
Gatewatcher NDR Platform
Multi-engine NDR with instant threat detection and generative AI incident response assistant.
Vendor Information
Gatewatcher NDR Platform Overview
Gatewatcher NDR Platform is a multi-engine Network Detection and Response solution from Gatewatcher, founded in 2015 by Jacques de La Rivière and Philippe Gillet and headquartered in Paris, France. The company employs 51-200 people and has raised $57.57M in funding from Move Capital and European Investment Bank, including a €25M Series A round in 2024. Gatewatcher was recognized as the only Visionary in the 2025 Gartner Magic Quadrant for Network Detection and Response, and its solutions are ANSSI-qualified as "Secured by Design" for protecting French vital operators and essential services.
The platform combines AIonIQ (core NDR engine), COCKPIT (unified management console), Reflex (incident response orchestration), and GAIA (generative AI assistant launched in 2024) to provide instant threat detection without baseline requirements. Multi-engine detection uses static analysis, heuristics, and machine learning to identify known threats, zero-days, encrypted traffic threats, and past threats through retro-hunt capabilities. The integrated Cyber Threat Intelligence platform built on acquired LastInfoSec technology and OpenCTI standards continuously monitors social networks, specialized sites, darknet, and deep web for indicators and early compromise signs. Deep Visibility monitors network infrastructure across IT and OT environments, while GTAP optical and copper TAPs provide non-intrusive network coverage.
GAIA revolutionizes SOC team workflows by simplifying threat detection, qualification, analysis, and incident response through conversational interactions. The Large Threat Behaviour Model unifies internal and external insights in real-time, while agentic AI handles triage, contextualization, interoperability, and reporting to reduce alert fatigue. The platform emphasizes European data sovereignty and supports regulatory requirements including NIS2, DORA, CRA, and PDIS for particularly exposed organizations with reinforced detection capabilities for sensitive and offline-deployed infrastructures. Key customers include PostFinance, SWISS Airlines, University of St. Gallen, KNDS France (defense), LYNRED (aerospace), Leeds United FC, and various healthcare organizations.
Key Capabilities
Standardized capabilities mapped to this product's security niche
Performs deep packet inspection on industrial protocols (Modbus, DNP3, EtherNet/IP, PROFINET, IEC 61850, OPC-UA), for behavioral monitoring of OT environments alongside IT network analysis.
Integrates with firewalls, NAC platforms, and switches to automatically block or quarantine hosts and traffic flows in response to confirmed detections, without requiring analyst-initiated action.
Extends network detection to cloud VPC traffic using VPC flow log analysis, cloud-native sensors, or mirroring, covering east-west traffic between cloud workloads.
Forwards enriched alerts with full session metadata, PCAP context, and network topology to SIEM platforms in CEF, LEEF, or native API formats.
Monitors lateral movement traffic between internal network segments and hosts, distinct from perimeter monitoring. Requires network tap or span port placement on internal switch infrastructure.
Detects threats in TLS-encrypted traffic using JA3/JA3S fingerprinting, certificate anomaly detection, and traffic behavioral analysis, without requiring decryption.
Builds per-device and per-application baselines of normal network communication patterns and detects deviations, enabling detection of novel C2 channels, data staging, and lateral movement.
Integrations
Compatible tools and platforms
Solution Details
Compliance & Certifications
Regulatory frameworks and security certifications
Deployment Options
Where and how this solution can be deployed
Support Channels
Available support and communication options
Pricing Model
How this solution is priced
How to buy
This profile hasn’t been claimed yet. Contact the vendor directly for pricing and purchasing options.
Is this your company?
Claim Your Profile