Devo Security Data Platform logo
Privacy Security · Security Fraud

Devo Security Data Platform

Devo Security Data Platform is an enterprise SaaS that replaces traditional SIEM tools, combining SIEM, SOAR and UEBA with attack-tracing AI so security operations centres can ingest any log source and investigate threats in real time.

Active GDPR compliant Contact Sales API available 18+ Verified by Guidaio
Overview

What is Devo Security Data Platform?

Devo Security Data Platform is a cloud-native security data platform built by Devo Technology, Inc. to replace the traditional SIEM at the centre of a security operations centre. Rather than selling detection, automation and behavioural analytics as separate products, Devo bundles SIEM, SOAR and UEBA onto a single ingestion and analytics layer, and adds AI on top of it.

That layer is the Data Analytics Cloud, a data-agnostic engine that ingests structured and unstructured data from any source or data lake and keeps it queryable in its original form. Devo claims sub-second query speed, streaming alerts without lag, and up to 400 days of hot data. Around it sit the product's named components. Devo Behavior Analytics provides the UEBA layer, applying a library of AI models across multi-petabyte datasets to flag unusual behaviour and quantify risk. ThreatLink automates alert triage, correlating and enriching alerts into high-fidelity cases and, according to the vendor, reducing thousands of daily alerts to tens. DeepTrace performs autonomous investigation and threat hunting using attack-tracing AI. A separate AI Assist feature, currently offered as a beta service, adds a conversational assistant.

The commercial catalogue has three entries: Data Analytics Cloud on its own, Intelligent SIEM Starter, and Intelligent SIEM. The two Intelligent SIEM packages both include unlimited users, detections and case management; the Starter tier caps behavioural models and automation playbooks at two each, while the full package removes those limits. None of the three carries a public price.

Devo licenses on ingest volume under a single metric, and markets that as predictable pricing. Deployment covers cloud, hybrid and on-premise environments, with separate regional entry points for the United States and the European Union. Integrations span email, cloud, database, operating system, web server and network log sources, plus threat intelligence feeds, third-party SOAR tools and ITSM platforms such as ServiceNow.

The company is headquartered in Massachusetts with operations across North America, Europe and Asia-Pacific, and cites Gartner, IDC and GigaOm recognition from 2024 alongside Fortune 500 customers including AT&T, Ulta Beauty and OneMain Financial.

What it does

  • Ingest any log source in its original form, with no prior transformation or schema work
  • Detect threats in real time using streaming correlation, enrichment and MITRE ATT&CK context
  • Collapse alert volume into a small number of enriched cases with automated triage
  • Run autonomous investigations and threat hunts with attack-tracing AI
  • Surface anomalous user, device and domain behaviour through a library of AI models
  • Automate response with no-code SOAR playbooks and decision automation
  • Route data by value, keeping high-value telemetry hot and storing the rest more cheaply
Audience

When to use Devo Security Data Platform / When not to

A quick filter to help you decide if Devo Security Data Platform is the right fit.

When to use Devo Security Data Platform

  • Enterprise SOC teams drowning in alerts, who need automated triage that collapses thousands of alerts into a handful of workable cases
  • Organisations planning to migrate off a legacy SIEM, with Splunk, Exabeam, Chronicle, Sentinel and Sumo Logic all addressed directly by the vendor
  • Managed security service providers, who need genuine multi-tenancy and per-customer separation on a single platform
  • Regulated sectors named by the vendor itself: financial services, public sector, telecommunications and higher education
  • IT operations teams that want the same ingestion layer for infrastructure and network telemetry, not only for security use cases

When not to use Devo Security Data Platform

  • Small teams or individuals: nothing is priced publicly, and every package routes to a sales conversation
  • Buyers who want to sign up and start today, since access begins with a demo request and a qualification call
  • Anyone looking for a free tier or an advertised free trial, neither of which exists
  • Mobile-first users, as there is no iOS or Android application of any kind
  • Workloads involving protected health information or payment card data, which the terms of service explicitly forbid storing
Get started

How to use Devo Security Data Platform

A typical end-to-end flow, from setup to results.

  1. Explore the public interactive demos, which walk through the platform, DeepTrace, ThreatLink and the Detecteam integration without any sign-up
  2. Use the Data Sizing Tool on the site to estimate your ingest volume, since licensing is based on it
  3. Submit a demo request; Devo schedules a 15-minute qualification call before the demonstration itself
  4. Work with the sales team to choose between Data Analytics Cloud, Intelligent SIEM Starter and Intelligent SIEM, and to obtain a quotation
  5. Agree the deployment model: Devo-hosted cloud, hybrid cloud in your own environment, or on-premise
  6. Onboard through the vendor's guided migration process, delivered with partners
  7. Connect log sources using the self-service data connectors, by category of source
  8. Sign in through the regional instance that applies to you, us.devo.com or eu.devo.com
  9. Configure detections, behavioural models and no-code SOAR playbooks, within the limits of your package
  10. Consult docs.devo.com for technical documentation and community.devo.com for peer support; raise tickets through the support portal or by phone
Quick read

Pros & Cons

Pros

  • Genuinely integrated scope: SIEM, SOAR, UEBA and AI investigation under one licence rather than four products
  • A single licensing metric based on ingest volume, which the vendor positions against unpredictable legacy SIEM billing
  • Unlimited users, detections and case management on both Intelligent SIEM packages
  • Deployment flexibility across cloud, hybrid and on-premise, with distinct EU and US instances
  • Public technical documentation and an open community, both reachable without a customer account
  • A published data processing addendum, Data Privacy Framework certification, and declared SOC 2 Type II and SOC 3 reports
  • Third-party analyst recognition from Gartner, IDC and GigaOm, cited and dated to 2024

Cons

  • No public pricing at all: each of the three packages routes to a contact form
  • No free plan, and no free trial is advertised anywhere on the site
  • Evaluation requires a sales cycle, beginning with a qualification call before any demonstration
  • No mobile application on either platform
  • AI Assist is a beta service, and enabling it grants Devo a perpetual licence over inputs and outputs to improve its products
  • No way to exclude your data from that improvement short of leaving the AI feature switched off entirely
  • Documentation hygiene is uneven: the privacy policy served on devo.com is written in the name of another brand, and the legal notice address contradicts the contact page
Pricing

Pricing & Plans

Devo does not publish any price. All three catalogue entries, Data Analytics Cloud, Intelligent SIEM Starter and Intelligent SIEM, direct the buyer to contact the vendor for pricing, so no entry-level amount or currency can be stated. There is no permanent free plan, and the site advertises no free trial; the only self-service route is a set of interactive product tours. Licensing is described as predictable and based on data ingest volume under a single licence metric, and a Data Sizing Tool is offered to estimate that volume. Professional services are sold separately.

Plan 1
Data Analytics Cloud
  • real-time
  • data-agnostic ingestion and analytics
  • includes interactive visualisations
  • self-service multitenancy
  • advanced analytics and open APIs
  • sold standalone or included with every Intelligent SIEM package
  • price on request
Plan 3
Intelligent SIEM
  • flagged 'Most Popular'
  • unlimited SIEM
  • SOAR and ThreatLink functionality
  • with unlimited behavioural models and automation playbooks
  • price on request
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Devo Security Data Platform handles your data.

GDPR overview

The privacy statement carries a dedicated GDPR section and asserts a commitment to compliance. Devo Technology Inc. and its Spanish branch are certified under the EU-U.S. Data Privacy Framework, its UK extension and the Swiss-U.S. Framework, yet the same page states that Devo does not rely on those frameworks for transfers in its processor role and uses standard contractual clauses instead. A data processing addendum is published as a PDF, incorporating the EU standard contractual clauses and a UK international data transfer addendum. No Article 27 representative is named, which is consistent with the company operating a Spanish branch inside the EU. Privacy enquiries go to privacy@devo.com, Framework complaints to legal@devo.com. One caveat: the privacy policy served on devo.com is written throughout in the name of a different brand, Strike48.

Who owns the data?

Under the AI Assist product terms, the customer keeps ownership of the Inputs it submits and owns the Outputs the system returns, except for any pre-existing Devo material embedded in them; Devo formally assigns to the customer whatever rights it might otherwise hold in those Outputs. In exchange the customer grants Devo a worldwide, non-exclusive, royalty-free and transferable licence over both Inputs and Outputs. That licence has two tiers: one limited to operating AI Assist, and a second, perpetual one allowing Devo to use the same material to develop and improve AI Assist and the wider Services. Devo may also exploit aggregated statistics generated by the system.

Reuse rights

Customers may use the Outputs freely within their own operations, and Devo does not require permission for that reuse; the terms warn instead that Outputs may not qualify for copyright protection, that identical Outputs may be returned to other customers, and that the customer alone is responsible for reviewing them before relying on them. The constraint runs the other way: enabling AI Assist grants Devo a perpetual right to reuse the customer's Inputs and Outputs to improve its products. Enabling the feature is optional and can be terminated at any time, but no setting excludes customer data from that improvement while the feature is in use.

Data retention & training

Retention summary
Devo keeps personal information only as long as necessary for the business purposes set out in its privacy statement, unless a law requires or permits longer retention. Records of privacy requests are kept separately for audit purposes. Account deletion requests are honoured within a reasonable time, though some data may be retained to meet legal or regulatory obligations. On termination of a subscription, access is disabled and customer content is deleted except where it survives in backups. No specific retention period is published for personal data. This is distinct from the platform's operational capability of keeping up to 400 days of log data hot and queryable, which is a product characteristic rather than a privacy commitment.
Trains on customer data
Yes
Subprocessors disclosed
Yes
DPA available
Yes
GDPR contact

Hosting summary

Devo names Amazon Web Services, of 410 Terry Avenue North, Seattle, as a cloud hosting subprocessor in Annex III of its data processing addendum. Clause 8.5 of the same document allows Devo to subcontract to AWS, Google Cloud Platform, Microsoft Azure or another comparable cloud hosting provider, so the named subprocessor is a floor rather than an exhaustive list. Two regional entry points exist, us.devo.com for the United States and eu.devo.com for the European Union, which indicates regional separation of customer environments. The terms of service also allow services to be hosted by the customer in its own environment or run on-premise, in which case hosting is outside Devo's control entirely. No specific hosting country or data centre region is declared anywhere on the site, and the privacy statement notes that personal data may be processed in any country where Devo, its affiliates or its providers operate, subject to standard contractual clauses.

Availability

Where Devo Security Data Platform works

Country-level availability.

Not available in

🇲🇲 Myanmar (Burma)🇨🇺 Cuba🇮🇷 Iran🇱🇾 Libya🇸🇩 Sudan🇸🇾 Syria🇰🇵 North Korea
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Devo Security Data Platform.

  • Enabling AI Assist grants Devo a perpetual licence over your inputs and outputs to improve its products; the only way out is to leave the feature switched off
  • AI Assist is supplied as a beta service and disclaims all warranties on its outputs, so analysts must verify conclusions rather than act on them directly
  • Autonomous investigation can encourage over-trust: if triage and hunting run at machine speed, teams risk losing the manual skills needed when the AI is wrong
  • The privacy policy served on devo.com is written in the name of a different brand, so any compliance commitment taken from it should be confirmed in the contract
  • Company addresses conflict between the legal notice and the contact page, and three different legal names appear across the site and public filings
  • SOC 2 Type II and SOC 3 are asserted without a certificate number, auditor or date, and the reports are only reachable through an external security profile
  • Ingest-based licensing shifts cost control onto data volume decisions, so poor orchestration choices can turn into budget surprises despite the vendor's predictability claim
Setup

Setup & Integrations

Technical difficulty

Moderate, and largely vendor-led. There is no self-service installation: onboarding runs through a guided migration process delivered with partners, on the back of more than a thousand enterprise deployments. Log sources connect through self-service connectors and data is ingested without prior transformation, which removes much of the schema work a legacy SIEM demands. Customers report faster implementation than expected and the vendor claims return on investment in under two months. Real effort lies in detection engineering, playbook design and ingest sizing rather than in installation. Professional services are available separately.

Deployment

Web appAPI

Integrations

Amazon Web Services Microsoft Azure Google Cloud Oracle MongoDB Palo Alto Networks Zscaler Cisco Akamai Juniper Networks Symantec Sophos Rapid7 Salesforce Office 365 ServiceNow Microsoft Sentinel Detecteam

Supported languages

EnglishSpanish
Company

Behind Devo Security Data Platform

Company name
Devo Technology, Inc.
Founded
INFORMATION_NOT_FOUND
Country of origin
🇺🇸 United States
Headquarters
255 Main St, Suite 702, Cambridge, MA 02142, United States
EU office
3-5 Calle Estebanez Calderon, 5th Floor, 28020 Madrid, Spain
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇺🇸 United States
Legal contact

Fundraising

Series D, 60 million USD, 15 September 2020, led by Georgian with Bessemer Venture Partners and Insight Partners
Series E, 250 million USD, 26 October 2021, led by TCV with new investors General Atlantic and Eurazeo, at a 1.5 billion USD valuation and more than 400 million USD raised in total
Series F, 100 million USD, 2 June 2022, led by Eurazeo with all existing investors and a strategic investment from ISAI Cap Venture, at a 2 billion USD valuation and more than 500 million USD raised in total
Backers listed by the company: Insight Partners, Georgian, TCV, General Atlantic, Bessemer Venture Partners, Kibo Ventures and Eurazeo

Social

Official links

Resources

All the official URLs gathered for verification and reference.

Compare

Alternatives

Tools that compete with or complement Devo Security Data Platform.

S SplunkE ExabeamG Google ChronicleM Microsoft SentinelS Sumo Logic
FAQ

Frequently asked questions

How much does Devo Security Data Platform cost?
Devo publishes no prices. All three packages, Data Analytics Cloud, Intelligent SIEM Starter and Intelligent SIEM, direct you to contact the vendor. Licensing is based on data ingest volume under a single metric.
Is there a free plan or a free trial?
There is no free plan and no advertised free trial. The website terms describe a registrable 30-day Demo Service on app.devo.com, but no commercial page presents it as a trial. Interactive product tours are freely available without signing up.
What is the difference between Intelligent SIEM Starter and Intelligent SIEM?
Both include unlimited users, detections and ThreatLink case management. Starter is capped at two behavioural models and two automation playbooks; the full Intelligent SIEM package removes both limits and includes full SOAR rather than a SOAR starter.
Does Devo offer an API?
Yes. Open APIs are listed as part of the Data Analytics Cloud package and the homepage advertises a comprehensive API. Technical documentation is published at docs.devo.com.
Is there a mobile app?
No. There is no iOS or Android application, and the site links to no app store.
Will my data be used to train Devo's AI?
If you enable AI Assist, yes. Its product terms grant Devo a perpetual licence to use your inputs and outputs to develop and improve AI Assist and the wider services. Enabling the feature is optional, but there is no separate opt-out while it is in use.
Where is the data hosted?
Devo names Amazon Web Services as a cloud hosting subprocessor in its data processing addendum, and its terms allow other major cloud providers. Separate United States and European Union instances exist, but no specific hosting country is declared.
What security certifications does Devo hold?
Devo declares a SOC 2 Type II report and publishes SOC 3 reports through its legal centre. No certificate number, auditor or validity date is published; the reports sit behind an external security profile.
Is a data processing agreement available?
Yes. A personal data processing addendum is published as a public PDF, incorporating the EU standard contractual clauses and a UK international data transfer addendum.
What is the minimum age to use the service?
The website terms require users to be over 18, or to have parental or guardian consent.
Conclusion

Should you pick Devo Security Data Platform?

Devo Security Data Platform is a credible enterprise contender rather than a tool an individual analyst picks up on a weekend. The integrated scope is its strongest argument: SIEM, SOAR, UEBA, automated case management and autonomous investigation sit on one ingestion layer under a single licence metric, which is genuinely unusual in a market that tends to sell these as separate products. More than 500 million USD raised, Fortune 500 references and 2024 analyst recognition from Gartner, IDC and GigaOm all support the claim that the platform operates at scale.

The trade-off is opacity. Nothing is priced publicly, there is no free plan and no advertised trial, and any serious evaluation starts with a qualification call. Buyers cannot compare Devo against alternatives on cost without engaging its sales team, and the ingest-based metric means the real bill depends on a volume estimate made before purchase. The interactive demos and the Data Sizing Tool soften this, but only slightly.

Two points deserve attention before signing. First, AI Assist is a beta feature whose terms grant Devo a perpetual licence over inputs and outputs to improve its products, with no opt-out other than leaving the feature disabled. Second, the company's published documents are inconsistent: the privacy policy served on devo.com is written throughout in the name of another brand, and the legal notice gives a Cambridge address that the contact page and site footer contradict with a Boston one. Neither undermines the product, but both mean that compliance facts drawn from those pages should be confirmed contractually rather than taken from the website.