A file does not have to be running to be dangerous. It can sit in a shared folder, politely named and perfectly still, until someone downloads it. The awkward interval between arrival and execution is where Deep Instinct wants to earn its keep. Its proposition is simple enough to sound unfashionable: inspect the file before it gets an opportunity to misbehave.
- The job: prevent malicious files from executing, including unfamiliar malware.
- The move: take the same deep-learning engine into storage and application file flows.
- The second act: use DIANNA to explain what the engine blocked.
- The buyer’s test: measure prevention alongside false positives, throughput and total cost.
Think of a business that accepts documents from customers. A file enters through an application, lands in storage, then reaches an employee. Checking only the employee’s machine leaves earlier handoffs to other controls. That is an illustrative file journey, but it explains the company’s expanding product map better than a parade of acronyms.
Deep Instinct’s argument concerns timing. Detection and response remain necessary; its ambition is to give those teams fewer incidents to handle. In a profession with an inexhaustible supply of alarms, a smaller queue is a respectable thing to sell.
A brain trained to say no
Founded in 2015 by Guy Caspi, Nadav Maman and Dr. Eli David, Deep Instinct built its identity around deep learning for cybersecurity. The distinction matters. Deep learning is a form of machine learning, not a rival kingdom of artificial intelligence. The company’s particular bet is that a neural network trained on raw data can recognize malicious patterns in files it has never encountered.
Its proprietary classification engine is now called DSX Brain. The company describes a system that produces a verdict without requiring the suspicious file to execute. This differs from waiting to observe harmful behavior, and from relying solely on a signature associated with a previously catalogued threat. The useful question is whether that difference catches an unfamiliar attack while leaving ordinary work alone.

“The biggest problem in security is prevention.”Guy Caspi, co-founder
Deep Instinct advertises verdicts in under 20 milliseconds, greater than 99% efficacy against unknown threats and a false-positive rate below 0.1%. Those are vendor claims. A verdict time also does not tell you how long a whole repository takes to inspect: reading files, unpacking archives, moving data and applying policy all belong in that calculation.
There is a more specific piece of evidence. In 2022, security firm Unit 221B assessed the prevention platform under a recommended configuration for a hardened environment. The reported combined accuracy was 99.78%; tested unknown attacks were prevented at 100%, custom attacks at 96.4%. That last figure is useful precisely because it has a blemish. A security result with conditions tells a buyer more than a number polished until it reflects everything.
Combined detection and prevention accuracy in the tested configuration.
Historical endpoint assessment. These results do not establish performance across every current cloud, NAS or application deployment.
The checkpoint moves upstream
The current platform, Data Security X, reaches across cloud storage, network-attached storage, applications and endpoints. The products share the prevention premise, but their installation points differ. An endpoint has a user waiting to open a file. An application has an upload path. A storage repository has a backlog and a stream of arrivals.
DSX for Applications is an agentless, Docker-based scanner that connects through an API or ICAP. A business can integrate it with middleware or custom applications to inspect files in transit. The practical attraction is a checkpoint where documents enter a workflow, before those documents spread through the organization.
For network-attached storage, Deep Instinct supports NetApp Vscan and Dell CAVA integrations. The company says its NAS offering scans files at rest and in motion and can quarantine or delete malicious content. It also says the underlying model requires only one or two updates annually. That is a maintenance claim about the model, rather than permission to stop maintaining the rest of the security stack.
The cloud expansion supplies a visible chronology. DSX for Cloud - Amazon S3 launched on AWS Marketplace in November 2024. Protection for Amazon FSx for NetApp ONTAP followed in January 2025. In June, Deep Instinct announced acceptance into AWS ISV Accelerate and the “Deployed on AWS” designation. Technical compatibility matters; so does making enterprise procurement less laborious.
A January 2026 company essay reached for Schrödinger’s cat to describe an unscanned bucket. The physics is a metaphor. The operational point is sound: permissions, encryption and backups answer different questions from whether a stored file contains malware. A locked cupboard can still contain something unpleasant.
A black box learns to explain itself
Blocking a file creates another task. Someone may need to establish why it was blocked, what it intended to do and whether the verdict warrants further investigation. A terse label can be sufficient for an automated policy and insufficient for the person responsible for defending it.
DIANNA, short for Deep Instinct’s Artificial Neural Network Assistant, is the company’s answer. Introduced in May 2024 and announced generally available in September 2025, it uses generative AI to explain known and unknown threats. DSX Brain supplies the classification; DIANNA supplies the narrative. The distinction keeps two different AI jobs from dissolving into one expensive adjective.
Deep Instinct says DIANNA can provide explanations in under ten seconds. An AWS technical account describes its use of Amazon Bedrock for malware analysis. This is a different proposition from an assistant that merely summarizes an existing alert log: the intended subject is the suspicious file and its characteristics.
An explanation still needs scrutiny. Buyers should check it against analyst findings, especially when it describes unfamiliar code. They should also establish which files or extracted content the assistant processes. Local prevention capabilities and a generative assistant’s data handling require separate examination, even when both appear on the same product slide.
Who buys fewer interruptions?
This is enterprise software for security and IT teams, with service providers extending its reach. Deep Instinct says hundreds of brands use its technology. Public customer references include Seiko Holdings Group, Australian financial-services company Equity Trustees and Palm Beach County. Their published testimonials emphasize unknown-threat protection, fewer false positives and less time spent operating the product.
The alternative depends on the job. Endpoint buyers already encounter Microsoft Defender, CrowdStrike and SentinelOne. Storage buyers may be comparing Trellix, Symantec or ClamAV, which Deep Instinct names in its own comparison materials. A broad endpoint platform and a file scanner do not carry identical responsibilities, so a useful comparison begins with the workflow being protected.
Deep Instinct itself promotes complementing Microsoft Defender and enhancing EDR. Its April 2023 eSentire partnership paired prevention with managed detection and response. That arrangement is revealing: the company can criticize late detection while still selling alongside investigators. Stopping malicious files leaves plenty of work involving identities, configurations and attacks outside that file path.
The money behind the milliseconds
The business sells enterprise licenses and subscriptions through direct sales, partners and marketplaces. Historical distribution included an OEM partnership for HP Sure Sense. These routes put the prevention engine into other companies’ products and commercial relationships, rather than requiring every customer to discover Deep Instinct independently.
The financing is substantial, though particular announced rounds are more useful than an uncertain lifetime total. Deep Instinct announced a $43 million Series C in 2020 and a $100 million Series D in 2021. Chrysalis Investments subsequently described a $62.5 million primary financing in September 2022. PayPal Ventures announced an investment in March 2023 without stating its size.
Capital did not make the journey smooth. Lane Bess, previously CEO of Palo Alto Networks and COO of Zscaler, became CEO in September 2022. In May 2025, Ctech reported approximately 20 layoffs following the closure of certain operations, with around 180 employees remaining. Chrysalis’s 2025 interim report said the company had yet to reach profitability and could require further funding.
Those disclosures document commercial pressure. They do not establish that a particular technical failure caused the storage expansion. The observable change is the widening product focus. The company’s recruiting material, meanwhile, emphasizes researchers and engineers tackling difficult problems in a distributed organization. Ambitious research and an awkward balance sheet can occupy the same office.
A pilot beats a promise
What does it cost a customer? The useful answer comes from a scoped deployment. A 2021 commissioned Forrester model, cited in the Series D announcement, estimated $0.6 million in three-year costs and $3.5 million in benefits for its modeled endpoint organization. That is historical scenario analysis, not a current DSX price or a result every buyer should expect.
Deep Instinct advertises a free 24-hour scan, offered in its labs or a customer’s AWS S3 environment. Treat that as an opening experiment. Choose representative files, include legitimate software and awkward archives, and count both malicious samples missed and benign files blocked. Measure the complete scan path, infrastructure use and time spent reviewing verdicts.
The lesson readers can copy is to follow their files. Map entry points, storage and execution; then find the handoffs existing controls overlook. Prevention helps only where the integration actually sees the content and policy acts on its verdict. Unsupported formats, exclusions, inaccessible encrypted content and threats outside the inspected file path are conditions to test explicitly.
Deep Instinct’s most interesting promise is a change in workload: fewer dangerous files reaching people, followed by a clearer explanation when a file is stopped. The pilot should show whether that happens in the buyer’s environment. The best sales conversation ends with an observable result and a shorter queue.