
Sqreen is the application security platform for the modern enterprise
Explore the risks and possibilities with a prompt for ChatGPT, Claude, or your agent.
Sqreen put attack detection and blocking inside production web applications. Founded in Paris in 2015 by former Apple security colleagues Pierre Betouin and Jean-Baptiste Aviat, it joined YC's Winter 2018 batch and was acquired by Datadog on April 12, 2021. Its useful idea survives in Datadog's application security products. [1] [6]
The acquisition connected application-level security with observability: performance traces and service context used to investigate production behavior. Datadog presented the combination as a way to extend its application-performance monitoring into security. [6]
Datadog initially disclosed approximately $260 million in cash and stock, subject to adjustments, with about 25% deferred. Its 2021 annual filing later recorded approximately $219.4 million consideration for the April security-platform acquisition. These are different transaction/accounting descriptions; neither establishes investor returns. [7] [8]
Image 1 / 1
Betouin had spent nine years at Apple, leading security assessments for its Internet Services department. He and Aviat brought offensive-security experience to a product aimed at the people building and operating applications. [1]
The problem was practical. A suspicious network request alone provides limited evidence about what the application actually executed. Sqreen's microagents added information from within the application, connecting requests with code activity and security controls. [17]
Alven recalls meeting a small team in January 2016, with a beta used by fewer than a dozen non-paying customers. Its retrospective also describes Lucas, a former Alven employee, becoming Sqreen's founding sales representative. The company needed commercial learning alongside its technical work. [3]
Betouin said the first two years emphasized product. Before YC, the company had roughly $3 million raised, 15 employees and 100 customers. He treated YC as a way to accelerate US entry, and described establishing a San Francisco office in 2019. The account describes product readiness and deliberate US entry. [2]
Sqreen combined two controls. Runtime application self-protection observes execution inside an application to detect and act on attacks. An in-app web application firewall inspects requests within the application's runtime. Datadog's acquisition account describes following suspicious requests toward code execution and helping responders investigate the cause. [17]
The company sold Application Security Management as a unified production-security platform. Its 2019 announcement describes microagents embedded in applications, rather than a new network appliance. Le Monde's CTO praised the attack insights; Swell Investing's CTO described straightforward integration and rule setup. These are attributed customer testimonials, not independent efficacy measurements. [4]
In 2018, Security Hub introduced configurable security plugins. Reported customers included Front, Mindbody, BlaBlaCar, Triplebyte, Toptal and Algolia. [18]
The architecture creates a tradeoff. Application instrumentation can connect a request to its execution context, but installation, runtime support, policy configuration and performance still matter. A detected attempt is not automatically a successful exploit; a recorded block does not prove every attack was prevented.
The 2021 acquisition announcement described the intended combination. The 2022 launch supplies the later product milestone: distributed tracing used for application-security monitoring, presented within Datadog's platform. Acquisition intent and a shipped integration are separate evidence. [9] [17]
Current AAP extends that account with API discovery, posture and protection. Datadog describes an in-app WAF, IP/user blocking and attack qualification using execution context. Qualification can remain unknown when evidence is insufficient. Blocking depends on compatible tracing libraries and configuration; support must be checked for the actual service. [10] [11]
Sqreen's developer-oriented deployment gave engineering teams a route into production security. That did not eliminate security-team ownership: the original announcement explicitly described collaboration between developers and security teams. [4]
Betouin saw observability vendors extending into security while traditional security vendors consolidated. His account connects that market observation to Datadog's adjacent product philosophy. A larger platform offered a distribution and shared-context route, but public material does not quantify how much standalone growth this displaced. [2]
The present market still includes distinct alternatives:
| Offering | Observed approach | Buyer must check |
|---|---|---|
| Datadog AAP | Application tracing, threat investigation and configured blocking | Runtime support, required Infrastructure Monitoring and billed hosts |
| Contrast Protect | In-runtime monitoring and defensive controls | Specific language/component support and deployment modes |
| Falco | Kernel-system-call events and rule evaluation | Host privileges, event loss, rule maintenance and application-context gaps |
The tools inspect different evidence and require different deployment work. Contrast documents Protect separately by language. Falco documents kernel events and warns that raw system-call arguments cannot easily be correlated with other events. [11] [14] [15] [16]
Sqreen was a SaaS security platform. Its 2019 funding release reported more than 500 protected companies and more than $18 million in funding. YC's later profile says more than 800 organizations trusted the product. Those statements use different dates and definitions; they do not disclose churn, revenue growth or annual contract value. [4] [1]
Standalone audited revenue, gross margin and burn were not established. Financing raised is not a company's sale value or a shareholder payout. Datadog's announced transaction description and later accounting consideration should retain their own labels. [7] [8]
Today's Datadog pricing page lists AAP starting at $31 per host per month, billed annually, or $36 on-demand. It says AAP can be sold separately but requires Infrastructure Monitoring. A comparison must include that prerequisite and the actual billable-host definition; it cannot assume buyers must purchase every observability product. [12]
The strongest causal evidence is Betouin's account: discussions began during Series B fundraising, the product visions were adjacent, and the founders expected to build faster together. This explains the choice they described. It leaves independent runway, rejected financing terms and alternative offers unknown. [2]
Shared application telemetry supplies a plausible mechanism. Engineers can investigate suspicious requests alongside application behavior, and an existing instrumentation footprint can reduce a separate deployment task. Datadog's later ASM launch supports the integration direction. It does not measure sales savings, switching costs or the counterfactual outcome had Sqreen stayed independent. [9]
Sqreen's standalone chapter ended with acquisition; application-security work continued inside Datadog. The current product's tracing-library prerequisites and explicit unknown attack qualifications show why the outcome is more than a checkbox. Instrumentation, evidence coverage and review still constrain useful protection. [11]
For a rebuild, the relevant opening is a testable workflow problem: helping a team establish which services are covered, what an event proves, and whether a narrowly scoped policy is safe to enforce. A new vendor must compare that job with current Datadog, Contrast and Falco workflows. A cheaper interface or a kernel probe alone does not establish better protection or demand.