Why SentinelOne remains a leader when it comes to endpoint protection platforms
From Purple AI to Prompt Security acquisition, SentinelOne is a company that is built upon AI and has a platform that can defeat the cyber threats at machine speed, says Kirs Day Senior Vice President and General Manager, Asia Pacific & Japan at SentinelOne.
SentinelOne financial results for its first quarter of fiscal year 2027 which ended on April 30th, 2026 witnessed the AI security vendor’s total revenue grow 21% to US$277 million. As the company pushes the frontier of autonomous, agentic defense across AI, data, cloud, and the endpoint, Tomer Weingarten, CEO of SentinelOne believes that enterprises are choosing SentinelOne as the foundation to build upon their AI journey securely.
A testament to the vendor’s success is its recognition by Gartner as SentinelOne is named a Leader in the 2026 Gartner Magic Quadrant for Endpoint Protection Platforms for the sixth consecutive year. Over the past year, SentinelOne has further advanced the Singularity Platform with AI driven innovations that extend protection across the modern attack surface. The company also completed strategic acquisitions of Prompt Security (AI usage control) and Observo AI (AI data pipelines), further strengthening the Singularity Platform offerings to address emerging AI-era threats and data management at scale.
In an interview with CRN Asia, Kris Day, Senior Vice President and General Manager, Asia Pacific & Japan at SentinelOne, pointed out that while AI is making headlines around the world as well in the region, there are multiple different components that companies need to look into when it comes to securing their AI journey.
This is also why SentinelOne made several acquisitions recently as it looks to improve its product offerings to meet customer requirements. One area in particular that has seen increased interest is the growing need for sovereign data.
“Businesses care about sovereign data and the need for it being on isolated systems and self-hosted systems, especially when you get into the more complex world of critical infrastructure and operational technology,” said Day.
According to Day, some of the biggest questions for businesses is where are they using their AI tools and where do they want these tools going to and how can they do it securely?
“Where do we want the data to go when we're sending these logs? Do we want them going into the cloud? Do we want those LLMs and AI models learning from the data that we are moving to it? Or do we want to kind of contain that? And so now there's questions being asked as to whether we want a sovereign AI type of capability as well,” he explained that these are some of the questions which SentinelOne is helping businesses address in their AI journey.
And this goes down to having the right security protocols in place when using data for AI. For Day, SentinelOne, a company that is built upon AI, has a platform that can defeat the cyber threats at machine speed. The platform combines prevention, detection, and response, which is also one of the reasons why SentinelOne has got an advantage in the world of sovereign protection.
“What we have is an AI-based agent. It's not cloud-dependent, in other words. There are traditional architectures that are signature based but AI can attack them. So signature-based architectures are not powerful in this world of AI-generated attacks. So then you've got the next-generation architectures, which then have this cloud lookup concept. So now they're going back and forth to the cloud, and pushing the need to respond dynamically. But if you're not connected to the cloud, then what?”
This is where Day highlighted that SentinelOne’s security agent, which is built on the premise of AI, sits on the endpoint itself. It doesn't need that cloud connectivity to have the intelligence. SentinelOne breaks down the data and rebuilds it to look at behavioral norms and behavioral anomalies, giving customers local capability and local capacity to solve the threats in real time.
Build Your Own AI
Today, organizations are focused on building their own AI, which is like bringing own devices to work. However, he believes that companies will face the same problems as they did with using own devices for work (BYOD).
For example, when BYOD started, a lot of companies tried to stop or ban people bringing their own devices. However, the reality is companies are never going to stop to be able to stop people bringing their own devices.
“So, you've just got to find a way to protect them. It's the same with AI. Shadow AI is a big problem, and you can't tell them to stop it. They're always going to use it. It's always going to be there and it’s increasing the number of attacks,” he said.
The problem here is data. How can companies ensure that sensitive data is not being used on shadow AI platforms. Companies need an observability platform.
SentinelOne acquired big-data developer Scalyr to power its Singularity XDR platform and launched DataSet, an enterprise live-data platform. It's a next generation non-schema-based architecture means that customers don't have this dependence upon creating index-based architectures and everything being structured.
“We can scale it fairly limitlessly. We can also capture everything in flight. So this helps us from a data reduction standpoint. And then there is the Observo AI acquisition that we made as well, which has a huge impact here because it's a data pipelining solution that uses AI to pass the data. So, we reduce data by as much as 80%, on the edge, before it even hits the data lake. So, you're not talking about ingesting the data and then reducing the data. It's before. And that helps as well because you're not talking about the same degree of data movement,” he explained.
For Day, the combination of the AI SIM architecture and the Observo AI acquisition, the AI-based parsing of data has a massive impact on reducing this problem of log blow and the data explosion.
Prompt Security acquisition
The Prompt Security acquisition is also something that Day believes will bring a huge benefit for customers as it now enables them to have address the expanded attack surface.
“So we sit across all of the browsers. We're able to essentially police the traffic and the interactions with the AI models. There are two things that we're looking for there. One is the prompt injections to see if this is really going head-to-head, machines versus machines, so that the models are not being outplayed by AI scripts and malicious intent language that has been inserted into those prompts. The other is to address the careless use of AI whereby ensuring employees do not upload company-sensitive data, any sort of harmful data into those models,” he explained.
Sitting above all of this is Purple AI. SentinelOne Purple AI is an agentic, AI-powered security analyst designed to accelerate threat hunting, incident investigations, and response times. Natively integrated into the Singularity Platform, it acts as a conversational interface that transforms natural English language into complex security queries
“Our Purple AI acts as an SOC analyst that goes through that data and sees how important is that data, what can be shared and what a user cat. That combined with our hyper-automation capability, we can even go further and fulfil some of the tasks that need to be fulfilled on those threats as well,” he concluded.