Imagine a suspicious email arriving at a large company. The email system knows the sender. An endpoint tool knows what ran on the recipient’s laptop. An identity system knows whether that person just logged in from somewhere unusual. Each holds a useful piece of the story. The analyst’s job is to persuade the pieces to meet. This is an illustrative workflow, but it gets close to the problem StrikeReady was created to address.
- Connect the security tools a business already owns.
- Automate repeatable work; reserve reasoning for judgment calls.
- Price investigations around the environment, without a usage meter.
Security has a peculiar shopping problem. Buying another instrument can improve detection while leaving the orchestra no easier to conduct. StrikeReady’s wager is that the work between instruments deserves its own product. For anyone paying for a security operations centre, that is a question worth sending to the person who approves the next purchase.
The expensive space between two tools
The company began in 2019 with Yasir Khalid and Anurag Gurtu. Khalid had spent a decade at FireEye, working on detection technologies. Gurtu brought experience from Splunk, FireEye and Cisco. Their early team included other FireEye veterans. These were people familiar with what security products could detect, and with the effort required to turn those detections into a coordinated response.
At the public launch in 2021, StrikeReady described conversations with hundreds of analysts and chief information security officers. Its diagnosis centred on skills, staffing and collaboration. Better tools were producing useful information; people still had to connect it. The constraint appeared in the workflow: retrieving evidence, interpreting unfamiliar systems and finding someone who knew the next step.

A $3.6 million seed round, led by 11.2 Capital, financed sales, market expansion and research. By the announcement, the company said its platform had already reached enterprises and government agencies in the United States and abroad. The origin is useful because it places the operational problem years before the current enthusiasm for AI agents.
CARA needs the keys to the filing cabinet
StrikeReady calls its platform a Security Command Center. It brings together alert handling, incident response, threat intelligence, vulnerability work and security validation. CARA, its conversational analyst, is built into that environment. An analyst can seek threat knowledge, ask about exposure or initiate an investigation without treating every connected tool as a separate destination.
Recon supplies another route in: start with intelligence about an attacker or campaign, then examine what matters to the organisation. Launched in July 2021, it combines internal and external intelligence. The practical question becomes whether a threat has a relationship to this company’s systems, rather than whether the threat deserves an impressive briefing slide.

The current architecture is marketed as Composite AI. Predictable agents assemble and maintain context; reasoning models handle decisions that need judgment. The platform describes a record of evidence and actions and offers automated, analyst-initiated or human-reviewed execution. That distinction matters. A routine lookup and a consequential containment decision should not require the same machinery or the same permission.
“we’re really good plumbers.”Alex Lanstein, CTO, in a public LinkedIn post
The plumbing metaphor is unusually helpful. It directs attention to whether evidence flows between systems. A fluent answer is easier to admire than a correctly joined asset record. In an investigation, the second may decide whether the first is useful.
The plumbing gets its own product
In August 2025, StrikeReady introduced StrikeStream, a data pipeline module inside the platform. It ingests and transforms security telemetry so that investigation and response can use it. The launch described more than 60 data types, including endpoint, firewall, cloud and identity information. The module was offered as an add-on, with pricing tied to protected assets and feature tier.
The announcement also described concrete actions: quarantine an endpoint, disable an identity, block traffic or create a ticket. Those verbs explain the ambition better than the AI label. The platform is intended to connect an observation to something a defender can actually do. Buyers should test those actions with their own systems and approval rules.
- 01GatherAlerts + assets + identities
- 02ConnectBuild the relevant context
- 03ReasonUse judgment where needed
- 04ActApply the team’s permissions
Channel partner DTG welcomed the prospect of reducing the engineering work involved in managing security platforms. This exposes another cost behind the subscription: somebody must keep integrations and workflows useful. Adding automation can create maintenance work of its own. Whether StrikeStream reduces that burden is a sensible question for a pilot.
A meter changes the investigation
StrikeReady’s current proposition includes unmetered investigations and pricing based on the customer’s environment. The commercial idea is straightforward: investigating more alerts should not create a fresh AI consumption charge each time. For a manager deciding how deeply to investigate ordinary-looking events, pricing can influence behaviour as much as a feature can.
There is a separate, disclosed cost of building the company. In April 2024, it announced a $12 million Series A led by 33N Ventures, with Hitachi Ventures, Monta Vista Capital and individual investors participating. Together with the seed round, that brought reported funding to $15.6 million. The announced priorities were product development, a larger global sales effort and infrastructure.
Capital raised is a financing measure, not revenue or a customer price.
The test is the handoff
There are established alternatives. Cortex XSOAR combines orchestration, automation and case management; Microsoft Security Copilot provides AI-assisted analysis. Both support connections beyond a single product. StrikeReady’s argument therefore rests on how its shared context, workflow and economics perform together. Integration counts alone cannot settle the buying decision.
A named customer offers a more revealing clue. Securnet’s Emanuel Santos describes choosing StrikeReady for a multi-tenant SOC, citing flexibility across technologies and customer environments. He also reports that feedback produced improvements and new integrations. In June 2026, stc Bahrain announced a cyber defence centre with StrikeReady, combining automation with specialist oversight.
The company currently reports more than 100 customers and 34.2 million alerts handled. Those are company figures. The lesson readers can copy is smaller and more practical: map the handoffs, connect the evidence, automate the repeatable steps, then decide where judgment belongs. Stale asset records, inaccessible tools or missing response permissions would constrain that approach. Start a pilot with a real alert and follow it all the way to a reviewed action. The interesting result is how much work disappears between the two.