Company breakdown · 2026-08-26

Lumu

Lumu Technologies provides a continuous compromise assessment platform that ingests network and log metadata to detect active threats, with automation features that can trigger response actions through existing security infrastructure.

Tracked tierPublic data only
2019
Company founded
Miami, Florida
Headquarters
Privately held
Ownership
Cisco Investments, Adams Street Partners
Notable investors

What Lumu does

Lumu Technologies operates a cloud-based platform built around what it calls Continuous Compromise Assessment, a model that analyzes network metadata, DNS traffic, logs, and other telemetry to identify indicators of compromise in near real time. The platform correlates this data against threat intelligence sources and presents findings through a dashboard that security teams use to prioritize incident response. Lumu also offers automation capabilities, marketed as Lumu Playbooks and integrations with firewalls, EDR tools, and SOAR platforms, allowing detected threats to trigger blocking or containment actions without full manual intervention.

The company is privately held and headquartered in Miami, Florida, with additional operations supporting customers across Latin America and North America. Lumu has raised venture funding from investors including Adams Street Partners and Cisco Investments, and it positions its platform as a complement to or replacement for traditional SIEM-heavy detection stacks. Public information on total headcount, revenue, or full customer counts is limited, and Lumu does not disclose these figures in detail through public filings since it remains a private company.

The agentic products

Documented from public materials · these are the products the AMS scores

Lumu Continuous Compromise Assessment

Shipping since 2019

The core platform ingests DNS queries, network flow data, and logs to detect compromise indicators continuously rather than relying solely on point-in-time scans. It maps findings against the MITRE ATT&CK framework and provides a compromise level score intended to help security teams prioritize response.

Lumu Playbooks

Shipping since 2021

Playbooks allow customers to define automated response actions, such as blocking malicious domains or IP addresses, that execute when the platform detects specific threat conditions. Playbooks integrate with third-party firewalls, EDR, and SOAR tools to carry out these actions inside the customer's existing security infrastructure.

Recent moves

2024 - 2026 ·gold = a monetization move· grey = product or capital

Funding round2022-01-01

Lumu raised a Series B funding round to expand its compromise assessment platform and go-to-market operations. Source

Product expansion2023-01-01

Lumu expanded its integration ecosystem and automation capabilities within Lumu Playbooks to support additional third-party security tools for automated response. Source

How Lumu charges today

Lumu does not publish pricing on its website, and no procurement or public filing data on pricing metrics was located as of the research cutoff. Industry commentary and Lumu's own marketing describe packaging tiers that reportedly scale with elements such as number of protected devices, data volume ingested, or number of network endpoints, but no verifiable figures or contract terms are publicly available to confirm this structure.

Pricing not public. Lumu's sales process is presented as consultative, requiring prospective customers to request a demo or quote directly, which is typical for mid-market and enterprise security vendors that negotiate contracts individually based on organization size and deployment scope.

There is no public evidence that Lumu separately meters or prices its Playbooks automation feature apart from the core platform subscription. No public information confirms whether automation actions carry usage-based or consumption-based pricing distinct from the base compromise assessment service.

Our monetization breakdown

Analyst layer · placement follows the documented capability above

Independence. Lumu's Playbooks feature can execute automated response actions, such as blocking a malicious domain, without requiring a human to manually approve each action once a playbook is configured. However, playbook rules must be defined and approved by security staff in advance, and most customers appear to use the platform primarily for detection and alerting rather than fully autonomous remediation, indicating meaningful human oversight remains standard practice.

Job width. The platform is scoped to a single function within the security operations workflow: detecting network-based compromise indicators and optionally triggering a narrow set of response actions such as blocking or isolating a threat. It does not extend into adjacent workflows like vulnerability management, identity governance, or broader IT operations, keeping its job width narrow and single-task oriented.

Output versus cost. Public evidence does not demonstrate an order-of-magnitude shift in detection throughput or response speed compared to conventional SIEM or network detection tools. Lumu markets continuous, real-time analysis as a differentiator over periodic scanning, but no published benchmark data supports a multiplier claim beyond incremental improvement, placing the output-to-cost profile in a linear range based on available evidence.

Monetization pattern. Lumu's public-facing commercial model follows a traditional subscription and quote-based enterprise security sales motion rather than a distinct usage-based or outcome-based pricing structure tied to automated actions. There is no public evidence of a separate meter, credit system, or consumption charge specifically tied to Playbooks or other automation features, suggesting the company has not yet introduced agent-specific monetization distinct from its core platform subscription.

Score and metric history

EditionAMS scoreChange
Aug 2026M · S · LinBaseline, first edition

Future editions add a row whenever the score or the metric moves, with the evidence that moved it.

Sources

About this data

Everything on this page is a synthesis of public information: published reporting, vendor documentation, and procurement data that anyone can access. We link to those sources throughout. Nothing on this page draws on private or confidential information, and the positions are Monetizely's analysis of that public record, refreshed monthly.