IT Brief US - Technology news for CIOs & IT decision-makers
Cloud cyber threat detection digital security data streams shields

SentinelOne to acquire Observo AI, promising faster security data

Yesterday

SentinelOne has announced its intention to acquire Observo AI in a move aimed at reshaping how Security Operations Centre (SOC) teams manage security telemetry and data pipelines.

The acquisition is expected to supplement SentinelOne's current AI-powered SIEM (Security Information and Event Management) and data offerings. According to the company, these solutions have recently delivered record contributions to quarterly bookings and are among the firm's fastest-growing product lines.

Security data pressures

Enterprises are generating larger and more complex streams of security data, placing pressure on security teams and leaving legacy SIEM tools struggling to keep up. The rising volume of telemetry can lead to higher costs, limited visibility, and slower security responses.

Observo AI manages an AI-native, real-time pipeline for telemetry data that processes and routes information before it reaches traditional storage or SIEM solutions. This capability, says SentinelOne, supports a reduction in data volumes by up to 80 percent, potentially driving down costs while improving the speed and quality of threat detection and response.

Commenting on the acquisition, Tomer Weingarten, Chief Executive Officer and Co-Founder of SentinelOne, stated,

"Security is, at its heart, a data problem, and legacy, rules-based data pipeline platforms simply weren't built for today's ever-growing attack surface and data rich security operations. Observo AI is miles ahead of its rivals and will uniquely benefit customers with an AI-native data architecture - one that is open by design, intelligent by default, and built for the scale and speed needed for autonomous security operations. As a result, we can deliver significant new customer and partner value – and customer and partner choice – by allowing for fast and seamless data routing into our AI SIEM, or any other destination."

Integration and capabilities

Observo AI's platform supports various industry-standard open formats, such as OCSF, JSON, OTLP, and Parquet. This enables organisations to move, enrich, and forward security telemetry to any destination, from SIEMs and data lakes to cloud services, without the restrictions of proprietary lock-in. The platform also features AI-driven enrichment, data masking, summarisation, and context-aware detection directly at the data source, which SentinelOne indicates will allow for more efficient operations and faster threat response.

Additionally, Observo AI provides features for large enterprise environments, including centralised management, zero-touch updates, PII masking, and the ability to automatically discover new data types for compliance and governance. This is intended to meet the demands of organisations with thousands of data sources.

Data pipeline evolution

The move to acquire Observo AI builds on SentinelOne's ongoing investment in large-scale data infrastructure, specifically through its Singularity Platform. By integrating Observo AI's technology, SentinelOne aims to create an end-to-end system where data can be ingested from any source, enriched in transit, and retained with full fidelity if required for deeper analysis.

Gurjeet Arora, Co-Founder and Chief Executive Officer of Observo AI, explained,

"Observo AI was born in the AI and cloud era to help security and DevOps teams tackle previously unimaginable data problems as a means of defending an ever growing attack surface. Bringing together Observo's AI-native data pipeline with the world's best AI-native cybersecurity platform is a huge win for customers and an opportunity for our team to work with an unprecedented network of partners, sellers and fellow innovators. As part of SentinelOne, we have a rare opportunity to define the future of autonomous security and solve the data problems that make that possible."

For SentinelOne, the agreement represents a step towards fully autonomous and open AI-driven security operations. Weingarten noted, "This acquisition marks the next phase in SentinelOne's vision to build the most autonomous, open, AI-powered security platform in the industry."

Transaction details

Under the terms of the agreement, SentinelOne will acquire Observo AI through a mix of cash and stock. The acquisition is targeted for completion in SentinelOne's third quarter of fiscal year 2026, pending regulatory approvals and customary closing conditions.

Both companies have highlighted that the transaction is subject to uncertainties and referenced a variety of potential risks that could affect the completion and integration of the deal. These include considerations around maintaining customer and vendor relationships and the potential for business disruption during the transition.

Enterprise customers may see new integration options and an expanded set of tools for tackling data management, intelligence, and security operations, should the acquisition complete as planned.

Follow us on:
Follow us on LinkedIn Follow us on X
Share on:
Share on LinkedIn Share on X