Darktrace AI Vendor Risk Profile
UK-based AI cybersecurity company using self-learning AI to detect and respond to cyber threats. Develops proprietary unsupervised learning models for anomaly detection in network, cloud, and email environments.
Risk overview
Risk score: 36/100
Risk tier: Moderate
Safety rating: 64/100 (higher is better)
Lower risk scores indicate lower assessed risk.
Last verified: Apr 19, 2026 Aging
Risk dimensions
| Dimension | Risk score |
|---|---|
| Data Handling | 66/100 |
| IP Exposure | 16/100 |
| Jurisdiction | 21/100 |
| Security | 30/100 |
| Regulatory Compliance | 40/100 |
| Transparency | 25/100 |
| Business Stability | 36/100 |
| Dependency Chain | 36/100 |
| Agent Governance | Not assessed |
Analyst summary
Rating: Acceptable
Darktrace pioneered self-learning AI for cyber defense, with per-customer model training that avoids cross-tenant data pooling. Post-2024 Thoma Bravo take-private, the UK-incorporated firm operates privately; historical short-seller concerns about accounting have been contested but remain in record.
Bottom line: Acceptable for UK/EU-anchored cyber AI deployments; treat the PE ownership as a governance consideration.
Strengths
- Per-customer self-learning models; no cross-tenant data pooling
- SOC 2 Type II, ISO 27001, UK Cyber Essentials Plus
- UK-incorporated (non-US jurisdiction advantage for some EU/UK workloads)
- Mature deployment options including on-premises and EU-region SaaS
Concerns
- Thoma Bravo take-private acquisition (October 2024) reduces public-company transparency
- Historical short-seller allegations (Quintessential Capital 2023) about accounting; denied by the company
- Pricing model perceived as expensive at scale by some customers
- Narrower feature set than consolidated platforms like Palo Alto Networks
Best for
- UK and EU enterprises wanting a non-US headquartered AI cyber vendor
- Organizations needing self-learning network detection without cross-tenant data sharing
- Regulated industries needing on-premises or EU-region cyber AI deployment
Avoid if
- Your procurement team is wary of private-equity-owned vendors for long-term commitments
- You need FedRAMP High authorized detection
- You prefer a consolidated platform vendor over a point product
Citations
- Data Handling — Data Residency Options
Darktrace offers deployment in US, EU (Ireland, Germany), UK, Asia-Pacific and on-premises options for data residency requirements.
- Data Handling — Trains On User Data
Darktrace's Self-Learning AI models are trained per-customer on the customer's own environment; Darktrace does not pool customer data to train cross-tenant models.
- Governance — Government Scrutiny
Darktrace was the subject of short-seller reports (Quintessential Capital in 2023) alleging accounting irregularities; the company denied the allegations and an internal review found no wrongdoing.
- Governance — Strategic Investors
Thoma Bravo completed its $5.3 billion take-private acquisition of Darktrace in October 2024, delisting the company from the London Stock Exchange.
- Jurisdiction Profiles — Incorporation Country
Darktrace plc was headquartered in Cambridge, UK; following the October 2024 Thoma Bravo take-private acquisition, Darktrace operates as a privately held UK-incorporated entity.
- Security Compliance — Iso 27001
Darktrace holds ISO/IEC 27001 certification and operates UK Cyber Essentials Plus accreditation.
- Security Compliance — Soc2 Type2
Darktrace is SOC 2 Type II certified and ISO 27001 certified across its platform.