Company breakdown · 2026-09-21

Sysdig

Sysdig is a cloud-native security company built on the open source Falco runtime engine. Its Sysdig Sage assistant applies generative AI to runtime findings so analysts can investigate and explain cloud attacks faster.

Emerging tierCloud Defense AgentsPublic data only
2013
Founded
Not verified
Employees
San Francisco, California
Headquarters
Private, venture backed
Ownership

What Sysdig does

Sysdig sells a cloud-native application protection platform that combines runtime threat detection, vulnerability management, posture management, and identity risk analysis. The technical core is Falco, the open source runtime security engine that Sysdig created and contributed to the Cloud Native Computing Foundation, where it reached graduated status. Commercial capability is delivered through Sysdig Secure for security teams and Sysdig Monitor for cloud and container observability, both documented in the company's product documentation.

The company was founded in 2013 by Loris Degioanni and is headquartered in San Francisco, California. It remains privately held and venture backed, and it has announced multiple financing rounds through its press release archive. Sysdig's AI layer, Sysdig Sage, is positioned as a cloud security analyst that sits on top of the same telemetry the platform already collects rather than as a separately deployed product line.

The agentic products

Documented from public materials · these are the products the AMS scores

Sysdig Sage

Shipping since 2024

Sysdig Sage is the company's generative AI cloud security analyst. It is exposed inside the Sysdig platform interface and works against the platform's own runtime, posture, and vulnerability data, summarizing findings, explaining detected activity, and guiding analysts through investigation steps. Public documentation and company materials describe it as an assistive layer for human analysts rather than an autonomous remediation engine. See sysdig.com and the Sysdig documentation.

Sysdig Secure

Shipping since 2018

Sysdig Secure is the commercial cloud-native application protection platform. Documented capability covers runtime threat detection built on Falco rules, container and host vulnerability management, cloud and Kubernetes posture management, identity and permission analysis, and incident response workflows for containers and cloud accounts. Deployment options include an agent installed on hosts and clusters as well as agentless cloud account connections, both described in the Sysdig documentation.

Falco

Falco

Falco is the open source runtime security project created by Sysdig and donated to the Cloud Native Computing Foundation, where it is a graduated project. It inspects kernel-level system calls and Kubernetes audit events against a rules engine to raise runtime alerts. Falco is free to use and forms the detection foundation that Sysdig extends commercially. See falco.org and the CNCF project page.

Recent moves

2024 - 2026 ·gold = a monetization move· grey = product or capital

Leadership change2024-01-01

Sysdig named William Welch chief executive officer, moving him from a co-leadership role into sole responsibility for the company. The announcement is listed in the company's press release archive.

Open source milestone2024-02-01

Falco, the runtime detection engine created by Sysdig, reached graduated status in the Cloud Native Computing Foundation. Graduation confirmed project maturity and governance independence while keeping Sysdig as the primary commercial distributor of Falco-based detection. See the CNCF project page and falco.org.

How Sysdig charges today

Pricing not public. Sysdig does not publish enterprise list prices for Sysdig Secure or for Sysdig Sage on its public website, and commercial terms are handled through sales engagement. Buyers can review the company's commercial pages at sysdig.com, but no rate card, tier price, or per-unit list figure is available in public sources as of the research cutoff.

What is documented publicly is the shape of consumption rather than the price. Sysdig's documentation describes deployment through host and cluster agents and through agentless connections to cloud accounts, which establishes hosts, nodes, containers, and connected cloud accounts as the natural units of measurement for a subscription. Falco remains free and open source under the Cloud Native Computing Foundation, so the paid boundary sits at managed detection content, platform workflows, retention, and support rather than at the detection engine itself.

There is no public evidence that Sysdig Sage carries its own meter, credit pool, or separate price. Public materials present Sage as a capability inside the platform interface that operates on data the customer already sends to Sysdig, which means AI usage is bundled into the underlying platform subscription rather than charged as a distinct consumption line.

Our monetization breakdown

Analyst layer · placement follows the documented capability above

Independence. Sysdig Sage is documented as an assistant that summarizes findings, answers analyst questions, and guides investigation. Public materials do not describe autonomous containment, unattended remediation, or closed-loop policy change without human approval. On that documented record, more than half of the work in an investigation still sits with the human responder, which places independence at S.

Job width. The relevant job is cloud threat investigation and triage inside the security function. Sysdig covers detection, context assembly across runtime, posture, vulnerability, and identity data, and investigative narrative in a single workflow, which is an end-to-end workflow inside one function rather than cross-functional work. That places job width at M.

Output versus cost. The economic effect is compression of manual investigation and rule authoring time against a subscription that is priced on infrastructure footprint rather than on analyst hours. Runtime detection at kernel level across large container estates, with AI summarization layered on top, produces throughput well above a one to ten multiple on manual review, but public evidence does not support a hundredfold or greater shift. That places output versus cost at Inflecting.

Documented monetization pattern. Sysdig monetizes a platform subscription sized to infrastructure, not an AI meter. The open source Falco engine is given away and the commercial value sits in managed content, workflows, scale, and support. Because Sage is bundled rather than separately metered, AI adoption currently shows up as retention and platform expansion rather than as a discrete revenue line, and no public pricing evidence contradicts that structure as of the cutoff.

Score and metric history

EditionAMS scoreMetric on recordChange
Aug 2026S · M · InflNo public list pricing; AI assistant bundled into platform subscriptionBaseline, first edition

Future editions add a row whenever the score or the metric moves, with the evidence that moved it.

Sources

About this data

Everything on this page is a synthesis of public information: published reporting, vendor documentation, and procurement data that anyone can access. We link to those sources throughout. Nothing on this page draws on private or confidential information, and the positions are Monetizely's analysis of that public record, refreshed monthly.