytics engine) and a 2023 raise explicitly earmarked for 'platform innovation and product development' indicate active investment, though no independent release-cadence tracking exists for a services-heavy MDR offering.
MDR is inherently designed to sit atop a customer's existing tools (SIEM/EDR/cloud logs) rather than requiring a rip-and-replace, and Deepwatch's named-analyst 'Squad' delivery model is a documented, differentiated operational approach versus rotating-shift SOCs.
$256M total raised, including a large 2023 round with a strategic investor (Splunk Ventures) and growth-stage lenders (Vista Credit Partners), plus a 2025 headquarters move upmarket to Palo Alto, are real, independently verifiable momentum signals.
MDR as a category is now mature and well-established; Deepwatch's Squad model and Splunk-ecosystem depth are competitive differentiators within the category rather than a fundamentally new approach to detection and response.
The scale of institutional backing (Goldman Sachs, Splunk Ventures) implies investor diligence found real traction, but Deepwatch has not published independent, third-party-validated detection/response performance metrics that this review could verify.
MDR remains one of the highest-demand categories in security operations as organizations struggle to staff 24/7 SOCs internally, making Deepwatch's core offering highly relevant to the current buyer environment.
Why CISOs Should Care
For a CISO who has decided to outsource 24/7 detection and response rather than staff an internal SOC, Deepwatch's named-analyst delivery model and deep Splunk-ecosystem integration are concrete reasons to shortlist it against MDR peers like Arctic Wolf or Expel.
What Makes It Different
A 'Squad' model that assigns a small, consistent, named analyst team per customer rather than a rotating shift-based SOC, combined with a strategic capital relationship with Splunk.
The Matrix Verdict
62/100 — INCREMENTAL INNOVATOR
A well-capitalized, credible MDR provider with real institutional backing and a differentiated delivery model, competing in a mature category where independent, third-party efficacy validation remains the main gap in public evidence.
Editorial Note: Claims vs. Verified Findings
Total funding (~$256M) and the February 2023 $180M round with named investors (Splunk Ventures, Vista Credit Partners, ABS Capital, Goldman Sachs) are independently reported by multiple outlets (SiliconANGLE, VentureBeat, BankInfoSecurity). Specific detection/response performance and efficacy claims on Deepwatch's own site are vendor-stated and were not independently verified in this review.
Sources
Alternatives to Deepwatch
Abnormal AI
AI-native behavioral security platform that analyzes sender identity and communication patterns, rather than message content alone, to stop…
Palo Alto Networks Cortex XSIAM
Palo Alto Networks' AI-driven 'autonomous SOC' platform that unifies SIEM, EDR, SOAR, and attack-surface data into a single…
Fenix24
Chattanooga-based ransomware recovery specialist that has restored operations after 500+ real-world incidents, including 30 Fortune 500 companies.
Torq
AI-native hyperautomation platform positioning itself as an 'agentic SOC,' using a multi-agent system to autonomously execute large volumes…
Anvilogic
Palo Alto-based AI security operations platform that automates SOC detection engineering across existing SIEMs and data lakes without…
Tines
No-code security automation platform letting SOC teams build and share automated workflows ('Stories') without proprietary scripting or vendor…