Darktrace

AI-native cybersecurity platform

Security & Safety Enterprise Has API
Researched · Published · Reviewed
RECATOOLS Score
7.4 / 10
Capability
8
Value for money
6
Ease of use
6
ASEAN readiness
7
API quality
5
Founded
2013
HQ
Cambridge, UK
Users
8000+ enterprise customers
Launched
Jul 2026
Developer
Poppy Gustafsson, Jack Stockdale, others

Overview

Darktrace built its name on self-learning threat detection that flags deviations from a network's own 'normal.' Thoma Bravo took the company private for $5.3 billion in October 2024, ending its LSE listing.

Advertisement

Pricing

Pricing shown for reference only. These figures reflect RECATOOLS research as of 11 Jul 2026 and may be out of date or incomplete. This is not financial or purchasing advice — always confirm the current price on the provider’s official website before making any decision.

Free
Free
Free trial available

Use cases

NDR Autonomous response AI cybersecurity
Advertisement

ASEAN Perspective

Darktrace in Southeast Asia

ASEAN-region availability and pricing notes coming soon. Drop the editorial team a note via /contact/ if you can supply local context (Singapore/Malaysia/Indonesia/Thailand/Vietnam).

RECATOOLS Verdict

Darktrace still does what it always did well: build a live behavioural model of each network and flag anomalies that signature-based tools miss, with Antigena able to throttle a compromised device automatically. That's genuinely useful against novel, no-CVE attacks. Thoma Bravo took the company private for $5.3 billion in October 2024, so the LSE ticker is gone and any framing of it as a public company is outdated. G2 puts it at 4.3 stars across 67 reviews — solid, not stellar — with recurring complaints about alert volume and the tuning period needed before it settles down. Pricing is quote-only and skews toward six-figure enterprise deals; there's a real ASEAN presence via regional offices, but this isn't a self-serve or API-first product.

Independent AI-assisted assessment by RECATOOLS.

What people say

Thoma Bravo closed its $5.3 billion take-private deal for Darktrace on October 1, 2024, so anything describing it as LSE-listed is now out of date. The company still runs as a stand-alone cybersecurity brand under new ownership, with the same core pitch: an unsupervised AI model learns what 'normal' looks like for a given network and flags deviations, rather than matching signatures.

On G2, Darktrace sits at 4.3 stars across 67 reviews. Gartner Peer Insights reviewers echo the same split: strong marks for catching novel, signature-less intrusions and for Antigena's ability to throttle a compromised device automatically, set against a recurring complaint about false positives during the first weeks of deployment. Several reviewers note the alert volume needs real tuning before the platform earns its keep, with 'a good deal of false positives' a phrase that shows up more than once in Gartner feedback.

Pricing is entirely quote-based and modular: separate SKUs for DETECT, RESPOND, EMAIL, CLOUD, ENDPOINT and INDUSTRIAL, with buyers reporting median annual deals around $55,000 and large enterprise contracts running past $300,000 to $500,000 once several modules are bundled. That puts it out of reach for smaller teams and firmly in the enterprise-security-budget category.

Skeptics still push back on how much of the 'AI' framing is marketing versus measurable outcome, a debate that predates the acquisition and hasn't gone away. What has changed is the ownership structure — worth flagging to anyone citing older Darktrace coverage that assumes it's still a public company.

Summary of public user & expert reviews, compiled by RECATOOLS.

Notable facts

  • Darktrace's co-founders include former members of GCHQ (the UK intelligence agency) and the US Department of Homeland Security — the same people who build government cyber defences.
  • The Antigena autonomous response system can identify and contain a ransomware attack within milliseconds — far faster than any human SOC analyst could respond.
  • Darktrace detected a novel cyberattack on a casino through an Internet-of-Things fish tank thermometer that was used as a network entry point.

Frequently asked questions

How is Darktrace different from traditional firewalls?
Darktrace uses unsupervised ML to detect anomalous behaviour within the network, while firewalls block known-bad traffic at the perimeter. Darktrace catches threats that have already entered.
What is Antigena?
Darktrace Antigena is the autonomous response module that takes real-time defensive actions to contain threats without human intervention.
Does Darktrace require a SOC team to operate?
No, though most customers integrate it with their existing SOC. Darktrace provides alerts and autonomous responses that reduce SOC workload.
Is Darktrace suitable for small businesses?
Darktrace targets mid-market and enterprise. Smaller businesses may find the cost and complexity prohibitive.
How is Darktrace deployed?
Via hardware appliance, virtual appliance, or cloud deployment, monitoring network traffic either from a SPAN port or via API integration.

About this listing

Researched on
Published on
Last reviewed

This entry was compiled from publicly available data including Darktrace's official website, press releases, documentation, and reputable third-party publications. RECATOOLS is not affiliated with Darktrace unless explicitly stated.

Data accuracy

Third-party AI tools update their pricing, features, availability, and policies frequently. Information here may be outdated by the time you read this — we make reasonable efforts to keep listings current, but cannot guarantee absolute accuracy.

For the latest details, please refer to Darktrace directly →

Spotted something out of date? Suggest an update →

Advertisement