Skip to main content
Panther Labs logo
Risk & ComplianceFounded 2018 · 8 yrs

Panther

Detect, investigate, and respond to threats at cloud scale — powered by code and AI.

By Panther Labs · 4.7/5 Value-Position score (estimate)

Positioning guardrails

Best for

  • Security teams replacing legacy SIEMs such as Splunk, Sumo Logic, or Elastic who want detections managed as code.
  • AWS-heavy cloud environments that want security data to stay in their own AWS account and Snowflake or Databricks warehouse.
  • SOC teams without dedicated detection engineers — built-in detection library plus AI and Simple detection builders lower the coding bar.
  • Security leaders trying to cut alert volume and investigation time; Panther cites 85% lower alert volume and 90% less investigation time.
  • Teams that want every AI action governed with human approval, logging, and configurable auto-resolve thresholds.

Ideal size: 2–50 security engineers people · Cloud-native scale-up or enterprise with an existing SOC or security engineering function

Not for

  • Organizations that need an on-premises or air-gapped deployment; Panther runs connected to your cloud data platform or fully hosted by Panther.
  • Buyers who want published self-serve list pricing and instant signup rather than a sales-led enterprise evaluation.
  • Teams with no cloud, SaaS, or identity log sources to ingest — Panther's value depends on petabyte-scale security data.

Value metrics scorecard

Time-to-Value

Days to first logs and detections

~7 days to first production value

Total Cost of Ownership

On request

Not published; sales-led enterprise pricing. Deploy against your own AWS, Snowflake or Databricks accounts, or in Panther's managed cloud.

Implementation Friction

2/5

Engineering + admin effort required

Value-Position score

4.7

out of 5 · model estimate

Full cost breakdown

Mandatory implementation fee

None

Seat tiers

Not listed

Add-on costs

  • None

Company & support

Who is behind Panther, and how your team gets help once it is live.

Company

Founded
2018 · 8 yrs in business
Headquarters
Not recorded

How you get support

  • PhoneNot listed
  • EmailPaid plans
  • Live chatPaid plans
  • Support portal / ticketsNot listed
  • Community forumAll plans
  • Help centre / docsAll plans
  • Dedicated account managerNot listed
  • In person / on-siteNot listed
Hours
24/7
Response time
Not stated

Standard technical support is 20 hours a day, 5 days a week via a dedicated Slack channel, in-app chat, or email. 24/7 on-call emergency support is offered to all customers.

“Not listed” means the vendor’s public pages don’t mention that channel, not that it is unavailable. Ask about it during evaluation.

Market position

Where Panther sits against its closest alternatives. Pick any two of cost, speed, friction and buyer score, and up to 9 companies to compare.

Quadrant view

Typical annual cost × Time-to-value

$0/yr$1/yr1d3d7d17d39dAnnual TCO ← betterDays to value better →Quick & CheapQuick & PriceySlow & CheapSlow & PriceyPantherPeblMalbekDidomiOsanoAdmin By Request

The lines cross at the median of the solutions shown, so about half sit on each side of each line.

Panther is outlined. Click any dot to open its dossier.

Companies on the chart 6 / 10

  • Panther
  • Pebl
  • Malbek
  • Didomi
  • Osano
  • Admin By Request
Add or change companies

Up to 10 companies including Panther. Listed closest first.

Stack fit signal

Compatibility with standard B2B ecosystems.

MCPNot supported

No supported MCP path today, so it cannot be driven from an AI client.

SalesforceNot supported
AWSNative
SnowflakeNative
HubSpotNot supported
Google WorkspaceNot supported
Microsoft 365Not supported
SAPNot supported
SlackIntegration

AI & MCP readiness

What Panther ships in AI, and what it asks of your ecosystem.

AI features shipped

AI added to an existing product
Agentic workflowsAI searchNLP automationAI governance tooling

AI SOC Agent runs scheduled and on-demand investigations across the data lake, classifies risk, auto-resolves low-risk alerts, drafts detections from natural language, and proposes tuning as reviewable Python. Human approval is required for writes and every AI action is logged.

Your data & models

Trains on your data
Never trains on your data
Runs on
Amazon
AI pricing
Not recorded

In your ecosystem

AI connection
Not supported
Model key
Not recorded
AI usage audit
Full audit trail

Compliance attestations

SOC 2 ISO 27001 GDPR — not listedHIPAA — not listedFedRAMP — not listedISO 42001 — not listedIAPP AIGP* — not listed

* IAPP AIGP certifies individuals, not products. It means named staff hold the credential — not that the platform does.

Bottom line

Panther is a cloud-native SIEM and AI SOC platform from Panther Labs. It ingests and normalizes security logs into a data lake in your own AWS, Snowflake or Databricks account or in Panther's managed cloud, runs Python detection-as-code, and applies an AI SOC Agent to alert triage, investigation, threat hunting and detection tuning. Human approval is required for every AI write and all AI actions are logged. Panther is now part of Databricks Lakewatch.

Frequently asked questions

Can Panther replace our existing SIEM?

Yes. Panther states that many customers migrate from Splunk, Sumo Logic, or Elastic. It is particularly well suited to AWS-heavy environments and teams who want to treat detections like software; teams that rely on GUI-based rule building can use Panther's Simple and AI Detection Builders.

How long does implementation take?

Panther says most teams are ingesting logs and running detections within days, not months. The main work is integrations, data validation, and tuning rather than infrastructure setup, and one customer reports standing up a fully deployed in-house enterprise SOC in a matter of weeks.

What does Panther cost?

Panther does not publish list pricing and sells through a sales conversation, so buyers should expect a bespoke quote. Published customer results cite large savings: Cockroach Labs cut SecOps costs by over $200K while processing 5x more data, and Zapier estimates $400K in annual savings.

Where does our security data live?

Two models. Panther can run inside your own AWS account against your Snowflake or Databricks warehouse, so data stays in your environment, or Panther can host a fully managed, single-tenant isolated cloud. Panther states there is no cross-tenant data sharing and no customer data in model training.

How does Panther keep AI actions safe and auditable?

Human approval is required for every write, every AI action is logged and reviewable, and permissions are enforced under the invoking identity. Auto-Resolve only closes alerts whose risk classification falls below a threshold you configure, with a full audit trail.

How does the Databricks acquisition affect Panther customers?

Databricks acquired Panther to accelerate a security lakehouse vision. Panther remains fully supported for existing customers while its AI SOC workflows and detection-as-code capabilities are integrated natively into Databricks Lakewatch, transitioning over time into a single unified offering.