Devo Security Data Platform
Devo Security Data Platform is an enterprise SaaS that replaces traditional SIEM tools, combining SIEM, SOAR and UEBA with attack-tracing AI so security operations centres can ingest any log source and investigate threats in real time.
What is Devo Security Data Platform?
Devo Security Data Platform is a cloud-native security data platform built by Devo Technology, Inc. to replace the traditional SIEM at the centre of a security operations centre. Rather than selling detection, automation and behavioural analytics as separate products, Devo bundles SIEM, SOAR and UEBA onto a single ingestion and analytics layer, and adds AI on top of it.
That layer is the Data Analytics Cloud, a data-agnostic engine that ingests structured and unstructured data from any source or data lake and keeps it queryable in its original form. Devo claims sub-second query speed, streaming alerts without lag, and up to 400 days of hot data. Around it sit the product's named components. Devo Behavior Analytics provides the UEBA layer, applying a library of AI models across multi-petabyte datasets to flag unusual behaviour and quantify risk. ThreatLink automates alert triage, correlating and enriching alerts into high-fidelity cases and, according to the vendor, reducing thousands of daily alerts to tens. DeepTrace performs autonomous investigation and threat hunting using attack-tracing AI. A separate AI Assist feature, currently offered as a beta service, adds a conversational assistant.
The commercial catalogue has three entries: Data Analytics Cloud on its own, Intelligent SIEM Starter, and Intelligent SIEM. The two Intelligent SIEM packages both include unlimited users, detections and case management; the Starter tier caps behavioural models and automation playbooks at two each, while the full package removes those limits. None of the three carries a public price.
Devo licenses on ingest volume under a single metric, and markets that as predictable pricing. Deployment covers cloud, hybrid and on-premise environments, with separate regional entry points for the United States and the European Union. Integrations span email, cloud, database, operating system, web server and network log sources, plus threat intelligence feeds, third-party SOAR tools and ITSM platforms such as ServiceNow.
The company is headquartered in Massachusetts with operations across North America, Europe and Asia-Pacific, and cites Gartner, IDC and GigaOm recognition from 2024 alongside Fortune 500 customers including AT&T, Ulta Beauty and OneMain Financial.
What it does
- Ingest any log source in its original form, with no prior transformation or schema work
- Detect threats in real time using streaming correlation, enrichment and MITRE ATT&CK context
- Collapse alert volume into a small number of enriched cases with automated triage
- Run autonomous investigations and threat hunts with attack-tracing AI
- Surface anomalous user, device and domain behaviour through a library of AI models
- Automate response with no-code SOAR playbooks and decision automation
- Route data by value, keeping high-value telemetry hot and storing the rest more cheaply
When to use Devo Security Data Platform / When not to
A quick filter to help you decide if Devo Security Data Platform is the right fit.
When to use Devo Security Data Platform
- Enterprise SOC teams drowning in alerts, who need automated triage that collapses thousands of alerts into a handful of workable cases
- Organisations planning to migrate off a legacy SIEM, with Splunk, Exabeam, Chronicle, Sentinel and Sumo Logic all addressed directly by the vendor
- Managed security service providers, who need genuine multi-tenancy and per-customer separation on a single platform
- Regulated sectors named by the vendor itself: financial services, public sector, telecommunications and higher education
- IT operations teams that want the same ingestion layer for infrastructure and network telemetry, not only for security use cases
When not to use Devo Security Data Platform
- Small teams or individuals: nothing is priced publicly, and every package routes to a sales conversation
- Buyers who want to sign up and start today, since access begins with a demo request and a qualification call
- Anyone looking for a free tier or an advertised free trial, neither of which exists
- Mobile-first users, as there is no iOS or Android application of any kind
- Workloads involving protected health information or payment card data, which the terms of service explicitly forbid storing
How to use Devo Security Data Platform
A typical end-to-end flow, from setup to results.
- Explore the public interactive demos, which walk through the platform, DeepTrace, ThreatLink and the Detecteam integration without any sign-up
- Use the Data Sizing Tool on the site to estimate your ingest volume, since licensing is based on it
- Submit a demo request; Devo schedules a 15-minute qualification call before the demonstration itself
- Work with the sales team to choose between Data Analytics Cloud, Intelligent SIEM Starter and Intelligent SIEM, and to obtain a quotation
- Agree the deployment model: Devo-hosted cloud, hybrid cloud in your own environment, or on-premise
- Onboard through the vendor's guided migration process, delivered with partners
- Connect log sources using the self-service data connectors, by category of source
- Sign in through the regional instance that applies to you, us.devo.com or eu.devo.com
- Configure detections, behavioural models and no-code SOAR playbooks, within the limits of your package
- Consult docs.devo.com for technical documentation and community.devo.com for peer support; raise tickets through the support portal or by phone
Pros & Cons
Pros
- Genuinely integrated scope: SIEM, SOAR, UEBA and AI investigation under one licence rather than four products
- A single licensing metric based on ingest volume, which the vendor positions against unpredictable legacy SIEM billing
- Unlimited users, detections and case management on both Intelligent SIEM packages
- Deployment flexibility across cloud, hybrid and on-premise, with distinct EU and US instances
- Public technical documentation and an open community, both reachable without a customer account
- A published data processing addendum, Data Privacy Framework certification, and declared SOC 2 Type II and SOC 3 reports
- Third-party analyst recognition from Gartner, IDC and GigaOm, cited and dated to 2024
Cons
- No public pricing at all: each of the three packages routes to a contact form
- No free plan, and no free trial is advertised anywhere on the site
- Evaluation requires a sales cycle, beginning with a qualification call before any demonstration
- No mobile application on either platform
- AI Assist is a beta service, and enabling it grants Devo a perpetual licence over inputs and outputs to improve its products
- No way to exclude your data from that improvement short of leaving the AI feature switched off entirely
- Documentation hygiene is uneven: the privacy policy served on devo.com is written in the name of another brand, and the legal notice address contradicts the contact page
Pricing & Plans
Devo does not publish any price. All three catalogue entries, Data Analytics Cloud, Intelligent SIEM Starter and Intelligent SIEM, direct the buyer to contact the vendor for pricing, so no entry-level amount or currency can be stated. There is no permanent free plan, and the site advertises no free trial; the only self-service route is a set of interactive product tours. Licensing is described as predictable and based on data ingest volume under a single licence metric, and a Data Sizing Tool is offered to estimate that volume. Professional services are sold separately.
- real-time
- data-agnostic ingestion and analytics
- includes interactive visualisations
- self-service multitenancy
- advanced analytics and open APIs
- sold standalone or included with every Intelligent SIEM package
- price on request
- entry package built on Data Analytics Cloud
- including SIEM
- a SOAR starter and ThreatLink
- unlimited users
- detections and case management
- but capped at 2 behavioural models and 2 automation playbooks
- price on request
- flagged 'Most Popular'
- unlimited SIEM
- SOAR and ThreatLink functionality
- with unlimited behavioural models and automation playbooks
- price on request
Data, GDPR & hosting
A consolidated view of how Devo Security Data Platform handles your data.
GDPR overview
The privacy statement carries a dedicated GDPR section and asserts a commitment to compliance. Devo Technology Inc. and its Spanish branch are certified under the EU-U.S. Data Privacy Framework, its UK extension and the Swiss-U.S. Framework, yet the same page states that Devo does not rely on those frameworks for transfers in its processor role and uses standard contractual clauses instead. A data processing addendum is published as a PDF, incorporating the EU standard contractual clauses and a UK international data transfer addendum. No Article 27 representative is named, which is consistent with the company operating a Spanish branch inside the EU. Privacy enquiries go to privacy@devo.com, Framework complaints to legal@devo.com. One caveat: the privacy policy served on devo.com is written throughout in the name of a different brand, Strike48.
Who owns the data?
Under the AI Assist product terms, the customer keeps ownership of the Inputs it submits and owns the Outputs the system returns, except for any pre-existing Devo material embedded in them; Devo formally assigns to the customer whatever rights it might otherwise hold in those Outputs. In exchange the customer grants Devo a worldwide, non-exclusive, royalty-free and transferable licence over both Inputs and Outputs. That licence has two tiers: one limited to operating AI Assist, and a second, perpetual one allowing Devo to use the same material to develop and improve AI Assist and the wider Services. Devo may also exploit aggregated statistics generated by the system.
Reuse rights
Customers may use the Outputs freely within their own operations, and Devo does not require permission for that reuse; the terms warn instead that Outputs may not qualify for copyright protection, that identical Outputs may be returned to other customers, and that the customer alone is responsible for reviewing them before relying on them. The constraint runs the other way: enabling AI Assist grants Devo a perpetual right to reuse the customer's Inputs and Outputs to improve its products. Enabling the feature is optional and can be terminated at any time, but no setting excludes customer data from that improvement while the feature is in use.
Data retention & training
Hosting summary
Devo names Amazon Web Services, of 410 Terry Avenue North, Seattle, as a cloud hosting subprocessor in Annex III of its data processing addendum. Clause 8.5 of the same document allows Devo to subcontract to AWS, Google Cloud Platform, Microsoft Azure or another comparable cloud hosting provider, so the named subprocessor is a floor rather than an exhaustive list. Two regional entry points exist, us.devo.com for the United States and eu.devo.com for the European Union, which indicates regional separation of customer environments. The terms of service also allow services to be hosted by the customer in its own environment or run on-premise, in which case hosting is outside Devo's control entirely. No specific hosting country or data centre region is declared anywhere on the site, and the privacy statement notes that personal data may be processed in any country where Devo, its affiliates or its providers operate, subject to standard contractual clauses.
Where Devo Security Data Platform works
Country-level availability.
Not available in
Things to keep in mind
Risks and trade-offs to weigh before adopting Devo Security Data Platform.
- Enabling AI Assist grants Devo a perpetual licence over your inputs and outputs to improve its products; the only way out is to leave the feature switched off
- AI Assist is supplied as a beta service and disclaims all warranties on its outputs, so analysts must verify conclusions rather than act on them directly
- Autonomous investigation can encourage over-trust: if triage and hunting run at machine speed, teams risk losing the manual skills needed when the AI is wrong
- The privacy policy served on devo.com is written in the name of a different brand, so any compliance commitment taken from it should be confirmed in the contract
- Company addresses conflict between the legal notice and the contact page, and three different legal names appear across the site and public filings
- SOC 2 Type II and SOC 3 are asserted without a certificate number, auditor or date, and the reports are only reachable through an external security profile
- Ingest-based licensing shifts cost control onto data volume decisions, so poor orchestration choices can turn into budget surprises despite the vendor's predictability claim
Setup & Integrations
Technical difficulty
Moderate, and largely vendor-led. There is no self-service installation: onboarding runs through a guided migration process delivered with partners, on the back of more than a thousand enterprise deployments. Log sources connect through self-service connectors and data is ingested without prior transformation, which removes much of the schema work a legacy SIEM demands. Customers report faster implementation than expected and the vendor claims return on investment in under two months. Real effort lies in detection engineering, playbook design and ingest sizing rather than in installation. Professional services are available separately.
Deployment
Integrations
Supported languages
Behind Devo Security Data Platform
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement Devo Security Data Platform.
Frequently asked questions
How much does Devo Security Data Platform cost?
Is there a free plan or a free trial?
What is the difference between Intelligent SIEM Starter and Intelligent SIEM?
Does Devo offer an API?
Is there a mobile app?
Will my data be used to train Devo's AI?
Where is the data hosted?
What security certifications does Devo hold?
Is a data processing agreement available?
What is the minimum age to use the service?
Should you pick Devo Security Data Platform?
Devo Security Data Platform is a credible enterprise contender rather than a tool an individual analyst picks up on a weekend. The integrated scope is its strongest argument: SIEM, SOAR, UEBA, automated case management and autonomous investigation sit on one ingestion layer under a single licence metric, which is genuinely unusual in a market that tends to sell these as separate products. More than 500 million USD raised, Fortune 500 references and 2024 analyst recognition from Gartner, IDC and GigaOm all support the claim that the platform operates at scale.
The trade-off is opacity. Nothing is priced publicly, there is no free plan and no advertised trial, and any serious evaluation starts with a qualification call. Buyers cannot compare Devo against alternatives on cost without engaging its sales team, and the ingest-based metric means the real bill depends on a volume estimate made before purchase. The interactive demos and the Data Sizing Tool soften this, but only slightly.
Two points deserve attention before signing. First, AI Assist is a beta feature whose terms grant Devo a perpetual licence over inputs and outputs to improve its products, with no opt-out other than leaving the feature disabled. Second, the company's published documents are inconsistent: the privacy policy served on devo.com is written throughout in the name of another brand, and the legal notice gives a Cambridge address that the contact page and site footer contradict with a Boston one. Neither undermines the product, but both mean that compliance facts drawn from those pages should be confirmed contractually rather than taken from the website.
- Choosing a selection results in a full page refresh.
- Opens in a new window.