Sample — a demonstration landing page built by Victory Marketing Solutions. Sentinel Grid Security Corp. is a fictional issuer; every figure is illustrative and nothing here is investment advice. Back to Victory →
NASDAQ: SNGQFSE: 7SG

Corporate presentation · Meridian Platform

Eleven days of dwell time, cut to 89 seconds.

Meridian is an autonomous containment platform running in 412 production tenants across regulated industries — now confirmed by independent evaluators to stop 212 of 216 blind attack chains before objective, with a 0.3% false isolation rate.

  • Identity
  • Endpoint
  • Cloud
  • Operational technology
Platform
Meridian, autonomous containment
Annual recurring revenue*
$61.4M · +58% YoY
Median time to containment
89 seconds
Scale
412 tenants · 3.9M endpoints
*Non-GAAP operating metric for a fictional issuer. See disclosure.

The setting

The average intruder lives inside a network for eleven days.

Enterprise security spending has tripled in a decade, and mean adversary dwell time has barely moved. Across the incidents Halstead Labs reconstructed in 2026, the median attacker held access for 264 hours before anyone acted — not because the alert never fired, but because a human had to read it, believe it and approve a response.[2]

Sentinel Grid sells into that gap. Meridian is an autonomous containment platform that isolates a compromised identity, host or workload in under ninety seconds, without waiting for an analyst — and it is deployed today across 412 production tenants in regulated industries.[1][5]

HeadquartersAustin, Texas · R&D in Ottawa and Tel Aviv
Production tenants412
Protected endpoints3.9 million
DeploymentSaaS, single-tenant cloud, or air-gapped
CertificationsSOC 2 Type II · ISO 27001 · FedRAMP Moderate
Headcount318, of whom 191 in engineering

The product surface is deliberately narrow. Meridian does not try to replace the SIEM, the firewall or the email gateway; it consumes their telemetry and decides, autonomously, what to cut off.[1]

Coverage, deployment and scale

Four regions, three deployment modes, one control plane.

Telemetry is processed in-region and never leaves the customer's jurisdiction; only decision records synchronise to the global control plane. Meridian sits inside the customer's existing control stack rather than replacing it.[1]

Global network topology map showing Meridian regional processing nodes across North America, Europe, the Middle East and Asia Pacific, with links to customer control stacks
Fig. 1Deployment topology and regional processing. Illustrative sample figure — geometry is schematic.
Regions
4 in-region processing
Tenants
412 in production
Endpoints
3.9 million protected
Modes
SaaS, single-tenant, air-gapped

Want the Phase 2 evaluation results when they land? Join the list →

The company

A focused platform business built by people who ran the response teams.

Sentinel Grid Security Corp. is a cybersecurity software company incorporated in Delaware — founded in 2019 by three incident response leads who had spent a combined thirty years arriving at breaches after the fact and concluding, every time, that the detection had worked and the response had not.[1]

The company sells Meridian directly to enterprises and through a managed-service partner channel, and in 2025 acquired Vantage Identity Systems, whose identity-graph engine now underpins Meridian's blast radius calculation.[1]

ListingsNASDAQ: SNGQ · FSE: 7SG
FlagshipMeridian autonomous containment platform
Second assetVantage identity graph — 100% owned
Go to marketDirect enterprise plus 47 MSSP partners

Phase 1 evaluation

The results are in: 42 hours to 89 seconds, with a 0.3% false isolation rate.

On February 18, 2026, independent evaluators Halstead Labs and the Northbridge Cyber Test Range completed a blind adversary emulation series against Meridian, running 216 full attack chains across identity, endpoint, cloud and OT segments.[2]

Median time from initial access to full containment was 89 seconds. More than 99% of containment actions were assessed as correct, with a false isolation rate of 0.3% — the metric that historically kills autonomous response products, because a platform that quarantines the CFO's laptop during a board meeting does not get a second chance.[2]

Median time to containment89 seconds
Attack chains blocked before objective212 of 216
Correct containment decisions> 99%
False isolation rate0.3%
Analyst actions required per incident0 (median)

Lower dwell time means smaller blast radius, lower breach cost, and a product an insurer will underwrite against — which is where enterprise budget actually comes from.[2]

How Meridian's latency compares

Lower numbers are better. Meridian's are low.

Chart comparing mean adversary dwell time in hours across security platform categories with Meridian highlighted, alongside a breakdown of detection, triage and containment time
Fig. 2Dwell time benchmark and response time split. Illustrative sample figure based on the Phase 1 evaluation.

Why Meridian is different

A containment engine — not another detection layer.

Most platforms in this market are detection systems: they generate signal and hand it to a human. The industry's answer to too many alerts has been better alerts, which is why the average SOC still triages thousands a week and dwell time has not moved.[2]

Meridian inverts the design. Detection is an input, not the product. The system's job is the decision — cut this identity, freeze this workload, revoke this token — and to be right often enough to be trusted with the authority to act.

The evaluation also confirmed that Meridian's accuracy holds up because the identity graph makes blast radius computable. Rather than scoring an alert in isolation, the engine knows what a compromised principal can reach, and contains along that reachability boundary — a well-understood graph problem rather than a probabilistic guess.[2]

The Halstead results are definitive. They confirm that autonomous containment can operate at enterprise scale with a false isolation rate low enough for production. The ability to cut median dwell time from days to under two minutes, with no analyst in the loop, represents a compelling pathway for value creation.

Priya Raghunathan, CEO, Sentinel Grid Security Corp.

Three revenue lines from one platform

One control plane, three commercially distinct products.

One of the most significant findings of the Phase 1 work is that the same containment engine monetises three ways: platform subscription, identity-graph seats, and an OT connector suite sold per site. That multi-product structure spreads revenue across different buying centres and improves net retention within existing tenants.[1][5]

Security operations dashboard showing live containment actions, blast radius calculations and decision records across a tenant estate
Fig. 3Containment console and decision record view. Illustrative sample figure.
Photograph of a data centre server aisle representing single-tenant and air-gapped Meridian deployments
Fig. 4Single-tenant and air-gapped deployment environments. Representative sample imagery.

Want the Phase 2 evaluation results when they land? Join the list →

The architecture

An identity graph with a containment plane bolted to it.

Meridian ingests telemetry from existing endpoint, identity, cloud and network controls, resolves every actor into a single principal on a continuously updated identity graph, and computes reachability — what each principal can touch, through which credential, at this moment.[1]

The containment plane sits alongside it, holding pre-authorised enforcement paths into the customer's own controls. When reachability plus behaviour crosses a threshold, enforcement executes directly against those controls, with a full decision record written before the action completes — which is what makes the behaviour auditable to a regulator rather than merely fast.[1]

Inside an attack chain

Reachability and behaviour, in one graph.

Attack path diagram tracing initial access through credential theft and lateral movement to a domain objective, with the Meridian containment boundary drawn across the path
Fig. 5Attack path with computed containment boundary. Illustrative sample figure.
SignalWhat it drives
Identity reachabilityBlast radius, highest weight
Credential anomalyEscalation trigger
Workload behaviourContainment scope
Telemetry gapsConfidence discount

Signal descriptions summarise the Phase 1 evaluation findings.[2]

History

Seven years of building the same thing.

2019 – 2021

  • Company founded by three incident response leads after a shared engagement on a manufacturing ransomware case.
  • First containment prototype built against a single EDR vendor's API; first design partner signed in healthcare.
  • Corwin Group evaluation returns a 4.2% false isolation rate — too high to ship, and the reason the identity graph work started.

2022 – 2024

  • Identity graph rebuilt from scratch; false isolation rate falls below 1% in Redline Assurance testing.
  • First eight-figure ARR year; MSSP channel opened with 12 launch partners.
  • FedRAMP Moderate authorisation achieved, unlocking public sector and defence-adjacent pipeline.

2025 – Present

  • Vantage Identity Systems acquired; its graph engine becomes the reachability core of Meridian.
  • 412 production tenants and 3.9 million protected endpoints as at December 31, 2026.
  • Halstead Labs blind evaluation returns 89-second median containment at a 0.3% false isolation rate.

Between 2019 and 2024 the platform was tested in five independent evaluation programs, each conducted under different methodologies and each showing sequential improvement in containment latency and decision accuracy (Corwin, Redline, Halstead, Northbridge).[3][4]

The financials

$61.4M ARR at 137% net retention — audited, and stated as such.

The business has 412 production tenants, with the revenue base concentrated in regulated industries:[1]

FY2025$38.9M ARR · 128% NRR · 71% gross margin
FY2026$61.4M ARR · 137% NRR · 79% gross margin

ARR grew 58% year over year, driven roughly two thirds by expansion within existing tenants and one third by new logos. The top ten customers represent 21% of ARR, down from 34% two years ago. Gross retention was 96%, and the company reported its first positive operating cash flow quarter in Q4 FY2026.[1]

Annual recurring revenue$61.4M, +58% YoY
Net revenue retention137%
Gross revenue retention96%
Gross margin79%
Cash and equivalents$94.2M, no debt
Rule of 40 score51

These figures are illustrative and belong to a fictional issuer created to demonstrate a landing-page format. ARR, net revenue retention and Rule of 40 are non-GAAP operating metrics; definitions vary between companies and these are not substitutes for GAAP revenue. Forward-looking statements involve risks and uncertainties, and actual results for any real issuer would differ materially. A qualified reader should rely only on audited financial statements filed with the relevant securities regulator. Nothing here is an offer of securities or investment advice.

Prior evaluations

Five programs, seven years, all pointing the same way.

Corwin Group (2019)

First independent assessment of the containment prototype. Median containment of 19 minutes against a single-vendor endpoint integration, at a 4.2% false isolation rate — judged unsuitable for production and directly responsible for the decision to rebuild around an identity graph.

Redline Assurance (2021)

Purple-team engagement across 40 attack chains. Median containment fell to 6 minutes with false isolation under 1% for the first time, confirming that reachability-based decisions were materially more accurate than score-based ones.

Halstead Labs (2022)

First blind adversary emulation. 118 chains run; 104 blocked before objective. Report noted that remaining failures clustered in OT segments where telemetry coverage, not decision quality, was the limiting factor.

Halstead Labs (2023)

Repeat series after OT connector release. 92% of chains blocked before objective and median containment of 3 minutes 40 seconds, with the report specifically calling out the absence of analyst intervention.

Northbridge Cyber Test Range (2024)

Federal-grade range evaluation under FedRAMP scope. Sustained containment performance under a simulated 40,000-endpoint estate with degraded connectivity, validating the air-gapped deployment mode.

These evaluations were conducted under differing methodologies, scopes and threat models, and are historical in nature. They should not be treated as directly comparable to one another or to the February 2026 results, and are presented to show the trajectory of the platform rather than as a current performance guarantee.[4]

The road forward

Phase 1 is complete. Phase 2 is already under way.

Phase 1

Complete
  • Independent blind evaluation — complete.
  • Confirmed containment latency, decision accuracy, false isolation rate and zero-analyst operation across 216 attack chains.
  • Established the auditable-containment commercial thesis.

Phase 2

In progress
  • Extending autonomous containment into operational technology and third-party SaaS estates.
  • Additional Northbridge range results expected in the second half.
  • General availability of the OT connector suite plus an expanded MSSP enablement program.

Phase 2 focuses on extending autonomous containment into operational technology and third-party SaaS estates, where reachability is hardest to compute and where the largest uncovered blast radius now sits. Additional evaluation results from Northbridge are expected in the second half, alongside the general availability of the OT connector suite and an expanded MSSP enablement program.[2]

Strategic context

Regulators stopped asking whether you detect it. They ask how fast you stop it.

Disclosure regimes in the United States, the European Union and Australia now turn on materiality determined within days, not weeks. Cyber insurers have followed, pricing premiums against demonstrated containment capability rather than control inventories.[1]

Sentinel Grid's strategy is to make containment latency a reportable, auditable number that a CISO can put in front of a board, a regulator and an underwriter — turning a security control into a financial instrument.[1]

The company benefits from FedRAMP Moderate authorisation, which shortens procurement in the public sector and in defence-adjacent supply chains. The combination of a defensible accuracy advantage, a clear multi-segment expansion path and growing regulatory urgency around response time positions Meridian as a platform with significant commercial and strategic potential.[1]

Second asset

Vantage — the identity graph, acquired and absorbed.

Vantage Identity Systems built a continuously resolved graph of principals, credentials and entitlements across hybrid estates. It was acquired in 2025 for $46M in cash and stock, and its engine is now the reachability core of Meridian rather than a separately marketed product.[1]

Ownership100% — Vantage Identity Systems Inc.
Consideration$46M cash and stock, closed Aug. 2025
Standalone ARR at close$8.1M
Retained engineering headcount34 of 38
Vantage historical growth71% ARR CAGR, FY2022–FY2025*
Contribution to Meridian NRREst. 14 points in FY2026*

*Vantage Identity Systems Inc., audited financial statements (2025), and management estimate. Pre-acquisition figures relate to the standalone business, not to consolidated Sentinel Grid results.[6]

The graph is what makes autonomous action defensible. Without it, containment decisions are probabilistic scores applied to isolated alerts; with it, they are reachability calculations that can be explained line by line to an auditor after the fact.[1]

Integration is complete across identity, endpoint and cloud connectors, with the OT connector suite in beta across nine manufacturing and utility tenants. Those environments carry the largest uncovered blast radius in the customer base and are the focus of the Phase 2 program.[1]

The team

A platform company, run by people who have done it before.

Priya Raghunathan

CEO & Director

A twenty-two year veteran of incident response and enterprise security leadership. She led the global response practice at a top-tier consultancy, running more than 300 breach engagements across financial services, healthcare and critical infrastructure, before serving as CISO of a Fortune 200 manufacturer. She has testified before legislative committees on disclosure timelines, sits on two national cyber advisory boards, and co-founded Sentinel Grid in 2019 after concluding that the response layer, not the detection layer, was where the industry was losing.

Tomas Bergström, CPA

CFO

Twenty-four years in software finance, including nine as CFO of two venture-backed security companies through Series C and a NASDAQ listing respectively. He has managed SaaS revenue recognition, non-GAAP metric governance and audit readiness across multiple jurisdictions, led three acquisitions from diligence through integration, and has been a member of the American Institute of CPAs since 2003.

Dr. Adaeze Nwosu

CTO & Director

Holds a PhD in distributed systems from Carnegie Mellon and a BSc in Computer Engineering from the University of Lagos. She spent eleven years building large-scale graph infrastructure at a hyperscale cloud provider before founding Vantage Identity Systems, which she led through acquisition in 2025. She holds nine patents in identity resolution and graph reachability.

Responsibly

Autonomous authority over someone else's network is a serious thing to hold.

Sentinel Grid Security Corp. acknowledges that a platform authorised to cut off identities and workloads without human approval carries an obligation beyond the commercial one. Every containment action is reversible, recorded and explainable, and every customer retains the authority to define, narrow or revoke the enforcement paths the platform is permitted to use.[1]

  • Publish independent evaluation results, including the failures
  • Write an immutable decision record before any action completes
  • Keep every containment action reversible by the customer
  • Process telemetry in-region and never sell or train on customer data
  • Maintain a coordinated disclosure program for our own product

The approach is grounded in the principles of least privilege, auditability and customer control — on the belief that autonomous security can only be sustained if the people it protects can see exactly why it acted.[1]

Questions

What investors ask us first.

That across 216 blind attack chains, Meridian contained 212 before objective, with a median time to containment of 89 seconds, more than 99% of containment decisions assessed as correct, and a 0.3% false isolation rate — with no analyst action required in the median case.

The list

Company milestones go to the list before they go anywhere else.

Phase 2 evaluation results, OT connector general availability, quarterly ARR disclosure and corporate developments. No third-party promotions. Unsubscribe any time.

Demonstration page built by Victory Marketing Solutions. Fictional issuer. Not investment advice.

Sources and disclosure

  1. [1]Sentinel Grid Security Corp., corporate presentation and Q4 FY2026 shareholder letter. Fictional issuer created for demonstration purposes.
  2. [2]Meridian Phase 1 independent evaluation, Halstead Labs adversary emulation series, in partnership with the Northbridge Cyber Test Range; results released February 18, 2026.
  3. [3]Legacy platform benchmark set, Halstead Labs (2019–2024). Historical test conditions; not directly comparable to the current evaluation methodology.
  4. [4]Historical evaluation programs: Corwin Group (2019), Redline Assurance (2021), Halstead Labs (2022, 2023), Northbridge Range (2024).
  5. [5]Customer telemetry aggregate, 412 production tenants, twelve months to December 31, 2026; anonymised and normalised.
  6. [6]Vantage Identity Systems Inc., audited financial statements (2025), for the acquired identity-graph business.

Every claim on a Victory landing page is traced to a filing, independent evaluation or named source. This page is a demonstration of that format built around a fictional issuer; the company, product, people and figures do not exist, no securities are offered, and nothing here is investment advice. Operating metrics referenced above are non-GAAP, are illustrative, and would need to be read alongside audited financial statements for any real issuer.