Vega Security announced a $120 million Series B on February 10, 2026, led by existing investor Accel, with participation from Cyberstarts, Redpoint and CRV. TechCrunch reported that the round brings Vega’s total funding to about $185 million and nearly doubles its valuation to approximately $700 million. The company says it will use the money for product development, go-to-market expansion and international growth.
Vega is building an AI-native “Security Analytics Mesh” (SAM): a federated layer intended to search, detect, investigate and respond across data that remains in existing SIEMs, clouds, data lakes and object stores. That is an alternative to copying every event into one central security-information and event-management (SIEM) system—not proof that every customer can eliminate a SIEM or reduce costs.
What the financing means
| Item | Reported detail |
|---|---|
| Round | $120 million Series B, announced February 10, 2026 |
| Lead investor | Accel, an existing investor |
| Other named investors | Cyberstarts, Redpoint and CRV |
| Total funding | Approximately $185 million, according to TechCrunch; Globes reported $182 million |
| Valuation | About $700 million in TechCrunch’s report; Globes cited an estimated $800 million |
| Stated use of proceeds | Product development, go-to-market hiring and global expansion |
Vega’s own news index contains a September 16, 2025 date for a similarly titled announcement, but the company and current financing coverage identify February 10, 2026 as the announcement date. The date above follows the financing report.
Vega has not published a precise spending breakdown. Coverage says the roadmap includes more work on AI-assisted triage, investigation and case management, alongside broader detection-to-response workflows.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
For a financing event, the valuation and total-funding numbers are reported figures, not audited public-company disclosures. The difference between the TechCrunch and Globes estimates is therefore material context for investors tracking the company.
What Vega is building
Founded in 2024 by Shay Sandler and Eli Rozen, Vega describes itself as an enterprise cybersecurity company rather than a generic AI vendor. Sandler is CEO and Rozen is CTO and co-founder. Both are associated with Israel’s Unit 8200; Sandler was also a founding employee of Granulate, acquired by Intel for $650 million in 2022. Vega has described a workforce of more than 100 people with operations in New York and Tel Aviv.
The company says it has signed multimillion-dollar contracts with global banks, healthcare organizations and Fortune 200 companies. Those are company-reported claims; public sources do not provide a complete customer list, renewal data, deployment sizes or independently measured savings.
The problem with putting every security log in one place
Large organizations rarely keep security telemetry in a single repository. Logs may sit in regional cloud accounts, data lakes, object storage, endpoint products, application platforms and an incumbent SIEM. Centralizing them can require connectors, parsing, schema normalization, migration work, indexed storage and continuing ingestion charges.
That creates a choice between cost and visibility. Teams may retain only recent or high-priority events in an expensive indexed tier while leaving older data in cheaper storage—or omit sources that are difficult to onboard. During threat hunting or an incident, the missing history can matter as much as the data already indexed.
Rank #2
- HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
- UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
- OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
- RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
- EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
Cloud and data-residency requirements make the “send everything to one place” model harder in some environments. Vega and its investors argue that the resulting problem is structural. The available sources do not independently establish that Vega is cheaper or more effective in every deployment.
How the Security Analytics Mesh is supposed to work
Vega presents SAM as a federated analytics layer. Instead of first copying all telemetry into a new repository, the platform connects to existing SIEMs, data lakes, cloud storage and object stores, then offers a common workflow across them. Vega’s platform materials describe natural-language and KQL querying, an MCP integration, and functions spanning search, detection, investigation, triage and response: Vega’s platform overview.
Consider a bank with logs in European and North American cloud storage, an existing SIEM and endpoint-security systems. Under Vega’s stated model, an analyst could search and investigate across those locations without making a wholesale migration first. That example describes the intended operating model, not an independently verified customer deployment.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11| Centralized SIEM model | Vega’s stated SAM model |
|---|---|
| Copies or ingests selected telemetry into a central system | Queries data in its existing locations |
| Ingestion, indexed storage and retention costs grow with data choices | Attempts to separate analytics access from mandatory centralization |
| Requires pipelines, parsers, schemas and migration projects | Claims zero forced migration and zero forced ingestion |
| Historical data may be moved to cheaper tiers or left out | Says it can analyze object-storage and other repository data |
| Detections generally run on the SIEM’s indexed data | Says detections can run across connected sources |
This is a conceptual comparison, not a benchmark. “No ingestion” does not establish that no metadata, cache, temporary index, connector or query-processing infrastructure is required. Federated access can also encounter source permissions, API limits, network latency, schema differences and unavailable repositories.
What the product claims to automate
Vega’s product pages emphasize several layers of functionality:
Rank #3
- 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
- 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
- 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
- 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
- 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
- Detection engineering: AI-assisted authoring, validation, continuous tuning and deployment across platforms.
- Coverage analysis: Detection-gap analysis mapped to MITRE ATT&CK.
- Hunting and investigation: Natural-language or KQL-based searches over connected data.
- Alert operations: AI-assisted or “agentic” triage intended to prioritize and enrich alerts.
- Response workflow: Case management and incident-response processes that Vega says it is expanding.
These should be separated from outcome claims. Federated architecture and product features are architecture and capability assertions. Faster detection, lower total cost, fewer false positives or reduced mean time to respond would require customer evidence or independent testing, which the available sources do not provide. Vega’s AI-detection claims are described at its AI-powered detections page, while its incident-response positioning appears at its incident-readiness page.
Why Accel and the other investors funded Vega
A large incumbent market
Splunk remains the reference point for the legacy SIEM market. Cisco completed its acquisition of Splunk for $28 billion in 2024, making the economics and architecture of enterprise security analytics strategically important well beyond one startup.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsMore data, more locations
AI workloads, cloud services and distributed applications increase the volume and geographic spread of telemetry. A platform that can add analytics without a two-year migration is a compelling buying argument, although Vega has not independently verified that implementation timeline.
Founder and early-customer credibility
The founders’ Unit 8200 and Granulate connections give investors a recognizable technical track record. Vega’s reported multimillion-dollar contracts suggest enterprise willingness to buy, but they do not by themselves prove broad adoption or repeatable economics.
A possible new buying category
Vega’s “post-SIEM” language could mean several things: a SIEM supplement, a data-access layer, a detection-engineering system, a response orchestrator or a combination. The financing thesis is strongest if the product becomes an operating layer above existing tools without forcing customers to discard them.
Rank #4
- Runs UniFi Network for full-stack network management
- Manages 30+ UniFi Network devices and 300+ clients
- 1 Gbps routing with IDS/IPS
- Multi-WAN load balancing
- 0.96" LCM status display
Is SAM a SIEM replacement?
Not on the evidence currently available. Vega can challenge the need to centralize every event, but organizations may still retain an incumbent SIEM for native detections, dashboards, compliance retention, identity context or response integrations. A federated layer may replace selected ingestion and search functions, complement the existing stack, or become an orchestration layer above it. Which outcome applies depends on source coverage, query performance, detection portability and the customer’s operating model.
Recommended Free Tools
Vega’s cost thesis also needs a full workload comparison. Relevant categories include ingestion, indexed and long-term storage, compute, egress, parsing and normalization, connector maintenance, migration, support and analyst time. Vega’s cost-positioning material argues for savings but does not publish a customer-level price model or independently verified calculation.
Where the approach may fit—and where it may not
Potentially attractive environments
- Large enterprises with security data spread across clouds, regions and object storage.
- SOCs that need historical hunting without migrating every archive.
- Teams seeking to preserve existing SIEM and point-product investments while adding cross-environment analytics.
- Programs struggling with source onboarding, detection coverage or alert triage.
Potential limitations
- Federated queries still need connectors, permissions, reliable source availability and compatible schemas.
- Latency and compute costs can vary by repository, region, format and network path.
- AI-generated detections and triage require validation, governance and human escalation.
- A common query layer may not match the depth of the system that owns the underlying data.
- “No migration” reduces one project category; it does not mean no implementation work.
Vega’s query-at-source explanation describes the intended architecture, but buyers should verify exactly what is queried directly, what is indexed or cached, and what data leaves their environment.
How it compares with other enterprise choices
| Option | Core architecture | Pricing signal | Best fit | Main concern |
|---|---|---|---|---|
| Vega | Federated, query-in-place analytics across distributed repositories | Custom, demo-led; no public price found | Large, distributed enterprises | Integration depth, maturity and limited public references |
| Splunk Enterprise Security | Broad centralized security-operations platform with multiple pricing metrics | Custom quote; workload and ingest models are described at Splunk’s security pricing page and pricing-model page | Mature enterprise SOCs | Licensing, ingestion economics and implementation complexity |
| Elastic Security | Cloud SIEM and security analytics with endpoint and cloud features | Workload-based estimator at Elastic’s pricing page; an August 2026 configuration displayed an illustrative $6,584 monthly and $79,010 annual estimate, not a quote | Teams willing to size and manage cloud analytics | Requires careful workload, retention and cost management |
The comparison is architectural and commercial, not a claim that one product wins every workload. Vega appears aimed at buyers specifically trying to avoid mandatory central ingestion; Splunk emphasizes breadth and maturity; Elastic exposes more public estimation but still requires deployment sizing.
Questions enterprise buyers should resolve
- Which repositories and security products are supported natively today?
- Does the platform query directly, create temporary indexes or maintain caches and metadata?
- What happens when a source is offline, a query times out or an API throttles?
- How are permissions, tenant boundaries and regional data-residency rules enforced?
- How are natural-language requests translated, validated and audited?
- Can existing Sigma, YARA, KQL, SPL and custom detections be imported and tested?
- What measured false-positive and false-negative rates exist for AI-assisted detections and triage?
- What is the pricing unit—data queried, storage, users, assets, detections, compute or a hybrid?
- What happens to detections, cases and metadata if the contract ends?
What the $120 million must prove
The round gives Vega resources to expand beyond its initial analytics proposition: more connectors and product engineering, a larger sales and customer-success operation, and international coverage. It also gives the company time to demonstrate whether federated analytics can become a dependable daily operating model rather than an additional abstraction over existing tools.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →The decisive evidence will be repeatable deployments, independently checkable cost comparisons, query and detection performance across heterogeneous sources, and clear controls around AI-generated actions. Until those are public, the financing validates investor interest in reducing dependence on centralized security-data ingestion—not a proven replacement for every SIEM.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




