About Guardian

We build the security platform we wished we had at 3 a.m.

Guardian was founded in 2016 by three people who had spent their careers on the wrong end of a breach call. A decade later, Guardian Sentinel defends 6,800 organisations in 142 countries — and the mission has not changed: give defenders back the time that attackers keep stealing from them.

Our mission

Make the defender faster than the adversary

Security has an arithmetic problem. An attacker needs one working path; a defender needs to hold every path, on every surface, at every hour, forever. For twenty years the industry answered that asymmetry by hiring more analysts and buying more consoles. It did not work — it just moved the bottleneck into the alert queue.

We believe the only durable answer is to give machines the parts of defence that machines are genuinely better at: watching everything, correlating everything, and acting in the first second rather than the first hour. Humans remain in charge of judgement, thresholds and accountability. That division of labour is the whole product thesis behind Guardian Sentinel — and the reason every autonomous action it takes is explainable, reversible and logged.

  • Autonomy with accountability. Every machine decision carries its evidence, its confidence score and a one-click rollback.
  • One graph, not one more console. Signals from every surface resolve to the same entities, so an incident is an incident — not five tickets in five products.
  • Your data stays yours. Regional data residency, customer-managed keys and a documented deletion path on every plan.

Founding story

It started with a breach nobody could explain

In March 2015, Marcus Reyes was running incident response for a global payments processor when an intrusion moved from a single contractor laptop to the card authorisation environment in under ninety minutes. The tooling was not missing. There were eleven security products deployed, and every relevant signal had been collected. They simply sat in eleven different places, owned by four different teams, none of which was awake at the same time.

The post-incident review ran to 140 pages. Its central finding was uncomfortable: no human, however good, could have joined those dots inside the attacker's window. The problem was not detection. It was the distance between detection and decision.

Marcus took that report to Dr. Amara Osei, a distributed-systems researcher who had spent four years building anomaly detection for network operators, and to Priya Raghunathan, who had shipped security products to regulated banks and knew exactly how much unexplained automation a risk committee will tolerate. In January 2016 the three of them incorporated Guardian Security in a converted warehouse in East Austin with one working hypothesis:

If the machine can see every surface at once, it can decide faster than the adversary can move — provided it can always show its work.

The first prototype did one thing: it fused endpoint process trees with authentication events and drew a single graph. It shipped to forty design partners in 2017 under the name Sentinel. The "show its work" requirement — an evidence trail attached to every automated action — was in the product from build one, because Priya was certain no bank would ever switch it on otherwise. She was right, and it remains the feature customers cite most often in renewals.

A decade on, Guardian employs 1,900 people across 24 offices, runs five 24/7 security operations centres, and correlates 4.2 trillion security events every week. Guardian Labs, our research arm, tracks 340 named adversary groups and publishes new detection logic to every customer tenant within hours of discovery. The warehouse is gone. The hypothesis held.

What we value

Six commitments we are willing to be measured against

Values are only useful if they cost something. Each of these has, at some point, led us to delay a release, refuse a deal or rewrite a subsystem.

Defender's advantage first

Every roadmap item answers one question: does this shrink the gap between what an attacker does and what a defender knows? Features that only improve a demo do not ship.

Evidence over assertion

We publish our efficacy methodology, our false-positive rates and our platform availability — including the quarters we missed our targets. If we claim a number on this website, you can ask us how we derived it.

Ship the boring parts

Agent stability, upgrade safety, RBAC, log export, deletion workflows. The work nobody writes a keynote about is the work that decides whether a platform survives its third year in production.

Adversary literacy

Every engineer at Guardian spends time in Guardian Labs during their first year. You cannot build detections for tradecraft you have never watched unfold in a live environment.

Customer sovereignty over data

Regional residency, customer-managed encryption keys, and no training of shared models on identifiable customer data without an explicit, revocable opt-in. We treat your telemetry as your property, because it is.

Radical clarity under pressure

During an incident — ours or yours — we say what we know, what we do not know, and when we will next update you. We publish our own security incidents to customers within 24 hours, whether or not disclosure is required.

Ten years

From forty design partners to a global platform

Guardian has raised $621 million across four institutional rounds and made two acquisitions. Every milestone below is a decision that changed what the platform could do for customers.

  1. 2016

    Guardian Security is incorporated

    Three founders, one warehouse in East Austin, and a prototype that fused endpoint process trees with authentication events into a single graph.

  2. 2017

    Sentinel ships to 40 design partners; Guardian Labs founded

    A $9M seed round funded the first research team. Guardian Labs published its first adversary profile — a commodity loader crew that later became one of the most prolific ransomware affiliates in Europe.

  3. 2018

    Series A, $32M — single-agent endpoint protection reaches GA

    One agent replaced antivirus, EDR and forensic collection. Customer count passed 400 and the first enterprise SOC deployment went live.

  4. 2019

    Series B, $80M — London and Singapore open; SOC 2 Type II

    Guardian's first two international offices and its first independent attestation. Regional data residency shipped the same year.

  5. 2020

    Cloud workload protection launches

    Container and Kubernetes runtime coverage arrived as remote work reshaped every customer's perimeter overnight. 1,250 organisations protected.

  6. 2021

    Series C, $190M — identity protection module; ISO 27001

    Identity became the dominant intrusion vector, so Guardian made it a first-class surface rather than a log source.

  7. 2022

    Kestrel Analytics acquired; Tokyo and Sydney open

    Kestrel's encrypted-traffic fingerprinting became Guardian's network detection engine, closing the last major telemetry gap in the platform.

  8. 2023

    The unified Sentinel platform launches; FedRAMP High authorisation

    Six modules collapsed into one console, one policy engine and one behavioural graph. Public-sector customers gained an authorised path to deployment.

  9. 2024

    Series D, $310M — 24/7 managed detection and response launches

    Guardian opened its fourth and fifth security operations centres and began offering a three-minute triage SLA to customers without an in-house SOC.

  10. 2025

    Sentinel AI Analyst reaches general availability

    Autonomous triage, narrative reconstruction and containment — with an evidence pack attached to every decision. Munich R&D centre opens.

  11. 2026

    6,800 organisations, 1,900 people, 24 offices

    Guardian now correlates 4.2 trillion security events a week and contains the median intrusion in 8.4 seconds.

Global presence

Follow-the-sun defence, staffed by people who live there

Five security operations centres hand over to each other every eight hours, so an incident raised in Frankfurt at 02:00 is triaged by a rested analyst in Austin. Twenty-four offices give customers local language, local regulation and local adversary context.

Austin London Tel Aviv Singapore Sydney 24/7 security operations centre Guardian office
Guardian operates 24 offices across five continents. Map is illustrative; see the contact page for registered addresses and regional entities.
Regional operations, as of 30 June 2026
Region Headquarters Offices People SOC coverage Data residency
North America Austin, Texas 9 880 Austin, 24/7 us-central, us-east, ca-central
Europe London, United Kingdom 7 520 London, 24/7 eu-west, eu-central, uk-south
Middle East & Africa Tel Aviv, Israel 3 210 Tel Aviv, 24/7 me-central, af-south
Asia Pacific Singapore 4 230 Singapore, 24/7 ap-southeast, ap-northeast, in-south
Oceania & LATAM Sydney, Australia 1 60 Sydney, 24/7 au-southeast, sa-east

Scroll the table sideways to see every column.

By the numbers

Ten years of compounding coverage

Growth matters here for one reason only: every additional protected estate makes the behavioural graph better at recognising an adversary the next customer has never seen before.

0 2,000 4,000 6,000 6,800 organisations 201620172018 201920202021 202220232024 20252026 Organisations protected by Guardian Sentinel, year end
6,800+ Organisations protected
142 Countries with active deployments
1,900 Guardians worldwide
340 Adversary groups tracked by Guardian Labs
$621M Raised across four institutional rounds
96% Gross revenue retention, trailing twelve months

How we operate

The questions we get asked most about the company

Is Guardian independent, and who owns it?

Guardian Security, Inc. is a privately held Delaware corporation. Ownership is split between the three founders, current and former employees, and four institutional investors with board representation. No customer, reseller or government entity holds an equity stake, and no single investor holds a controlling interest.

What happens to customer telemetry?

Telemetry stays in the region you select, encrypted at rest with keys you can manage yourself. We never sell, broker or share it with third parties. Shared detection models are trained on adversary artefacts and synthetic data by default; contributing identifiable customer data requires an explicit, written and revocable opt-in.

Our full commitments, sub-processor list and deletion timelines are documented on the trust and security page.

How does Guardian handle its own security incidents?

We run Guardian Sentinel against our own estate under the same policies we recommend to customers, and our internal SOC is staffed by the same rotation. Any incident that could affect customer data or platform integrity is disclosed to affected customers within 24 hours of confirmation, whether or not a regulator requires it, with a written root-cause analysis inside ten business days.

Do you work with government and defence customers?

Yes. Guardian holds FedRAMP High authorisation for its US public-sector environment and supports air-gapped deployments for classified networks. We publish an annual transparency report covering lawful-access requests, and we decline engagements where the platform would be used for domestic surveillance of civil society. That policy has cost us business, and we have kept it.

How is the company structured for remote and hybrid work?

Roughly 45% of Guardians are fully remote, 40% hybrid against one of our 24 offices, and 15% onsite by necessity — largely SOC analysts working in secured facilities. Every team publishes a written operating charter, and all decision-making happens in documents rather than meetings so that time zones never determine influence.

Read more on the careers page.

Join us

We are hiring defenders, builders and researchers

Guardian has open roles across threat research, platform engineering, security operations, product and go-to-market — in Austin, London, Munich, Tel Aviv, Singapore, Sydney and fully remote.