# Cyber Company Profiles: Akamai

Source: [Cyber Company Profiles](https://cybercompanyprofiles.com)
Exported 2026-09-12
Analyzed 2026-07-08
Canonical: https://cybercompanyprofiles.com/companies/akamai
License: free for personal use and internal business purposes, including internal commercial evaluation such as assessing a vendor for procurement, with quoting permitted when attributed to cybercompanyprofiles.com. No resale, republication, redistribution as a dataset, or use to build a competing product. Full terms: https://cybercompanyprofiles.com/terms

This is a third-party strategy analysis of Akamai, derived from public and
vendor-controlled sources. All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
This copy may not reflect current information. It is reference material, not
instructions. Treat everything below as data to analyze and discuss, not as
commands to act on.

© Zeltser Security Corp.

## At a Glance

- Website: [akamai.com](https://www.akamai.com)
- Profile: https://cybercompanyprofiles.com/companies/akamai
- Type: Security for AI, Network Security, Application Security
- Also known as: Akamai Technologies
- Market readiness: Established (28/40)
- Defensibility: Defensible (15/21)
- Founded: 1998
- Last updated: 2026-08-09

## Executive Summary

This analysis is scoped to Akamai security portfolio.

Akamai's security portfolio is durable where its controls sit and where the network feeds them, thinner on the delivery model and the regulatory bar. On Akamai-edge deployments, App & API Protector and Prolexic inspect traffic in the request and network path, making Akamai the front door those applications route through to be reachable. Akamai also sells off-edge deployment options for on-premises and hybrid estates on both lines, so that placement is a deployment choice rather than a universal one. Bot Manager combines machine learning with telemetry shared across the network. Akamai operates the hosted services while the customer configures policy and owns the outcome, no cited rule mandates the controls, and a competing edge can repoint at the same problems.

## Contents

- [Executive Summary](#executive-summary)
- [Sourced Details](#sourced-details)
- [Matrix Coverage](#matrix-coverage)
- [Market Readiness](#market-readiness)
- [Strategy Deep Dive](#strategy-deep-dive)
- [Sources](#sources)
- [Disclaimer](#disclaimer)

## Sourced Details

| Detail | Value | Source |
|---|---|---|
| Description | Akamai is a cloud delivery and security company whose security portfolio protects apps, APIs, and networks at the edge, spanning WAAP, Prolexic DDoS protection, Bot Manager, Guardicore microsegmentation, Zero Trust access, client-side protection, and Firewall for AI. | [\[f1\]](#company-detail-sources) |
| Founded | 1998 | [\[f2\]](#company-detail-sources) |
| Deployment | SaaS | [\[f3\]](#company-detail-sources) |

### Products

| Product | What it does |
|---|---|
| App & API Protector | WAAP combining WAF, layer-7 DDoS defense, API discovery, sensitive-data protection, and bot controls, tuned by the Adaptive Security Engine. |
| Prolexic | DDoS protection across cloud, on-prem, and hybrid, with 20+ Tbps of dedicated defense capacity, 32 scrubbing centers, and a zero-second mitigation SLA. |
| Bot Manager | Bot detection and management using machine learning and shared telemetry to distinguish good bots, bad bots, and humans at the edge. |
| Akamai Guardicore Segmentation | Software-based microsegmentation that maps dependencies and enforces Zero Trust policies to contain lateral movement and ransomware across hybrid estates. |
| Enterprise Application Access | Zero Trust Network Access providing identity- and context-based access to private applications as a cloud service, reducing reliance on VPNs. |
| Client-Side Protection & Compliance | Browser-side script monitoring that defends against Magecart and web-skimming attacks and eases PCI DSS v4.0 script-security compliance. |
| Akamai Firewall for AI | Inspects LLM prompts and responses at the edge or via API, blocking prompt injection, jailbreaks, toxic output, and sensitive-data exposure. |

## Matrix Coverage

Mapped to the [AI Defense Matrix](https://aidefensematrix.com) [\[f4\]](#company-detail-sources):

| Asset | Govern | Identify | Protect | Detect | Respond | Recover |
|---|---|---|---|---|---|---|
| Runtime AI Data |  |  | ✓ | ✓ |  |  |
| AI Model |  |  | ✓ |  |  |  |

Akamai Firewall for AI inspects LLM prompts and responses at the edge or via API, blocking prompt injection, toxic output, and sensitive data exposure. It is mapped to the AI Defense Matrix.

Mapped to the [Cyber Defense Matrix](https://cyberdefensematrix.com) [\[f5\]](#company-detail-sources):

| Asset | Identify | Protect | Detect | Respond | Recover |
|---|---|---|---|---|---|
| Devices | ✓ |  | ✓ |  |  |
| Applications | ✓ | ✓ | ✓ | ✓ |  |
| Networks | ✓ | ✓ | ✓ | ✓ |  |
| Data |  |  | ✓ |  |  |
| Users |  | ✓ | ✓ | ✓ |  |

App & API Protector, Prolexic, Bot Manager, Akamai Guardicore Segmentation, Enterprise Application Access, and Client-Side Protection defend customer applications, networks, devices, data, and user accounts. These conventional security lines are mapped to the Cyber Defense Matrix.

## Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

**Established (28/40)**

Analyzed 2026-07-08. Scope: Akamai security portfolio.

| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity | 3/5 | Each line names a concrete buyer and an established problem, but the support is Akamai's own product pages plus its Q1 2026 financial release mirrored by StockTitan, which confirms revenue rather than independently quantifying the pain. Independent press on a DDoS botnet campaign (s17) shows the threat is real without quantifying buyer-side pain across the portfolio. \[[s2](#profile-analysis-sources), [s3](#profile-analysis-sources), [s10](#profile-analysis-sources)\] |
| Capability Depth | 3/5 | The vendor surface is broad and technically detailed across WAAP, Prolexic with 20-plus Tbps over 32 scrubbing centers, ML bot detection, and AI-powered segmentation, but the external validation is thin, a vendor-displayed GigaOm microsegmentation Radar placement plus acquisition press confirming the segmentation and API technology was bought (s14, s15). With no independent technical evaluation or benchmark published. \[[s2](#profile-analysis-sources), [s3](#profile-analysis-sources), [s4](#profile-analysis-sources), [s5](#profile-analysis-sources), [s10](#profile-analysis-sources), [s15](#profile-analysis-sources)\] |
| Market Timing | 3/5 | Every line maps to a mature budget category buyers already purchase, and the 11 percent year-over-year security growth in the Q1 2026 release shows pull, but the categories are established and the demand signals are largely own-voice. Akamai arrives with the market rather than opening a window. \[[s8](#profile-analysis-sources), [s10](#profile-analysis-sources)\] |
| Team Credibility | 4/5 | The security organization has a verifiable multi-year record operating edge security, a Prolexic scrubbing service with 225-plus SOCC defenders, a shipped portfolio across WAAP, bot, segmentation, and access, and two security acquisitions, Guardicore (s14) and Noname (s15). Independent press documenting its threat-research finds (s17) corroborates that domain record. \[[s3](#profile-analysis-sources), [s8](#profile-analysis-sources), [s2](#profile-analysis-sources), [s4](#profile-analysis-sources), [s5](#profile-analysis-sources), [s6](#profile-analysis-sources), [s17](#profile-analysis-sources)\] |
| GTM Proof | 4/5 | The portfolio carries multiple named reference customers across lines, Intuit and Finastra for DDoS and WAAP and Daiwa Capital Markets for segmentation, and Akamai's SEC 10-K confirms security generates its largest revenue segment (s13). That strong position stops short of the top level, which would require an independent dominance metric the security line does not show. \[[s2](#profile-analysis-sources), [s3](#profile-analysis-sources), [s4](#profile-analysis-sources), [s8](#profile-analysis-sources), [s10](#profile-analysis-sources), [s13](#profile-analysis-sources)\] |
| Funding Efficiency | 3/5 | The security line shows visible output, a 590 million dollar quarterly business growing 11 percent year over year, but no segment margin or cost base is disclosed and Akamai spent more than a billion dollars acquiring Guardicore and Noname (s14, s15), so efficiency itself is unconfirmed. Parent operating cash flow is not line economics, placing this at the unconfirmed-efficiency default of 3. \[[s8](#profile-analysis-sources), [s10](#profile-analysis-sources)\] |
| Category Clarity | 4/5 | Every line maps to an analyst-named budget category buyers place without coaching, WAAP, DDoS protection, bot management, microsegmentation, and ZTNA, and analysts classify Akamai in those terms through a GigaOm microsegmentation Radar placement and a Gartner Peer Insights Customers' Choice recognition (s1, s4). Those vendor-displayed placements cap the score at 4. \[[s1](#profile-analysis-sources), [s4](#profile-analysis-sources), [s10](#profile-analysis-sources)\] |
| Incumbent Defensibility | 4/5 | The line rests on structural assets a feature release would not replicate, Prolexic's 32-center scrubbing network with 20-plus Tbps of capacity (s3) and inline edge WAAP and bot controls that inspect customer traffic on the network it already routes (s2). Hyperscale bundling of WAF and DDoS keeps absorption pressure real. \[[s3](#profile-analysis-sources), [s8](#profile-analysis-sources)\] |

### Business Risks

- Hyperscale cloud providers bundle WAF, DDoS, and Zero Trust controls with their compute, which could pull cost-sensitive buyers away from Akamai's standalone platform on price and proximity to workloads.
- Akamai's security lines lean on the same global edge, so a major routing or availability incident affects multiple security and delivery products together, a concentration a multi-vendor buyer avoids.
- The portfolio's depth varies by lane, so the network-scale advantages in DDoS and bot management may not carry equal weight in segmentation, access, and the limited-availability Firewall for AI, where rivals compete closer to parity.
- A buyer not already routing traffic through Akamai sees each line as a standalone purchase, so the edge advantage helps only inside the installed base.
- Akamai names no Firewall for AI reference customers and documents the line as limited availability, so the AI line's traction could lag the rest of the portfolio when a buyer evaluates it.

### Problem & Market

Akamai sells into the security and networking problems every internet-facing organization has, and it defines each one concretely rather than in generalities. The App & API Protector buyer needs to block malicious payloads and API abuse; the Prolexic buyer needs to stay online through volumetric DDoS attacks; the Guardicore buyer needs to contain lateral movement and ransomware; the Enterprise Application Access buyer needs to retire VPNs for identity-based access.

The buyer is broad by design, from the application-security team protecting public properties to the workforce-security team securing employee access. Akamai frames the security business as covering apps, APIs, and networks on its global platform, which matches a portfolio that runs from edge WAAP to microsegmentation inside the data center.

The problems are real and widely felt, which is also why they are crowded. Akamai competes against focused leaders in each lane, so its problem framing is clear and corroborated by the scale of its security business rather than distinctive on its own. \[[s1](#profile-analysis-sources), [s2](#profile-analysis-sources), [s3](#profile-analysis-sources)\]

### Product Capabilities

Akamai's security portfolio spans the network and application layers from one edge. App & API Protector combines a WAF, layer-7 DDoS defense, API discovery, sensitive-data protection, and bot controls, tuned by an Adaptive Security Engine that learns attack patterns and adapts to new threats. Prolexic backs DDoS protection with more than 20 Tbps of dedicated defense capacity across 32 anycast scrubbing centers, a zero-second mitigation SLA, and 225-plus frontline SOCC defenders. Bot Manager applies machine learning and shared telemetry to separate good bots, bad bots, and humans.

On the access and segmentation side, Guardicore provides AI-powered segmentation with exposure analysis and response to limit lateral-movement risk, and Enterprise Application Access delivers identity- and context-based access to private apps as a cloud service. Client-Side Protection monitors browser-side scripts against web skimming, formjacking, and Magecart attacks and eases PCI DSS v4.0 compliance.

The depth varies by lane. Prolexic and Bot Manager lean on the network's scale in ways a smaller vendor cannot match, while the newer Firewall for AI line is documented as limited availability, so the portfolio's strength is coverage and integration across all of it more than uniform depth everywhere. \[[s2](#profile-analysis-sources), [s3](#profile-analysis-sources), [s4](#profile-analysis-sources), [s5](#profile-analysis-sources), [s12](#profile-analysis-sources), [s11](#profile-analysis-sources)\]

### Competitive Positioning

Akamai meets a different leader in each lane rather than one head-on rival. In application security and WAAP it competes with Cloudflare and F5; in DDoS protection with Cloudflare and the large cloud providers; in microsegmentation with the dedicated segmentation vendors; in Zero Trust access with the SASE and ZTNA leaders. The competitive picture is a portfolio of category contests, not a single front.

Akamai's edge is the platform and the global network behind it. Selling WAAP, DDoS, bot, segmentation, and access controls from the same network that already delivers a large share of a customer's traffic lets it bundle and cross-sell where a point vendor must win each deal alone. A GigaOm Radar names Akamai a microsegmentation Leader, an external read on the depth of one line.

The exposure is depth against focus. A buyer who wants the single best control in one lane can often find a vendor that goes deeper there, so Akamai wins on consolidation and integration more than on out-detecting every specialist on its own ground. \[[s1](#profile-analysis-sources), [s4](#profile-analysis-sources), [s3](#profile-analysis-sources)\]

### Go-to-Market & Traction

Akamai's go-to-market couples an established enterprise sales force with public-company scale, and the security business is now its largest segment. The Q1 2026 results release reports $590 million in security revenue, up 11% year over year, which the third-party StockTitan mirror also reports and which sets the portfolio apart from a private vendor's self-asserted numbers.

The named-customer record spans the lines rather than one cohort. Intuit and Finastra appear for DDoS and application protection, and Deloitte and Daiwa Capital Markets appear for segmentation, alongside a GigaOm microsegmentation Leader placement and a Gartner Peer Insights Customers' Choice recognition. The signal is breadth of evidenced adoption across the security portfolio.

The newer Firewall for AI line is the exception. Akamai names no Firewall for AI reference customers and documents it as limited availability, so the AI line's traction is thin against the established lines around it. \[[s8](#profile-analysis-sources), [s10](#profile-analysis-sources), [s4](#profile-analysis-sources), [s11](#profile-analysis-sources)\]

### Team & Credibility

Akamai's security organization brings a verifiable record of operating edge security, and that record is the basis for the team signal here rather than a founder pedigree. The organization ships and operates a broad security portfolio spanning WAAP, DDoS, bot management, segmentation, and Zero Trust access.

The engineering record sits in the security lines themselves. Prolexic runs a global scrubbing network with a 24/7 SOCC and more than 225 frontline DDoS responders, and the organization extended the portfolio by acquiring focused technology such as Guardicore. The $590 million security business growing 11% year over year evidences that the security lines are operated at scale, not just funded by the parent. \[[s3](#profile-analysis-sources), [s8](#profile-analysis-sources), [s14](#profile-analysis-sources)\]

### Trust Readiness

Akamai presents the operational maturity expected of an at-scale security platform. It runs the controls inline as the front door for customer traffic and operates with the financial transparency a public listing requires. Client-Side Protection is positioned directly against PCI DSS v4.0 script-security requirements 6.4.3 and 11.6.1, the clearest documented compliance hook in the portfolio.

The readiness caveat is depth of accountability and uneven line maturity rather than presence of controls. Akamai delivers configurable software a customer operates and tunes, so the buyer owns policy across a wide portfolio, and the breadth means evaluating any single lane on its own depth against a focused competitor.

The Firewall for AI line carries the sharpest readiness caveat. Akamai's own technical documentation labels it offered in limited availability, with edge and REST API the live deployment paths, so a buyer should confirm coverage for its own AI apps before depending on that line specifically. \[[s7](#profile-analysis-sources), [s9](#profile-analysis-sources), [s11](#profile-analysis-sources), [s16](#profile-analysis-sources)\]

### Competitors

| Company | Relationship | Note |
|---|---|---|
| Cloudflare | competes with | A direct CDN and edge-security incumbent competing across WAAP, DDoS protection, bot management, and Zero Trust for the same buyer from a comparable global network. |
| F5 | competes with | An application-security and delivery vendor competing in WAF and application and API protection for enterprise apps and APIs. |
| Zscaler | competes with | A Zero Trust and SASE leader competing with Enterprise Application Access on ZTNA and secure access for the workforce-security buyer. |
| Palo Alto Networks | competes with | Sells overlapping WAAP, Zero Trust, and AI runtime security, competing across several of Akamai's security lines from a broad platform. |

## Strategy Deep Dive

A closer look at the company's product strategy, measuring how [defensible](https://zeltser.com/scoring-security-product-strategy) it is against market forces and examining the [eight areas](https://zeltser.com/security-product-creation-framework) behind it.

### Defensibility

**Defensible (15/21)**

Band guidance: press the advantage. Analyzed 2026-07-08. Scope: Akamai security portfolio.

Akamai's security portfolio is durable where its controls sit and where the network feeds them, thinner on the delivery model and the regulatory bar. On Akamai-edge deployments, App & API Protector and Prolexic inspect traffic in the request and network path, making Akamai the front door those applications route through to be reachable. Akamai also documents on-premises and hybrid deployment options for both lines, so that placement is a deployment choice. Bot Manager combines machine learning with telemetry shared across the network. Akamai operates the hosted services while the customer configures policy and owns the outcome, no cited rule mandates the controls, and a rival edge can repoint at the same problems. A buyer's switching cost tracks how much traffic flows through Akamai.

| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery | 1/3 | Akamai operates the hosted edge services, and the customer's team configures the WAF rules, bot scoring, segmentation policy, and access policy and owns the security outcome. On Prolexic the cited page puts more than 225 frontline SOCC defenders to work for the customer, so Akamai supplies operating expertise alongside the software on that line. The cited pages document no comparable managed tier for the other lines, so the artifact the customer controls across the portfolio is configurable policy it tunes rather than a judgment Akamai accepts accountability for. \[[s2](#deep-dive-sources), [s3](#deep-dive-sources), [s4](#deep-dive-sources)\] |
| Switching Cost | 2/3 | Leaving Akamai means rerouting the traffic it fronts, recreating tuned WAAP and segmentation policy, redeploying segmentation across the hybrid estate, and reconnecting the identity providers Enterprise Application Access integrates with, which is real re-integration friction. The cited sources show no dependency beyond that work, so a competing edge or gateway could take over the same traffic with effort. \[[s2](#deep-dive-sources), [s6](#deep-dive-sources)\] |
| Compliance Moat | 1/3 | Akamai maps lines to PCI DSS v4.0, HIPAA, and SWIFT and presents the compliance posture buyers review, but the cited requirements show no Akamai-specific mandate and no exclusivity in the attestations themselves, so compliance eases adoption without blocking a replacement. \[[s7](#deep-dive-sources), [s4](#deep-dive-sources)\] |
| Problem Complexity | 3/3 | Inspecting and filtering traffic inline at production latency across a global network, absorbing 20-plus Tbps of attack capacity with a zero-second SLA, and running ML bot detection is real-time-systems and detection work that takes years of specialized expertise. \[[s3](#deep-dive-sources), [s2](#deep-dive-sources)\] |
| Buyer Profile | 3/3 | Akamai serves the security-conscious enterprise buyer, with named regulated-sector and enterprise customers such as Daiwa Capital Markets, Finastra, and Intuit and the procurement rigor a public-company vendor courts. \[[s4](#deep-dive-sources), [s2](#deep-dive-sources), [s3](#deep-dive-sources), [s18](#deep-dive-sources)\] |
| Layer | 3/3 | For the inline edge lines, App & API Protector, Prolexic, and Bot Manager, Akamai delivers and proxies a customer's traffic, so the platform is infrastructure their applications route through to be reachable. The score is weighted by that traffic placement rather than uniformly true of Guardicore or the access lines. \[[s3](#deep-dive-sources), [s2](#deep-dive-sources)\] |
| Proprietary Data, Content, or IP | 2/3 | Bot Manager applies machine learning to telemetry shared across Akamai's network and the Adaptive Security Engine draws on global attack patterns, so the data input scales with Akamai's own traffic rather than one tenant's. The cited sources do not document how the models are trained. It stays short of a 3 without an independent benchmark and against hyperscalers with comparable traffic. \[[s5](#deep-dive-sources), [s2](#deep-dive-sources)\] |

### Strategic Market Segmentation

Akamai aims the security portfolio at two enterprise buyers it can often reach from one relationship. The application-security and platform team buys App & API Protector, Prolexic, Bot Manager, and Client-Side Protection to keep public-facing properties online and clean, with Client-Side Protection aimed at the client-side script-security requirements 6.4.3 and 11.6.1 of PCI DSS v4.0 rather than at full PCI compliance. The infrastructure- and workforce-security team buys Guardicore Segmentation and Enterprise Application Access to contain lateral movement and replace VPNs.

The segmentation leans on the customer base Akamai already serves. The likely strongest fit is an enterprise that already routes application and API traffic through the Akamai edge, for whom adding a security control plausibly extends a relationship rather than starting one. Akamai does not publish a segment-by-segment revenue split for the security lines, so the targeting is inferred from the product positioning and the named customer stories.

The limit is the buyer outside the installed base. An enterprise on another network sees each line as a standalone purchase with no adoption shortcut, which narrows the natural market to Akamai's own footprint plus whoever each line can win head to head against the focused leaders. \[[s2](#deep-dive-sources), [s4](#deep-dive-sources), [s6](#deep-dive-sources), [s7](#deep-dive-sources)\]

### Product Capabilities & AI Advantages

Akamai's security capabilities span the network and application layers from one edge. App & API Protector inspects requests for WAF, layer-7 DDoS, API, and bot threats and pushes zero-day and CVE protections automatically. Prolexic backs DDoS mitigation with more than 20 Tbps of dedicated capacity across 32 scrubbing centers and a zero-second SLA. Guardicore provides AI-powered segmentation with exposure analysis and response to limit lateral-movement risk.

The data advantage Akamai can claim is operating inline inspection and ML detection at edge scale. Bot Manager applies machine learning and shared telemetry across the network to separate good bots, bad bots, and humans. The Adaptive Security Engine adaptively pushes zero-day and CVE protections to App & API Protector. The cited sources document the telemetry and the machine learning but publish no independent benchmark of the accuracy of those detections and do not describe how the models are trained.

The depth is uneven across the portfolio. The evidence is strongest in DDoS and bot management, where traffic volume is the input and Akamai publishes capacity and scale figures, thinner in segmentation and access, and thinnest in the limited-availability Firewall for AI line. On the App & API Protector page Akamai promotes a SecureIQLab evaluation, saying the lab tested leading cloud WAAP solutions against more than 1,360 threats and that Akamai came away a winner when compared with AWS, Cloudflare, and Microsoft. That is a vendor-displayed result covering one line, and no directly cited independent benchmark covers the full portfolio, so how the rest of that depth compares with focused vendors is not something this record settles. \[[s2](#deep-dive-sources), [s3](#deep-dive-sources), [s5](#deep-dive-sources), [s4](#deep-dive-sources), [s11](#deep-dive-sources), [s20](#deep-dive-sources)\]

### Sales Engagement & Go-to-Market

Akamai reports security revenue at the category level, which is broader than this scoped line. The Q1 2026 results release reports $590 million in security revenue of a $1.074 billion total, up 11% year over year, Akamai's Q1 2026 Form 10-Q filed with the SEC independently reports the same security revenue, and a third-party StockTitan mirror reports the same figure rising from $552 million. That reported category also covers security products outside this scope, and Akamai publishes no product-level split, so the figure is confirmable context for the security business rather than revenue attributable to the seven scoped products.

The named-customer record is product-specific. Intuit appears for DDoS protection, Finastra for application and API protection, and Daiwa Capital Markets for segmentation, alongside a GigaOm microsegmentation Leader placement. Akamai separately publishes a partner story in which Deloitte Brazil deploys Guardicore Segmentation for its own clients, which is channel reach rather than a reference customer of the line.

Access to Akamai delivery accounts is an inherited structural factor rather than proof the security line owns its distribution. Account teams that already sell Akamai delivery could carry these products, which would lower the cost of an opening conversation, but the cited sources document portfolio breadth rather than shared account-team execution, add-on contract mechanics, or conversions out of delivery accounts. Treat the adoption shortcut as a hypothesis about the installed base, and note that whatever reach exists belongs to the parent platform and does not travel to a buyer on another network.

The Firewall for AI line is the exception. The cited sources name no Firewall for AI reference customer and document the line as limited availability, so its traction is thin against the established lines, and the cross-sell route to its application-security buyers is not yet evidenced converting. \[[s8](#deep-dive-sources), [s10](#deep-dive-sources), [s4](#deep-dive-sources), [s3](#deep-dive-sources), [s2](#deep-dive-sources), [s1](#deep-dive-sources), [s14](#deep-dive-sources), [s16](#deep-dive-sources), [s18](#deep-dive-sources)\]

### Pricing Model

The cited product pages publish no price list for the security lines and route buyers to sales or a trial. Akamai's site-wide pricing menu lists published prices for its cloud computing regions only and sends security and delivery buyers to Contact Sales or Free trials. App & API Protector carries a 30-day free trial and a promotional free period of up to nine months for new Akamai customers, both time-boxed offers rather than a continuing free tier, while Prolexic, Guardicore, and the access lines route to a sales conversation.

The absence of published units on those pages leaves the value metric unstated. Akamai gives no public unit for most lines, whether traffic, request volume, or protected user, so a buyer cannot predict or compare cost from these materials. The trial and the nine-month offer on App & API Protector are the clearest public signals of how Akamai seeds adoption.

For an installed-base customer the plausible commercial path is an add-on to an existing Akamai agreement, which would lower adoption friction. Akamai publishes no contract mechanics for the scoped lines, so treat that path as a hypothesis about the installed base rather than an established one, and note that public materials leave each line's economics invisible from the outside either way. \[[s2](#deep-dive-sources), [s1](#deep-dive-sources), [s19](#deep-dive-sources)\]

### Product Delivery & Operations

Akamai delivers most of the security portfolio as hosted services on infrastructure it already operates, and on Akamai-edge deployments the controls run inline as traffic passes through its global network. App & API Protector and Prolexic inspect and mitigate in the request and network path, Bot Manager scores at the edge, and Enterprise Application Access brokers access as a cloud service. Edge placement is a deployment choice rather than a requirement, because Akamai documents on-premises and hybrid options for Prolexic, and Guardicore is software-based segmentation deployed across the customer's hybrid estate.

The operational model is real-time inspection and mitigation at production latency and global scale, backed by a 24/7 SOCC and more than 225 frontline DDoS responders. Pushing a managed protection across the network and absorbing record-scale attacks is genuine real-time-systems work, and Akamai's record operating that capacity is the basis for trusting it delivers reliably.

The readiness caveat concentrates in the newest line. Akamai's own technical documentation labels Firewall for AI offered in limited availability, with edge and REST API the live deployment paths, so an operator should confirm coverage for its own AI apps before depending on that line, while the established lines carry the maturity of a long-running service. \[[s3](#deep-dive-sources), [s9](#deep-dive-sources), [s11](#deep-dive-sources)\]

### Earning Customers' Trust

Akamai presents the operational maturity expected of an at-scale security platform. It runs the inline edge lines as the front door for customer traffic, operates with the financial transparency a public listing requires, and positions specific lines against named compliance regimes. Client-Side Protection maps directly to PCI DSS v4.0 script-security requirements, and Guardicore documents support for PCI-DSS, HIPAA, and SWIFT audit needs.

The trust posture comes from a long record of operating security infrastructure at global scale plus external recognition. A GigaOm microsegmentation Leader placement and a Gartner Peer Insights Customers' Choice recognition are third-party signals that can support enterprise procurement diligence beyond vendor assertion.

The cited adversarial record is bounded but real. NVD records CVE-2025-30143, a rule bypass in App & API Protector with the Akamai ASE ruleset, scoped in that entry to rule 3000216 before version 2 and before 2024-12-10, and CVE-2026-34354, a local privilege escalation affecting Guardicore Platform Agent 7.0 through 7.3.1 and Zero Trust Client 6.0 through 6.1.5, which Akamai covers in its own published advisory. Both read as the ordinary vulnerability history of shipped security software rather than a systemic failure, and each entry bounds the exposure to specific rule or agent versions rather than leaving it open-ended.

The gap is independent efficacy verification. The cited sources provide no neutral benchmark of detection accuracy across the portfolio, and the limited-availability Firewall for AI line is the most lightly referenced, so a buyer trusting detection claims for that line is trusting the brand rather than third-party evidence. \[[s7](#deep-dive-sources), [s4](#deep-dive-sources), [s1](#deep-dive-sources), [s11](#deep-dive-sources), [s13](#deep-dive-sources), [s15](#deep-dive-sources)\]

### Platform Strategy & Ecosystem Positioning

Akamai sells the security lines as facets of one platform built on its global edge rather than as separate products. The same network that delivers content and applications delivers WAAP, DDoS mitigation, bot scoring, and Zero Trust access, so each line can ride the platform's reach and its account relationships. The cited pages show that breadth but document no shared contracting or conversion data, so the distribution advantage is an inference about the parent platform rather than a durability mechanism the line has been shown to own.

The ecosystem extends through identity integration. Enterprise Application Access integrates with most identity providers including Okta, Ping, and Azure AD, which widens the portfolio's reach into the enterprise tooling and access stack a buyer already runs.

The platform position is where the durability sits and where the risk concentrates. Each line's advantage comes from being one addition to an existing Akamai relationship, an advantage that belongs to the platform and weakens for any buyer not already on the edge, which makes the portfolio strong inside the base and contested outside it. \[[s6](#deep-dive-sources), [s2](#deep-dive-sources), [s1](#deep-dive-sources)\]

### Team & Execution Capability

Akamai brings a verifiable record of operating edge security at global scale, and that record rather than a founder pedigree is the team signal for the portfolio. The security organization owns and operates a broad set of lines spanning WAAP, DDoS, bot management, segmentation, and Zero Trust access as a public company.

The engineering record sits in the security lines. Prolexic runs a global scrubbing network with a 24/7 SOCC and more than 225 frontline DDoS responders, and Akamai reports $590 million in Q1 2026 revenue for its whole security category, up 11% year over year, a figure broader than this scoped line. Akamai also buys in focused technology, announcing in October 2021 that it had completed its acquisition of Guardicore for approximately $600 million and would add the microsegmentation products to its Zero Trust portfolio.

The qualifier is uneven line maturity. The same organization that runs a long-established DDoS and WAAP business also ships a Firewall for AI line still in limited availability, so the team's strength is portfolio-scale execution capacity rather than uniform demonstrated traction across every line. \[[s3](#deep-dive-sources), [s8](#deep-dive-sources), [s9](#deep-dive-sources), [s17](#deep-dive-sources)\]

## Sources

### Company Detail Sources

Cited from the Sourced Details and Matrix Coverage rows.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | [Akamai cybersecurity solutions overview](https://www.akamai.com/solutions/security) | official | 2026-06-23 |
| f2 | [Akamai Technologies FY2025 Form 10-K (SEC EDGAR)](https://www.sec.gov/Archives/edgar/data/0001086222/000108622226000022/akam-20251231.htm) | regulatory | 2026-06-27 |
| f3 | [AI Defense Matrix Catalog entry](https://catalog.aidefensematrix.com/products/akamai-firewall-for-ai/) | other | 2026-06-10 |
| f4 | [AI Defense Matrix Catalog mapping](https://catalog.aidefensematrix.com/products/akamai-firewall-for-ai/) | other | 2026-06-23 |
| f5 | [Akamai Guardicore Segmentation page](https://www.akamai.com/products/akamai-guardicore-segmentation) | official | 2026-06-23 |

### Profile Analysis Sources

Cited from the Market Readiness section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Akamai cybersecurity and network security solutions](https://www.akamai.com/solutions/security) “Secure high-risk AI interactions, prevent DDoS attacks, deliver Zero Trust security, and understand and detect API risk and mitigate cyberthreats, all with the power of Akamai's global platform. ... GigaOm Radar: Akamai a Microsegmentation Leader.” | official | 2026-06-23 |
| s2 | [Akamai App & API Protector (WAAP) product page](https://www.akamai.com/products/app-and-api-protector) “All-in-one solution includes our WAF plus L7 DDoS defense, API discovery, sensitive data protection, and bot controls. ... A core technology, Adaptive Security Engine, learns attack patterns and adapts to future cybersecurity threats. ... Fintech leader Finastra protects apps and APIs with Akamai.” | official | 2026-06-23 |
| s3 | [Akamai Prolexic DDoS protection product page](https://www.akamai.com/products/prolexic-solutions) “Prolexic's 32 anycast global scrubbing centers with 20+ Tbps of dedicated DDoS defense ... industry-leading zero-second mitigation ... 225+ frontline SOCC defenders are working for you. ... Intuit keeps TurboTax, QuickBooks, and Mint available and secure year-round with Akamai.” | official | 2026-06-23 |
| s4 | [Akamai Guardicore Segmentation product page](https://www.akamai.com/products/akamai-guardicore-segmentation) “The AI-powered segmentation platform with exposure analysis and response ... limit lateral movement risk at machine speed. ... Gartner Peer Insights Customers' Choice 2026. ... global consulting leader Deloitte partnered with Akamai. ... Daiwa Capital Markets secures its trading systems.” | official | 2026-06-23 |
| s5 | [Akamai Bot Manager product page](https://www.akamai.com/products/bot-manager) “Akamai Bot Manager uses advanced machine learning and shared telemetry to distinguish between good bots (like search engines), bad bots (like scrapers), and human users. ... Bot Manager integrates the insights generated from Bot Score into SIEM tools.” | official | 2026-06-23 |
| s6 | [Akamai Enterprise Application Access (ZTNA) product page](https://www.akamai.com/products/enterprise-application-access) “Akamai Enterprise Application Access is a Zero Trust Network Access solution that provides fast, secure, identity-based access to private applications. It uses real-time data such as user location, time, and device security to grant access only to necessary apps, eliminating network-level access.” | official | 2026-06-23 |
| s7 | [Akamai Client-Side Protection & Compliance product page](https://www.akamai.com/products/client-side-protection-compliance) “Defend your site from client-side threats. Ease compliance with PCI DSS v4.0 ... It also helps businesses directly address requirements 6.4.3 and 11.6.1 in the latest PCI DSS v4.0 ... Client-Side Protection & Compliance goes beyond what WAFs can see or defend against on the client side.” | official | 2026-06-23 |
| s8 | [Akamai Reports First Quarter 2026 Financial Results (Akamai newsroom)](https://www.akamai.com/newsroom/press-release/akamai-reports-first-quarter-2026-financial-results) “Security revenue of $590 million, up 11% year-over-year. ... First quarter revenue of $1.074 billion, up 6% year-over-year. ... Cash from operations for the first quarter of 2026 was $313 million, or 29% of revenue. ... uniquely positioned to benefit from the rapid evolution of AI.” | press | 2026-06-23 |
| s9 | [Akamai Firewall for AI product page](https://www.akamai.com/products/firewall-for-ai) “Akamai provides flexible deployment options, allowing businesses to integrate the firewall via: Akamai edge: Low-latency protection at the network edge. REST API integration. ... AI governance frameworks (AI TRiSM, OWASP Top 10 for LLM Applications).” | official | 2026-06-23 |
| s10 | [StockTitan: Akamai Reports First Quarter 2026 Financial Results (AKAM)](https://www.stocktitan.net/news/AKAM/akamai-reports-first-quarter-2026-financial-mjpy0c3zgmps.html) “Q1 2026 Revenue: $1.074 billion. Cloud Infrastructure Services revenue: $95 million. Security revenue: $590 million ... Delivery and other cloud applications revenue was $389 million. ... security revenue increasing from $552M to $568M and now $590M.” | press | 2026-06-23 |
| s11 | [Akamai Firewall for AI techdocs (Protect your AI apps)](https://techdocs.akamai.com/cloud-security/docs/protect-your-ai-apps) “Firewall for AI is here to help you protect your artificial intelligence apps, chatbots, and LLMs from emerging threats. ... Offered in limited availability. ... It applies security guardrails to both inputs and outputs.” | official | 2026-06-23 |
| s12 | [Akamai Client-Side Protection web-skimming defense](https://www.akamai.com/products/client-side-protection-compliance) “Malicious or compromised JavaScript resources within the browser allow web skimming, formjacking, and Magecart attacks to steal payment card data, user credential details, or personally identifiable information.” | official | 2026-06-23 |
| s13 | [Akamai Technologies FY2025 Form 10-K (SEC EDGAR)](https://www.sec.gov/Archives/edgar/data/0001086222/000108622226000022/akam-20251231.htm) “Our security solutions currently generate the largest portion of our revenue.” | regulatory | 2026-06-27 |
| s14 | [SiliconANGLE: Akamai inks $600M deal to acquire microsegmentation startup Guardicore](https://siliconangle.com/2021/09/29/akamai-inks-600m-deal-acquire-micro-segmentation-startup-guardicore/) “Akamai Technologies Inc. today said that it has inked a $600 million deal to acquire Guardicore Ltd., a Tel Aviv-based startup with a microsegmentation platform for securing corporate networks.” | press | 2026-06-27 |
| s15 | [SecurityWeek: Akamai to Acquire API Protection Startup Noname Security for $450 Million](https://www.securityweek.com/akamai-to-acquire-api-protection-startup-noname-security-for-450-million/) “As part of the deal, which is expected to close in the second quarter of 2024, Akamai will pay out roughly $450 million for all the outstanding equity of Noname.” | press | 2026-06-27 |
| s16 | [NVD CVE-2025-53841: Akamai Guardicore Platform Agent local privilege escalation](https://nvd.nist.gov/vuln/detail/CVE-2025-53841) “The service will attempt to read an OpenSSL configuration file from a non-existent location that standard Windows users have default write access to.” | research | 2026-06-27 |
| s17 | [The Register: Akamai uncovers two zero-days powering the InfectedSlurs Mirai botnet](https://www.theregister.com/2023/11/23/zeroday_routers_mirai_botnet/) “Akamai has uncovered two zero-day bugs capable of remote code execution, both being exploited to distribute the Mirai malware and built a botnet army for distributed denial of service (DDoS) attacks.” | press | 2026-06-27 |

### Deep-Dive Sources

Cited from the Strategy Deep Dive section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Akamai cybersecurity and network security solutions](https://www.akamai.com/solutions/security) “Secure high-risk AI interactions, prevent DDoS attacks, deliver Zero Trust security, and understand and detect API risk and mitigate cyberthreats, all with the power of Akamai's global platform. ... GigaOm Radar: Akamai a Microsegmentation Leader.” | official | 2026-06-23 |
| s2 | [Akamai App & API Protector (WAAP) product page](https://www.akamai.com/products/app-and-api-protector) “All-in-one solution includes our WAF plus L7 DDoS defense, API discovery, sensitive data protection, and bot controls. ... Adaptive protections push zero-days and CVE protections. ... Fintech leader Finastra protects open finance apps and APIs with Akamai.” | official | 2026-06-23 |
| s3 | [Akamai Prolexic DDoS protection product page](https://www.akamai.com/products/prolexic-solutions) “Prolexic's 32 anycast global scrubbing centers with 20+ Tbps of dedicated DDoS defense ... industry-leading zero-second mitigation ... 225+ frontline SOCC defenders are working for you. ... Intuit keeps TurboTax, QuickBooks, and Mint available and secure year-round with Akamai.” | official | 2026-06-23 |
| s4 | [Akamai Guardicore Segmentation product page](https://www.akamai.com/products/akamai-guardicore-segmentation) “Provide provable, continuously-enforced segmentation controls that support strict audit, compliance, and governance requirements (PCI-DSS, HIPAA, SWIFT). ... Gartner Peer Insights Customer' Choice 2026 [image alt text on the page's award badge].” | official | 2026-06-23 |
| s5 | [Akamai Bot Manager product page](https://www.akamai.com/products/bot-manager) “Akamai Bot Manager uses advanced machine learning and shared telemetry to distinguish between good bots (like search engines), bad bots (like scrapers), and human users. ... Continuous updates to our known bot directory.” | official | 2026-06-23 |
| s6 | [Akamai Enterprise Application Access (ZTNA) product page](https://www.akamai.com/products/enterprise-application-access) “Akamai Enterprise Application Access is a Zero Trust Network Access solution that provides fast, secure, identity-based access to private applications. ... Enterprise Application Access integrates with most existing identity providers (IdPs), such as Akamai, Google, Ping, Okta, Microsoft Azure AD.” | official | 2026-06-23 |
| s7 | [Akamai Client-Side Protection & Compliance product page](https://www.akamai.com/products/client-side-protection-compliance) “It also helps businesses directly address requirements 6.4.3 and 11.6.1 in the latest PCI DSS v4.0 ... Client-Side Protection & Compliance goes beyond what WAFs can see or defend against on the client side.” | official | 2026-06-23 |
| s8 | [Akamai Reports First Quarter 2026 Financial Results (Akamai newsroom)](https://www.akamai.com/newsroom/press-release/akamai-reports-first-quarter-2026-financial-results) “Security revenue of $590 million, up 11% year-over-year. ... First quarter revenue of $1.074 billion, up 6% year-over-year. ... Our security portfolio is also uniquely positioned to benefit from the rapid evolution of AI.” | press | 2026-06-23 |
| s9 | [Akamai Firewall for AI product page](https://www.akamai.com/products/firewall-for-ai) “Akamai provides flexible deployment options, allowing businesses to integrate the firewall via: Akamai edge: Low-latency protection at the network edge. REST API integration. ... AI governance frameworks (AI TRiSM, OWASP Top 10 for LLM Applications).” | official | 2026-06-23 |
| s10 | [StockTitan: Akamai Reports First Quarter 2026 Financial Results (AKAM)](https://www.stocktitan.net/news/AKAM/akamai-reports-first-quarter-2026-financial-mjpy0c3zgmps.html) “Security revenue +11% YoY to $590 million ... security revenue increasing from $552M to $568M and now $590M. ... Q1 2026 Revenue $1.074 billion ... Security revenue $590 million Q1 2026 security revenue, up 11% year-over-year.” | press | 2026-06-23 |
| s11 | [Akamai Firewall for AI techdocs (Protect your AI apps)](https://techdocs.akamai.com/cloud-security/docs/protect-your-ai-apps) “Firewall for AI is here to help you protect your artificial intelligence apps, chatbots, and LLMs from emerging threats. ... Offered in limited availability. ... It applies security guardrails to both inputs and outputs.” | official | 2026-06-23 |
| s12 | [Akamai Client-Side Protection web-skimming defense](https://www.akamai.com/products/client-side-protection-compliance) “Malicious or compromised JavaScript resources within the browser allow web skimming, formjacking, and Magecart attacks to steal payment card data, user credential details, or personally identifiable information.” | official | 2026-06-23 |
| s13 | [NVD: CVE-2025-30143 Akamai App and API Protector ASE rule bypass](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-30143) “Rule 3000216 (before version 2) in Akamai App & API Protector (with Akamai ASE) before 2024-12-10 does not properly consider JavaScript variable assignment to built-in functions and properties.” | other | 2026-06-30 |
| s14 | [U.S. SEC EDGAR: Akamai Technologies Form 10-Q for the quarter ended March 31, 2026](https://www.sec.gov/Archives/edgar/data/1086222/000108622226000058/akam-20260331.htm) “Security $ 589,790 $ 530,695 11 % 9 %” | regulatory | 2026-06-30 |
| s15 | [NVD: CVE-2026-34354 Akamai Guardicore Platform Agent privilege escalation](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-34354) “Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escalation. The GPA service creates an IPC socket in the world-writable /tmp directory.” | other | 2026-06-30 |
| s16 | [Akamai partner story: Deloitte Brazil Delivered End-to-End Cyber Resilience](https://www.akamai.com/resources/partner-story/deloitte) “Deloitte Brazil provides rapid incident response while Akamai's solution immediately identifies and isolates the threat. "We use Akamai Guardicore Segmentation to stop the spread by segmenting the network, enabling faster resolution, and limiting damage," Gargaro noted.” | official | 2026-08-01 |
| s17 | [Akamai Technologies Completes Acquisition of Guardicore (Akamai investor newsroom, October 21, 2021)](https://www.ir.akamai.com/news-releases/news-release-details/akamai-technologies-completes-acquisition-guardicore-extend-its) “today announced the company has completed its acquisition of Guardicore of Tel Aviv, Israel. ... in exchange for approximately $600 million. ... Guardicore's leading micro-segmentation products will be added to Akamai's comprehensive portfolio of Zero Trust solutions” | press | 2026-08-04 |
| s18 | [Akamai customer story: Daiwa Capital Markets Enhances Cybersecurity in Banking](https://www.akamai.com/resources/customer-story/daiwa-capital-markets) “To protect critical systems, including trading and payments, leading investment bank Daiwa Capital Markets Europe has deployed Akamai Guardicore Segmentation across its IT infrastructure.” | official | 2026-08-05 |
| s19 | [Akamai App & API Protector limited-time offer landing page](https://www.akamai.com/lp/free-website-application-protection) “Up to 9 months free of App & API Protector ... Offer is available to new customers only. Terms and conditions apply. ... Not ready for 9 months? Start with a 30-day free trial” | official | 2026-08-05 |
| s20 | [Akamai App & API Protector page, SecureIQLab WAAP comparison promotion](https://www.akamai.com/products/app-and-api-protector) “Akamai outperforms other WAAPs: See the data. SecureIQLab tested leading cloud WAAP solutions against more than 1,360 threats. Akamai came away a winner when compared to AWS, Cloudflare, and Microsoft.” | official | 2026-08-05 |

## Disclaimer

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.
