Fundraising Fox

Gradient Cyber

Founded 2017 · 54 employees on LinkedIn · 1 known investors

Gradient Cyber provides Managed Extended Detection and Response (MXDR) built for mid-market organizations, using its Quorum AI platform to run an 8-stage pipeline that normalizes, enriches, correlates, and responds to telemetry from endpoint, network, cloud, identity, and SaaS sources. The service is backed by a 24x7 human-led security operations center (SOC) and maps detections to the MITRE ATT&CK framework.

Also known as Gradient Cyber, LLC

Investors · 1

Funding

SEC filings, press & company announcements

Source: company announcements and press reports — follow each round's link for the claim.

Company profile

researched Aug 2026

Gradient Cyber is a cybersecurity services company headquartered in Southlake, Texas, that provides Managed Extended Detection and Response (MXDR) for mid-market organizations. Its service combines a proprietary XDR platform, branded Quorum AI, with a 24x7 in-house security operations center staffed by security analysts. The platform ingests telemetry from network, endpoint, cloud, SaaS and identity sources and processes it through an eight-stage detection and response pipeline: events are normalized to the open OCSF standard, enriched with asset and vulnerability context, evaluated by dual detection engines (rule-based and behavioral anomaly detection), and correlated into attack narratives mapped to the MITRE ATT&CK framework before a human analyst reviews the finding.

Beyond core detection and response, the company offers adjacent security services including risk and threat assessments, penetration testing, vulnerability assessment, incident response, security awareness training and virtual CISO (vCISO) advisory. Gradient Cyber positions its architecture as open and additive, integrating with tools customers already own rather than requiring replacement of an existing security stack. It also publishes a Situation Report (SitRep) API and data structures intended for use by other security teams, and shares threat findings at industry events.

Founding story

Founded in 2017 to address what the company describes as a gap for mid-sized businesses, which it says were underserved by traditional cybersecurity providers offering either overpriced enterprise solutions or standardized services poorly matched to their needs. James Hamilton is listed as founder, president and CEO.

Business model

B2B subscription and managed-services model: customers contract for ongoing MXDR monitoring and response delivered from Gradient Cyber's SOC on top of the Quorum AI platform, with additional professional services such as penetration testing, incident response and vCISO advisory available. Third-party profiles categorize the customer profile as subscription SaaS plus services and consulting.

Recurring managed security service subscriptions supplemented by project-based security services. One third-party data provider lists an estimated annual revenue of $7.5 million and revenue per employee of about $145,000; these figures are provider estimates rather than company-reported results.

Traction

The company reports analyzing more than three terabytes of telemetry daily and publishes customer testimonials from a multinational industrial company, a midsize medical group, a large US hospitality company, a regional bank and a retail business. Third-party sources place headcount at roughly 52 employees (51-100 range), with departmental data indicating concentrations in IT/security operations (16) and sales (10), and cite total funding of $10-12 million.

Latest developments

The most recent publicly dated development is the Quorum AI platform, announced in a company post dated January 18, 2026 and recorded by a market-data provider as launched January 20, 2026. The company continues to publish security research and awareness content, including an August 2026 post on autonomous frontier-model attack chains and network-level detection.

Full profile — market position, technology, go-to-market, geography, history, risks & controversies

Market position

Positioned as a mid-market-focused alternative to enterprise MDR/MXDR providers, differentiating on analyst coverage density (a stated 10:1 client-to-analyst ratio versus ratios as high as 75:1 cited for other providers) and on integrating with existing customer tooling. Third-party comparables analysis lists Pondurance, UnderDefense and Proficio as similar companies.

Stated differentiators include an outcome- rather than alert-oriented service, a low client-to-analyst ratio, human analyst review of every finding after automated pipeline processing, claimed 99% false-positive elimination, an open architecture that layers onto existing security tools, MITRE ATT&CK coverage mapping, SOC 2 Type 2 certification and a 30-day no-commitment trial.

Technology

Quorum AI, the company's XDR platform, executes an eight-stage pipeline covering OCSF normalization, multi-layer enrichment with asset and vulnerability context, threat intelligence integration, dual-engine detection combining rules with behavioral anomaly detection, and correlation of events into MITRE ATT&CK-mapped attack narratives, with response actions calibrated to business risk. The company also exposes a Situation Report (SitRep) API for interoperability. Public technology-stack data indicates use of HubSpot CMS and Analytics, Cloudflare CDN and bot management, Envoy, Google Analytics and Mailchimp on its web properties.

Go-to-market

Direct enterprise sales supported by a sales, business development and sales-operations organization, with website-driven demo requests and a free 30-day trial of the MXDR service that runs alongside a prospect's incumbent detection and response tooling. Content marketing (blog posts, cybersecurity awareness training series, case studies and testimonials) and participation in industry events support lead generation.

Mid-market organizations with limited internal security staff and budget, across sectors indicated by customer references including industrial manufacturing, healthcare/medical groups, hospitality, regional banking and retail.

Geography

Headquartered at 1900 W Kirkwood Blvd, Suite 4500C, Southlake, Texas 76092, United States, serving customers including multinational and US-based mid-market organizations.

History

Established in 2017 in Southlake, Texas, Gradient Cyber built a proprietary XDR platform paired with a 24/7 in-house SOC. Third-party funding records indicate a seed round in August 2017, a debt facility in March 2022 (RevTek Capital) and a Series A dated April 25, 2025 led by First Analysis, with total funding reported at $12 million. In January 2026 the company introduced Quorum AI, an eight-stage AI-assisted detection and response pipeline described as the next evolution of its MXDR service.

Risks & controversies

Performance and scale claims such as 99% false-positive elimination, the 10:1 client-to-analyst ratio and daily telemetry volumes are company-stated and not independently verified. Financial figures differ across third-party aggregators, which variously report total funding of $10 million and $12 million and provide algorithmically estimated revenue and valuation figures.

Compiled by commissioned research from 6 cited public sources — announcements, filings, and press listed under research sources below.

Key figures

latest reported
Client-to-analyst ratioJan 202610 to 1
Employee countJan 202652 employees
Employee rangeJan 202651-100 employees
False positive eliminationJan 202699%
HeadcountAug 202654
Telemetry analyzed dailyJan 20263 terabytes per day (3+)
Total funding raisedApr 2025$12M

Company-reported or press-reported figures, each dated to when it was claimed — not independently audited.

Timeline · 2

launches, deals, and filings
Jan 2026
Launch of Quorum AI platform

Gradient Cyber introduced Quorum AI, described as the next evolution of its MXDR offering; the platform runs an 8-stage detection and response pipeline. A company blog post titled 'Quorum AI: The Next Evolution of MXDR' is dated Jan 18, 2026, and a market signal records the launch on Jan 20, 2026.

source ↗

Jan 2025
SOC 2 Type 2 certification cited

Company profile material states Gradient Cyber is SOC 2 Type 2 certified.

source ↗

Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.

In the news

Research sources · 6

primary sources listed

6 public sources were cited for this profile; the first-party ones are listed here.

Frequently asked questions

What does Gradient Cyber do?
Gradient Cyber delivers managed extended detection and response (MXDR) services to mid-market organizations from a 24/7 in-house SOC.
Who are Gradient Cyber's investors?
Gradient Cyber's investors include First Analysis.