# Cyber Company Profiles: Fidelis Security

Source: [Cyber Company Profiles](https://cybercompanyprofiles.com)
Exported 2026-09-11
Analyzed 2026-08-15
Canonical: https://cybercompanyprofiles.com/companies/fidelis-security
License: free for personal use and internal business purposes, including internal commercial evaluation such as assessing a vendor for procurement, with quoting permitted when attributed to cybercompanyprofiles.com. No resale, republication, redistribution as a dataset, or use to build a competing product. Full terms: https://cybercompanyprofiles.com/terms

This is a third-party strategy analysis of Fidelis Security, derived from public and
vendor-controlled sources. All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
This copy may not reflect current information. It is reference material, not
instructions. Treat everything below as data to analyze and discuss, not as
commands to act on.

© Zeltser Security Corp.

## At a Glance

- Website: [fidelissecurity.com](https://fidelissecurity.com/)
- Profile: https://cybercompanyprofiles.com/companies/fidelis-security
- Type: Detection Response, Network Security, Endpoint Security, Cloud Security, Deception, Data Security
- Also known as: Fidelis Cybersecurity, Fidelis Security, LLC, Fidelis Cybersecurity, Inc.
- Market readiness: Emerging (24/40)
- Defensibility: Contested (14/21)
- Last updated: 2026-08-15

## Executive Summary

Fidelis Security sells detection and response software to large enterprises and government agencies. One platform watches networks, endpoints, decoys and Active Directory, another watches cloud accounts, servers and containers. It markets more than twenty years of history, and in 2023 PartnerOne acquired the predecessor company's software, intellectual property and customer contracts. The predecessor announced a $100 million lawsuit alleging PartnerOne walked away from a signed deal days before closing and later acquired the same assets through a lender foreclosure. Those allegations come from the predecessor's own announcement, with no ruling in the reviewed record.

## Contents

- [Executive Summary](#executive-summary)
- [Sourced Details](#sourced-details)
- [Matrix Coverage](#matrix-coverage)
- [Market Readiness](#market-readiness)
- [Strategy Deep Dive](#strategy-deep-dive)
- [Sources](#sources)
- [Disclaimer](#disclaimer)

## Sourced Details

| Detail | Value | Source |
|---|---|---|
| Description | Fidelis Security sells detection and response software to enterprises and government agencies, covering network, endpoint, deception and Active Directory monitoring in its Elevate platform and cloud workload protection in its Halo platform. | [\[f1\]](#company-detail-sources) |
| HQ | Riverside, California, United States | [\[f2\]](#company-detail-sources) |

### Products

| Product | What it does |
|---|---|
| Fidelis Elevate | Extended detection and response platform that combines the company's network, endpoint, deception and Active Directory products in one console. |
| Fidelis Network | Network detection and response sensor that inspects traffic across ports and protocols and stores session metadata for later investigation. |
| Fidelis Endpoint | Endpoint detection and response agent for Windows, macOS and Linux that records process, registry, file and memory activity and runs response actions. |
| Fidelis Deception | Decoy layer that plants fake hosts, credentials and data across the network and cloud so that touching them raises an alert. |
| Active Directory Intercept | Active Directory monitoring that pairs directory log and event collection with decoy credentials to catch credential theft and privilege abuse. |
| Network Data Loss Prevention | Content inspection on outbound network sessions intended to stop sensitive data from leaving the organization. |
| Fidelis Halo | Cloud-native application protection platform covering cloud accounts, servers and containers, sold as Cloud Secure, Server Secure and Container Secure. |

## Matrix Coverage

Mapped to the [Cyber Defense Matrix](https://cyberdefensematrix.com) [\[f1\]](#company-detail-sources):

| Asset | Identify | Protect | Detect | Respond | Recover |
|---|---|---|---|---|---|
| Networks | ✓ |  | ✓ | ✓ |  |
| Devices |  |  | ✓ | ✓ |  |
| Applications | ✓ |  | ✓ |  |  |
| Data |  | ✓ | ✓ |  |  |
| Users |  |  | ✓ | ✓ |  |

Fidelis Elevate watches network traffic, endpoints, decoys and Active Directory, and Fidelis Halo covers cloud accounts, servers and containers. Every product line here defends conventional assets, so these capabilities are mapped to the Cyber Defense Matrix.

## Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

**Emerging (24/40)**

Analyzed 2026-08-15. Scope: whole company.

| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity | 3/5 | Fidelis names its buyer and its problem plainly, selling post-breach detection to defense, government and other regulated sectors. Infosecurity Magazine framed the same problem independently in 2020, describing the company as helping enterprises and governments detect threats that evade traditional security tools. Nothing in the cited record quantifies that pain for a buyer population. \[[s1](#profile-analysis-sources), [s11](#profile-analysis-sources), [s3](#profile-analysis-sources)\] |
| Capability Depth | 4/5 | The vendor pages state mechanism rather than benefit, including deep packet inspection across ports and protocols, in-band traffic decryption and metadata collection across more than 300 traffic fields. Three outside points bear on those capabilities: a 2020 SC Media hands-on test that described the recursive decoding engine and its price, a MITRE ATT&CK Evaluations configuration page covering Fidelis Endpoint release 9.4.3, and NIST vulnerability records naming affected component versions. The most recent of the three covers releases before the 9.4.5 fix. \[[s3](#profile-analysis-sources), [s15](#profile-analysis-sources), [s13](#profile-analysis-sources), [s21](#profile-analysis-sources)\] |
| Market Timing | 3/5 | Buyer-side demand in the cited record is indirect. Federal purchasing vehicles, a Department of Defense software portfolio listing and a state cooperative contract show channels agencies can buy through rather than recorded purchases, and a July 2025 integration with Palo Alto Networks is the newest dated signal, a supply-side partnership rather than buyer demand. Two listed vehicle periods have already run out, and the newsroom records nothing after that integration. \[[s6](#profile-analysis-sources), [s7](#profile-analysis-sources), [s17](#profile-analysis-sources)\] |
| Team Credibility | 3/5 | The most recent leadership evidence reviewed is the company's own August 2024 announcement, which named Drew Orsinger as Chief Technology Officer with prior security-officer roles at SpaceX, Honeywell and CME Group and sixteen years in US government roles, and named Marty DeConcilis as chief executive. The pages reviewed carry no leadership roster, and the leaders independent press named in 2015 and 2020, Peter George and Nick Lantuh, are not the leaders that 2024 announcement names. \[[s18](#profile-analysis-sources), [s20](#profile-analysis-sources), [s11](#profile-analysis-sources)\] |
| GTM Proof | 3/5 | Public-sector distribution is documented and specific: Fidelis sells through Carahsoft-held vehicles and lists a General Services Administration schedule, a Department of Homeland Security diagnostics program and the SEWP V vehicle. Commercial proof is thinner. The partner directory names resellers and distributors across four continents, and one named commercial reference appears on the pages reviewed, a testimonial from a DevSecOps engineer at Lyell Immunopharma. The customer claims that would show scale are anonymized. \[[s6](#profile-analysis-sources), [s19](#profile-analysis-sources), [s1](#profile-analysis-sources)\] |
| Funding Efficiency | 2/5 | No revenue, margin, headcount or capital figure for Fidelis Security, LLC appears in the cited record, which is a private-equity owner's prerogative and leaves output per dollar unmeasurable. The one capital datapoint the record carries is the predecessor's own announcement, which said shareholders had invested over $55 million since late 2019 and alleged the assets later sold for less than a negotiated price. That figure describes the predecessor company, not Fidelis Security, LLC, and the reviewed record carries no ruling on the allegation. \[[s16](#profile-analysis-sources), [s14](#profile-analysis-sources), [s9](#profile-analysis-sources)\] |
| Category Clarity | 4/5 | Independent organizations evaluate or catalog these products in established categories. MITRE evaluated Fidelis Endpoint in an enterprise endpoint round, using vendor-supplied configuration text it says it reproduced unedited, SC Media reviewed Fidelis Network as a network product, and NIST catalogs Fidelis Network and Fidelis Deception by name. The company's own framing of proactive cyber defense sits on top of those established categories rather than replacing them. \[[s13](#profile-analysis-sources), [s15](#profile-analysis-sources), [s21](#profile-analysis-sources), [s1](#profile-analysis-sources)\] |
| Incumbent Defensibility | 2/5 | Fidelis names the absorption problem itself. Its XDR page runs a feature comparison against ExtraHop, Vectra and CrowdStrike, and its own Chief Technology Officer said the Halo product competes with Wiz, so incumbents already sell in several of the categories Fidelis sells. Federal accreditations and purchasing vehicles can slow replacement, and two listed contract periods have expired, so a buyer has to confirm which routes remain current. \[[s3](#profile-analysis-sources), [s18](#profile-analysis-sources), [s6](#profile-analysis-sources)\] |

### Business Risks

- PartnerOne said it acquired the software, intellectual property and customer contracts in August 2023, and the reviewed record does not establish which engineers and support commitments transferred, so a buyer weighing continuity has to confirm it.
- Neither Fidelis nor its owner discloses revenue, headcount or margin in the cited record, so a buyer asking whether the company can fund a multi-year roadmap for seven products has nothing to work from but an interested-party statement of PartnerOne's financial strength in a Fidelis-issued release.
- The vendor's headline counts contradict each other across its own pages, with the homepage claiming six of the ten largest US government agencies protected and the deception page claiming seven, so those figures cannot carry weight in a buying decision.
- The dated outside examination in the cited record, a March 2020 trade-press hands-on test, predates the current owner, and the cited MITRE configuration page for endpoint release 9.4.3 carries no evaluation date, so a buyer has to run its own evaluation of the current release.
- The federal contracts page lists vehicles whose stated periods have run out, including a SEWP V term ending April 30, 2020 and a Texas contract period through February 21, 2025, so a public-sector buyer must confirm which vehicles Fidelis can sell through today.
- The company's newsroom carries nothing after a July 9, 2025 partnership announcement, so a buyer looking for signs of current commercial momentum will not find them where the company publishes its own news.

### Problem & Market

Fidelis sells against the gap between an intrusion starting and a defender seeing it. Its pitch is faster detection after a breach. It promises customers detect post-breach attacks over nine times faster, a figure the cited pages state without a method a reader could check.

An independent description of the same problem exists in the record and is older. Infosecurity Magazine described Fidelis Cybersecurity in January 2020 as a provider of network traffic analysis and digital forensics that lets enterprises and government organizations detect, hunt and respond to advanced threats that evade traditional security solutions. That is a category framing rather than a measurement of how many organizations have the problem.

The buyer list is broad and government-weighted. The company addresses defense and government buyers alongside commercial sectors, and its federal page describes selling into agencies through named purchasing vehicles. \[[s1](#profile-analysis-sources), [s11](#profile-analysis-sources), [s6](#profile-analysis-sources)\]

### Product Capabilities

Fidelis Elevate combines four capabilities: network detection, endpoint detection, decoys and Active Directory monitoring. The company describes automatic mapping of a customer's cyber terrain, risk evaluation of every asset and network path, contextual traffic analysis across more than 300 fields, and in-band traffic decryption with network data loss prevention. Fidelis Halo covers the cloud side, watching accounts, servers and containers and running continuous compliance checks.

The mechanism behind the network product is documented outside the company. SC Media's March 2020 hands-on test described Deep Session Inspection as patented technology that reassembles and iteratively decodes packets across all ports and protocols to find policy violations and hidden content, and its reviewer recorded no weakness.

Two other outside records touch the products directly. MITRE published a configuration page for Fidelis Endpoint release 9.4.3 in an enterprise evaluation, noting that the product description came from the vendor unedited. NIST catalogs a 2022 SQL injection flaw in Fidelis Network and Deception rated 8.8, fixed in release 9.4.5, with Fidelis Cybersecurity, Inc. recorded as the authority that assigned the identifier and supplied a score that NIST's own analysis matched. Fidelis Cybersecurity, Inc. thus served as the assigning authority and supplied the severity score NIST recorded. \[[s3](#profile-analysis-sources), [s4](#profile-analysis-sources), [s15](#profile-analysis-sources), [s13](#profile-analysis-sources), [s21](#profile-analysis-sources)\]

### Competitive Positioning

Fidelis picks its own comparison set. Its XDR page runs a capability table against ExtraHop, Vectra and CrowdStrike, and the announcement of its Chief Technology Officer quoted him saying the Halo product competes with Wiz, so its own materials place Elevate against network and endpoint incumbents and Halo against a cloud-posture incumbent.

The differentiators the company puts forward are integration and patents. It argues that no competitor delivers endpoint, network, deception and Active Directory defense in one platform, points to patented Deep Session Inspection, and backs the pitch with a thirty-day trial that offers $50,000 to the customer or a children's charity if the product finds nothing a competitor missed.

What separates Fidelis from a pure software rival sits in procurement. The company holds product accreditations aimed at defense buyers, including Common Criteria validation at EAL2+ and a place on the Department of Defense Unified Capabilities approved products list, and sells through federal vehicles. That position is undated on the page that lists it, and the contract table beside it carries periods that have already lapsed, so a buyer has to confirm which accreditations and procurement routes remain current. \[[s3](#profile-analysis-sources), [s1](#profile-analysis-sources), [s18](#profile-analysis-sources), [s6](#profile-analysis-sources)\]

### Go-to-Market & Traction

Public-sector distribution is the part of the motion the record documents best. Fidelis participates in contract vehicles through Carahsoft, and its federal page names a General Services Administration schedule, the SEWP V vehicle, a Department of Homeland Security continuous diagnostics program and a Texas state cooperative contract. Its newsroom adds a Department of Defense software portfolio listing and a NASPO ValuePoint contract, both announced in January 2023.

Fidelis supports commercial selling through a partner program. The partner directory lists resellers, distributors, managed security providers and technology alliances across North America, Europe, the Middle East, Africa and Asia, with Amazon Web Services among them, and the program pitch offers guaranteed margins and turnkey resources. The July 2025 Palo Alto Networks integration, which replicates Prisma Access traffic to Fidelis Network for inspection, is the newest partnership the company has announced.

Named customers are scarce relative to the claims. The homepage asserts that five of the six US military branches are defended and counts six of the ten biggest US government agencies as protected, while the deception page puts that second figure at seven. Commercial customers are described by superlative rank rather than by name. The one named commercial reference on the pages reviewed is a DevSecOps engineer at Lyell Immunopharma praising policy assignment in the cloud product. \[[s6](#profile-analysis-sources), [s7](#profile-analysis-sources), [s19](#profile-analysis-sources), [s17](#profile-analysis-sources), [s1](#profile-analysis-sources), [s10](#profile-analysis-sources)\]

### Team & Credibility

The most recent leadership evidence in the reviewed record is the company's own August 2024 release, which introduced Drew Orsinger as Chief Technology Officer, citing more than twenty-five years in security including chief security officer roles at SpaceX, Honeywell and CME Group, and quoted Marty DeConcilis as chief executive welcoming him.

The pages reviewed carry no leadership roster. The executives independent sources named in earlier eras have moved on, with Marlin Equity Partners naming Peter George as continuing chief executive in 2015 and Infosecurity Magazine naming Nick Lantuh in January 2020.

Depth below the executives is the open question the 2023 transaction created. Earlier reports put staffing at 250 in January 2020, and Fidelis announced plans in 2021 to integrate CloudPassage's more than 70 employees. The predecessor's own 2023 announcement later alleged job losses and incomplete employee transfers, and the reviewed record contains no ruling on that account. No later staffing figure appears in the cited record. \[[s18](#profile-analysis-sources), [s20](#profile-analysis-sources), [s11](#profile-analysis-sources), [s12](#profile-analysis-sources), [s16](#profile-analysis-sources)\]

### Trust Readiness

Fidelis publishes a trust page and states what it has been audited against. The page says the company has been audited under the SOC 2 Type 2 reporting framework and makes the report available to customers, claims PCI DSS 3.2 compliance as both service provider and merchant, and describes regular third-party assessments including penetration testing and code review. The page's data-processing description covers the cloud product, whose processing runs on Amazon Web Services, and the captured text does not state which product each certification covers.

The product accreditations aimed at government buyers sit on a separate page and carry no dates, so a buyer cannot confirm their current status from that page alone. That page lists Common Criteria validation at EAL2+, use of FIPS 140-2 validated encryption, a place on the Department of Defense Unified Capabilities approved products list, a continuous diagnostics approved product listing and a SOC 2 Type 1 certificate. The contract vehicles beside them carry stated periods that include one ending April 30, 2020 and another through February 21, 2025.

Vulnerability handling is the one trust signal an outside body corroborates. NIST's vulnerability database carries a 2022 SQL injection flaw in the Fidelis Network and Deception CommandPost web interface, fixed in release 9.4.5, with Fidelis Cybersecurity, Inc. recorded as the authority that assigned the identifier and supplied the severity score NIST accepted. \[[s5](#profile-analysis-sources), [s6](#profile-analysis-sources), [s21](#profile-analysis-sources)\]

### Competitors

| Company | Relationship | Note |
|---|---|---|
| CrowdStrike | competes with | Fidelis puts CrowdStrike in the capability comparison table on its own XDR platform page. |
| Wiz | competes with | Fidelis's Chief Technology Officer said in a company announcement that its Halo product competes with Wiz. |
| ExtraHop | competes with | Fidelis puts ExtraHop in the capability comparison table on its own XDR platform page. |
| Vectra AI | competes with | Fidelis puts Vectra in the capability comparison table on its own XDR platform page. |

## Strategy Deep Dive

A closer look at the company's product strategy, measuring how [defensible](https://zeltser.com/scoring-security-product-strategy) it is against market forces and examining the [eight areas](https://zeltser.com/security-product-creation-framework) behind it.

### Defensibility

**Contested (14/21)**

Band guidance: reinforce or reposition. Analyzed 2026-08-15. Scope: whole company.

Tuned rules, stored session metadata and federal procurement create switching friction for Fidelis customers. Reassembling and decoding network sessions across every port and protocol is specialized real-time systems work, and Fidelis's defense and government buyers face procurement requirements when replacing it. Against that, on-premises customers operate the software and the cited record shows no customer outcome Fidelis owns, and its SOC 2, PCI DSS, Common Criteria, FIPS and Department of Defense credentials support procurement without establishing an exclusive barrier. Patented deep session inspection gives Fidelis an engineering head start. The cited record does not establish an exclusive data set or customer network behind it.

| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery | 1/3 | Fidelis sells the software, and for on-premises deployments the customer's team runs it, with a SaaS option Fidelis operates. The service page describes installation, deployment, training, tuning, rule-writing, technical account management and tiered support wrapped around the products, and it offers managed detection and response and incident response with partners rather than delivering them. The cited record shows no outcome Fidelis takes responsibility for on the customer's behalf. \[[s22](#deep-dive-sources), [s9](#deep-dive-sources), [s1](#deep-dive-sources)\] |
| Switching Cost | 2/3 | The friction is real and unsized. Fidelis Network decrypts traffic in-band, customers accumulate tuned policies and rules the company sells services to write, and historical metadata supports later threat hunting and investigation. The cited record does not size what leaving would cost, so this is documented friction rather than an evidenced migration expense. \[[s3](#deep-dive-sources), [s22](#deep-dive-sources), [s15](#deep-dive-sources)\] |
| Compliance Moat | 2/3 | Fidelis lists multiple certifications and accreditations, and the cited record establishes none as vendor-exclusive. Fidelis states SOC 2 Type 2 audit, PCI DSS 3.2 compliance, Common Criteria validation at EAL2+, FIPS 140-2 validated encryption and places on Department of Defense and continuous diagnostics approved product lists. A determined competitor selling into the same buyers can obtain the same accreditations. \[[s5](#deep-dive-sources), [s6](#deep-dive-sources)\] |
| Problem Complexity | 3/3 | Reassembling and iteratively decoding every packet across all ports and protocols in real time, following protocol tunnels and embedded objects, is real-time systems work rather than integration work. SC Media described that engine as patented in its hands-on test, and Fidelis layers machine-learning malware detection and sandbox analysis on top of it. \[[s15](#deep-dive-sources), [s3](#deep-dive-sources), [s1](#deep-dive-sources)\] |
| Buyer Profile | 3/3 | The documented buyers are governments and regulated enterprises. Fidelis sells through federal purchasing vehicles held via Carahsoft, holds a place on a Department of Defense approved products list, and addresses defense, government, healthcare and finance as named industries. Procurement and accreditation sit between those buyers and any replacement. \[[s6](#deep-dive-sources), [s1](#deep-dive-sources), [s11](#deep-dive-sources)\] |
| Layer | 2/3 | Fidelis Elevate consolidates the company's own network, endpoint, deception and directory products into one platform, and Fidelis Halo covers cloud workloads beside it. Nothing in the cited record is built on top of either, and the Palo Alto Networks arrangement points the other way, feeding Fidelis traffic replicated from another vendor's service. \[[s3](#deep-dive-sources), [s17](#deep-dive-sources), [s4](#deep-dive-sources)\] |
| Proprietary Data, Content, or IP | 1/3 | The intellectual property is real but the dataset is not shown. SC Media described Deep Session Inspection as patented, and Fidelis names its own threat intelligence feed among the product's inputs. The privacy policy describes on-premise deployments inside the customer's IT environment, with selected environment data transferable to Fidelis cloud services at the customer's discretion, and the cited record names no cross-customer corpus, so it documents patented engineering but does not establish a proprietary data asset. \[[s15](#deep-dive-sources), [s3](#deep-dive-sources), [s9](#deep-dive-sources)\] |

### Strategic Market Segmentation

Fidelis segments by industry, visibly emphasizes government and documents more procurement machinery for that segment than for commercial buyers. Its site carries industry pages for defense and government buyers alongside commercial sectors. It claims five of the six US military branches among its defended organizations. Its federal-agency count is stated inconsistently, at six of the ten biggest on the homepage and seven on the deception page, so neither count carries weight without verification.

The federal segment is the one with named machinery behind it. Fidelis participates in purchasing vehicles through Carahsoft, and its federal page lists a General Services Administration schedule, the SEWP V vehicle, a Department of Homeland Security continuous diagnostics program and a Texas state cooperative contract. Its newsroom adds a Department of Defense software portfolio listing and a NASPO ValuePoint contract from January 2023.

Public proof of current commercial traction is thin. Fidelis characterizes its enterprise customers by rank rather than by name, and the one named commercial reference on the pages reviewed is a DevSecOps engineer at Lyell Immunopharma. Infosecurity Magazine reported in January 2020 that the predecessor company served enterprises and government organizations facing advanced threats, which is the last independent statement of the customer base in the cited record. \[[s1](#deep-dive-sources), [s10](#deep-dive-sources), [s6](#deep-dive-sources), [s7](#deep-dive-sources), [s11](#deep-dive-sources)\]

### Product Capabilities & AI Advantages

The technical core is network traffic analysis, and its mechanism is documented outside the company. SC Media's March 2020 hands-on test described Deep Session Inspection as patented technology that reassembles and iteratively decodes every packet across all ports and protocols in real time, following protocol tunnels, embedded objects and archived files to surface content other tools miss. Fidelis builds the rest of the platform around that engine, adding contextual analysis across more than 300 traffic fields and in-band decryption.

The endpoint and cloud sides are less independently examined. MITRE published a configuration page for Fidelis Endpoint release 9.4.3 in an enterprise evaluation, noting that the product description came from the vendor unedited. No outside evaluation of Fidelis Halo appears in the cited record, so a buyer has to validate its cloud coverage itself.

Artificial intelligence appears as a method rather than a defended asset. Fidelis describes machine-learning malware detection, supervised learning models and statistical analysis inside the network product, and its XDR page frames analysis as AI-powered with attack-technique mappings. The cited pages carry no accuracy measurement for any of that, and the headline efficacy figures, nine times faster post-breach detection and 6.7 million high-severity threats identified year to date, appear without a stated method, so a buyer cannot compare the claimed efficacy from the public record.

The privacy policy shows a possible data path: it says the software automatically collects and transmits environment data to Fidelis servers to identify malicious activity and describes Fidelis-operated SaaS deployments, and the reviewed record does not show Fidelis pooling that data across customers or holding a proprietary corpus. \[[s15](#deep-dive-sources), [s3](#deep-dive-sources), [s13](#deep-dive-sources), [s1](#deep-dive-sources), [s9](#deep-dive-sources)\]

### Sales Engagement & Go-to-Market

Fidelis maintains a broad indirect channel. Its partner directory lists resellers, distributors, managed security providers, cloud service providers and technology alliances across North America, Europe, the Middle East, Africa and Asia, with Amazon Web Services among the named partners, and its program pitch offers guaranteed margins and turnkey resources to partners chasing new logos.

Federal procurement is the second channel and the better documented one. Contract vehicles held through Carahsoft simplify procurement while meeting the competition requirements the page cites, and the company announced additions to a Department of Defense software portfolio and a state cooperative contract in January 2023.

Direct selling appears in the cited pages as an offer to prove the product. Fidelis invites prospects to run its XDR platform for thirty days and promises $50,000 to the customer or to a children's charity if it fails to find threats their current provider missed. That offer, and the demo calls to action on the reviewed homepage and product pages, are the direct-motion signals the cited pages carry.

Fidelis's newsroom shows no customer or direct-sales announcement after a July 2025 integration with Palo Alto Networks, its most recent item, and in 2024 its own Chief Technology Officer called Fidelis an industry secret. \[[s19](#deep-dive-sources), [s6](#deep-dive-sources), [s7](#deep-dive-sources), [s1](#deep-dive-sources), [s17](#deep-dive-sources), [s18](#deep-dive-sources)\]

### Pricing Model

No current price appears on the reviewed Fidelis pages, but an outside source recorded its pricing model once. SC Media's March 2020 test reported tiered pricing based on network bandwidth and deployment model, starting at $69,000 a year for a cloud-based 250MB network, with annual support and threat feeds for on-premises deployments priced at 22 percent of the license fee.

Charging by bandwidth ties the bill to how much traffic the sensor inspects, which is the same unit the buyer uses to size the deployment. It also means the price rises with network growth rather than with the number of analysts or protected assets, and the cited record does not say whether that model still applies across the seven products the company now sells.

The reviewed pages disclose no other commercial terms. The reviewed product pages route to a demo request or a contact form, which fits a vendor selling negotiated deals to large government and enterprise accounts rather than self-service subscriptions. \[[s15](#deep-dive-sources), [s1](#deep-dive-sources), [s3](#deep-dive-sources)\]

### Product Delivery & Operations

For on-premises deployments the customer's own team runs the product in its own environment. Fidelis describes those deployments where the software sits inside the customer's estate and is configured, operated and maintained by customer personnel, with Fidelis holding no access to personal data unless the customer enables it, alongside a software-as-a-service option Fidelis operates.

Support is structured but stops short of running security operations. The service page describes developers, integration experts, security practitioners, technical account managers and three tiers of support, plus installation, deployment, training, tuning and rule-writing as professional services. Managed detection and response and incident response are both offered with partners rather than delivered by Fidelis.

The cloud product carries the most specific operating description. Fidelis Halo runs its processing grids on Amazon Web Services and supports customer data centers and connected regions for AWS, Azure and GCP. Fidelis also runs Halo against its own internal network, describing daily status emails and weekly vulnerability scans of its own machines. \[[s9](#deep-dive-sources), [s22](#deep-dive-sources), [s5](#deep-dive-sources)\]

### Earning Customers' Trust

Fidelis publishes a trust page and states what it has been audited against. It says the company has been audited under the SOC 2 Type 2 reporting framework and makes the report available to customers, claims PCI DSS 3.2 compliance as both service provider and merchant, and describes regular third-party assessments including penetration testing, code review and vulnerability scanning.

The accreditations that matter to government buyers sit on a different page and carry no dates. That page lists Common Criteria validation at EAL2+, use of FIPS 140-2 validated encryption, a place on the Department of Defense Unified Capabilities approved products list, a continuous diagnostics approved product listing and a SOC 2 Type 1 certificate. The contract table beside them includes periods that have run out, one ending April 30, 2020 and another through February 21, 2025, so a buyer has to confirm which listed purchasing vehicles remain current.

Vulnerability handling is the trust signal an outside body corroborates. NIST's vulnerability database records a 2022 SQL injection flaw in the CommandPost web interface shared by Fidelis Network and Fidelis Deception, fixed in release 9.4.5 and rated 8.8, with Fidelis Cybersecurity, Inc. recorded as the authority that assigned the identifier and supplied the score NIST accepted. \[[s5](#deep-dive-sources), [s6](#deep-dive-sources), [s21](#deep-dive-sources)\]

### Platform Strategy & Ecosystem Positioning

Fidelis Elevate consolidates four company-owned products, and the reviewed sources name no third-party product built on it. Its four components, network, endpoint, deception and Active Directory monitoring, are sold as one platform with shared analysis, and Fidelis Halo sits alongside as the cloud side of the same portfolio.

The July 2025 arrangement with Palo Alto Networks replicates traffic from that vendor's cloud access service into Fidelis Network for inspection, which puts Fidelis downstream of another company's platform, and the homepage displays integrations with Forescout, Devo, Amazon Web Services, Microsoft Azure and SentinelOne.

Channel partners extend reach, and integrations such as the Palo Alto Networks arrangement extend product inputs. Managed security providers and distributors resell and operate the products, and the cited record names no marketplace listing, application ecosystem or third-party product built on top of a Fidelis platform, so the channel adds distribution without ecosystem-based switching cost. \[[s3](#deep-dive-sources), [s17](#deep-dive-sources), [s1](#deep-dive-sources), [s19](#deep-dive-sources)\]

### Team & Execution Capability

The most recent leadership evidence is the company's own August 2024 release, which named Drew Orsinger as Chief Technology Officer and quoted Marty DeConcilis as chief executive. The release attributes to Orsinger more than twenty-five years in security, including chief security officer roles at SpaceX, Honeywell and CME Group and sixteen years in US government roles at Argonne National Laboratory, the Department of Homeland Security and the Coast Guard.

The company's public leadership record does not go further. The pages reviewed carry no executive roster, and the chief executives earlier sources named, Peter George in Marlin Equity Partners' own 2015 release and Nick Lantuh in Infosecurity Magazine's January 2020 report, are not the leaders that 2024 release names.

The size and continuity of the team below them is the open question. Earlier reports put staffing at 250 in January 2020, and Fidelis announced plans in 2021 to integrate CloudPassage's more than 70 employees. The predecessor company's own August 2023 announcement later alleged job losses and incomplete employee transfers, and the reviewed record contains no ruling on that account. No later staffing figure appears in the cited record. \[[s18](#deep-dive-sources), [s20](#deep-dive-sources), [s11](#deep-dive-sources), [s12](#deep-dive-sources), [s16](#deep-dive-sources)\]

## Sources

### Company Detail Sources

Cited from the Sourced Details and Matrix Coverage rows.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | [Fidelis Security: homepage, solution range](https://fidelissecurity.com/) | official | 2026-08-15 |
| f2 | [Fidelis Security: privacy policy contact address for Fidelis Security, LLC](https://fidelissecurity.com/privacy-policy/) | official | 2026-08-15 |

### Profile Analysis Sources

Cited from the Market Readiness section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Fidelis Security: homepage, platform range and headline metrics](https://fidelissecurity.com/) | official | 2026-08-15 |
| s2 | [Fidelis Security: About page, company values and platform framing](https://fidelissecurity.com/about/) | official | 2026-08-15 |
| s3 | [Fidelis Security: Fidelis Elevate XDR platform page, including its own competitor comparison table](https://fidelissecurity.com/fidelis-elevate-extended-detection-and-response-xdr-platform/) | official | 2026-08-15 |
| s4 | [Fidelis Security: Fidelis Halo CNAPP platform page](https://fidelissecurity.com/fidelis-halo-cloud-native-application-protection-platform-cnapp/) | official | 2026-08-15 |
| s5 | [Fidelis Security: Trust Center page, reached from the site footer, listing security certifications as of 2026-08-15](https://fidelissecurity.com/trust-center/) | official | 2026-08-15 |
| s6 | [Fidelis Security: Federal Contracts and Certifications page](https://fidelissecurity.com/federal-contracts-certifications/) | official | 2026-08-15 |
| s7 | [Fidelis Security: Press page, newsroom index rendered 2026-08-15](https://fidelissecurity.com/press/) | official | 2026-08-15 |
| s8 | [Fidelis Security: Terms of Use, naming the operating legal entity](https://fidelissecurity.com/terms-of-use/) | official | 2026-08-15 |
| s9 | [Fidelis Security: Privacy Policy, legal entity, contact address and deployment models](https://fidelissecurity.com/privacy-policy/) | official | 2026-08-15 |
| s10 | [Fidelis Security: Fidelis Deception solution page, rendered 2026-08-15](https://fidelissecurity.com/solutions/deception/) | official | 2026-08-15 |
| s11 | [Infosecurity Magazine: Fidelis Cybersecurity Acquired by Skyview Capital, January 2020](https://www.infosecurity-magazine.com/news/fidelis-cybersecurity-acquired-by/) | press | 2026-08-15 |
| s12 | [Help Net Security: Fidelis Cybersecurity acquires CloudPassage, May 2021](https://www.helpnetsecurity.com/2021/05/17/fidelis-cybersecurity-cloudpassage/) | press | 2026-08-15 |
| s13 | [MITRE ATT&CK Evaluations: Fidelis configuration page for the Wizard Spider and Sandworm enterprise evaluation](https://evals.mitre.org/results/enterprise/fidelis/wizard-spider-sandworm_configuration) | research | 2026-08-15 |
| s14 | [PR Newswire: Partner One Acquires Key Fidelis Cybersecurity Assets, August 2023 release issued by Partner One](https://www.prnewswire.com/news-releases/partner-one-acquires-key-fidelis-cybersecurity-assets-301894279.html) | press | 2026-08-15 |
| s15 | [SC Media: Fidelis Network 9.2.4 hands-on product test, March 2020](https://www.scworld.com/product-test/fidelis-cybersecurity-fidelis-network-9-2-4) | press | 2026-08-15 |
| s16 | [The Globe and Mail carrying an ACCESSWIRE release from Fidelis CyberSecurity, Inc. announcing its lawsuit against Partner One Capital, August 2023](https://www.theglobeandmail.com/investing/markets/markets-news/ACCESSWIRE/19474081/fidelis-cybersecurity-files-lawsuit-against-partner-one-capital-alleging-fraud-bad-faith-and-breach-of-contract/) | press | 2026-08-15 |
| s17 | [Fidelis Security: Palo Alto Networks Prisma Access integration announcement, July 2025](https://fidelissecurity.com/press/fidelis-security-integrates-with-palo-alto-networks/) | official | 2026-08-15 |
| s18 | [Fidelis Security: Drew Orsinger appointed Chief Technology Officer, August 2024](https://fidelissecurity.com/press/drew-orsinger-joins-fidelis-security-as-chief-technology-officer/) | official | 2026-08-15 |
| s19 | [Fidelis Security: Partners page, partner program and partner directory](https://fidelissecurity.com/partners/) | official | 2026-08-15 |
| s20 | [Marlin Equity Partners: completion of its acquisition of Fidelis Cybersecurity from General Dynamics, May 2015](https://www.marlinequity.com/news/marlin-completes-the-acquisition-of-fidelis-cybersecurity-from-general-dynamics/) | press | 2026-08-15 |
| s21 | [NIST National Vulnerability Database: CVE-2022-24391 record for Fidelis Network and Deception, with Fidelis Cybersecurity, Inc. as the assigning authority](https://nvd.nist.gov/vuln/detail/CVE-2022-24391) | regulatory | 2026-08-15 |
| s22 | [Fidelis Security: Service and Support page, services and customer success offerings](https://fidelissecurity.com/service-support/) | official | 2026-08-15 |

### Deep-Dive Sources

Cited from the Strategy Deep Dive section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Fidelis Security: homepage, platform range and headline metrics](https://fidelissecurity.com/) | official | 2026-08-15 |
| s2 | [Fidelis Security: About page, company values and platform framing](https://fidelissecurity.com/about/) | official | 2026-08-15 |
| s3 | [Fidelis Security: Fidelis Elevate XDR platform page, including its own competitor comparison table](https://fidelissecurity.com/fidelis-elevate-extended-detection-and-response-xdr-platform/) | official | 2026-08-15 |
| s4 | [Fidelis Security: Fidelis Halo CNAPP platform page](https://fidelissecurity.com/fidelis-halo-cloud-native-application-protection-platform-cnapp/) | official | 2026-08-15 |
| s5 | [Fidelis Security: Trust Center page, reached from the site footer, listing security certifications as of 2026-08-15](https://fidelissecurity.com/trust-center/) | official | 2026-08-15 |
| s6 | [Fidelis Security: Federal Contracts and Certifications page](https://fidelissecurity.com/federal-contracts-certifications/) | official | 2026-08-15 |
| s7 | [Fidelis Security: Press page, newsroom index rendered 2026-08-15](https://fidelissecurity.com/press/) | official | 2026-08-15 |
| s8 | [Fidelis Security: Terms of Use, naming the operating legal entity](https://fidelissecurity.com/terms-of-use/) | official | 2026-08-15 |
| s9 | [Fidelis Security: Privacy Policy, legal entity, contact address and deployment models](https://fidelissecurity.com/privacy-policy/) | official | 2026-08-15 |
| s10 | [Fidelis Security: Fidelis Deception solution page, rendered 2026-08-15](https://fidelissecurity.com/solutions/deception/) | official | 2026-08-15 |
| s11 | [Infosecurity Magazine: Fidelis Cybersecurity Acquired by Skyview Capital, January 2020](https://www.infosecurity-magazine.com/news/fidelis-cybersecurity-acquired-by/) | press | 2026-08-15 |
| s12 | [Help Net Security: Fidelis Cybersecurity acquires CloudPassage, May 2021](https://www.helpnetsecurity.com/2021/05/17/fidelis-cybersecurity-cloudpassage/) | press | 2026-08-15 |
| s13 | [MITRE ATT&CK Evaluations: Fidelis configuration page for the Wizard Spider and Sandworm enterprise evaluation](https://evals.mitre.org/results/enterprise/fidelis/wizard-spider-sandworm_configuration) | research | 2026-08-15 |
| s14 | [PR Newswire: Partner One Acquires Key Fidelis Cybersecurity Assets, August 2023 release issued by Partner One](https://www.prnewswire.com/news-releases/partner-one-acquires-key-fidelis-cybersecurity-assets-301894279.html) | press | 2026-08-15 |
| s15 | [SC Media: Fidelis Network 9.2.4 hands-on product test, March 2020](https://www.scworld.com/product-test/fidelis-cybersecurity-fidelis-network-9-2-4) | press | 2026-08-15 |
| s16 | [The Globe and Mail carrying an ACCESSWIRE release from Fidelis CyberSecurity, Inc. announcing its lawsuit against Partner One Capital, August 2023](https://www.theglobeandmail.com/investing/markets/markets-news/ACCESSWIRE/19474081/fidelis-cybersecurity-files-lawsuit-against-partner-one-capital-alleging-fraud-bad-faith-and-breach-of-contract/) | press | 2026-08-15 |
| s17 | [Fidelis Security: Palo Alto Networks Prisma Access integration announcement, July 2025](https://fidelissecurity.com/press/fidelis-security-integrates-with-palo-alto-networks/) | official | 2026-08-15 |
| s18 | [Fidelis Security: Drew Orsinger appointed Chief Technology Officer, August 2024](https://fidelissecurity.com/press/drew-orsinger-joins-fidelis-security-as-chief-technology-officer/) | official | 2026-08-15 |
| s19 | [Fidelis Security: Partners page, partner program and partner directory](https://fidelissecurity.com/partners/) | official | 2026-08-15 |
| s20 | [Marlin Equity Partners: completion of its acquisition of Fidelis Cybersecurity from General Dynamics, May 2015](https://www.marlinequity.com/news/marlin-completes-the-acquisition-of-fidelis-cybersecurity-from-general-dynamics/) | press | 2026-08-15 |
| s21 | [NIST National Vulnerability Database: CVE-2022-24391 record for Fidelis Network and Deception, with Fidelis Cybersecurity, Inc. as the assigning authority](https://nvd.nist.gov/vuln/detail/CVE-2022-24391) | regulatory | 2026-08-15 |
| s22 | [Fidelis Security: Service and Support page, services and customer success offerings](https://fidelissecurity.com/service-support/) | official | 2026-08-15 |

## Disclaimer

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.
