
Work Here?
Industries
Data & Analytics
Enterprise Software
Cybersecurity
Company Size
501-1,000
Company Stage
Series G
Total Funding
$729.5M
Headquarters
San Francisco, California
Founded
2013
Sysdig provides cloud-native security and monitoring solutions for applications running in containers and Kubernetes. It offers products like Sysdig Secure for security and Sysdig Monitor for performance monitoring, delivering data collection from cloud-native environments to help enterprises manage compliance, security, and performance. The platform typically uses agents and a SaaS or on-premises interface to collect telemetry, run security checks, and present dashboards, enabling real-time visibility and risk management across complex IT stacks. What sets Sysdig apart is its integrated approach that combines security, monitoring, and compliance tooling in one platform with scalable tiers, targeting large organizations across technology, finance, healthcare, and government sectors. The company’s goal is to help customers securely run cloud-native applications with continuous visibility and control, reducing risk while maintaining high performance.
Help us improve and share your feedback! Did you find this helpful?
Total Funding
$729.5M
Above
Industry Average
Funded Over
8 Rounds
Flexible Work Hours
Mental Health Support
Company Equity
Professional Development Budget
Sysdig donates $70,000 to Falco Project marking 10 years of open source cloud security. #news #trending Imagine building security infrastructure for a cloud that barely existed yet. That was 2016. Ten years on, the open source tool born from that challenge - Falco - turns ten, and its creator just wrote a $70,000 check to ensure open source cloud security has the runway it deserves. Sysdig announced the donation to The Falco Project at KubeCon + CloudNativeCon Europe 2026 in Amsterdam, a ten-year celebration that landed not as a quiet press release but as a public financial commitment to the community that built runtime security into the fabric of modern cloud infrastructure. The event runs March 23-26 in Amsterdam, and the timing is no coincidence - Falco's birthday deserves the biggest stage cloud-native computing has. The donation flows through the Linux Foundation's crowdfunding initiative, a structural choice that matters. It means the money sits outside Sysdig's direct control and is governed by the foundation's existing accountability framework - not a vendor's roadmap meeting. As AI workloads grow more compute-intensive and energy-hungry, the Kubernetes clusters running them have become critical targets. Sysdig positioned the gift in exactly that context: Falco as essential security infrastructure "as Kubernetes becomes the backbone of AI innovation." The case for open source cloud security: A decade of community trust. Open source security wins when trust is non-negotiable - and Falco has spent ten years earning every bit of it. The project doesn't ask teams to trust a vendor's black box. It shows its work. Falco was created in 2016 to solve a precise, urgent problem: containers moved faster than traditional security tools could follow. By monitoring Linux kernel syscalls in real time, Falco could tell teams exactly what was happening inside a container at the moment it mattered - not in a log review hours later, not from a signature match against known malware, but live, at the syscall level. That was new. That was necessary. The project's path through the Cloud Native Computing Foundation tells the story in numbers. Accepted into the CNCF on October 10, 2018. Elevated to Incubating status on January 8, 2020. Achieved Graduated status on February 29, 2024 - the foundation's highest honor, shared by Kubernetes itself. Three milestones. Three proofs of community confidence. As of March 2026, the Falco rules repository lists 93 detection rules across containers, hosts, and Kubernetes environments. They aren't marketing copy; they are battle-tested detections, reviewed and debated by the practitioners who run them in production every day, and the changelog shows they are updated continuously as threat patterns shift. What $70,000 actually buys. Donations don't sustain open source projects by themselves. That's the honest answer - and that's exactly what makes the framing of this one worth examining closely. Most corporate open source contributions are symbolic. A few thousand dollars. A logo on a conference banner. Sysdig's $70,000 is sized differently. In practical terms, the stated goals - accelerate innovation, expand community participation, strengthen long-term sustainability - translate to specific, unglamorous line items: maintainer time, documentation, tooling, security audits, and the ongoing work of keeping 93 detection rules current against threats that evolve daily. Sysdig's announcement described the company as "the leader in real-time AI-powered cloud defense" and framed the donation as a continued investment in the open source community that made Falco what it is. The Linux Foundation crowdfunding route signals an intent to make the project's financial health visible - contributors and users can see where money goes, not just where it came from. For a security tool whose core value proposition is transparency, that architectural choice reinforces the message. The speed at which AI tools now generate outputs that outpace previous state-of-the-art systems mirrors what's happening in cloud infrastructure: the attack surface expands faster than any single team can manually monitor. Automated, community-maintained detection at scale isn't optional anymore. It is the architecture of necessity. The donation funds that architecture directly. Community trust vs. Corporate backing: where projects fracture. Here is where most open source security projects split apart. Community development produces trust and breadth. Corporate funding produces velocity and reliability. Getting both at once is genuinely hard - and most projects never manage it. Falco's arc through the CNCF suggests it has found a working balance. The community built the rules, the integrations, and the ecosystem. Sysdig provided original engineering and, now, sustained financial commitment through a structure designed to outlast any single vendor's priorities. The tension worth naming honestly: a project whose primary funder is also its original creator carries concentration risk. If Sysdig's priorities shift, Falco's funding could follow. But the public nature of this commitment changes the calculus somewhat. Announcing $70,000 at KubeCon + CloudNativeCon Europe 2026 - in front of the very community that would hold Sysdig accountable - is a harder promise to walk back than a quiet internal budget line. Routing it through the Linux Foundation adds another layer of institutional structure. For security teams choosing runtime protection today, the comparison is concrete. Falco offers syscall-level detection, CNCF Graduated credibility, 93 community-vetted and publicly auditable rules, and a funded roadmap. Proprietary alternatives offer vendor SLAs and consolidated support contracts. The cost of the proprietary path is auditability - the ability to see exactly how your security tool decides what is a threat and what is not, with no hidden logic and no vendor lock-in on the rules themselves. Much like conservation efforts that reintroduce keystone species to restore ecosystem balance, Falco has reintroduced something essential to cloud infrastructure: shared, inspectable security that no single vendor controls. The $70,000 donation is a bet that this model is worth sustaining - not just for Sysdig's customer base, but for every team running workloads in the cloud. Ten years ago, no tool existed to watch what containers were actually doing in real time. Today, that tool turns ten, backed by the strongest financial signal yet that the next decade is funded, community-owned, and ready. Frequently asked questions. Q: What is Falco and why is it important for cloud security? A: Falco is an open source runtime security tool that detects threats by monitoring Linux kernel syscalls in real time inside containers and Kubernetes environments. It is a CNCF Graduated project and is widely considered the standard for cloud-native runtime security. Q: How much has Sysdig donated to the Falco Project and what will it fund? A: Sysdig has donated $70,000 to The Falco Project through the Linux Foundation's crowdfunding initiative to mark its 10th anniversary. The funds are intended to accelerate project innovation, expand community participation, and strengthen Falco's long-term sustainability - covering maintainer time, tooling, documentation, and keeping detection rules current. Q: When did Falco achieve CNCF Graduated status? A: Falco achieved CNCF Graduated status on February 29, 2024. It first joined the CNCF in October 2018 and reached Incubating status in January 2020. Q: How many detection rules does the Falco Project maintain? A: As of March 2026, the Falco rules repository lists 93 detection rules covering threats across containers, hosts, and Kubernetes environments. Each rule is publicly auditable and community-vetted. Q: Where was the Sysdig donation to Falco announced? A: The donation was announced at KubeCon + CloudNativeCon Europe 2026, held March 23-26, 2026 in Amsterdam, Netherlands. Q: Why was the donation routed through the Linux Foundation? A: Routing through the Linux Foundation's crowdfunding initiative means the funds are governed by the foundation's accountability framework rather than managed directly by Sysdig, reinforcing the project's independence and financial transparency. This article was researched and written with AI assistance, then reviewed for accuracy and quality. DRS Web Development uses AI tools to help produce content faster while maintaining editorial standards.
Sysdig has launched runtime security for AI coding agents, enabling organisations to monitor autonomous development tools like Claude Code, Codex and Gemini. The platform provides real-time visibility to identify risky behaviour across cloud and development environments. The security solution detects suspicious activities including new AI coding agent installations, unauthorised credential access attempts, risky command-line arguments and dangerous actions like reverse shells within developer environments. As AI agents gain elevated system permissions and access to sensitive data, they present growing security risks. Founded by the creators of Falco and Wireshark, Sysdig serves over 60% of the Fortune 500. The company's detections help security teams protect against compromised AI tools whilst maintaining runtime security and compliance for AI-assisted development.
Sysdig named a Leader in CNAPP as runtime redefines cloud security in 2026. Committed to real-time, AI-powered cloud defense, Sysdig is recognized as a Leader in CNAPP by an industry-leading analyst firm SAN FRANCISCO-(BUSINESS WIRE)-Sysdig today announced that it has been named a Leader in "The Forrester Wave(TM): Cloud Native Application Protection Solutions, Q1 2026" report, earning the distinction alongside just two other companies. Out of 14 vendors evaluated, Sysdig was also one of only three cloud security providers rated above average for customer feedback, which Sysdig sees as a reflection of strong customer trust as organizations continue to realize increasing value from Sysdig's runtime-powered platform. The Forrester report recognized that, "Sysdig's formidable vision focuses on articulating and tracking business outcomes (application risk management) from code to cloud. The vendor's roadmap includes connecting posture with vulnerability and runtime telemetry, role-specific workflows for admins and incident responders, and a semantic attack graph. Pricing flexibility and community strategies are also strengths..." To stay ahead of modern threats, organizations need unified, real-time security. Unlike posture-first and point solutions, the Sysdig cloud-native application protection platform (CNAPP) was born in runtime and built on the deepest telemetry in the cloud. This empowers security teams to make the most informed decisions and take the most precise actions to reduce risk. "We built Sysdig with the steadfast belief that runtime would decide the future of cloud security," said Loris Degioanni, Founder and CTO of Sysdig. "In an AI-driven world where attacks can unfold in 10 minutes, understanding what's running and acting with precision is the only way to defend the cloud. For us, Forrester's recognition confirms what our customers already know: runtime wins." You can't defend what you don't understand Early cloud security focused on posture, compliance, and static indicators of risk. That approach is no longer sufficient. Cloud environments are growing faster and more dynamic, fueled by the rapid rise of AI adoption and agentic coding. Kubernetes now runs 82% of AI workloads, up from 54% just two years ago, according to the Cloud Native Computing Foundation. As attack surfaces expand and AI-assisted threats accelerate the pace of exploitation, cloud-native security demands real-time understanding and action. Sysdig sees the Forrester evaluation's results as reinforcement of its long-held conviction that runtime insights are the foundation of effective cloud defense, enabling teams to cut through alert noise, understand true risk, and act with confidence across the application lifecycle. "The industry used to say, 'You can't protect what you can't see.' But just seeing is no longer enough," said Enrique Salem, Chairman at Sysdig. "In a threat landscape increasingly driven by AI, you can't defend what you don't understand. Security that can't take action in real time has become irrelevant." As a trailblazer in real-time, AI-powered cloud defense, Sysdig delivers a complete CNAPP built on the truth of runtime. Sysdig Sage(TM), the industry's first agentic AI cloud security analyst, leverages Sysdig's deep runtime telemetry to help teams focus on the risks that matter most, accelerate threat investigations, and take precise action across complex multi-cloud environments. To date, Sysdig Sage has helped users reduce mean time to respond by 76%, shrink exposure to critical vulnerabilities from days to minutes, and reclaim more than 80 hours per week previously lost to manual triage. Forrester does not endorse any company, product, brand, or service included in its research publications and does not advise any person to select the products or services of any company or brand based on the ratings included in such publications. Information is based on the best available resources. Opinions reflect judgment at the time and are subject to change. For more information, read about Forrester's objectivity here. About Sysdig Sysdig delivers cloud security the right way with open innovation, agentic AI, and the uncompromising truth of runtime. In a world of black boxes and blind spots, Sysdig helps security and development teams prevent, detect, and respond to threats in the moment. AI is only as powerful as the signals it receives, and Sysdig Sage(TM)- the first agentic AI analyst for cloud security - is fueled by the deepest runtime intelligence in the industry. It doesn't just observe. It reasons and acts with the context, speed, and precision that modern teams need to build and defend innovation in real time. Founded by the creators of Falco and Wireshark, Sysdig is trusted by more than 60% of the Fortune 500 and is built for those who refuse to compromise on security.
Its customers have spoken: Sysdig rated a Strong Performer in gartner(r) Voice of the Customer for Cloud-Native Application Protection Platforms. Since Gartner coined the term cloud-native application protection platform (CNAPP) in 2021, both the demand and supply of CNAPP solutions have continued to grow. After all, traditional tools can't offer the visibility and security needed in its brave new world of microservices, containers, Kubernetes, and multicloud architectures. A CNAPP is an integrated cloud security solution that helps organizations secure applications and infrastructure across the entire application lifecycle. It combines the functions of cloud security posture management (CSPM), cloud workload protection (CWP), cloud infrastructure entitlement management (CIEM), and more into a single, unified platform. To help security teams choose from the ever-growing array of CNAPP vendors, Gartner releases their Voice of the Customer for Cloud-Native Application Protection Platforms report. "Voice of the Customer" is a document that synthesizes Gartner Peer Insights reviews into insights for buyers of technology and services. This aggregated peer perspective, along with the individual detailed reviews, is complementary to Gartner expert research and can play a key role in your buying process. And Sysdig Inc. is proud to announce that Sysdig's customers continue to love its work, which Sysdig Inc. believe has led to Sysdig Inc. being recognized as a Strong Performer in this category. What Sysdig's customers say about Sysdig Inc.. Its customers on Gartner Peer Insights rated its CNAPP a 4.8 out of 5 (based on 287 ratings as of January 2026). Out of the 156 customer responses in the latest Voice of the Customer report, a full 94% said they would recommend its CNAPP solution. Sysdig Inc. also received high ratings across the board for its product capabilities (4.6/5 based on 156 reviews), sales experience (4.8/5 based on 119 reviews), deployment experience (4.7/5 based on 150 reviews), and support experience (4.9/5 based on 154 reviews). Here are just a few quotes from the reviews its customers left: "Sysdig's CNAPP Suite Offers Robust Security Features through Detailed Threat Detection and AI Capabilities "The Sysdig CNAPP security suite is amongst the best in the business. The product itself is fairly comprehensive and they are able to capture signals that most other vendors can't. The account team has been phenomenal and has been engaged since we first reached out. Overall, we're very happy with the service and the team." "Sysdig Platform Provides Unified Cloud Security With Real-Time Threat Detection "We chose Sysdig because it successfully unifies multiple tools (CSPM, Vulnerability Management, Runtime Security, etc.) into a single platform, eliminating siloed views and tool sprawl. The primary benefit is the shift from static scanning to real-time, runtime security. It gives us confidence that threats are detected and contained instantly in our cloud environments." Comprehensive cloud security, the right way. What makes Sysdig's CNAPP stand out from the crowd? Sysdig Inc. is committed to providing a new standard for cloud security: transparency instead of black boxes, clarity instead of guesswork, and speed without sacrificing security. From code to cloud, builders stay in control, and defenders stay uncompromised. Its CNAPP is built on agentic AI, open source, and runtime insights, all in one seamless solution to provide true real-time, end-to-end security. Gartner, Voice of the Customer for Cloud-Native Application Protection Platforms, Peer Community Contributor, 24 December 2025 Gartner and Peer Insights are trademarks of Gartner, Inc. and/or its affiliates. Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences with the vendors listed on the platform, should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose. This graphic was published by Gartner, Inc. as part of a larger research document and should be evaluated in the context of the entire document. The Gartner document is available upon request from Sysdig.
Sysdig Falco and Stratoshark strengthen open source cloud security. Sysdig introduces new Falco features that integrate seamlessly with Stratoshark. These updates enable automatic capture of system data for forensic investigation in the event of specific threats. Falco, which graduated from the CNCF in February 2024, can now store system capture (SCAP) files as soon as certain security rules are triggered. These files can be used directly in Stratoshark, known as the "Wireshark for the cloud." The integration enables moving from real-time detection to in-depth post-event analysis. The platform has now reached more than 175 million downloads. Users have access to comprehensive tools for investigating cloud threats. Improved plug-ins for contextual insight. Sysdig has also optimized the Falco plugins k8saudit and gcpaudit. These plugins help Stratoshark uncover crucial context in source events. As a result, teams can convert raw security data into actionable information. The combination leads to a process that combines rapid detection and forensic investigation. "Falco has cemented itself as the gold standard for runtime cloud threat detection, and Stratoshark is quickly becoming the industry's tool of choice for deep cloud system analysis," said Loris Degioanni, founder and CTO of Sysdig. These developments bring the open source community closer to a platform-like experience for complete detection and response in the cloud. What users can expect. The enhanced integration between Falco and Stratoshark means users can detect attacks in real time and search captured data with precision. "With Falco now producing Stratoshark-consumable SCAP files and enriched cloud log metadata, we're bridging the open source gap between real-time threat detection and granular forensics," said Gerald Combs, Director of Open Source Projects at Sysdig. The new capabilities offer three concrete benefits. First, teams gain uniform workflows. They detect threats in real time with Falco, capture in-depth incident details from the moment Falco flags suspicious behavior, and investigate with precision in Stratoshark. Second, the developments are driven by the community. Open source security is strengthened by collaborative progress, transparency, and collective insight. Teams can easily zoom in and out on system activity. This power and extensibility, previously reserved for commercial cloud platforms, is now open source and available for free.
Find jobs on Simplify and start your career today
Industries
Data & Analytics
Enterprise Software
Cybersecurity
Company Size
501-1,000
Company Stage
Series G
Total Funding
$729.5M
Headquarters
San Francisco, California
Founded
2013
Find jobs on Simplify and start your career today