[MDR 7] Red Canary Under Zscaler: When Your Zero Trust Vendor Owns Your SOC

Red Canary was the reference implementation of vendor-neutral managed detection until Zscaler bought it in August 2025. That transaction turns a straightforward evaluation into a question about what happens when your zero trust enforcement vendor also holds your detection contract.


Red Canary was the reference implementation of vendor-neutral managed detection. It works with whichever endpoint tool you already chose, publishes its detection logic as code, and puts a human analyst in front of every alert before anything reaches you. In August 2025 Zscaler bought it. That transaction is the most interesting thing about this profile, because it turns a straightforward evaluation into a question about what happens when your zero trust enforcement vendor also holds your detection contract.

The service itself remains the strongest expression of the operate-your-stack model at scale. It consumes signal from nine endpoint platforms, including Defender for Endpoint alongside CrowdStrike, SentinelOne and others, plus its own Linux sensor. Their Microsoft coverage claims the full Defender breadth: endpoint, identity, cloud apps, Office and Entra ID Protection. Detection content is written and versioned as code and mapped to a common adversary framework, which makes it inspectable in a way that most competitors’ detection logic is not.


Authority you buy separately and scope explicitly

The response model is two-tier and unusually legible. The base service contains threats through automated playbooks that call Defender’s live response capability once a threat is confirmed. That is containment, driven by automation, within what your integration permits.

Hands-on-keyboard remediation is a separate annual purchase. When you buy it, you designate remediation groups: specific collections of endpoints that their response engineers are permitted to work on, and you grant access to your Defender console for that purpose. On a confirmed threat inside a designated group, orchestration isolates the host immediately while their engineers carry out the remediation.

I like this design. Authority is not assumed by default and it is not a single yes or no at contract signature. It is bought deliberately, scoped to a named set of machines, and expandable as trust develops. An organisation can start with a pilot group, watch how the engineers work, and widen the scope on evidence. That is how I would want to introduce an external party to my production estate, and very few providers structure it that way.

There is no published service level. Operations run from a single confirmed centre in Denver with no documented follow-the-sun model, which is worth raising if your business spans time zones or your risk appetite requires geographic redundancy in the people rather than just the platform.


The acquisition, stated fairly

Zscaler announced the deal in May 2025 and closed it on the first of August for approximately six hundred and seventy five million dollars, against annual recurring revenue of roughly a hundred and forty million. The stated strategic logic was to build an agentic security operations capability on top of Zscaler’s data platform, with Red Canary providing the human layer and the operational maturity. The unit was to operate separately at first.

Two quarters later, on the February 2026 earnings call, Zscaler’s chief financial officer said on the record that post-acquisition churn at Red Canary had been elevated, and characterised the transaction as primarily a technology and talent acquisition. Forward revenue guidance for the unit was raised to around a hundred and thirty million. Independent commentary has tracked declining mindshare, and Forrester has publicly flagged that the vendor-neutral positioning may erode under platform ownership.

A technology and talent acquisition is a different thing from a customer acquisition, and the difference shows up at renewal rather than at signature.

I am not going to tell you that means avoid them. Acquisitions of good businesses often go well, the operational capability that made the service worth buying is still there, and elevated churn immediately after a deal is common and sometimes recovers. What I will say is that vendor neutrality is now a claim about a business owned by a vendor with a competing architectural interest, and that is a question to put directly to them during diligence rather than to assume away because the documentation still says agnostic.


The AI demonstration, and where the licence boundary sits

This deserves its own section because it is the capability people come away from a demonstration most impressed by, and because the impression is architecturally misleading if you do not know where the boundary falls.

Blocking users from unapproved generative AI tools, inspecting what they type into approved ones, applying data loss controls to prompts, isolating risky access in a remote browser: all of that is real, it works, and it is the strongest answer to the shadow AI problem among the providers in this series. It is also, without exception, Zscaler platform capability. It runs inline on the network path through their secure access platform. It is not managed detection and response, and it does not arrive because you bought the detection service.

So the architectural answer to whether the AI control requires platform licensing on top of the managed service is yes. Whether Zscaler chooses to bundle or discount the two together in a given deal is a commercial matter that lives in your contract and nowhere I can verify. The correct question in the room, after the demonstration, is which line items produce what you just watched. A demonstration showed you the platform. The detection contract buys you the operators.

On AI inside their own operations, the claim is specific and has mechanism behind it: investigation agents trained on a decade of accumulated investigation data, augmenting rather than replacing tier two analysis, with a human reviewing every alert before it reaches the customer. That passes the test I apply throughout this series.


Cost shape and overlap

Pricing is resource-based, billed across endpoints, identities and cloud resources, which their own material confirms as a model without publishing the figures. Reported numbers put the entry tier around a hundred and twenty dollars per endpoint plus a hundred per user plus two hundred and fifty per cloud resource annually, with higher tiers above. Treat those as directional. The structural point worth noting is that identity coverage is metered per user separately, so an organisation with more people than machines should model it carefully rather than reasoning from an endpoint count.

On telemetry there is minimal duplication, since they ride the Defender stack you already own. The overlap arrives if the platform side comes with it, because their secure access products cover the same ground as Entra’s own internet and private access capabilities. That is a comparison the Global Secure Access series on this site handles properly and I am not going to relitigate it here. The point for this profile is simply that the overlap risk in this engagement lives at the network layer rather than the endpoint one, which is the reverse of most providers in this series.


Concentration or coherence

The framing question for this provider is not whether the service is good. On the evidence it is: mature detection engineering, granular scoped authority, real analyst rigour, and a genuinely strong answer on AI governance if you take the platform with it.

The question is whether you want one vendor holding both your network enforcement path and your detection and response contract. There is a real case for yes. Signal from the network path and signal from the endpoint arriving in one analytical system, operated by people who see both, is a coherence argument that a stitched-together arrangement cannot match. There is an equally real case for no, which is that concentration of that kind removes your ability to change one without disturbing the other, and does so at the exact layer where you would least like to be locked in.

That is a decision about your architecture and your appetite for supplier concentration, not a decision about detection quality. Make it deliberately, and make it knowing that the vendor-neutral positioning this business was built on is now a matter of corporate policy rather than corporate structure.


MDR
‹ Previous: [MDR 6] Expel: Authority With Guardrails
Next: [MDR 8] Critical Start: The Only Service Level With a Clock and a Remedy