Company breakdown · 2026-09-21

Sysdig

Sysdig provides a cloud security platform with AI-based defense agents that investigate, prioritize, and help remediate risks across cloud infrastructure, Kubernetes, containers, hosts, and serverless workloads. Its agentic and headless offerings extend the platform into security workflows and AI coding agents.

Established tierCloud Defense AgentsPublic data only
2013
Founded
722 estimated, Mar. 2026
Employees
San Francisco, CA
Headquarters
Venture-backed private company
Ownership

What Sysdig does

Sysdig is a privately held cloud security vendor founded in 2013 by Loris Degioanni. Its Sysdig Secure platform combines cloud security posture management, identity and entitlement management, vulnerability management, runtime detection and response, and attack-path analysis for cloud-native environments.

The company is headquartered in San Francisco and remains venture-backed. Sysdig last publicly announced a $350 million Series G financing in December 2021, led by Permira's growth fund. Employee-count data is not company disclosed; Revelio Labs estimated 722 employees worldwide as of March 2026.

The agentic products

Documented from public materials · these are the products the AMS scores

Sysdig Secure AI

Shipping since 2026

Generally available from August 2026, Sysdig Secure AI is an AI-native offering built on Sysdig Secure. It includes agentic AI in the Sysdig interface, Headless Cloud Security for external AI coding-agent workflows, and a GenAI assistant. Sysdig states that the agents can investigate, prioritize, and respond to cloud risks while retaining auditable actions and customer-defined guardrails.

Sysdig Headless Cloud Security

Shipping since 2026

Launched in May 2026, Headless Cloud Security delivers Sysdig CNAPP capabilities through plug-ins, command-line interfaces, Model Context Protocol services, and APIs for use in AI coding-agent workflows. Sysdig documents use cases for vulnerability prioritization and fixes, posture remediation, runtime-threat investigation, and guided onboarding.

Sysdig Secure

Sysdig Secure

Sysdig Secure is the company's cloud-native application protection platform. It covers cloud, containers, Kubernetes, hosts, and serverless workloads, with agent-based and agentless scanning, in-use vulnerability prioritization, posture and permissions management, and real-time detection and response. It supplies the cloud-security foundation for Sysdig Secure AI.

Recent moves

2024 - 2026 ·gold = a monetization move· grey = product or capital

Product launch2024-07-31

Sysdig introduced Sysdig Sage for Cloud Detection and Response, an AI security analyst designed to help users analyze and investigate cloud-detection events. Source

Product launch2025-08-05

Sysdig announced agentic cloud security, with specialized AI agents for semantic analysis, risk prioritization, remediation guidance, ticket creation, and ownership assignment. The release was offered as early access to eligible Sysdig Sage platform customers. Source

How Sysdig charges today

Pricing not public. Sysdig directs prospective buyers to request a quote rather than publishing list prices. Its public pricing page states that CNAPP licensing is based on the number of hosts in a customer's environment, with compute instances used for CSPM. Detection and response is also host based, with cloud-log detection licensed per events processed.

Subscription documentation shows product tier, contract billing cycle, and reserved and on-demand resources. Documented meters include units or host agents, serverless agents, cloud-log volume, and, for applicable subscriptions, time series. Public materials reviewed do not document standard contract lengths, discount schedules, or committed-spend discounts.

The AI offering has a distinct documented usage meter: Sysdig Sage prompts are metered per prompt, with included prompt limits and monthly usage shown in subscription reporting. The documentation does not publish a separate unit price for prompts or a separate public meter for headless or agentic AI actions.

Our monetization breakdown

Analyst layer · placement follows the documented capability above

Independence: Moderate. This is a provisional assessment. Sysdig's documented agents can investigate, prioritize, generate remediation guidance, create tickets, assign ownership, and operate within customer-defined guardrails. Sysdig also states that people define desired outcomes and remain in control for critical decisions.

Job width: Cross-functional. The documented agent workflows span cloud-security activities that commonly cross security operations, cloud engineering, platform engineering, and development teams: vulnerability remediation, posture management, runtime-threat investigation, ticketing, ownership assignment, and AI coding-agent workflows.

Output versus cost: Inflecting. Sysdig documents that Secure AI can shift repetitive investigation, ticketing, reporting, and coordination work to AI agents. The company publishes an illustrative comparison of more than 10 times as many investigations at 88% lower cost. This is vendor-reported evidence and is used only to support the provisional inflecting classification.

Monetization pattern. Sysdig monetizes the underlying platform through contracted host, compute, unit, event, and usage-based entitlements rather than publishing standalone agent prices. The public subscription documentation identifies a separate prompt meter for Sysdig Sage, now described by Sysdig as its GenAI assistant, indicating that AI-assistant usage can be separately entitled and monitored.

Score and metric history

EditionAMS scoreMetric on recordChange
Aug 2026M · L · InflProvisional AMS score based on publicly documented Sysdig Secure AI and Headless Cloud Security capabilities.Baseline, first edition

Future editions add a row whenever the score or the metric moves, with the evidence that moved it.

Sources

About this data

Everything on this page is a synthesis of public information: published reporting, vendor documentation, and procurement data that anyone can access. We link to those sources throughout. Nothing on this page draws on private or confidential information, and the positions are Monetizely's analysis of that public record, refreshed monthly.