Company Intelligence

SentinelOne

SentinelOne was founded in 2013 by Tomer Weingarten and Almog Cohen, and is headquartered in Mountain View, California,…

In this profile

Quick Facts

  • Founded 2013
  • Country United States
  • Industry AI in Cybersecurity
  • Company Type Public
  • Founders Tomer Weingarten, Almog Cohen, Tomer Weingarten SentinelOne
  • Website Official site
  • Last Reviewed Jul 2026

Executive Summary

SentinelOne was founded in 2013 by Tomer Weingarten and Almog Cohen, and is headquartered in Mountain View, California, with significant engineering operations rooted in the founders' Israeli technology background. The company went public on the New York Stock Exchange in June 2021 under the ticker S, in one of the larger cybersecurity IPOs of that year. From the outset, SentinelOne positioned itself against the market's dominant approach to endpoint security, which at the time relied heavily on cloud lookups and human analyst review for every suspicious event. Its pitch was that endpoint protection should be able to detect and contain threats autonomously, on the device itself, without waiting on a round trip to the cloud. From its earliest product versions, SentinelOne marketed a two-layer detection model: a pre-execution machine-learning model it called Static AI, which evaluates files before they run, paired with a runtime behavioral engine that would later evolve into ActiveEDR. That distinction between static, file-based analysis and continuous behavioral monitoring has remained central to how the company explains its approach relative to vendors relying primarily on signatures or cloud lookups alone.The core of that pitch is a patented technology called Storyline, which automatically correlates raw process, file, and network events on an endpoint into a coherent narrative of an attack as it unfolds, rather than presenting analysts with a disconnected stream of alerts. Combined with ActiveEDR, SentinelOne's real-time detection and response engine, this lets the Singularity platform take automated remediation action — killing a process, quarantining a file, rolling back ransomware-encrypted files to a known-good state — without requiring a human to first triage the event. Over time, Singularity expanded from endpoint protection into a broader platform covering cloud workload security, identity threat detection, and a unified data lake for security operations, following the same trajectory as most of its major competitors toward consolidated XDR platforms.SentinelOne has also pursued acquisitions to round out that platform. It acquired Attivo Networks in 2022 to add identity detection and deception technology, later rebranding that capability as Singularity Identity and extending detection into Active Directory and credential-based attacks, and it acquired PingSafe in 2024 to add cloud-native application protection (CNAPP) capabilities, folded into Singularity Cloud Security, positioning the company more directly against cloud security specialists like Wiz and Orca Security as well as fellow endpoint vendors. In 2023 and 2024, SentinelOne introduced Purple AI, a generative AI security analyst built into Singularity that lets security teams query telemetry in natural language and receive suggested hunting queries and investigation summaries — a similar move to CrowdStrike's Charlotte AI, reflecting a broader industry shift toward natural-language interfaces sitting on top of existing detection data rather than replacing the underlying detection engines themselves.As a public company, SentinelOne has reported strong revenue growth in its filings but, like many venture-scale cybersecurity companies that reached the public markets in 2021, has taken longer to reach consistent GAAP profitability than some of its larger competitors, prioritizing revenue growth and platform expansion. It competes most directly with CrowdStrike and Microsoft Defender for endpoint and XDR budgets, and increasingly with cloud security specialists as its Singularity platform absorbs more of the CNAPP feature set. Unlike CrowdStrike, SentinelOne has not experienced a comparably scaled public operational incident; its public track record centers on steady platform expansion and acquisition-driven capability additions rather than a defining crisis event.SentinelOne also competes against a market dynamic that is distinctive to endpoint security: Microsoft bundles a baseline version of Defender for Endpoint into many enterprise licensing agreements, giving it a low-friction default option that SentinelOne, CrowdStrike, and other independent vendors must actively displace to win new business. SentinelOne has generally positioned itself on detection and response depth rather than price, arguing that a bundled baseline tier is not equivalent to a dedicated XDR platform for organizations facing sophisticated or targeted threats — a competitive argument common across the broader endpoint security market rather than unique to any single vendor.For readers tracking how autonomous response claims hold up across the endpoint security category, SentinelOne is a useful comparison point precisely because its founding thesis — on-device, machine-speed containment rather than cloud-dependent human triage — is one of the more explicit architectural bets in the sector. Its acquisition history also illustrates a broader consolidation pattern in cybersecurity, where endpoint, identity, and cloud security vendors are converging toward similar bundled platforms rather than remaining as distinct point products, driven in part by customers wanting fewer agents and fewer vendor relationships to manage.

Why It Matters

SentinelOne is a direct comparison point to CrowdStrike on autonomous, on-device response claims, and its acquisition history illustrates the broader consolidation of endpoint, identity, and cloud security into unified XDR platforms.

Products

Founders

Recent Developments

  1. 2013 Company founded

    SentinelOne was founded in 2013 per the company profile source on file.

    Source

Connected Reports

Connected Insights

Industries

Technologies

Introduction

SentinelOne was founded in 2013 by Tomer Weingarten and Almog Cohen, and is headquartered in Mountain View, California, with significant engineering operations rooted in the founders' Israeli technology background. The company went public on the New York Stock Exchange in June 2021 under the ticker S, in one of the larger cybersecurity IPOs of that year. From the outset, SentinelOne positioned itself against the market's dominant approach to endpoint security, which at the time relied heavily on cloud lookups and human analyst review for every suspicious event. Its pitch was that endpoint protection should be able to detect and contain threats autonomously, on the device itself, without waiting on a round trip to the cloud. From its earliest product versions, SentinelOne marketed a two-layer detection model: a pre-execution machine-learning model it called Static AI, which evaluates files before they run, paired with a runtime behavioral engine that would later evolve into ActiveEDR. That distinction between static, file-based analysis and continuous behavioral monitoring has remained central to how the company explains its approach relative to vendors relying primarily on signatures or cloud lookups alone.

The core of that pitch is a patented technology called Storyline, which automatically correlates raw process, file, and network events on an endpoint into a coherent narrative of an attack as it unfolds, rather than presenting analysts with a disconnected stream of alerts. Combined with ActiveEDR, SentinelOne's real-time detection and response engine, this lets the Singularity platform take automated remediation action — killing a process, quarantining a file, rolling back ransomware-encrypted files to a known-good state — without requiring a human to first triage the event. Over time, Singularity expanded from endpoint protection into a broader platform covering cloud workload security, identity threat detection, and a unified data lake for security operations, following the same trajectory as most of its major competitors toward consolidated XDR platforms.

SentinelOne has also pursued acquisitions to round out that platform. It acquired Attivo Networks in 2022 to add identity detection and deception technology, later rebranding that capability as Singularity Identity and extending detection into Active Directory and credential-based attacks, and it acquired PingSafe in 2024 to add cloud-native application protection (CNAPP) capabilities, folded into Singularity Cloud Security, positioning the company more directly against cloud security specialists like Wiz and Orca Security as well as fellow endpoint vendors. In 2023 and 2024, SentinelOne introduced Purple AI, a generative AI security analyst built into Singularity that lets security teams query telemetry in natural language and receive suggested hunting queries and investigation summaries — a similar move to CrowdStrike's Charlotte AI, reflecting a broader industry shift toward natural-language interfaces sitting on top of existing detection data rather than replacing the underlying detection engines themselves.

As a public company, SentinelOne has reported strong revenue growth in its filings but, like many venture-scale cybersecurity companies that reached the public markets in 2021, has taken longer to reach consistent GAAP profitability than some of its larger competitors, prioritizing revenue growth and platform expansion. It competes most directly with CrowdStrike and Microsoft Defender for endpoint and XDR budgets, and increasingly with cloud security specialists as its Singularity platform absorbs more of the CNAPP feature set. Unlike CrowdStrike, SentinelOne has not experienced a comparably scaled public operational incident; its public track record centers on steady platform expansion and acquisition-driven capability additions rather than a defining crisis event.

SentinelOne also competes against a market dynamic that is distinctive to endpoint security: Microsoft bundles a baseline version of Defender for Endpoint into many enterprise licensing agreements, giving it a low-friction default option that SentinelOne, CrowdStrike, and other independent vendors must actively displace to win new business. SentinelOne has generally positioned itself on detection and response depth rather than price, arguing that a bundled baseline tier is not equivalent to a dedicated XDR platform for organizations facing sophisticated or targeted threats — a competitive argument common across the broader endpoint security market rather than unique to any single vendor.

For readers tracking how autonomous response claims hold up across the endpoint security category, SentinelOne is a useful comparison point precisely because its founding thesis — on-device, machine-speed containment rather than cloud-dependent human triage — is one of the more explicit architectural bets in the sector. Its acquisition history also illustrates a broader consolidation pattern in cybersecurity, where endpoint, identity, and cloud security vendors are converging toward similar bundled platforms rather than remaining as distinct point products, driven in part by customers wanting fewer agents and fewer vendor relationships to manage.

What the company does

Singularity platform: autonomous endpoint EDR/XDR, cloud workload and CNAPP security (via PingSafe), identity threat detection (via Attivo Networks), and the Purple AI analyst assistant.

Who it serves

Enterprises replacing legacy antivirus and consolidating endpoint, identity, and cloud security under one platform.

Company background

Founded 2013.Tomer Weingarten, Almog Cohen United States

Product and AI capabilities

Singularity platform: autonomous endpoint EDR/XDR, cloud workload and CNAPP security (via PingSafe), identity threat detection (via Attivo Networks), and the Purple AI analyst assistant.

Key developments

Public company (NYSE: S), IPO June 2021. Attivo Networks (2022) and PingSafe (2024) acquisitions confirmed via SentinelOne press releases.

Why it matters

SentinelOne is a direct comparison point to CrowdStrike on autonomous, on-device response claims, and its acquisition history illustrates the broader consolidation of endpoint, identity, and cloud security into unified XDR platforms.

Sector context

See Brel’s Cybersecurity sector hub for related profiles.

Sources and references

Official: https://www.sentinelone.com/company/

Official resources

Sources and references

This article draws on publicly available company information, official websites, filings, interviews, announcements, and other cited sources. Information may change over time.

Company information is based on publicly available sources and is reviewed periodically. If you represent this company and would like to request a correction, contact Brel.

Explore Related Intelligence

The AI Brief

Weekly company intelligence in your inbox.

Subscribe