- Team size
- 201–500
- Pricing model
- Subscription
- Notable clients
- AARP, Benjamin Moore, Cinemark, Fulton Bank, Informatica, Genuine Parts Company, QuidelOrtho, Cotiviti, Xactly, WaFd Bank
- Best for
- Enterprises and large mid-market organisations wanting MDR plus vulnerability and exposure management from one provider.
About Deepwatch
The best evidenced record in this batch. Where most MDR providers name no customers at all, Deepwatch names more than a dozen, and they are substantial and checkable: AARP, Cinemark, Genuine Parts Company, Fulton Bank, Informatica. That alone justifies a strong placement on a managed SOC list, because a reader can verify the claim.
Palo Alto headquarters, so it qualifies for US filtered lists. Service range extends past detection into vulnerability management, continuous threat exposure management, dark web monitoring and managed firewall, which suits a buyer consolidating several contracts rather than one buying monitoring alone.
Both a service and a platform, sold as AI native MDR on the Guardian platform, so the reader is buying a service that comes with the vendor's technology attached. Founding year, team size and pricing are not stated. Given the client roster, the missing pricing is the only real gap for the SMB oriented lists, where this is likely too far upmarket anyway.
Assumes you already run a SIEM and endpoint tooling, with a heavy Splunk orientation. Worth pricing that starting point if you are not there yet.
Featured work
Informatica — vulnerability management across 100+ teams
Informatica had built its own data pipelines to normalise vulnerability findings from several tools, and those pipelines broke whenever a tool changed. Deepwatch replaced them with the Guardian MDR Platform, adding layer-aware attribution for containerised workloads so a finding could be traced to the team that owns it. The case study reports $77K in annual operating savings from retiring the internal pipelines and reporting that engineering, leadership and auditors work from the same figures. It shows Deepwatch handling vulnerability data at enterprise scale rather than only alert triage.
- Vulnerability Management
- MDR
- Enterprise Software
City National Bank of Florida — managed SOC on the bank's own Splunk
A regulated bank without the internal headcount to run enterprise detection brought in Deepwatch for 24/7/365 MDR plus firewall management, built on the Splunk deployment the bank already owned. The bank reports audit readiness dropping from days to minutes and close to an 80% reduction in cyber insurance premiums. The relevant capability for a buyer is that Deepwatch operated an existing SIEM investment under regulatory scrutiny instead of asking for a platform migration.
- MDR
- Splunk
- Financial Services
SBA Communications — consolidating a fragmented SOC across global infrastructure
A wireless infrastructure operator with a scattered SOC, high false-positive volume and poor hybrid-cloud visibility moved detection onto the Guardian platform with MITRE ATT&CK mapping, bidirectional ticketing and ongoing detection tuning. The case study reports no incidents requiring formal declaration over two years and a Security Index score of 9.64 against Deepwatch's own benchmark. It demonstrates a multi-year engagement with continuous tuning rather than a one-time deployment.
- MDR
- Hybrid Cloud
- Telecom










