/Companies

Panther Labs

Founded 2018 · 259 employees on LinkedIn · 10 known investors

Find your way into Panther Labs

Each arrow is one introduction. Sign up to fill in the first one.

394 people can intro you to Jack

Ask Sean Leach to introduce you to Jack Naglieri

You →Sean · together at Verisign →Jack

Sign up to find every way you can get introduced to Panther Labs

  • Your email: who you already know at Panther Labs, and who your contacts know
  • 2nd- and 3rd-degree connections: people you know who worked, studied or invested with the Panther Labs team
  • Your LinkedIn: the connections who can make the intro for you

We rank every route by how warm it is, so you raise on warm intros instead of cold emails.

Panther is an AI-powered SOC (security operations center) platform that ingests and normalizes security logs at scale, lets teams write detection rules in Python or via natural language, and uses agents to triage alerts, run investigations, and hunt threats. It serves enterprise security teams and offers both a hosted managed cloud and a model that runs inside a customer's own AWS account against Snowflake or Databricks.

Also known as Panther Labs · Panther, Inc.

Founders & leadership

Panther Labs was founded in 2018 by Jack Naglieri.

JNJack Naglieri
Jack NaglieriFounder & CEOJack Naglieri began his career as an incident responder at Yahoo before moving to Airbnb, where he led development of StreamAlert, an open-source framework for security log analysis in Python. He founded Panther, an AI-powered SOC platform that combines security data lakes, detection-as-code, and AI agents for enterprise security teams.

Investors · 10

Company profile

researched Aug 2026

Panther offers what it calls a complete AI SOC platform, combining SIEM capabilities with agentic automation across the detection and response lifecycle. The platform is positioned as an alternative to legacy SIEM and SOAR tooling that has had AI added on top, and to point solutions that operate across fragmented data sources such as separate cloud log stores, EDR portals and MDR consoles.

Functionally, the product covers four areas: detection engineering, in which agents handle repetitive work and detections can be created from natural language descriptions while quality is governed at each step; scheduled proactive threat hunting, in which agents query the full data lake on a cadence and route findings into new detections through a governed workflow; automated triage, in which each alert is investigated with context and confirmed-benign alerts are closed automatically while outcomes are stored to suppress repeat alerts; and investigation and response, in which the agent assembles cross-system investigations and analysts review and direct agentic runbooks. Detection engineering also supports Python.

Governance controls are a stated design element: human approval is required for every write action, all AI actions are logged and reviewable, user permissions are enforced with agents acting under the invoking identity, and each customer runs in an isolated tenant on Amazon Bedrock with no cross-tenant data sharing and no customer data used for model training.

Traction

The company cites customer results including an 85% reduction in alerts reaching the queue through outcome-based suppression, and a customer statement that a fully deployed in-house enterprise SOC was stood up in a matter of weeks using Panther's SIEM and AI SOC.

Latest developments

Panther announced that it is joining Databricks to build the future of the security lakehouse.

▸Full profile — market position, technology, go-to-market

Market position

Panther positions itself as purpose-built for agents from the outset rather than AI layered onto legacy SIEM and SOAR products or agents assembled across fragmented data sources. It emphasizes a closed loop in which every alert is investigated and every outcome is retained to improve future detections and reduce alert volume, alongside transparency controls such as human-in-the-loop approval and reviewable agent actions, and it contrasts its cost model with incumbents whose bills grow without added value.

Technology

The platform is built around agents operating over a centralized security data lake rather than siloed consoles. Detections can be authored in Python or generated from natural language, and agent outputs feed back into the system so that stored investigation outcomes inform subsequent triage and suppress repeat alerts. AI inference runs in an isolated per-customer tenant on Amazon Bedrock, with logging of agent actions, enforcement of the invoking user's permissions, and mandatory human approval for write operations.

Go-to-market

Enterprise and mid-market security operations teams, including in-house SOC and detection engineering functions; a published testimonial references a security team of five engineers and a reviewer at an organization with more than 500 employees.

Compiled by commissioned research from 9 cited public sources — announcements, filings, and press listed under research sources below.

Key figures

latest reported
Customer cost savingsJan 2026$400K
Faster detection tuningJan 202670%
Faster investigationsJan 2026~2x faster investigations
Out-of-the-box data integrationsJun 2026100 integrations
Reduction in alerts reaching the analyst queueJan 202585%
Reduction in alerts reaching the queueJan 202685%
Total venture capital raisedJan 2023$100M

Company-reported or press-reported figures, each dated to when it was claimed — not independently audited.

Timeline · 2

launches, deals, and filings
Jun 2026
Databricks agrees to acquire Panther

Databricks announced at Data + AI Summit its intent to acquire Panther, an AI SOC platform, to advance its security lakehouse vision and its Lakewatch product. The deal, Databricks' third security acquisition after Antimatter and SiftD.ai, was subject to customary closing conditions including required regulatory clearances.

source ↗

Jan 2025
Panther joins Databricks to build the security lakehouse

Panther announced on its website that it is joining Databricks to build the future of the security lakehouse.

source ↗

Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.

In the news

▸Research sources · 9

primary sources listed

9 public sources were cited for this profile; the first-party ones are listed here.

Frequently asked questions

What does Panther Labs do?
Panther is an AI-driven security operations platform that automates detection engineering, alert triage, and investigations.
Who founded Panther Labs?
Panther Labs was founded by Jack Naglieri in 2018.
Who are Panther Labs's investors?
Panther Labs's investors include Coatue Management, ICONIQ, Lightspeed Venture Partners, Sampac Tech Fund, Vibe Capital, ICONIQ Capital, ICONIQ Growth, Innovation Endeavors and 2 more.