Pangea
API-based security platform for application developers, now including AI guardrails, acquired by CrowdStrike in 2025.
Visit Website ↗ + Add to Compare Claim This CompanyOverview
Pangea (marketed as Pangea Cyber) built a “Security Platform as a Service”: a catalog of API-based security building blocks — authentication, authorization, audit logging, secrets management, PII redaction, file and URL scanning, and threat-intelligence lookups — that application developers can drop into their own software with a few lines of code instead of building and maintaining the equivalent security logic themselves. More recently the company shifted emphasis toward AI security, offering guardrail APIs that let teams add prompt-injection defense, output filtering, and other controls to AI applications without building that infrastructure from scratch.
Founded in 2021 by Oliver Friedrichs and Sourabh Satish — who previously built Phantom Cyber, a SOAR platform Splunk acquired in 2018 — Pangea is based in Palo Alto and raised roughly $53.5 million across a $25 million Series A (May 2022, led by Ballistic Ventures) and a $26 million Series B (November 2022, led by GV). On September 17, 2025, CrowdStrike announced it had acquired Pangea, folding its API-based security and AI guardrail services into CrowdStrike’s own platform.
Innovation Matrix Assessment
Evolved from general developer-security APIs (auth, redaction, secrets) to a dedicated AI-guardrails product line as demand shifted toward securing AI applications, shipping new capability areas over roughly four years of independent operation.
Lets engineering teams without dedicated AppSec staff add authentication, redaction, and AI guardrails via API calls instead of building that logic in-house, a real reduction in engineering burden.
Raised roughly $53.5M across a $25M Series A (Ballistic Ventures) and $26M Series B (GV) from credible investors, and was acquired by CrowdStrike in September 2025 — strong, independently verifiable momentum.
API-based 'security as a service' is a real and growing pattern, but Pangea is one of several vendors pursuing it rather than the sole definer of the category.
No independent benchmarks, audits, or named customer case studies with concrete outcome metrics were found; efficacy claims rely on vendor descriptions.
Embedding security and AI-guardrail controls directly into application code via API is likely to stay relevant as AI-native application development accelerates and teams look to avoid building guardrails from scratch.
Why CISOs Should Care
Lets engineering teams bake in authentication, data redaction, and AI-application guardrails via API calls, reducing the odds that security gets skipped under deadline pressure.
What Makes It Different
Packages security controls, including AI guardrails, as discrete, composable APIs rather than as a platform requiring adoption of a full product suite.
The Matrix Verdict
65/100 — INCREMENTAL INNOVATOR
Incremental Innovator. Pangea built a credible API-security business, raised meaningful capital from name-brand investors, and reached a strong outcome via its 2025 acquisition by CrowdStrike, but independent efficacy evidence is limited and the API-security-as-a-service approach is not unique to Pangea.
Editorial Note: Claims vs. Verified Findings
Funding amounts and the CrowdStrike acquisition are independently reported; efficacy and guardrail-effectiveness claims come from Pangea/CrowdStrike marketing materials.
Sources
- Series A announcement (BusinessWire) — https://www.businesswire.com/news/home/20220517005446/en/Pangea-Cyber-Secures-$25M-Series-A-to-Launch-API-based-Cloud-Security-Services-for-Application-Builders
- TechCrunch coverage — https://techcrunch.com/2022/11/30/pangea-cyber-wants-to-simplify-security-for-developers-with-an-api-approach
- Pangea website — https://pangea.cloud/
Alternatives to Pangea
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…