The modern internet has an unflattering physical reality. Every streaming session, banking login, mobile connection and AI prompt eventually becomes traffic looking for somewhere to go. The elegant interface disappears. What remains is a queue, a destination and a machine deciding whether the request should pass. A10 Networks makes that machine.
The San Jose company sits in a peculiar part of the technology market: important enough to support national telecom networks, but quiet enough that most people will never encounter its name. Its application delivery controllers spread work across servers. Its carrier-grade network address translation equipment lets service providers stretch scarce IPv4 addresses. Its DDoS systems spot and absorb malicious floods. Its firewalls inspect encrypted traffic. All of it is built around one job - keeping a critical application fast, reachable and difficult to knock over.
That job has acquired a new payload. AI applications generate heavy, uneven traffic and introduce attacks that look less like malicious code than malicious language. A prompt can ask a model to ignore its rules. An agent can call the wrong tool. A response can leak data without tripping a conventional signature. A10 is trying to turn two decades of traffic control into an advantage here, moving from packets and ports toward prompts, APIs and model behavior.
The useful place in the middle
A10’s founding story begins in 2004 with Lee Chen, a networking veteran and co-founder of Foundry Networks. The young company first worked on identity management, then found its center in application delivery. By 2014 it had reached the New York Stock Exchange. The IPO put about $120 million in net proceeds into A10, but the durable asset was architectural: its Advanced Core Operating System, or ACOS, running across a family of specialized hardware and software products.
Think of an application delivery controller as a maître d’ for servers. It sees incoming demand, knows which table has capacity and sends each party to the right place. At small scale, cloud software can do this invisibly. At carrier or large-enterprise scale, the requirements become harsher: millions of simultaneous connections, tiny latency budgets, encrypted sessions, bursts that arrive without warning and attackers deliberately trying to exhaust capacity.
A10’s pitch is that several decisions can happen at that same middle point. Thunder ADC handles load balancing and application availability. Thunder CGN performs the address translation that allows many subscribers to share limited public IPv4 space while networks inch toward IPv6. Thunder CFW combines firewall, VPN, translation, delivery and encrypted-traffic inspection. A10 Defend detects and mitigates DDoS attacks. A10 Control gives operators a central view across the estate.
The combination matters. A telecom operator can buy separate tools for translation, firewalling, DDoS defense and analytics, then pay people to make them cooperate. A10 instead sells consolidation on a shared architecture. That can reduce appliances and operational seams, although a buyer who prefers a specialist for every function may see the same bundle as a compromise. The real competition is not merely another box. It is the organizational question of one integrated control point versus a collection of point products.
“AI-driven architectures are fundamentally increasing the volume, velocity, and complexity of network traffic.”
Who pays for invisible reliability
A10 reports more than 7,000 customers. They cluster where downtime has a price: communications carriers, cloud and web platforms, large enterprises, public agencies, universities, payment businesses and healthcare networks. Its published customer work ranges from SK Telecom’s early commercial 5G rollout to Uber’s IPv4 exhaustion problem, Turk Telekom’s DDoS protection service and universities balancing applications between on-premises systems and the cloud.
These buyers are not shopping for consumer delight. They want throughput, predictable latency, fewer outages and an operations team that can understand what is happening. They also tend to keep infrastructure longer than a software fashion cycle. Once a platform is tested inside a carrier core or a critical application path, replacement is expensive and risky. That creates a useful kind of stickiness, tempered by long sales cycles and the purchasing power of very large customers.
The company makes money from physical appliances, perpetual and term licenses, subscriptions, maintenance, support and professional services. It can deliver the same broad capabilities as optimized hardware, bare-metal software, a virtual appliance, a containerized deployment or a cloud service. Direct sellers work alongside distributors, resellers, integrators and technology partners. In other words, the business model looks less like pure SaaS and more like a portfolio designed to follow customers across old data centers, new clouds and everything awkwardly hybrid between them.
That mix produced record 2025 revenue of $290.6 million, up 11 percent. In the second quarter of 2026, revenue reached $80.1 million, up 15.5 percent from the prior year. Products supplied $49 million and services $31.1 million. Management raised its full-year revenue-growth outlook to 12 to 14 percent. This is not startup hypergrowth. For a two-decade-old infrastructure supplier, it signals that the traffic problem is expanding rather than disappearing.
Moving up the stack
A10’s recent acquisitions clarify the direction. In early 2025 it acquired ThreatX Protect assets and key staff, adding a cloud web application and API protection service. ThreatX watches behavior across requests instead of relying only on static rules. It profiles attackers, manages bots, protects APIs and acts as a next-generation web application firewall. The deal gave A10 a subscription product higher in the application stack and a way to protect workloads that may never sit behind a traditional A10 appliance.
Then came TrojAI in June 2026. TrojAI tests models and agents before release, runs protection while they are live and governs the increasingly strange world of Model Context Protocol servers and tools. Its red-teaming product simulates adversarial conversations. Its runtime layer blocks prompt injection, jailbreaking, toxic output and data leakage. A customer can run it on premises or inside its own cloud, useful for governments and regulated companies that do not want sensitive model traffic shipped to somebody else’s security service.
This creates a layered story: deliver the application, protect its API, inspect its model interactions and test the agent before it ships. The risk is familiar to any incumbent entering a fashionable market. AI security is crowded, terminology is fluid and buyers may favor cloud-native specialists. A10’s counterargument is practical. It already sits in the data path, understands high-throughput enforcement and can deploy where the customer’s data lives.
Different by architecture, not adjectives
In application delivery, F5 is the obvious broad rival. Cisco, Citrix NetScaler, Radware and Fortinet overlap in networking and security. Cloudflare, Akamai and Fastly compete around application protection, edge delivery and DDoS defense, while AWS, Microsoft Azure and Google Cloud bundle native services with their platforms. AI security adds another set of young specialists. There is no clean, single competitive box around A10 because its portfolio crosses several buying categories.
Its difference is clearest at high scale. A10 has years of carrier-grade work, an operating system shared across products, hardware acceleration where software alone is insufficient and flexible licenses that can move capacity among deployments. Its partnership with Ericsson puts A10 technology inside a packet-core firewall for mobile networks. Fastly technology powers an integrated next-generation WAF. A multi-year Microsoft agreement, disclosed with the latest results, aligns A10 with scaled AI infrastructure deployment.
Partnerships also reveal the company’s market position. A10 is rarely the whole stack. It is the connective and enforcement layer that makes a larger stack usable. That is less theatrical than owning the cloud or training the model, but it can be defensible. The company’s expertise is accumulated in the unpleasant edge cases: a flood that resembles legitimate demand, a scarce address shared among subscribers, a certificate that must be decrypted without wrecking latency, or an AI response that is fluent and unsafe.
The lesson to steal is not “add AI” to an old product. It is to notice where a new technology recreates an old constraint. AI changes the payload, but it does not abolish queues, routing, capacity, inspection or failure. In fact, it makes each one more expensive. A10 has spent 22 years learning what happens when too much traffic meets too little tolerance for delay.
That leaves the company in an interesting middle age. It is small beside the platform giants, established beside AI-security startups and profitable enough to fund acquisitions while returning capital to shareholders. Its future depends on whether customers see one continuous problem from network to model - and whether A10 can make a broad portfolio feel simpler than the alternatives. The internet will keep producing bottlenecks. A10’s wager is that the most valuable place remains directly in front of them.