Startup Diligence
Diligence report cybersecurity Series E 2026-06-23

Aviatrix

Multicloud cloud-network-security platform with strong product fit but heavy valuation and execution uncertainty

Aviatrix has credible multicloud security technology and real enterprise proof points, but opaque financials, a difficult competitive landscape, and a sharp gap between its 2021 primary valuation and 2026 secondary signal keep the stock in track-not-buy territory.

Cover facts

2021 Primary Valuation 01
2000 USD M [CV001]
2026 Secondary Implied EV 02
411 USD M [CV009]
Total Raised 03
346 USD M [CV004]
ARR (2024 est.) 04
64 USD M [CI001]

Company profile

Aviatrix is a private Santa Clara-based cloud network security company founded in 2014 that evolved from multicloud networking into a Cloud Native Security Fabric platform spanning distributed firewalling, multicloud transit, workload-level zero trust, and emerging AI-runtime controls. Public evidence supports meaningful enterprise adoption—500+ customers, named reference accounts, and repeated Deloitte Fast 500 recognition—but not current profitability, NRR, or current-period revenue disclosure. The company remains strategically relevant because multicloud enforcement is hard, yet its private-market story now sits between a verified 2021 $2B Series E anchor and a much lower, thin-liquidity 2026 secondary signal.

Website
aviatrix.com
Founded
2014-01-01
Founding location
Santa Clara, California, USA
Headquarters
Santa Clara, California, USA
Product
Cloud Native Security Fabric providing multicloud networking, distributed cloud firewalling, workload segmentation, zero-trust enforcement, and AI-related runtime security controls across AWS, Azure, GCP, Kubernetes, and hybrid environments.
Customers
Large enterprises and regulated organizations operating complex multicloud and hybrid-cloud environments.
Business model
Enterprise subscription software with custom-priced tiers, implementation services, training, and channel-assisted deployment.
Stage
Series E (private)
Funding status
Raised a $200M Series E in September 2021 at a $2B post-money valuation; public aggregators place total primary funding around $346M, with no new primary round announced through June 2026.
[CO001, CO004, CO007, CO008, CO010, CU001, CV030]

Executive summary

Top strengths

  • Aviatrix addresses a real multicloud security problem with a differentiated workload-level enforcement architecture instead of central chokepoint firewalls.
  • Public customer proof is better than many private security peers: the company claims 500+ enterprises, roughly 10% of the Fortune 500, and several named reference accounts.
  • Third-party ARR estimates imply rapid 2023-2024 growth, and the company has sustained strong market visibility through CNSF, Microsoft, Wiz, and Deloitte recognition.

Top risks

  • Hyperscaler-native networking and firewall products from AWS, Azure, and Google increasingly compress Aviatrix's original transit-networking wedge.
  • Aviatrix has not publicly disclosed current ARR, gross margin, NRR, burn, or current headcount, making quality-of-revenue and durability impossible to verify from public data.
  • The 2021 $2B Series E anchor appears difficult to defend against 2026 secondary-market and comparable-multiple evidence, raising recapitalization or down-round risk.

Open gaps

  • Current ARR, revenue, gross margin, and burn remain undisclosed; public numbers are third-party estimates rather than company filings.
  • Net revenue retention, gross revenue retention, churn, and customer concentration are not publicly available.
  • Cap-table details, liquidation preferences, and the extent of any secondary transactions after Series E are not public.

Contents

Chapter 01

01Company Overview

1.1 Company Identity and Product Focus

Aviatrix Systems, Inc.—marketed as Aviatrix®—is a cloud network security company headquartered at 2901 Tasman Drive, Santa Clara, California 95054. The name "Aviatrix," meaning "female pilot," honors the company's female founder and its spirit of innovation in the cloud era. Founded in 2014, Aviatrix initially developed a cloud networking abstraction layer offering multicloud connectivity and advanced routing across AWS, Azure, Google Cloud, and Oracle Cloud. By 2024–2026, management repositioned the company around the Cloud Native Security Fabric (CNSF)—an embedded enforcement platform that governs workload-to-workload communication at the network layer rather than at a central perimeter chokepoint. The company describes this architectural distinction as "containment architecture" versus legacy "chokepoint security," arguing that 92% of organizations running multi-cloud environments require enforcement at each workload, not at a shared transit firewall. Aviatrix's current flagship offering, the Cloud Native Security Fabric, unifies cloud networking and security across public clouds and Kubernetes environments. Key products include the Distributed Cloud Firewall (DCF, launched 2023), Agentguard for AI workload protection, and a June 2026 Microsoft Agent Control Specification integration enabling single-policy-file governance of AI agents across AWS, Azure, Google Cloud, and on-premises Kubernetes. The company also operates the Aviatrix Certified Engineer (ACE) program, described as the industry's leading multicloud networking and security certification. As of June 2026, Aviatrix operates a Threat Research Center including an interactive Cloud Threat Command Center, and is actively positioning itself in the agentic AI security category through its "Containment Era" thought-leadership series. Revenue and pricing remain private. The Snapshot KPI table and Summary KPI figure that follow summarize the key cover metrics; the Company Snapshot flow shows how identity, product, customers, and capital connect. [CO001, CO002, CO003, CO004, CO026, CO034]

Snapshot KPI table
MetricValue / StatusDate / PeriodConfidenceEvidence Gap or Caveat
HeadquartersSanta Clara, CA (2901 Tasman Dr.)CurrentHighNone
Founded2014HistoricalMediumExact founding date not confirmed in fetched sources
StageSeries E (last round)Sept 2021HighNo round announced since 2021
Last Valuation$2 billionSept 2021HighPost-2021 valuation unknown; no secondary market data
Total Raised (est.)~$340M+ (estimated)Cumulative to 2021LowNot confirmed from primary sources; analyst estimate only
Customer Count500+ enterprises2025–2026HighExact count undisclosed; company-stated figure
Fortune 500 Penetration~10%2024–2025MediumCompany claim; no independent verification found
Employee Count~350 (2023 estimate)Mid-2023LowNo 2024/2026 headcount disclosed
ARR / RevenueNot disclosedPrivate company; no public filing
CEODoug MerrittJuly 2023 – presentHighNone
Last Major Product LaunchMicrosoft ACS IntegrationJune 4, 2026HighNone
Primary Investor (Series E)TCV (Technology Crossover Ventures)Sept 2021HighTCV page returned 404; confirmed via CRN/press

Revenue, ARR, headcount beyond mid-2023, and post-2021 valuation are private and not confirmed from fetched sources. Estimated total raised (~$340M+) is based on analyst context and has not been independently verified. The Fortune 500 penetration and customer count figures are company-stated. Date fields reflect the most recent period for which evidence was found.

[CO001, CO002, CO007, CO008, CO005, CO006]
FO003: Snapshot KPIs

Aviatrix ecosystem and scale signals as of June 2026: developer presence, certification reach, media coverage, and multi-cloud product breadth.

Total raised is an industry estimate not confirmed from primary sources. Headcount is stale (mid-2023). Revenue and ARR are not available for private companies absent voluntary disclosure.

[CO020, CO021, CO033, CO038, CO031]

1.2 Leadership, Founders, and Governance

Aviatrix's founding story centers on a female entrepreneur whose vision is embedded in the company name. The company's About page explicitly states the name honors "our female founder," but no fetched public source names the founder directly. Prior industry context names Sherry Wei as co-founder, consistent with the About page narrative, but this was not independently verified from fetched sources and is carried as an evidence gap. Steve Mullaney—former CEO of Nicira (acquired by VMware in 2012) and a Palo Alto Networks executive—joined Aviatrix as CEO in 2019, four years before the leadership transition. Mullaney described his own leadership sweet spot as the $1M–$100M growth stage and acknowledged that Doug Merritt's skills were better suited for the $100M–$1B stage, facilitating an organized CEO succession effective July 6, 2023. Mullaney's tenure coincided with the company's Series E funding at a $2 billion valuation and the launch of the Distributed Cloud Firewall product. Doug Merritt became CEO and President of Aviatrix in July 2023, following his six-year tenure as CEO of Splunk (2015–2021) during which Splunk's ARR grew from approximately $100 million to nearly $3 billion. Since joining Aviatrix, Merritt has undertaken an aggressive bench- building initiative, recruiting executives with deep cybersecurity and cloud credentials from Cloudflare (CRO Ken Horner), Google (VP Engineering Murali Damisetti), Cisco (Chief Network Architect Satish Mahadevan), Walmart (Chief Architect Georgi Khomeriki), and SAP (CMO Scott Leatherman). Chris McHenry serves as Chief Product Officer, as confirmed in the June 2026 Microsoft ACS announcement. Nick Sturiale, Managing Partner of Ignition Partners (an early investor), holds a board seat. Key-person dependency on Merritt is assessed as high: he owns strategic vision, GTM, and product roadmap transformation, and his exit would create substantial leadership discontinuity. Board composition and governance rights for other investors remain opaque due to the company's private status. [CO003, CO010, CO011, CO012, CO013, CO014]

Leadership and founder table
PersonRolePrior OrganizationAviatrix TenureKey-Person Dependency
Sherry WeiCo-FounderNot publicly confirmed in fetched sources2014 – present (estimated)High – founding vision and female-founder brand identity
Doug MerrittCEO & PresidentSplunk (CEO 2015–2021), Cisco, BaynoteJuly 2023 – presentHigh – strategic vision, GTM, product roadmap
Ken HornerCROCloudflare, Flexera, Splunk, HP, Cisco2025 – presentMedium – revenue leadership
Scott LeathermanCMOVeritone, Interana (acq. Twitter), SAP2025 – presentMedium – marketing and pipeline
Chris McHenryCPONot confirmed in fetched sources2024 – present (est.)Medium – product direction
Varsha VigCHROPaxos, Blink Health, Compass, Lyft, McDonald'sMay 2024 – presentLow – HR and culture
Georgi KhomerikiChief Architect, EngineeringWalmartMay 2024 – presentMedium – engineering architecture
Satish MahadevanChief Network ArchitectCisco (20 yrs)May 2024 – presentMedium – product architecture
John JendricksCIONot confirmed in fetched sources2024 – present (est.)Low – internal operations
Steve MullaneyFormer CEO (departed)Nicira/VMware, Palo Alto Networks2019 – July 2023Exited – historical key person
Nick SturialeBoard Member (Ignition Partners)Ignition Partners (Managing Partner)Early-stage – presentMedium – investor oversight

Tenure dates marked "est." are inferred from press release publication dates, not directly confirmed. Sherry Wei as co-founder is provided as commissioning context; no fetched source explicitly names her. Key-person dependency ratings are qualitative assessments based on role scope and strategic centrality.

[CO003, CO010, CO011, CO012, CO013, CO015]

1.3 Funding, Valuation, and Capital Stack

Aviatrix's most recent and largest financing round was a $200 million Series E closed in September 2021, led by TCV (Technology Crossover Ventures), at a $2 billion post-money valuation—achieving unicorn status. The CRN coverage of the 2023 CEO transition explicitly confirms TCV's lead role. Earlier rounds included at minimum a Series B and Series C; Ignition Partners participated in earlier rounds, as evidenced by founding-era board member Nick Sturiale (Ignition Managing Partner) featured on the company's About page. Cumulative capital raised is commonly cited as approximately $340 million in analyst and media accounts, but this figure was not independently confirmed from a primary source during this research run and is carried as an evidence gap. No new financing round or IPO announcement has been publicly made since the 2021 Series E as of the research date of June 23, 2026. The company remains private with no public financial disclosures. TCV's investor page for Aviatrix returned a 404 during fetching, and TechCrunch's original Series E coverage was also unavailable, reducing independent corroboration. Any updated valuation—whether through secondary transactions, down-round exposure, or new fundraising—is unknown. Diligence must independently obtain the capitalization table, confirm investor rights (including liquidation preferences, pro-rata, and anti-dilution provisions), identify any debt facilities, and determine whether secondary transactions occurred between 2021 and the present. The Stakeholder/Investor Map table that follows enumerates known economic stakeholders and outstanding diligence asks. [CO007, CO008, CO009, CO019, CO030]

Stakeholder or investor map
StakeholderTypeEconomic / Control ImportanceDiligence Ask
TCV (Technology Crossover Ventures)Lead institutional investor (Series E)Led $200M Series E at $2B valuation (Sept 2021); likely holds significant equity and board rightsConfirm board seat, ownership stake, liquidation preferences, and anti-dilution provisions
Ignition Partners (Nick Sturiale)Early-stage institutional investor / board memberBoard seat confirmed on About page; participated in pre-Series E roundsConfirm ownership stake, governance rights, and pro-rata participation in Series E
Doug MerrittCEO & President / equity holderPrimary executive decision-maker; likely holds meaningful options or equity grantConfirm equity structure, vesting schedule, and acceleration provisions
Sherry WeiCo-Founder / equity holder (unconfirmed)Founding-team equity holder if still employed or retained post-transitionConfirm current involvement, equity position, and any transfer or vesting events
Pre-Series E investors (Series A/B/C)Earlier venture investors (identities unconfirmed)Participated in earlier rounds; ownership likely diluted by Series EIdentify all earlier institutional investors; confirm any liquidation preferences stacking
Steve MullaneyFormer CEO (departed July 2023)Equity holder from CEO tenure; may retain vested sharesConfirm equity treatment and lockup on departure; any ongoing governance rights
MicrosoftStrategic technology partnerDeep integration via ACS partnership and Microsoft Security Store listing; ecosystem leverageConfirm partnership agreement scope, exclusivity or non-exclusivity, and revenue-sharing terms
AWSCloud marketplace partnerAWS Marketplace listing confirmed; distribution channelConfirm marketplace tier, incentive payments, and co-sell agreement status
Other potential Series D investorsUnknownA possible Series D was not confirmed in any fetched sourceIndependently confirm full funding history and cap table with company

The pre-Series E investor list is incomplete; only Ignition Partners was confirmed. TCV investor page returned 404. Full cap table, liquidation preferences, and board composition must be confirmed through primary company diligence.

[CO007, CO008, CO009, CO019, CO030]

1.4 Scale Metrics and Market Presence

Aviatrix publicly claims 500+ enterprise customers globally as of 2025–2026, with the customer base reportedly including approximately 10% of the Fortune 500. Named reference customers visible on the company's customers page include Anheuser-Busch InBev, IHG Hotels and Resorts, Republic Airways, and Better (a financial services firm), spanning financial services, hospitality, transportation, and manufacturing verticals. The company targets large enterprises managing multicloud infrastructure—primarily cloud security teams, cloud architects, network engineering teams, and FinOps practitioners—in regulated industries. Its ACE certification program reinforces practitioner loyalty and positions Aviatrix as an educational standard in multicloud networking. The most recent publicly disclosed employee count was approximately 350 as of mid-2023 during the CEO transition. No updated 2024 or 2026 headcount figure was available from fetched sources; the company operates a remote-first culture globally. The GitHub organization AviatrixSystems maintained 39+ public repositories as of June 2026—including active Terraform providers, ACE lab guides, Kubernetes firewall charts, and a Splunk integration—indicating a substantial developer and partner ecosystem. Revenue, ARR, gross margin, NRR, and burn rate remain undisclosed. Aviatrix operates on a subscription software model with professional services; exact pricing is private. The Company Snapshot flow figure below visualizes how identity, product, customers, capital, and ecosystem dependencies connect structurally. [CO005, CO006, CO020, CO021, CO029, CO031]

FO002: Company Snapshot Logic Flow

Structural map showing how Aviatrix's identity, product, customers, capital, and ecosystem dependencies connect as of June 2026.

[CO001, CO004, CO005, CO007, CO008, CO021]

1.5 Milestones and Strategic Evolution

Aviatrix's strategic evolution tracks three distinct phases. Phase One (2014–2019) was the founding and early product phase, establishing the company's multicloud networking abstraction layer. Phase Two (2019–2023), under Steve Mullaney, drove rapid scale to unicorn status through the 2021 Series E and initial positioning as the "cloud networking expert." The 2023 Distributed Cloud Firewall launch marked the beginning of a security pivot. Phase Three (2023–present), under Doug Merritt, executes a deliberate repositioning from networking to a security-first platform—the Cloud Native Security Fabric—aligned with the "Containment Era" thesis that prevention and detection are insufficient and containment at the workload level is the necessary architectural answer. A materially adverse data point shapes this pivot narrative: a July 2025 BankInfoSecurity interview with Merritt reveals that customers were already choosing Aviatrix primarily for security capabilities, not networking. This suggests the pivot was reactive to customer revelation rather than proactive category creation—a distinction with important implications for Aviatrix's competitive moat and category ownership. The June 2026 Microsoft Agent Control Specification integration, Microsoft Security Store partnership, and OISF membership demonstrate sustained partnering momentum. The Milestone table and Company Timeline figure below provide a full chronological record of financing, product, governance, and partnership events; milestone items without independent confirmation are noted with evidence gaps. [CO007, CO008, CO022, CO023, CO024, CO025]

Milestone table
DateEventTypeAmount / Valuation / StatusParticipantsStrategic Implication
2014Aviatrix founded in Santa Clara, CAfoundingSherry Wei + founding team (unconfirmed)Establishes multicloud networking abstraction layer; founding team-market fit in enterprise cloud
2019Steve Mullaney joins as CEOgovernanceSteve MullaneyFormer Nicira/VMware CEO brings growth-stage experience; accelerates enterprise sales motion
2021-09Series E financing closes at $2B valuationfinancing$200M at $2B post-moneyTCV (lead) + existing investorsAchieves unicorn status; validates multicloud networking as enterprise infrastructure category
2023-06Distributed Cloud Firewall (DCF) launchedproductAviatrixMarks first formal security product; DCF wins Cybersecurity Excellence Award; signals security pivot beginning
2023-07-06CEO transition: Mullaney exits; Merritt appointed CEO/PresidentgovernanceSteve Mullaney → Doug MerrittMaterial key-person change; Merritt brings Splunk scale-up track record; headcount ~350 at transition
2023CRN names Aviatrix one of 10 Hottest Cloud Computing Startups of 2023scaleCRNIndependent third-party validation of competitive position at a critical growth inflection
2023-2024Named to inaugural Fortune Cyber 60 listscaleFortune magazineRecognition as top private cybersecurity company; brand building in security category
2024-05-15New executive leadership team announced (CMO, CHRO, CRO, multiple VPs)governanceDoug Merritt + new hires from Cloudflare, Venafi, PaxosBench-building for next growth phase; signals intent to scale GTM and customer success aggressively
2024Cloud Native Security Fabric (CNSF) positioned as primary brand/platformproductAviatrixFormal repositioning from networking to security; 'Containment Architecture' thesis introduced
2025Named first cloud network security company in Microsoft Security StorepartnershipMicrosoft + AviatrixDeepens Microsoft ecosystem integration; potential enterprise distribution upside via M365 security buyers
2025Named one of 20 Coolest Network Security Companies of 2025 by CRNscaleCRNSustained analyst recognition post-pivot; validates market acceptance of new positioning
2025-07-14BankInfoSecurity reports Aviatrix pivot driven by customer security demand, not proactive category creationadverseISMG/BankInfoSecurity, Doug Merritt interviewAdverse signal: pivot was reactive; raises questions about whether Aviatrix is creating a category or chasing demand
2026-06-04Microsoft Agent Control Specification integration announced at Microsoft Build 2026productMicrosoft + AviatrixPositions Aviatrix in agentic AI security; enforces AI agent policy at the network layer across AWS/Azure/GCP
2026-06Aviatrix joins Open Information Security Foundation (OISF)partnershipOISFStrengthens open-source threat detection credibility; signals community-first security positioning

Events marked "—" for Amount/Valuation indicate no financial figure was disclosed. Pre-2019 milestones are underrepresented due to limited accessible historical sources; evidence gap EG005 covers this. The OISF membership (June 2026) was confirmed via newsroom listing but the individual press release URL returned 404.

[CO007, CO008, CO009, CO010, CO012, CO022]
FO001: Aviatrix Company Milestone Timeline

Chronological milestones across Aviatrix's founding, financing, product, governance, and partnership history from 2014 to June 2026.

Pre-2021 founding-phase milestone dates are approximate; exact month/day of 2014 founding and earlier financing rounds are not confirmed from available fetched sources.

[CO002, CO007, CO008, CO009, CO010, CO012]

1.6 Exhibits

Chapter 02

02Market Analysis

2.1 Market Boundary, Included Spend, and Status-Quo Substitutes

Aviatrix competes at the intersection of multi-cloud networking infrastructure and cloud-native security enforcement, a category that does not map cleanly onto any single analyst definition. Included spend encompasses workload-to-workload traffic enforcement across multi-cloud and hybrid-cloud environments (east-west and north-south flows), distributed cloud firewall policy management, multi-cloud network visibility and analytics, zero trust network access (ZTNA) for both user-to-application and workload-to-workload traffic, cloud networking operations tooling including transit gateways and route management, and Kubernetes network security policy enforcement. Excluded spend includes endpoint detection and response (EDR), email security gateways, SIEM/SOAR platforms, single-cloud native controls (AWS Security Groups, Azure NSGs) used in isolation without cross-cloud policy, physical network appliances, and data loss prevention tooling unrelated to network enforcement. Status-quo substitutes include cloud-native networking and firewall services from hyperscalers (AWS Network Firewall, Azure Firewall, Google Cloud Firewall), traditional network security vendors extending to cloud (Palo Alto Prisma, Cisco Multicloud Defense), SASE platforms with competing cloud networking capabilities (Zscaler, Netskope, Cloudflare One), and in-house custom multi-cloud networking built on open-source transit or routing tools. The market sits at the structural convergence of cloud security — estimated at USD 34.37 billion in 2026 by MarketsandMarkets and USD 35.84 billion in 2024 by Grand View Research — and the broader enterprise network security category projected at USD 84.50 billion in 2025 (MarketsandMarkets). Defining the boundary precisely before any sizing exercise is essential: Aviatrix's value proposition spans both categories but does not capture the full spend of either.[CM001, CM002, CM005, CM009, CM012, CM026]

Market definition table
Segment / categoryIncluded spendExcluded spendBuyer / payerRelevance
Cloud network security enforcementDistributed cloud firewalls, workload-to-workload policy, network segmentation, east-west traffic enforcement, Kubernetes network policiesEndpoint security, SIEM, SaaS email security, single-cloud native controls used in isolationCloud security team, cloud architects, CISO; IT security or cloud infrastructure budgetCore product layer for Aviatrix CNSF and Distributed Cloud Firewall
Multi-cloud networking infrastructureTransit gateways, cloud routing, SD-WAN for cloud, multi-cloud connectivity orchestration, visibility toolingPhysical WAN/LAN equipment, on-premises switching/routingCloud architects, network engineers; infrastructure platform budgetCore infrastructure layer aligned to Aviatrix's networking heritage
Zero Trust Network Access (ZTNA)Application-layer access enforcement, identity-based east-west/north-south access, ZTNA overlay for workloadsPure IdP/SSO software, endpoint agents in isolation, identity management unrelated to network enforcementCISO, network security team; security budgetAdjacent security layer; part of SASE/SSE spend partially overlapping Aviatrix's posture
SASE / Secure Access Service EdgeSD-WAN plus SSE convergence layer, FWaaS, CASB, SWG where network and security convergePure email security, pure endpoint DLP, non-network security spendCISO, network, cloud teams; converged network and security budgetBroader category into which Aviatrix competes for convergence-platform budget
Cloud-native application security (adjacent)CNAPP, CWPP, CSPM when the policy surface overlaps with network enforcementSAST, DAST, code scanning, code repositories, non-network layersDevSecOps, cloud security; engineering security budgetAdjacency where Aviatrix's CNSF intersects with cloud workload security platforms

Boundary definitions differ across analyst firms; MnM and GVR include different sub-categories under cloud security, contributing to the 30%+ scope discrepancy noted in the sizing section. Status-quo substitutes (hyperscaler-native tools, SASE incumbents) are excluded from included spend because they represent buyer alternatives, not the spend Aviatrix is capturing.

[CM001, CM005, CM009, CM012, CM026, CM035]

2.2 Multiple Sizing Lenses — TAM Context and the Convergence Layer

No single analyst estimate cleanly represents Aviatrix's serviceable addressable market because the company straddles multiple adjacent categories. The broadest proxy is the global cloud security market: MarketsandMarkets pegs it at USD 34.37 billion in 2026 growing to USD 59.34 billion by 2031 at 11.5% CAGR, while Grand View Research estimates USD 35.84 billion in 2024 growing to USD 75.26 billion by 2030 at 13.3% CAGR. These figures are not directly comparable — GVR's 2024 baseline of USD 35.84 billion already exceeds MnM's 2026 estimate of USD 34.37 billion, implying scope differences of more than 30% at roughly the same horizon when GVR's trajectory is extrapolated forward. The broader network security market provides outer-bound context at USD 84.50 billion in 2025 (MnM). For Aviatrix's specific convergence of cloud networking and security, the SASE market (USD 19.19 billion in 2026 growing to USD 68.06 billion by 2030 at 28.8% CAGR) and the narrower multi-cloud networking segment (USD 7.6 billion by 2027 at 22.5% CAGR) are more proximate sizing references. The Zero Trust Security market (USD 78.7 billion by 2029 at 16.6% CAGR) and Zero Trust Architecture segment (USD 38.5 billion by 2028 at 17.3% CAGR) provide demand-side context for the security posture shift driving cloud networking adoption. Within cloud security, the CNAPP segment shows the highest sub-category CAGR at 14.6% through 2031 (MnM), mirroring Aviatrix's CNSF thesis that workload-level enforcement is the next architecture generation. No analyst firm publishes a standalone report for a distributed cloud firewall or cloud network security enforcement market that directly matches Aviatrix's precise product boundary; a company-specific SAM must be estimated bottom-up from the SASE intersection and the multi-cloud networking layer.[CM001, CM002, CM003, CM005, CM008, CM009]

TAM/SAM/SOM or sizing lens table
PublisherYearGeographyValueCAGRMethodologyConfidenceLimitation
MarketsandMarkets2026-2031GlobalUSD 34.37B (2026) → USD 59.34B (2031)11.5%Secondary research, expert interviews; includes CNAPP, CASB, analyticsmediumBroad cloud security scope; scope differs from GVR by 30%+ at the same horizon
Grand View Research2024-2030GlobalUSD 35.84B (2024) → USD 75.26B (2030)13.3%Analyst market research; includes diverse cloud security sub-segmentsmedium2024 baseline higher than MnM 2026 estimate; definitional scope not disclosed; accessed via web archive
MarketsandMarkets2025-2030GlobalUSD 84.50B (2025) → USD 119.70B (2030)7.2%Analyst forecast of broader network security (firewalls, UTM, NAC, NDR)mediumIncludes on-premises network security; much broader than cloud security alone; outer-bound reference
MarketsandMarkets2026-2030GlobalUSD 19.19B (2026) → USD 68.06B (2030)28.8%Analyst forecast of SASE market; includes SD-WAN and SSE (ZTNA, CASB, SWG, FWaaS)mediumIncludes SD-WAN component; partially overlaps Aviatrix's product scope; most proximate convergence lens
MarketsandMarkets2024-2029Globalto USD 78.7B by 202916.6%Zero Trust Security broad market forecast covering ZTA, ZTNA, microsegmentationmediumCovers ZT broadly including identity; not network-layer specific; demand-side signal only
MarketsandMarkets2022-2027Globalto USD 7.6B by 202722.5%Multi-cloud networking market forecast (September 2022 vintage)lowNarrowest proxy for Aviatrix's networking layer; predates Aviatrix's 2023 security pivot; may underweight security enforcement premium

These lenses must not be averaged. The GVR vs. MnM cloud security discrepancy (~30% scope difference extrapolated to 2026) likely reflects whether SASE is included inside or outside cloud security definitions. Aviatrix's SAM sits below all headline TAM figures because no estimate isolates the distributed cloud firewall plus multicloud networking enforcement segment.

[CM001, CM002, CM005, CM009, CM010, CM011]
FM001: Market sizing lens

Three nested market lenses from broadest (cloud security TAM) to most specific (multi-cloud networking), each in the same USD billion unit at the stated base year. These are not directly additive or comparable; they represent different boundary assumptions for Aviatrix's opportunity context.

Cloud security and SASE figures are from the same 2026 calendar year. Multi-cloud networking is the 2027 projected endpoint. These three lenses cannot be stacked or summed; they are distinct market segment estimates with different scope boundaries.

[CM001, CM004, CM005, CM012, CM026]
FM002: Market estimate range

Low-to-high range for four key market estimates relevant to Aviatrix's TAM context, all in USD billions at either a base year or a projected endpoint. Items are not comparable across rows; each reflects a different market scope and time horizon.

All items use USD billions but cover different years, scopes, and methodologies. The MnM cloud security 2026 base and GVR cloud security 2024 base imply a ~30% scope discrepancy when extrapolated to the same horizon; this should not be interpreted as a range of uncertainty for the same definition but as two distinct category boundaries.

[CM001, CM002, CM005, CM009, CM012, CM013]

2.3 Buyer, User, and Payer Segmentation with Adoption Path

Aviatrix's addressable buyer population sits within enterprises that operate multi-cloud infrastructure and require centralized, programmable enforcement of network security policy. Three primary buyer types are evidenced from public sources. First are large enterprises (10,000+ employees) operating across two or more hyperscalers, primarily in financial services, healthcare, and government — segments that Grand View Research identifies as the highest-spend cloud security verticals. Large enterprises account for more than 74% of cloud security market revenue in 2024 (GVR). In these organizations, cloud security teams and cloud architects are the champion users, and budget authority typically resides at the CISO, VP of Cloud Infrastructure, or Chief Network Architect level. Second are mid-market organizations undergoing active cloud migration, where platform engineering and FinOps teams own the tool evaluation; Flexera's finding that managing cloud spending is the top challenge two consecutive years is a deal-friction signal for this segment, with over 29% of organizations spending more than USD 12 million annually on public cloud. Third are U.S. federal agencies and regulated-sector organizations compelled by OMB M-22-09 to adopt zero trust architecture by defined deadlines. More than two-thirds of organizations surveyed in a 2024 TechTarget Enterprise Strategy Group report stated they are implementing zero trust policies (IBM citing ESG 2024). The adoption path in all segments follows: multi-cloud deployment onset, followed by policy fragmentation pain (IP exhaustion, Azure NAT gateway changes), then active evaluation and proof-of-concept, followed by enterprise-wide deployment with expanding use cases. Aviatrix's CMO cited IP exhaustion, Azure NAT gateway policy changes, and infrastructure modernization as primary adoption triggers in a February 2025 press release, consistent with the company's reported 500+ enterprise customer base including 10% of the Fortune 500.[CM006, CM014, CM015, CM016, CM021, CM022]

Segment / buyer map
SegmentBuyerUserPayerWorkflowBudget ownerAdoption trigger
Large enterprise multi-cloud (financial services, healthcare, government)CISO, VP Cloud Infrastructure, Chief Network ArchitectCloud security team, cloud architects, network engineersIT security and cloud infrastructure budgetsMulti-cloud design → policy fragmentation pain → evaluation → POC → enterprise rolloutCISO or CTO with network security P&LIP address exhaustion, inconsistent security posture across clouds, compliance mandate
Mid-market enterprise (active cloud migration)VP IT or Cloud Platform LeadPlatform engineering, DevOps, FinOps teamsCloud platform or infrastructure budgetCloud migration → hybrid networking → security tool evaluation → procurementVP Engineering or CTO with infrastructure budgetCloud cost visibility and governance, scaling beyond single-cloud controls
U.S. federal and regulated sector (ZTA mandate)Agency CIO, CISO, or IT DirectorNetwork security operations, cloud infrastructure teamGovernment IT modernization or compliance budgetOMB M-22-09 mandate → ZTA architecture planning → vendor procurement → deploymentAgency CIO or CISO aligned to OMB M-22-09 deadlinesFederal ZTA compliance mandate (OMB M-22-09) and FedRAMP authorization requirements
Cloud-native hyperscale (large enterprise with Kubernetes and AI workloads)Head of Platform Security or Cloud ArchitecturePlatform engineering, Kubernetes cluster admins, AI/ML infrastructure teamEngineering infrastructure or security budgetAI agent deployment → east-west network governance requirement → tool evaluationCTO or VP Platform EngineeringAI workload security, Kubernetes network policy enforcement, multi-cloud AI agent governance

Buyer, user, and payer roles are inferred from Aviatrix press releases, customer page evidence, and analyst segment data. No public source discloses Aviatrix's internal segment revenue mix or customer acquisition funnel metrics. Federal segment adoption is mandate-driven; commercial segments are pain-point-driven.

[CM006, CM014, CM015, CM021, CM022, CM037]
FM003: Buyer / segment map

Buyer-user-payer structure across Aviatrix's four primary enterprise segments, with adoption path and budget owner for each.

[CM006, CM014, CM016, CM021, CM022, CM037]

2.4 Growth Drivers and Adoption Constraints

Multiple structural forces are accelerating demand for cloud network security platforms in 2026. Multi-cloud adoption has reached near-saturation among surveyed organizations: Flexera's 2024 State of the Cloud Report found 89% using multi-cloud, up from 87% the prior year, with 61% of large enterprises specifically using multi-cloud security tools. Identity-based attack vectors have emerged as the primary cloud threat driver: Unit 42's 2026 Global Incident Response Report (750+ cases) found identity weaknesses exploited in 89% of investigations, identity-based techniques driving 65% of initial access, and 87% of attacks spanning multiple surfaces simultaneously. Government mandates create a compliance-driven demand floor: NIST SP 800-207 defines the authoritative federal ZTA framework, and OMB M-22-09 directed all U.S. federal civilian agencies to adopt zero trust architecture. CISA's Zero Trust Maturity Model Version 2.0 provides the five-pillar implementation roadmap. DevSecOps and cloud-native development trends require integrating security into the application lifecycle, expanding the cloud security buyer base. The AI workload exposure thesis introduces a new demand vector: as enterprises deploy AI agents across multi-cloud environments, workload-to-workload governance becomes a new enforcement surface, consistent with Aviatrix's Agentguard product. Adoption constraints are equally significant. Cloud budget scrutiny is intense: managing cloud spending was the top challenge two years running (Flexera), with over 29% of organizations spending more than USD 12 million annually on public cloud. Switching costs from existing investments in hyperscaler-native tools and incumbent SASE platforms are a structural barrier. Cisco highlights that quantum computing will eventually render traditional security protocols obsolete, requiring post-quantum cryptography migration. Regulatory complexity across GDPR, CCPA, HIPAA, SOX, and FedRAMP adds implementation friction across multi-cloud environments.[CM014, CM015, CM016, CM017, CM018, CM019]

Growth drivers and constraints table
Driver / constraintDirectionTimingImplicationDiligence ask
Multi-cloud adoption saturation (89% of enterprises)PositiveCurrent / 2024-2026Near-universal multi-cloud creates structural demand for cross-cloud network governance toolsVerify Aviatrix win rate in multi-cloud accounts vs. single-cloud customers
Identity-based attack surge (89% of IR investigations involve identity weakness, 65% of initial access)PositiveCurrent / 2026Escalating threat severity creates urgency for zero trust network enforcement platformsAssess whether Aviatrix's containment architecture addresses identity-to-network lateral movement specifically
U.S. federal ZTA mandate (OMB M-22-09, CISA ZTMM, NIST SP 800-207)Positive2022-2025 mandate horizonCreates a bounded compliance-driven demand pool among federal agencies and regulated contractorsConfirm Aviatrix's FedRAMP status and federal pipeline size
Cloud budget scrutiny (top challenge two consecutive years; 29%+ spend >USD 12M annually)NegativeCurrent / 2024-2026Budget friction in discretionary security tooling purchases; longer sales cyclesObtain average sales cycle length and win/loss data vs. hyperscaler-native alternatives
Hyperscaler-native tool improvement and competitive responseNegativeOngoing / acceleratingAWS, Azure, and GCP continuously improve native networking and security services, raising the substitute ceilingAssess feature gap between Aviatrix and AWS Network Firewall, Azure Firewall in customer evaluations
Post-quantum cryptography migration requirementNegative (long-horizon)2027-2035Traditional network security protocols will require full re-architecture; creates both risk (disruption) and opportunity (new procurement cycle)Confirm Aviatrix product roadmap for post-quantum protocol support

The six rows mix current (2026) market dynamics with longer-horizon structural shifts. The positive drivers are sourced from Flexera, Unit 42, and government mandate records; the negative constraints are inferred from Flexera spending data, industry analyst commentary, and Cisco's network security horizon analysis. All drivers and constraints apply at the category level; company-specific capture will depend on Aviatrix's competitive positioning.

[CM014, CM015, CM016, CM017, CM018, CM019]
FM004: Adoption funnel or value-chain map

Enterprise cloud network security adoption funnel, narrowing from the broad multi-cloud adoption base through progressively qualified buyer stages to Aviatrix's confirmed customer footprint. Values represent approximate percentages of organizations or enterprise headcount at each stage.

The funnel uses percentages from different surveys and populations; items are not from a single cohort study. Stage 3 uses incident-rate data (Thales 2024 via GVR) as a proxy for procurement urgency, not a direct ZT procurement rate. Stage 4 uses Aviatrix's company-claimed Fortune 500 penetration.

[CM007, CM014, CM015, CM037]

2.5 Diligence Gaps, Contradictory Estimates, and SAM Uncertainty

This chapter preserves material uncertainties rather than resolving them artificially. The most significant gap is the absence of any analyst-sourced SAM or SOM for Aviatrix's specific distributed-cloud-firewall-plus-multicloud-networking boundary. The three nearest proxies — cloud security (USD 34–46 billion in 2026 depending on source scope), SASE (USD 19.19 billion in 2026), and multi-cloud networking (USD 7.6 billion by 2027) — are non-comparable, address different spend categories, and none maps cleanly to Aviatrix's actual product scope. The scope discrepancy between MnM's 2026 cloud security estimate of USD 34.37 billion and GVR's 2024 baseline of USD 35.84 billion (which extrapolates to approximately USD 46 billion by 2026 at GVR's 13.3% CAGR) represents a more than 30% spread for the same headline category in roughly the same period. Neither firm explains what drives the discrepancy. A second gap concerns Aviatrix's private financial metrics: with no disclosed ARR, no post-2021 valuation update, and no 2024-2026 headcount figure confirmed, it is impossible to assess current market share against any of the sizing lenses. The company's 500+ enterprise customer count and 10% Fortune 500 penetration confirm meaningful traction, but without revenue per customer, these metrics cannot bridge from broad TAM to Aviatrix's actual revenue capture. Third, the multi-cloud networking market estimate (MnM September 2022) predates Aviatrix's 2023-2026 security pivot and may underweight the security enforcement layer that now anchors Aviatrix's pitch. These gaps must be preserved as open diligence asks and not resolved through assumption.[CM001, CM005, CM007, CM009, CM012, CM026]

Chapter 03

03Competitors

3.1 Direct Competitors and Cloud Networking Pure-Plays

Alkira is the closest direct competitor to Aviatrix in the pure-play multicloud networking infrastructure category. Alkira positions itself as a Network Infrastructure-as-a-Service (NIaaS) platform that abstracts connectivity across AWS, Azure, GCP, and Oracle Cloud Infrastructure (OCI) with a drag-and-drop interface, integrated ZTNA, and embedded next-generation firewall capabilities. Its marketing claims 96% reduction in cloud setup time, 47% reduction in network management time, and up to 40% lower total cost of ownership versus alternatives. Alkira's pricing is consumption-based with commitment-based options, charging based on network element size, connectors, NGFW instances, and egress. Its ecosystem integrations mirror Aviatrix's: Cisco SD-WAN, Palo Alto Networks, Fortinet NGFW, F5, Splunk, and ServiceNow. Enterprise customers cited by Alkira include Michaels (1,400 stores), Koch Industries, and SITA (aviation). The feature overlap with Aviatrix is material—both provide multicloud transit, single-pane visibility, and partner-NGFW embedding—which means buyer evaluation will center on operational maturity, ecosystem depth, and pricing model. Prosimo is a second direct NIaaS competitor that has targeted the distributed cloud networking space. Prosimo's product scope, current funding status, and go-to-market strategy could not be independently verified during this research run because the prosimo.io domain was inaccessible. This is a material evidence gap; independent analyst and channel sources should be consulted to determine whether Prosimo remains an active competitor or has pivoted, been acquired, or exited the market. PeerSpot review data groups Aviatrix comparisons with Cisco ACI, Meraki SD-WAN, and Megaport, but does not surface Prosimo in top-of-mind competitive comparisons, suggesting either limited enterprise mindshare or a gap in review-site adoption. Aviatrix itself is rated 8.0 out of 10 on PeerSpot, ranked #3 in Software Defined Networking, and is most commonly compared to Cisco ACI. Its PeerSpot user base skews to large enterprises (50%) with 16% from financial services—high-value accounts that validate enterprise credibility but also represent a buyer segment that Palo Alto, Cisco, and Fortinet already penetrate deeply through existing security and networking relationships. [CP001, CP002, CP003, CP004, CP005, CP006]

Competitor Profile Table
CompetitorCategoryScale / Funding SignalTarget SegmentCore DifferentiationKey Limitation vs. Aviatrix
AlkiraDirect NIaaS peerPrivate; claims 40% TCO reduction vs. alternativesMid-to-large enterprise; manufacturing, financial services, healthcareDrag-and-drop NIaaS, Global Backbone-as-a-Service, OCI support, consumption pricingOverlaps heavily on multicloud transit; similar partner NGFW model; Aviatrix has broader installed base
ProsimoDirect NIaaS peerUnknown (site inaccessible at research time)Unknown (see evidence gap)Distributed cloud networking fabric (limited current data)Competitive profile unverifiable; excluded from capability matrix
Cisco Multicloud DefenseExpanded incumbentPublic (CSCO); large enterprise installed baseMid-to-large enterprise; Cisco Secure Firewall installed baseSingle SaaS control plane, ingress/egress/east-west, Hybrid Mesh Firewall narrativeNarrower multicloud transit capability; positioned as security overlay rather than network fabric
Palo Alto Prisma (Cloud + SASE)Expanded incumbentPublic (PANW); $10B+ annual revenueLarge enterprise; existing Prisma/Cortex accountsCode-to-cloud platform, 1T events/day, Prisma SASE, AI-powered consolidationNo dedicated multicloud networking fabric; relies on SASE for connectivity
Fortinet FortiGateExpanded incumbentPublic (FTNT); >50% global NGFW market shareAll segments; strong in midmarket and manufacturingPatented ASICs, AI/ML threat intel, built-in ZTNA, quantum-safe IPsecOn-premises and cloud-VM model less cloud-native than Aviatrix's SaaS controller
AWS Transit Gateway + Network FirewallHyperscaler-native substituteAWS (AMZN) cloud service; included in committed spendAWS-centric enterprisesDeep AWS integration, near-zero incremental cost, shared DNS/AD/IPS across regionsSingle-cloud only; no Azure/GCP visibility; limited policy granularity across clouds
Azure Virtual WAN + FirewallHyperscaler-native substituteAzure (MSFT) cloud service; included in committed spendAzure-centric enterprisesGlobal hub-and-spoke, native Azure Firewall Policy managementSingle-cloud only; no AWS/GCP integration; limited multicloud orchestration
GCP Cloud NGFWHyperscaler-native substituteGCP (GOOGL) cloud service; included in committed spendGCP-centric enterprisesHierarchical firewall policies, Cloud NGFW at VPC levelSingle-cloud only; immature relative to AWS and Azure cloud networking services
Cato NetworksSASE substitutePrivate; $773M raised (per public reports); $1B+ valuationDistributed enterprise; hybrid workforce focusConverged SD-WAN + Cloud Network + SSE, global PoP backbone, identity-drivenUser-access focus rather than cloud workload east-west; limited multicloud transit for large cloud footprints
NetskopeSASE/ZTNA substitutePrivate; $1B+ raised (per public reports)Enterprise; hybrid workforce and cloud-app accessUniversal ZTNA, NewEdge global network, converged SSE/SASEZTNA orientation; weaker multicloud network fabric vs. Aviatrix
Zscaler (ZPA)ZTNA substitutePublic (ZS); $8B+ ARR run-rateEnterprise; remote access and zero-trust accessWorld's most-deployed ZTNA, AI-powered user-to-app segmentation, workload-to-workloadDoes not provide multicloud routing or transit; positions network-layer access as unnecessary
IllumioAdjacent (microsegmentation)Private; substantial institutional backing (Franklin Templeton, others)Enterprise; security operations, breach containmentForrester Wave Leader in Microsegmentation 2024, Gartner Customers' Choice 2026Workload-level enforcement, not network routing; complementary not substitutive
WizAdjacent (CSPM/AI security)Private; $300M raised; $12B valuation (post-Series E, per prior coverage)Large enterprise; cloud-native teamsMore than 50% Fortune 100 penetration, 200+ integrations, cloud and AI security postureVisibility and posture layer, no network enforcement; competes for security budget not data-plane control

Scale and funding figures for private companies are drawn from public sources and public claims where available; Prosimo funding and Cato/Netskope/Wiz/Illumio exact ARR are not independently verified in this research run. Palo Alto and Fortinet revenue figures are approximate public-company order-of- magnitude references. Null cells indicate unknown. The table covers categories identified through primary web research; it does not claim to be exhaustive of all market participants.

[CP001, CP002, CP003, CP006, CP007, CP008]
FP001: Competitive Positioning Map

Competitors positioned on multicloud breadth (x-axis: single-cloud to all-cloud) versus security depth (y-axis: connectivity only to full security stack). Positions are ordinal estimates based on product documentation; no source-backed numeric scores available.

Axes are 1-5 ordinal scales. Multicloud breadth: 1=single cloud, 5=all major clouds plus OCI and on-premises. Security depth: 1=connectivity only, 5=full code-to-cloud security stack. All positions are inferred from vendor product documentation and marketing claims; they do not reflect independent analyst benchmark data or win-rate data. Wiz and Illumio occupy adjacent rather than directly competitive positions but are included to complete the buyer landscape.

[CP001, CP008, CP011, CP014, CP017, CP022]

3.2 Incumbents with Expanded Cloud Capabilities

Cisco Multicloud Defense provides a single SaaS control plane that manages security policy across public and private cloud environments, offering ingress, egress, and east-west traffic inspection from one management plane. This directly overlaps with Aviatrix's Distributed Cloud Firewall value proposition—blocking inbound attacks, lateral movement, and data exfiltration. Cisco differentiates through automation of underlying cloud network constructs and native Infrastructure-as-Code (IaC) integration, and it bundles Multicloud Defense within a broader Hybrid Mesh Firewall narrative that spans campus, data center, and cloud enforcement under unified policy. Cisco's go-to-market advantage is its large existing account base for Secure Firewall and Meraki, which enables cross-sell without Aviatrix's greenfield advantage. Palo Alto Networks takes a platform-consolidation approach with Prisma Cloud (code-to-cloud security analyzing 1 trillion events per day and detecting 1.5 million new attacks daily) and Prisma SASE (the company's "most comprehensive SASE" claim covering users, apps, data, and devices on a multicloud architecture). Palo Alto's Cortex platform strategy aggregates network security, endpoint, cloud security posture, and SOC capabilities under one vendor, making it a formidable incumbent in enterprise accounts. The risk to Aviatrix is greatest where a Palo Alto account already uses Prisma SD-WAN or Prisma Access, because Palo Alto has incentives to extend those customers into multicloud networking rather than allow a third-party like Aviatrix to land. Fortinet holds the #1 position in network firewalls worldwide with more than 50% global market share, backed by patented ASIC-based processing and AI/ML-powered threat intelligence (FortiGuard). FortiGate NGFWs include built-in ZTNA capabilities and SD-WAN integration, enabling Fortinet to offer an end-to-end solution that competes with the Aviatrix-plus-NGFW bundle. Fortinet also supports quantum-safe cryptography (post-quantum IPsec VPN) and has a quantum-safe roadmap, which matters in government and regulated-industry accounts. Its distribution advantage—largest installed base in the firewall market—is a structural barrier Aviatrix must account for when competing in brownfield enterprise environments. [CP008, CP009, CP010, CP011, CP012, CP013]

Feature and Capability Matrix
CapabilityAviatrixAlkiraCisco Multicloud DefensePalo Alto PrismaAWS TGW + ANFWCato NetworksZscaler ZPA
Multicloud transit (AWS + Azure + GCP)YesYesLimited (policy overlay, no transit fabric)NoAWS-onlyVia global PoP backboneNo
East-west traffic inspectionYesYesYes (ingress/egress/east-west)Via Prisma Cloud (posture, not inline)AWS-only (Network Firewall)YesLimited (workload-to-workload segmentation)
Partner NGFW embedding (Palo Alto/Fortinet)YesYesN/A (Cisco is the NGFW)N/A (Palo Alto is the NGFW)NoFWaaS built-inNo
Drag-and-drop / low-code provisioningPartial (CoPilot UI)YesPartial (IaC integration)Partial (Prisma Copilot)AWS Console (limited)YesPartial
Global cloud backbone / PoP networkNoYes (Global Backbone-as-a-Service)NoVia Prisma SD-WAN PoPsAWS backbone (AWS-only)Yes (50+ PoPs)Yes (Zscaler cloud)
Zero Trust Network Access (ZTNA)Via partner integrationYes (built-in)NoVia Prisma AccessNoYes (built-in)Yes (core product)
Single-pane-of-glass visibility (multi-cloud)Yes (CoPilot)YesAcross Cisco-managed cloudsWithin Prisma/CortexAWS-onlyYesZPA-scope only
OCI (Oracle Cloud) supportYesYesUnknownUnknownNoUnknownNo
IaC / Terraform integrationYesYesYesYesYesPartialPartial
Consumption / usage-based pricingUnknown (subscription model)YesNot publicly disclosedSubscriptionPay-per-useSubscriptionSubscription

Matrix cells reflect vendor-published documentation and product pages as of June 2026. Cells marked Unknown indicate no verifiable public evidence. Partial indicates the capability exists with limitations. Aviatrix ZTNA and global backbone capabilities are delivered via partner integration rather than natively. This matrix covers primary buying criteria; many secondary capabilities are omitted for clarity.

[CP001, CP003, CP005, CP008, CP009, CP010]
FP002: Feature Breadth Map by Competitor

Capability coverage scores (0=absent, 1=partial/via integration, 2=native) across six key buying criteria for eight competitors, illustrating where Aviatrix is distinctively strong and where gaps exist.

Scores (0=absent, 1=partial/integration-dependent, 2=native) are inferred from product documentation as of June 2026. "East-west inspection" for Palo Alto Prisma is scored 1 because Prisma Cloud provides posture/CSPM rather than inline traffic inspection at the network layer. Scores do not reflect performance or scale benchmarks. Illumio and Wiz omitted because their positioning is adjacent rather than directly comparable on these axes.

[CP003, CP005, CP008, CP009, CP013, CP015]

3.3 Hyperscaler-Native Substitutes and the Status-Quo Option

The most immediate status-quo substitute for Aviatrix is each cloud provider's native networking stack: AWS Transit Gateway for VPC interconnect, AWS Network Firewall for perimeter enforcement, Azure Virtual WAN for global hub-and-spoke, Azure Firewall for policy enforcement, and Google Cloud's hierarchical firewall policies with Cloud Next Generation Firewall (Cloud NGFW). Each is deeply integrated with its respective provider's identity, logging, and billing infrastructure, and is priced at marginal cost or bundled within existing cloud committed-spend agreements—effectively zero incremental cost for organizations already operating at scale on one cloud. The structural limitation of hyperscaler-native solutions is single-cloud scope. AWS Transit Gateway connects thousands of VPCs across AWS regions but cannot natively manage Azure VNets or GCP VPCs. Azure Virtual WAN similarly operates within the Microsoft ecosystem. GCP's Cloud NGFW enforces policies at the VPC level but has no cross-cloud control plane. For organizations operating exclusively or predominantly on a single cloud provider, this limitation may be acceptable, and Aviatrix's value proposition is weakest there. But for organizations running two or more clouds—a majority of large enterprises—the operational complexity of managing separate native stacks creates exactly the problem Aviatrix (and Alkira) solve. The internal-build or manual-configuration status quo—stitching together native TGW, VPC peering, BGP routing, and native firewall rules—is the path most enterprises start with and progressively abandon as their cloud footprint grows. Aviatrix's customer acquisition pattern historically tracked this curve: enterprises that outgrow native networking complexity become buyers. The risk is that hyperscalers continue to improve cross-account, cross-region management and eventually absorb the multicloud overlay use case from below. AWS's inter-region peering and GCP's hierarchical policies are recent capabilities that shift the threshold at which third-party tools become necessary. [CP017, CP018, CP019, CP020, CP021, CP037]

Pricing and Packaging Comparison
VendorPricing ModelPrimary Cost DriverBundling / Committed DiscountKey UnknownImplication for Aviatrix
AviatrixSubscription (per gateway, bandwidth tier, feature module)Number of cloud gateways and throughputVolume discounts; enterprise agreementsList pricing not publicly disclosed; no self-serve price pagePotential disadvantage vs. consumption-only vendors in initial TCO comparison
AlkiraConsumption-based or commitment-based; per CXP size, connector, NGFW instance, egressNetwork element (CXP) size and bandwidthYes (commitment-based tier)Exact rates not independently verified beyond vendor claimsAlkira's consumption model may appear lower-cost to buyers early in deployment; total cost converges at scale
Cisco Multicloud DefenseSubscription (SaaS); bundled with broader Cisco Security Cloud Control agreementsExisting Cisco security seat countStrong bundling via Cisco ELA/EA agreementsStandalone pricing not publicly availableCisco can bundle Multicloud Defense into existing renewals, reducing perceived cost of switching to Aviatrix
Palo Alto Prisma (Cloud + SASE)Subscription; per seat/workload/bandwidth depending on moduleWorkload credits (CNSP), seat count (SASE)Strong platform discount incentive for customers using Cortex, Prisma, and StrataStandalone vs. platform pricing gap not disclosedPlatform bundling undercuts per-module comparisons; accounts already on Prisma have a lower incremental cost
AWS TGW + Network FirewallPay-per-use; per attachment, data processed, firewall endpoint-hourData transfer and gateway attachment countNone (consumption); no committed discount unless bundled in cloud spend commitTotal cost at high traffic volume vs. Aviatrix at scaleNear-zero perceived cost for AWS-committed enterprises; displaces Aviatrix at the low end
Azure Virtual WAN + FirewallPay-per-use; per deployment hour, processed data, routing unitData processed through hubMay be included in Azure MACC committed spendTotal cost at high scaleSimilar AWS dynamic; Azure-committed buyers have low switching cost from native to Aviatrix
Cato NetworksSubscription; per user seat, site, and bandwidth tierUser count and WAN bandwidthVolume discounts for large enterprise; multi-year contractsExact per-user pricing not publicly disclosedCato's per-seat SASE model is familiar to enterprise buyers; may appear simpler than Aviatrix's gateway model

All pricing information is based on public product pages, vendor documentation, and vendor claims. None of the vendors publish list pricing for enterprise agreements; negotiated discounts are not reflected. Aviatrix pricing is not publicly disclosed; the gateway/throughput model is inferred from product documentation and sales positioning. AWS/Azure hyperscaler pricing is based on public pricing pages. All figures should be verified against current vendor quotes before procurement decisions.

[CP004, CP006, CP009, CP017, CP019, CP021]

3.4 SASE, Zero-Trust, and Adjacent Security Players

The SASE category, popularized by Gartner, converges SD-WAN, cloud networking, and Security Service Edge (SSE) functions—firewall-as-a-service, CASB, DLP, SWG, and ZTNA—into a unified cloud-native service. Cato Networks is both a pioneering SASE vendor and a direct description of where the buyer conversation is heading: identity-driven, cloud-native, globally distributed, and covering every edge. Cato's Global Cloud Network competes directly with Alkira's Global Backbone-as-a-Service and Aviatrix's multicloud transit by delivering optimized global routing as a managed service rather than as a deployed overlay. Cato's customers report outcomes such as "faster, more secure, happy users, happy team—all for less cost and more business value," positioning the Cato SASE bundle as a consolidated alternative to point solutions including Aviatrix. Netskope's Netskope One Private Access delivers universal ZTNA via the Netskope One Platform, combining SSE, SASE, and converged gateway services on its NewEdge global network. Zscaler Private Access (ZPA) claims to be the world's most deployed ZTNA solution and frames its value proposition against VPN and network-centric approaches: 91% of organizations are concerned that VPNs compromise security, and 56% of organizations suffered one or more VPN-related attacks in 2023-2024. ZPA's argument—that connecting users to applications rather than the network reduces lateral movement risk—is conceptually at odds with Aviatrix's network-centric architecture. If buyers accept the ZTNA framing, they may deprioritize the multicloud networking layer in favor of identity-based access, reducing Aviatrix's addressable footprint. Illumio occupies the microsegmentation and breach-containment space adjacent to Aviatrix. Named a 2024 Forrester Wave Leader in Microsegmentation and a 2026 Gartner Customers' Choice for Network Security Microsegmentation (4.8/5 from 59 reviews), Illumio's AI security graph enforces zero-trust segmentation across hybrid and multi-cloud environments at the workload level rather than the network layer. This is complementary in most deployments but competes for the same security budget line item in organizations seeking to consolidate vendors. Wiz is trusted by more than 50% of Fortune 100 companies and provides cloud and AI security posture management with 200+ integrations. Wiz operates at the visibility and risk-prioritization layer (infrastructure, models, data, runtime) and does not enforce network-level traffic policy, so it is not a direct competitor at the data plane. However, both Wiz and Aviatrix are sold to the same cloud security buyer, and in consolidated-platform deals, investment in Wiz's broad CSPM platform may displace budget for Aviatrix's narrower multicloud networking layer. [CP022, CP023, CP024, CP025, CP026, CP027]

FP003: Aviatrix Competitive Moat and Readiness KPIs

Qualitative assessment of Aviatrix's competitive moat dimensions, rated on a three-level scale (Strong / Moderate / Weak) based on available evidence.

All ratings are qualitative judgments based on product documentation, competitive positioning, and publicly available signals. No win-rate, renewal-rate, or NPS data is available to independently validate these assessments. Actual moat strength should be tested against Aviatrix's churn data, competitive displacement incidents, and customer expansion patterns.

[CP036, CP037, CP038, CP039, CP040, CP044]

3.5 Moat Durability, Switching Costs, and Competitive Risk

Aviatrix's primary competitive moat is its cloud-neutral, provider-agnostic control plane embedded deeply in customer cloud networking topology. Once an enterprise deploys Aviatrix's transit gateway fabric across AWS, Azure, and GCP—with route tables, security domains, firewall associations, and BGP peering configured through the Aviatrix controller—the switching cost is high. Migrating multicloud networking topology requires coordinated reconfiguration across VPCs, VNets, firewall rules, routing tables, and operational runbooks. This stickiness is reinforced by Aviatrix's CoPilot visibility and troubleshooting capabilities, which integrate into network operations workflows and create process-level lock-in. However, the moat has meaningful holes. First, greenfield accounts—enterprises starting their multicloud journey—may adopt Alkira or a hyperscaler-native approach from the outset, bypassing Aviatrix entirely. Alkira's drag-and-drop interface and NIaaS pricing make it an attractive first choice for organizations that have not yet built operational familiarity with Aviatrix. Second, Cisco and Palo Alto have distribution power through existing security and networking contracts that Aviatrix lacks; these incumbents can offer multicloud networking capabilities as an incremental feature of a broader platform renewal rather than requiring a net-new procurement. Third, the SASE re-framing of network security as a user-access problem (zero-trust, identity-first) rather than a routing problem may reduce the perceived value of a dedicated multicloud networking layer for security-first buyers. Multi-homing is uncommon but not impossible: some enterprises deploy both Aviatrix (for east-west enforcement) and a SASE solution (for user-to-app access), creating parallel architectures that increase overall IT complexity. This can work in Aviatrix's favor (it coexists with SASE) or against it (buyers eventually seek to consolidate). The commoditization risk is most acute at the low end: enterprises with limited multicloud complexity may find that AWS TGW plus native firewall or Azure vWAN plus Azure Firewall is "good enough" without a third-party overlay. Aviatrix's partner-NGFW integration model—where Palo Alto, Fortinet, or Check Point firewalls are embedded in the transit fabric—also creates a co-dependency: if a partner NGFW vendor builds its own native multicloud transit to displace Aviatrix's orchestration layer, the integration becomes a competitive entry point rather than a moat. [CP034, CP036, CP037, CP039, CP040, CP044]

Moat Durability and Competitive Risk Register
Moat ClaimSpecific ThreatThreat CategorySeverityMitigation / Diligence Ask
Cloud-neutral multicloud control plane; switching cost of redeploying topologyAlkira or Cisco Multicloud Defense wins greenfield accounts before Aviatrix embedsGreenfield displacementHighTrack win/loss rates in greenfield vs. installed-base accounts; quantify average deployment age
Provider-agnostic visibility (CoPilot) integrated into network ops workflowsHyperscaler-native tools improve cross-region and cross-account visibility, narrowing Aviatrix's observability advantageFeature commoditization by hyperscalerMediumMonitor AWS, Azure, GCP roadmaps for multicloud observability capabilities; re-survey customer switching intent annually
Embedded partner NGFW integrations (Palo Alto, Fortinet, Check Point)Palo Alto or Fortinet builds native multicloud transit to displace Aviatrix's orchestration layer for its own NGFW customersCo-dependency becoming competitive entry pointHighVerify whether any partner NGFW vendor has publicly announced multicloud transit roadmap features; assess contractual protections
Large-enterprise concentration with operational process lock-in (financial services, federal)Palo Alto or Cisco displaces Aviatrix via platform renewal bundling with zero net-new spend from buyerIncumbent channel powerHighAssess what share of Aviatrix revenue is in accounts where Palo Alto or Cisco already holds a dominant platform position
OCI and non-hyperscaler cloud support (differentiates from hyperscaler-native)Multi-cloud market stabilizes on big-3 hyperscalers; OCI support provides limited differentiationMarket concentration reducing breadth valueLowTrack OCI adoption within Aviatrix's customer base; assess whether OCI support drives net-new wins
SASE and ZTNA substitution riskSecurity buyers re-frame cloud networking as an access problem, reducing demand for network-layer overlayMarket-definition displacementMediumMonitor SASE adoption rates among Aviatrix target accounts; track whether SASE RFPs include or exclude multicloud transit
Aviatrix's cloud-native SaaS controller architectureFortinet or Cisco offers full cloud-native parity with distribution advantagesFeature parity by incumbentsMediumBenchmark Cisco Multicloud Defense and Fortinet cloud-native capabilities against Aviatrix annually

Severity ratings are qualitative assessments based on available competitive evidence and are not derived from win-rate or market-share data. The high severity ratings reflect structural distribution advantages of incumbents and the greenfield vulnerability of a networking infrastructure platform, not near-term revenue risk estimates. All threat assessments require validation against Aviatrix's actual customer retention, win-rate, and pipeline data.

[CP036, CP037, CP038, CP039, CP040, CP041]

3.6 Exhibits

Chapter 04

04Financials

4.1 Revenue Model and ARR Trajectory

Aviatrix operates a B2B SaaS model built on annual enterprise subscriptions for its multicloud networking and cloud network security platform. Revenue accrues primarily through gateway software licenses sold on a subscription basis, augmented by professional services, premium support, and training revenue from its Aviatrix Certified Engineer (ACE) program. The platform is deployed as software-defined gateways in customer cloud environments rather than as a managed service, which limits Aviatrix's hosting cost exposure and supports software-like gross margins in theory, though actual margins remain undisclosed. Third-party data from Latka estimates Aviatrix's ARR at approximately $63.9M as of October 2024, up from roughly $35.3M in November 2023 and $15.7M in early 2021. This represents compound annual growth of approximately 66% from 2021 to 2024 and a single-year acceleration of roughly 81% from 2023 to 2024. These figures are Latka's compiled estimates and have not been publicly confirmed by Aviatrix. Revenue quality indicators are positive: multi-year enterprise contracts, a customer base of 500+ enterprises including roughly 10% of the Fortune 500, and four consecutive Deloitte Technology Fast 500 rankings (2022–2025) measured on fiscal-year revenue growth from 2021 to 2024. A third-party site (Growjo) extrapolates current ARR at approximately $135M, but this algorithmic projection carries high uncertainty and should be treated as an upper-bound estimate only. The company's pivot in 2024–2025 from pure multicloud networking to a cloud network security position — anchored by the Cloud Native Security Fabric (CNSF) and Zero Trust for Workloads — may affect revenue recognition patterns if bundling or rebundling occurs, but no evidence of a material revenue recognition change has been identified. Revenue appears to be recognized ratably over the contract term per standard SaaS accounting. [CI001, CI002, CI003, CI004, CI005, CI018]

Revenue Streams Analysis
StreamMechanismUnitCurrent Status / ValueRevenue QualityDiligence Ask
Subscription softwarePer-gateway annual license for multicloud networking and securityGateway-months~$64M ARR est. (2024); ~$135M est. (2025–2026)High — recurring, multi-year enterprise contractsConfirm actual ARR via audited revenue schedule
Professional servicesImplementation, migration, and deployment consultingStatement of workUndisclosed; estimated 10–15% of ACVMedium — one-time; may compress gross marginDisclose as separate revenue line; confirm margin
Premium supportSLA-backed technical support tiersSeat/tier annual feeBundled or add-on; not separately disclosedMedium — recurring but at lower margin than softwareConfirm whether in ARR or separate
Training and certification (ACE)Aviatrix Certified Engineer exam and coursewarePer-exam / per-seatUndisclosed; likely <5% of total revenueLow — transactional; high margin but smallQuantify ACE program revenue contribution
Channel/marketplaceRevenue via VAR, ISV reseller, CSP marketplace listingsCommission / net revenue after channel feesAWS Marketplace listing present; share undisclosedMedium — broadens reach but reduces net ASPDisclose channel revenue split and net margin impact

All ARR values are third-party estimates (Latka, Growjo); Aviatrix has not publicly confirmed specific ARR figures. Professional services and certification revenue are inferred from product positioning and industry norms; no separate line-item disclosure is available. Null cells indicate undisclosed data.

[CI001, CI002, CI018, CI021]
FI001: Aviatrix Revenue Model Flow

Customer cloud workloads deploy Aviatrix gateways; gateway-months generate subscription ARR net of hosting cost and support, producing gross profit that funds R&D and go-to-market investment.

Revenue and gross margin are estimated from third-party sources. Aviatrix does not publicly disclose gross margin or cost of revenue. Flow direction and node weights are qualitative.

[CI001, CI018, CI034]

4.2 Pricing Architecture and GTM Economics

Aviatrix uses a custom-quoted enterprise pricing model with no public list price. As of June 2026, CostBench documents two tiers — Basic and Enterprise — ranging from approximately $2,500 to $15,000 per month. The per-unit infrastructure layer charges approximately $0.14 per hour per gateway (~$102/month) and ~$0.16 per hour per VPC attachment (~$117/month). Vendr's buyer-side benchmarks, drawn from actual enterprise purchasing data, show a median annual contract value of $194,034. There are documented hidden costs beyond list price — implementation fees, training, and add-on modules — estimated at 15–23% of the contract total, pushing all-in median spend higher. High-availability deployments requiring redundant gateways effectively double gateway costs. Aviatrix's go-to-market strategy is structured around a direct enterprise sales force (led by CRO Ken Horner, appointed in 2025) and an indirect channel spanning value-added resellers (VARs), independent software vendors (ISVs), and cloud service providers (CSPs). The company publicly references 10% Fortune 500 penetration and 500+ total enterprise customers, suggesting a typical ACV in the low-to-mid six figures that is consistent with the Vendr median. Sales cycle, customer acquisition cost (CAC), and payback period are not publicly disclosed. The CAC structure is likely elevated given the enterprise motion and the technical complexity of multicloud deployments, but no proxy data is available to quantify this. The channel partner program formally launched in 2024–2025 and is positioned as a key lever for scaling revenue without proportional headcount growth, though no channel revenue split has been disclosed. [CI006, CI007, CI008, CI009, CI010, CI011]

Pricing and Monetization Summary
Tier / UnitList PriceRealized / Benchmarked PriceContract TermsSource
Basic tierCustom; contact sales$2,500–$5,000/month (estimated)Annual; targets mid-market enterprisesCostBench (May 2026)
Enterprise tierCustom; contact sales$5,000–$15,000/month (estimated)Multi-year; large organizationsCostBench (May 2026)
Per-gateway unit rate~$0.14/hour (~$102/month)Not separately confirmedHourly usage billing layerIndustry benchmarks; not official
VPC attachment~$0.16/hour (~$117/month)Not separately confirmedAdd-on to gateway licensingIndustry benchmarks; not official
Median enterprise ACVNot disclosed~$194,034/year (Vendr buyer-side data)Based on actual customer transaction dataVendr (2025)
Hidden cost adderNot disclosed+15–23% beyond list (implementation/training)Two documented hidden cost categoriesCostBench (May 2026)

All pricing is custom-quoted and negotiated. List prices represent documented market-observed ranges from third-party benchmarking services (CostBench, Vendr) as of mid-2026; actual realized prices vary by contract volume, term, and negotiation. Per-gateway rates are based on market observations, not official Aviatrix list pricing.

[CI006, CI007, CI008, CI009]

4.3 Capital Adequacy and Funding Position

Aviatrix has raised approximately $346M (Tracxn) to $383M (Yahoo Finance / Sacra) across six rounds since founding in 2014. The funding history — Series A ($10M, Sep 2015), Series B ($15M, Jan 2017), Series C ($46M, Oct 2019), Series D ($75M, Feb 2021), and Series E ($200M, Sep 2021) — reflects an increasingly rapid cadence that peaked in 2021 alongside the broader SaaS market. The Series E was led by TCV with participation from Insight Partners and Tiger Global as new investors, and existing investors including CRV, General Catalyst, Greenspring Associates, Meritech Capital, TrueBridge Capital Partners, Ignition Partners, and Liberty Global Ventures. The round established a $2B valuation, more than doubling the company's value in six months from the Series D. As of June 2026, more than four years have elapsed since the last primary funding round with no public announcement of a new raise. This absence could indicate the company is approaching profitability or operating on strong internal cash generation, or alternatively that market conditions made an equity raise unattractive at the $2B Series E mark. The Forge secondary market price of $3.48/share as of June 22, 2026 implies a market capitalization of approximately $411M — a roughly 79% markdown from the Series E valuation, consistent with the 60–70% post-peak contraction seen across private high-growth SaaS companies since 2022. Cash on hand, monthly burn rate, and runway are not publicly disclosed. No public evidence of debt financing, credit facilities, or project-finance obligations has been identified, but these cannot be ruled out for a private company at this scale. The appointment of a new CFO (Ken Tinsley) as reported in November 2025 signals continued financial infrastructure investment and possible preparation for a future capital event. [CI013, CI014, CI015, CI016, CI017, CI022]

Capital Adequacy Snapshot
ItemAmount / StatusNotesSource
Series A (Sep 2015)$10MLed by Formation 8 and Ignition PartnersTracxn funding table
Series B (Jan 2017)$15MCRV, Formation 8, IgnitionTracxn funding table
Series C (Oct 2019)$46MLed by CRV; SEC Form D filed Nov 4 2019Tracxn / SEC EDGAR Form D
Series D (Feb 2021)$75MLed by General CatalystTracxn funding table
Series E (Sep 2021)$200M at $2B post-money valuationLed by TCV; Insight Partners and Tiger Global new investorsAviatrix official press release
Total raised~$346M (Tracxn) / ~$383M (Yahoo Finance)Discrepancy may reflect different round attributionTracxn; Yahoo Finance
Cash on hand (current)Not disclosedPrivate company; no public balance sheetN/A
Monthly burn rateNot disclosedInferred: likely $3–7M/month at current scaleAnalyst estimate; not confirmed
Runway estimateNot disclosedDependent on burn and cash balanceN/A
Next-round signalNone publicly announced as of Jun 20264+ years since last primary raisePublic sources

Cash on hand, burn, and runway are not publicly available for Aviatrix. Monthly burn estimate of $3–7M is a third-party inference based on revenue scale and comparable SaaS companies at similar stages; it is not company-confirmed. Total funding discrepancies across sources likely reflect different treatments of convertible notes or seed rounds.

[CI013, CI014, CI015, CI016, CI022, CI023]
FI003: Aviatrix Financial Estimate Ranges (2024–2026)

Point estimates for key Aviatrix financial metrics show wide uncertainty bands reflecting the absence of official disclosure. All ranges are derived from third-party benchmarks, secondary market data, and public-comp proxies.

All ranges are approximations. ARR is third-party estimated. Valuation range spans Forge secondary market model (low) and last primary round mark (high). Burn and gross margin are inferred from analogous SaaS companies. No value is company-confirmed.

[CI001, CI002, CI028, CI033, CI034, CI037]
FI004: Cumulative Funding Raised by Round (Waterfall)

Aviatrix raised approximately $346M across six equity rounds from 2015 to 2021. The Series E alone accounted for 58% of total capital raised, anchoring the company's $2B last-round valuation.

Total of $346M per Tracxn; Yahoo Finance and Sacra report $383M, likely due to different treatment of sub-rounds or convertible notes. Series C amount per Tracxn ($46M); some sources cite $40M.

[CI013, CI014, CI015, CI016, CI022, CI023]

4.4 Unit Economics, Margins, and Comparable Context

Aviatrix discloses no standard SaaS operating metrics. Gross margin, net revenue retention (NRR), gross revenue retention (GRR), customer acquisition cost (CAC), lifetime value (LTV), and payback period are all private. Using public-company comparables as a proxy: Zscaler (the closest public peer in cloud network security) reports non-GAAP gross margins of approximately 80–81%; Cloudflare reports approximately 75–77% non-GAAP gross margins. Software-only deployment models (Aviatrix does not operate managed infrastructure beyond controllers) typically support gross margins of 70–80% for mature SaaS companies. Aviatrix's cost structure is likely dominated by R&D (engineering for platform development and cloud-provider integrations) and sales and marketing (enterprise field sales, channel enablement, and customer success). Professional services costs may compress blended gross margins if implementation revenue is included in the top-line ARR figures. For valuation context, the SaaS Capital Index showed a median public SaaS ARR multiple of 7.0x as of early 2025. The DealMatrix benchmark for the privacy and security sector (Q1 2025) was 3.8x EV/ARR as a median for private companies. Using Latka's 2024 ARR estimate of $63.9M and Aviatrix's $2B Series E valuation, the implied multiple is approximately 31x — reflecting peak-2021 conditions that are structurally stale. Applying the Forge secondary market implied valuation of $411M yields approximately 6.4x on 2024 ARR — at the upper bound of the private security SaaS median (3.8x) but below the public SaaS sector median. Growjo estimates revenue per employee at approximately $259K based on ~521 employees and $135M estimated ARR, below the ~$300K benchmark associated with efficient enterprise SaaS at scale. [CI034, CI035, CI036, CI037, CI039, CI040]

Unit Economics Scorecard
MetricValueConfidenceWhy It MattersDiligence Ask
ARR (2024 est.)~$63.9MLow–Medium (Latka estimate)Top-line scale and growth anchorConfirm via audited ARR schedule
YoY ARR growth (2023–2024 est.)~81%Low–Medium (derived estimate)Pricing power and market share gain signalReconcile against actual bookings ledger
Gross marginNot disclosed; peer proxy: 70–80%Low (proxy only)Unit profitability; required for underwritingAudited P&L gross profit line
Net revenue retention (NRR)Not disclosed; sector benchmark 110–130%Low (proxy only)Expansion revenue quality and churn healthCohort-level NRR by vintage year
Customer acquisition cost (CAC)Not disclosedUnknownCAC/LTV ratio drives capital efficiencySales + marketing expense per net-new ACV
Median ACV$194,034/year (Vendr buyer benchmark)MediumAverage deal size and upsell headroomConfirm against internal bookings data
Revenue per employee~$259K/year (Growjo est., based on $135M ARR est.)Low (dependent on uncertain ARR estimate)Operational efficiency vs. SaaS benchmark (~$300K)Confirm headcount and actual ARR
Implied EV/ARR multiple (Forge 2026)~6.4x (using $411M Forge implied valuation / $64M ARR)Low–Medium (both inputs estimated)Valuation entry point contextConfirm ARR; obtain cap table for share count

All metrics marked "Not disclosed" are unavailable from public sources. Proxy values are drawn from public-company comparable benchmarks (Zscaler, Cloudflare) and private-market benchmarks (SaaS Capital, DealMatrix). ARR-based calculations use Latka's 2024 estimate which has not been confirmed by Aviatrix. Confidence levels reflect evidence quality, not Aviatrix's actual performance.

[CI001, CI003, CI034, CI035, CI036, CI037]
FI002: Unit Economics Bridge (Qualitative)

The unit economics chain from customer acquisition through LTV is partially observable via ACV benchmarks but breaks down at gross margin, NRR, CAC, and LTV — all of which are undisclosed.

All nodes except initial ACV (Vendr benchmark) are estimated or undisclosed. Gross margin proxy uses public-comp benchmarks for Zscaler and Cloudflare. NRR uses enterprise cloud security sector norms. CAC and LTV are completely unknown from public sources.

[CI007, CI035, CI043]

4.5 Financial Gaps, Disclosure Quality, and Verdict

Aviatrix is a private company headquartered in Santa Clara, California, incorporated in Delaware (confirmed by SEC Form D filing, accession 0001792033-19-000002, filed November 4, 2019), with no obligation to publish audited financials. The resulting disclosure gap is substantial. All ARR figures are third-party estimates (Latka, Growjo) that Aviatrix has neither confirmed nor denied publicly. Gross margin, NRR, burn rate, CAC, and runway cannot be determined from public sources. The only reliable financial anchors are: (1) confirmed funding rounds totaling approximately $346M, (2) the $2B Series E valuation from September 2021 (now stale), (3) Forge secondary market data suggesting a current implied valuation near $411M, and (4) Deloitte Fast 500 eligibility criteria that require at least $5M in current-year revenues and 50%+ growth — confirming that Aviatrix exceeded these thresholds in the measurement period (2021–2024). The financial verdict on current evidence: Aviatrix demonstrates strong revenue growth and enterprise traction, but the critical unit economics — gross margin trajectory, NRR, burn, and CAC efficiency — remain behind private disclosure walls. The $2B valuation is a 2021 artifact; the Forge secondary market data implies a significantly more modest mark-to-market. Four years without a primary raise introduces ambiguity: the company may be capital-efficient and near profitability, or may be conserving equity rather than accepting a down round. The appointment of a new CFO in late 2025 and continued Deloitte Fast 500 inclusion suggest operational stability, but these are qualitative signals, not financial proof. Primary diligence must obtain audited P&L, ARR schedule, cohort NRR, and runway projections before any investment judgment can be made. [CI044, CI045, CI046, CI047, CI048]

Public Financial Disclosure Gaps
Missing MetricBusiness ImpactExact Diligence Path
Audited ARR (confirmed)All Latka / Growjo estimates are unverified; no underwriting basisRequest audited or management-confirmed ARR schedule by quarter; cross-check against bookings
Gross marginWithout margin, cannot model contribution or capital intensityRequest GAAP P&L; calculate gross profit / revenue; compare to Zscaler/Cloudflare benchmarks
Net revenue retention (NRR)NRR determines organic growth quality and churn riskRequest cohort-level NRR data by customer vintage; verify against invoicing records
Burn rate and cash positionNo runway visibility; cannot assess near-term financing riskRequest monthly P&L and cash flow statement; confirm runway as of Sep 2021 deployment
CAC and sales efficiencyWithout CAC, capital efficiency of GTM cannot be assessedRequest S&M expense by quarter; segment field vs. channel vs. inside sales
Revenue by product lineCannot assess mix shift risk or margin profile by segmentRequest revenue breakdown: networking vs. security vs. services vs. ACE

All items represent metrics that are standard in SaaS diligence but unavailable for Aviatrix as a private company. None of these gaps can be estimated with sufficient precision from public data to support investment underwriting without direct data room access.

[CI044, CI045, CI046, CI047]

4.6 Exhibits

Chapter 05

05Product & Technology

5.1 Platform Architecture — The Cloud Native Security Fabric

Aviatrix positions the Cloud Native Security Fabric (CNSF) as its flagship platform umbrella, organized into two product lines: Zero Trust for Workloads (runtime enforcement at cloud workloads) and Zero Trust for Networking (encrypted connectivity across cloud networks). The two lines share a common control plane—the Aviatrix Controller—that interfaces with cloud provider APIs across AWS, Azure, GCP, and OCI to auto-inventory workloads, distribute policies, and orchestrate gateway lifecycle. CNSF operates agentlessly: no SDK changes, no kernel modules, and no application rewrites are required. Spoke gateways are deployed as software instances within each VPC or VNet and perform inline L4-L7 inspection at the first hop, eliminating the hairpin routing latency of centralized firewall appliances. The architecture's central organizing principle is "Containment Architecture" as distinct from "Chokepoint Security." In the chokepoint model (legacy NGFW or transit firewall), only traffic routed through the inspection point is governed; east-west VPC traffic, Kubernetes pod egress, and newly deployed workloads can all bypass it. In Containment Architecture, policy is auto-propagated to every workload at deploy time across all supported clouds, enforcing one-to-one communication governance at the workload boundary rather than at a shared egress point. Aviatrix CoPilot provides a unified cross-cloud visibility, monitoring, and compliance-reporting layer on top of this distributed enforcement fabric. The platform documentation is hosted at docs.aviatrix.com and as of June 2026 the production version is 9.0. [CE001, CE002, CE003, CE004, CE005, CE006]

Technology and Architecture Components
Layer / ComponentRoleTechnologyKey DependencyRisk
Aviatrix ControllerCentral policy engine; cloud API integration; route orchestration; key managementSaaS control plane (Python-based)Cloud provider APIs (AWS, Azure, GCP, OCI); compute availabilitySingle orchestration point; CVE-2024-50603 showed unauthenticated RCE risk; HA required
Spoke GatewayInline enforcement per VPC/VNet; first-hop L4-L7 traffic inspectionSoftware instance on cloud compute (EC2, Azure VM, GCE)Cloud compute budget; VPC routing tablesPerformance tied to VM instance type; cost scales with traffic volume
SmartGroupsIdentity-based workload policy grouping; spans multiple cloudsCloud Asset Inventory metadata + cloud taggingCloud provider tagging hygieneStale or misconfigured tags can cause policy mismatches
Suricata IPS EngineInline deep packet inspection; AI threat rule matching; TLS decryptionOpen-source Suricata (OISF consortium member); 556 AI-specific custom rulesOISF open-source community maintenance; TLS decrypt adds latencyRule update cycle tied to platform release; IPS + TLS Decrypt mode performance impact not benchmarked
High Performance Encryption (HPE) EngineSoftware-defined encryption for east-west, north-south, cross-cloud trafficPatented multi-tunnel ECMP on cloud CPU; no hardware offloadCloud compute CPU capacityCPU cost scales with encrypted throughput; PQC not yet deployed (crypto-agility roadmap)
CoPilot AnalyticsVisibility, monitoring, compliance telemetry, policy visualizationSaaS analytics layer fed by ControllerController data pipeline; latency in telemetry deliverySingle monitoring plane; lag possible in high-traffic environments
Terraform ProviderInfrastructure-as-code automation for gateway and policy lifecycleAviatrixSystems/aviatrix provider on registry.terraform.ioTerraform version compatibility; Aviatrix API stabilityAPI changes can break IaC pipelines; provider versioning discipline required
AgentGuard Discovery (Shadow AI)Shadow AI agent inventory via network telemetry; no gateway requiredVPC Flow Logs + DNS logs + Cloud Asset Inventory analysisCloud provider log enablement (VPC Flow Logs must be on)Flow Logs and DNS logs must be explicitly enabled; egress via non-standard ports may not be captured

Technology details from aviatrix.ai product pages and docs.aviatrix.com. CVE history from NVD and The Hacker News. Terraform provider from registry.terraform.io.

[CE004, CE008, CE012, CE013, CE015, CE027]
FE001: Aviatrix CNSF Platform Architecture Layers

Five-layer containment architecture from cloud infrastructure through CoPilot analytics, showing how CNSF embeds enforcement in the data plane rather than routing traffic to a centralized firewall.

Layer boundaries derived from aviatrix.ai product documentation; exact internal microservice decomposition not public.

[CE001, CE004, CE006]

5.2 Core Product Modules

**Distributed Cloud Firewall (DCF)** is the primary workload enforcement product. DCF discovers every workload across AWS, Azure, and GCP using Cloud Asset Inventory (CAI) and groups them into identity-based SmartGroups, allowing policies to be authored once and enforced consistently across clouds without IP-address rules or per-cloud tools. Inline enforcement at spoke gateways drops unauthorized connections at the first hop (L4-L7), preventing lateral movement before it propagates. North-south internet egress is controlled via WebGroups supporting FQDN and full URL-path filtering. ExternalGroups govern policy for external destinations. All DCF policies are managed as code through Terraform and CI/CD pipelines, enabling version control, peer review, and automated deployment. The Aviatrix Controller and CoPilot provide the single rule engine and unified visibility layer. **High Performance Encryption (HPE)** is built on a patented multi-tunnel, multi-core architecture that breaks past the single-core VPN bottleneck—a standard AWS or Azure VPN gateway tops out near 1.25 Gbps per tunnel. HPE achieves 100+ Gbps hybrid throughput and up to 1 Tbps+ cloud-to-cloud using parallel tunnels and ECMP. All encryption is software-defined, scaling with cloud compute without hardware appliances. HPE includes a Crypto-Agility Engine designed for seamless algorithm upgrades including post-quantum cryptography (PQC) readiness. **Workload Threat Visibility (WTV)** transforms Aviatrix NAT Gateways into intelligent security sensors, providing unified cross-cloud outbound visibility into workload connections—exposing malicious egress destinations and reducing NAT cost and complexity. WTV feeds compliance-ready telemetry for DORA, NIS2, and PCI DSS 4.0. **CoPilot** serves as the centralized visibility, monitoring, and analytics layer. It provides a single-pane view of traffic flows, threat events, policy status, and compliance posture across all clouds. [CE008, CE009, CE010, CE011, CE012, CE013]

Aviatrix Product Module Matrix
ModuleDelivery ModelCloud CoverageGA StatusKey DifferentiatorEvidence Gap
Distributed Cloud Firewall (DCF)SaaS gateway overlayAWS · Azure · GCPGAIdentity-based SmartGroups; inline L4-L7 no hairpinInternal throughput metrics not public
High Performance Encryption (HPE)SaaS gateway overlayAWS · Azure · GCP · OCIGAPatented multi-tunnel ECMP; 1 Tbps+ cloud-to-cloudPerformance independently unverified
Workload Threat Visibility (WTV)SaaS via NAT Gateway sensorsAWS · Azure · GCPGANAT-as-sensor; zero additional infraCoverage limits not published
AgentGuard — Shadow AI DiscoverySaaS via VPC Flow Logs + DNSAWS · Azure · GCPEarly AccessAgentless; 15-min discovery inc. shadow AIPre-GA; limited customer evidence
AgentGuard — Network EnforcementSaaS gateway overlayAWS · Azure · GCPGA (via ZT for Workloads)SDK-independent AI agent containmentDistinct product scope vs. DCF not fully clarified
AgentGuard — Deep AI ObservabilitySaaS gateway overlayAWS · Azure · GCPRoadmap Q3 2026MCP invocation + tool-traffic inspection inlineTimeline unverified; GA date not confirmed
AgentGuard — Advanced AI GuardrailsSaaS gateway overlayAWS · Azure · GCPRoadmap Q3 2026SDK-independent guardrails on live trafficTimeline unverified; GA date not confirmed
ACS Integration (Microsoft Agent Control Spec)CI/CD compile to DCF CRDAWS · Azure · GCP · K8sEarly AccessFirst multicloud network-layer ACS substrateEarly Access only; limited production deployments
CoPilot (Visibility & Compliance)SaaS analyticsAll supported cloudsGAUnified cross-cloud visibility and audit telemetryAPI coverage details not fully public

GA Status derived from aviatrix.ai product pages (June 2026); performance figures are company-claimed unless noted. Roadmap dates taken from AgentGuard product page and not independently confirmed.

[CE008, CE013, CE019, CE022, CE023]
Aviatrix Workflow and Use-Case Table
User JobCurrent ProblemAviatrix SolutionMeasurable Benefit ClaimedLimitation
Prevent lateral movement in multi-cloudIP-based rules per cloud provider; no cross-cloud governance; east-west VPC traffic ungovernedDCF SmartGroups enforce inline at first hop across AWS/Azure/GCPUnauthorized east-west connections dropped at source; new workloads auto-secured at deploy timeController single point of orchestration; CVE-2024-50603 showed controller can be exploited
Encrypt all cross-cloud traffic at scaleSingle IPsec VPN tops at 1.25 Gbps per AWS or Azure VPN gateway; hardware VPNs add latency and costHPE multi-tunnel ECMP on cloud compute100+ Gbps hybrid, up to 1 Tbps+ cloud-to-cloud (company-claimed)Performance not independently benchmarked; CPU cost scales with traffic
Discover and govern shadow AI agentsNo visibility into unauthorized AI agents calling LLMs; code-based tools miss network-native shadow AIAgentGuard Shadow AI Discovery via VPC Flow Logs + DNS + Cloud Asset Inventory15-minute time to first discovery (company-claimed); every AI agent risk-scored by blast radiusEarly Access only; advanced capabilities (Deep AI Observability, Advanced AI Guardrails) not yet GA
Govern AI agents against exfiltration and C2SDK guardrails deceivable by jailbroken prompts or poisoned dependencies (e.g. LiteLLM Mar 2026)ACS integration compiles policy file into DCF network enforcement; network-layer holds even if SDK failsArchitecture-independent enforcement; detection-independent (holds before alert fires)ACS integration in Early Access as of June 2026; production track record limited
Produce compliance evidence (HIPAA/PCI DSS/DORA)Fragmented telemetry across clouds; separate tools per cloud providerCoPilot audit-ready telemetry; HPE encryption covering CISA ZTMM 2.0, NIST 800-207 alignmentSupports HIPAA 2025, PCI DSS 4.0, DORA, NIS2 compliance reportingCompliance support is product-alignment claim; QSA/third-party audit scope not public
Reduce NAT Gateway egress costs while gaining visibilityNAT Gateway bills scale with egress traffic; no visibility into what exitsWTV transforms NAT Gateways into security sensors with cross-cloud outbound telemetryReduced NAT complexity; compliance telemetry for NIS2, DORA, PCI DSS 4.0Coverage limits (e.g. serverless egress) not fully documented

Benefits in 'Measurable Benefit Claimed' column are from Aviatrix official product pages and press releases; independent customer metrics are not available for most line items.

[CE008, CE013, CE019, CE023, CE029, CE034]
FE004: Product Capability Maturity Matrix

Capability matrix covering all current Aviatrix products across GA status, cloud coverage, agentless deployment, and AI-readiness as of June 2026.

[CE008, CE013, CE016, CE019, CE022]

5.3 AI Security and 2026 Roadmap

Aviatrix launched AgentGuard in early access (June 2026) to address AI agent governance. The product takes a network-native approach: security teams deploy it without requiring developers to install SDKs or change application code. Shadow AI Discovery—available immediately in early access—analyzes VPC Flow Logs, DNS logs, and Cloud Asset Inventory to surface every AI agent, MCP server, and LLM endpoint in a cloud environment within 15 minutes, including shadow agents that application teams did not authorize. The product risk-scores each discovered workload by blast radius. AgentGuard comprises four progressive capabilities: (1) Shadow AI Discovery (early access now); (2) Network Enforcement, available today via Zero Trust for AI Workloads; (3) Deep AI Observability (MCP invocation and tool traffic inspection); and (4) Advanced AI Guardrails—both #3 and #4 are on the roadmap for Q3 2026. AgentGuard covers AI agent frameworks including Strands, LangChain, and AutoGen, and supports major LLM providers (OpenAI, Anthropic, Bedrock, Vertex, Cohere, Mistral). On June 4, 2026, Aviatrix announced it is one of the first multicloud network-layer enforcement substrates for the Microsoft Agent Control Specification (ACS)—an open standard unveiled at Microsoft Build 2026. The integration carries a single .guardrails.yaml policy file from the agent runtime into live network enforcement across AWS, Azure, GCP, and on-premises Kubernetes via CI/CD. Aviatrix's CPO Chris McHenry noted: "After running Microsoft Agent Control Specification in private preview, what became clear is that a shared standard is only as strong as the layer that enforces it everywhere the agent operates." The integration is available at no additional cost to existing Aviatrix customers. On June 8, 2026, Aviatrix joined OISF as a consortium member to advance Suricata for cloud-native environments. Suricata has been embedded in the Aviatrix platform as its core IPS engine since initial integration—performing deep packet inspection, processing custom rulesets, and decrypting TLS traffic in IPS + TLS Decrypt mode. Aviatrix has developed 556 purpose-built Suricata rules for AI-specific threat categories: prompt injection and jailbreak detection, sensitive data leakage, malicious tool usage, data exfiltration, and agent-to-agent threats. Aviatrix's OISF membership contributes these rules and multicloud reference architectures (AWS, Azure, GCP) back to the open-source community. OWASP's 2025 Top 10 for Agentic Applications and the LiteLLM supply chain attack (March 2026, affecting versions 1.82.7–1.82.8) provide external validation of the network-layer enforcement thesis: a poisoned dependency running inside the trusted process can exfiltrate credentials to external endpoints, bypassing any SDK guardrail. Deep AI Observability and Advanced AI Guardrails remain roadmap items with an unverified Q3 2026 timeline. [CE019, CE020, CE021, CE022, CE023, CE024]

Product Roadmap and Key Milestones
Date / StageFeature / MilestoneStatusStrategic ImplicationSource
Oct–Nov 2024CVE-2024-50603 reported; hot patch issued (v6.7+); targeted customer outreachCompletedRapid response demonstrates security posture; controller exposure risk now documentedThe Hacker News / NVD
Dec 19, 2024Permanent CVE fix for supported trains v7.1.4191 and v7.2.4996; public disclosure Jan 7, 2025CompletedPatches pre-dated PoC exploit publication; CISA KEV listing Jan 16 confirmed active exploitationThe Hacker News / CISA
Dec 2025OWASP Top 10 for Agentic Applications released (external)Completed (external)Formalizes AI agent risk taxonomy that AgentGuard and ACS integration addressOWASP GenAI Security Project
Mar 2026LiteLLM supply chain attack (external, v1.82.7–1.82.8)Completed (external incident)Validates network-layer enforcement thesis: poisoned dependency bypassed in-process SDK guardrailsAviatrix blog (ACS article) / CNSF product positioning
Jun 4, 2026Microsoft Agent Control Specification integration announced; Early Access at no additional costEarly Access GAFirst multicloud network-layer ACS substrate; positions Aviatrix for AI governance expansionAviatrix press release / ACS product page
Jun 8, 2026OISF consortium membership; 556 AI-specific Suricata rules contributed to open sourceCompletedStrengthens IPS detection capability and open-source community alignment; multicloud rule sets now publicAviatrix blog / OISF membership page
Jun 2026AgentGuard Shadow AI Discovery — Early Access launchedEarly Access GAFirst commercial capability for AI agent governance; 15-min shadow AI inventoryaviatrix.ai/products/agentguard
Q3 2026AgentGuard Deep AI Observability + Advanced AI GuardrailsRoadmapCompletes 4-capability AgentGuard suite; MCP invocation and tool-traffic inspection inlineaviatrix.ai/products/agentguard (company-stated roadmap)
OngoingCrypto-Agility Engine for post-quantum cryptography (PQC) readinessRoadmapFuture-proofs HPE against quantum threat; PQC not yet deployed or standardized at Aviatrixaviatrix.ai/products/high-performance-encryption

Dates 'Jun 2026' and 'Q3 2026' are company-stated. OWASP and LiteLLM rows are external milestones cited in Aviatrix marketing materials. Roadmap items are not binding commitments.

[CE022, CE023, CE026, CE031, CE033]
FE002: Customer Deployment and Policy Enforcement Workflow

End-to-end GitOps-driven workflow from controller deployment through automated inline policy enforcement and CoPilot compliance reporting.

[CE005, CE011, CE036]

5.4 Trust, Compliance, and Security Controls

Aviatrix's Trust Center (trust.aviatrix.com) lists five audits and certifications: SOC 2 (document available), ISO 27001, TISAX, GDPR compliance, and CCPA compliance. An additional 30 documents cover policies (15), pentest reports (2), HR practices (6), and other categories. The platform's product-level claims include support for HIPAA 2025, PCI DSS 4.0, DORA, NIS2, and CISA Zero Trust Maturity Model (ZTMM) 2.0 through audit-ready compliance telemetry generated by CoPilot and enforced by HPE. The most material security risk is CVE-2024-50603, a CVSS 10.0 unauthenticated remote code execution vulnerability in the Aviatrix Controller API, discovered by Jakub Korepta at Securing and first disclosed in late October 2024. The vulnerability resulted from API endpoints failing to sanitize user-supplied input, allowing OS command injection. Wiz reported that 3% of cloud enterprise environments had the Aviatrix Controller deployed, and 65% of those environments had a lateral movement path to administrative cloud control plane permissions by default on AWS. Active exploitation was observed in January 2025, deploying XMRig cryptocurrency miners and the Sliver C2 framework. CISA added CVE-2024-50603 to the Known Exploited Vulnerabilities catalog on January 16, 2025, requiring federal agencies to patch by February 6, 2025. Aviatrix issued a hot patch in early November 2024 for versions down to 6.7 (including some end-of-support releases) and permanent fixes for supported trains 7.1 (v7.1.4191) and 7.2 (v7.2.4996) on December 19, 2024—prior to the public PoC exploit's availability. The company ran targeted customer outreach campaigns and pushed in-product banners to maximize patch coverage before public disclosure on January 7, 2025. The Controller-as-single-orchestration-point architecture is a structural risk: a compromised Controller could affect policy enforcement across an entire enterprise multi-cloud estate. Aviatrix supports Controller HA configurations, and the spoke gateways continue to enforce last-known-good policy when disconnected from the Controller, but the CVE-2024-50603 incident underscores the need for rigorous Controller access hardening. [CE030, CE031, CE032, CE033, CE034, CE035]

Trust, Compliance, and Certification Status
Control / CertificationStatusScopeVerifiable SourceGap / Caveat
SOC 2Certified (document available)Aviatrix SaaS platformtrust.aviatrix.com (1 document)Report details (Type I vs II, period, scope) not publicly disclosed
ISO 27001CertifiedAviatrix Systems, Inc.trust.aviatrix.comCertification date, scope, and certifying body not published
TISAXCertifiedAviatrix Systems, Inc.trust.aviatrix.comAssessment level (AL1/AL2/AL3) and scope not public; automotive sector relevance unclear
GDPRCompliant (by declaration)Data processing activitiestrust.aviatrix.com (policy documents)No third-party audit attestation confirmed
CCPACompliant (by declaration)California consumer datatrust.aviatrix.com (policy documents)Compliance by internal declaration; no external assessment found
HIPAA 2025Product-aligned (not an org-level attestation)CNSF encryption + audit telemetryaviatrix.ai/products/ claimsNo Business Associate Agreement structure or BAA template cited publicly
PCI DSS 4.0Product-aligned (not a QSA assessment)HPE + CoPilot telemetryaviatrix.ai/products/ claimsNo QSA report or Attestation of Compliance (AOC) found
CISA ZTMM 2.0Product-aligned (self-assessed)Network and Data ZT pillarsaviatrix.ai/products/ claimsFormal CISA recognition or third-party ZTMM assessment not confirmed
NIST SP 800-207 Zero TrustProduct-aligned (self-assessed)CNSF architectureaviatrix.ai/products/ claimsNo NIST-certifying body; alignment is self-described against published standard

Status classifications: 'Certified' = third-party audit with document at trust.aviatrix.com; 'Product-aligned' = company claim based on product feature set; no independent QSA or CISA assessment found.

[CE030, CE033, CE034, CE035]

5.5 Deployment, Integrations, and Differentiation

CNSF is deployed as software-defined overlays. Spoke gateways are provisioned inside customer-owned VPCs and VNets as cloud compute instances (no hardware appliances, no network re-architecture). The Aviatrix Controller automates provisioning, tunnel orchestration, policy enforcement, and lifecycle operations including centralized key management. A single Terraform provider (AviatrixSystems/aviatrix on registry.terraform.io) enables full infrastructure-as-code integration, combining network and application CI/CD pipelines. The platform is available on AWS Marketplace and Azure Marketplace; a 30-day free trial of Aviatrix Enterprise is available on both. A free Workload Attack Path Assessment tool provides breach-chain visualization and risk discovery without requiring deployment. Peerspot reviews (2026) confirm customer use across multicloud enterprise environments. The core differentiation versus native cloud controls (AWS Network Firewall, Azure Firewall, GCP VPC Firewall) is policy consistency: native tools are per-cloud, per-region, IP-based, and require separate management. Aviatrix CNSF defines policy once and enforces across clouds without per-cloud tooling or manual coordination. Versus traditional chokepoint firewalls (Palo Alto Networks Prisma, Cisco Multicloud Defense), Aviatrix avoids hairpin routing by enforcing at the workload boundary. Versus Illumio (micro-segmentation with endpoint agents), Aviatrix operates agentlessly and extends into networking and encryption. Versus Zscaler (SASE/ZTNA, user-to-app focus), Aviatrix addresses workload-to-workload communication that ZTNA architectures do not govern. The weakest differentiation claim is AgentGuard: the product is pre-GA, the Advanced AI Guardrails and Deep AI Observability capabilities are roadmap items, and the 15-minute discovery claim and blast-radius quantification have not been independently verified. The Microsoft ACS integration was released June 2026 and is also in early access, so production track record is limited. HPE's 100+ Gbps and 1 Tbps+ performance figures are company-claimed and have not been validated by independent benchmarks. [CE036, CE037, CE038, CE039, CE040, CE041]

FE003: Aviatrix Critical Technology Dependencies

Directed dependency graph showing platform dependencies on cloud provider APIs, Suricata IPS, Terraform, and the Microsoft ACS standard, plus AgentGuard's log-data dependencies.

[CE003, CE020, CE025, CE027]

5.6 Exhibits

Chapter 06

06Customers

6.1 Customer Profile and Market Segmentation

Aviatrix's buyer profile is concentrated in large and mid-market enterprises undergoing multi-cloud or hybrid-cloud migrations. According to PeerSpot research data, the large enterprise segment accounts for approximately 50% of researchers evaluating Aviatrix, with financial services firms representing 16% of all product views — the single largest industry vertical. Manufacturing, outsourcing, retail, construction, healthcare, telecommunications, and insurance round out the secondary verticals. The company targets cloud architects, senior network engineers, DevOps leads, and security teams in organizations managing connectivity across two or more cloud providers. The core buyer persona is an enterprise IT leader responsible for multi-cloud infrastructure who needs a vendor-neutral control plane that abstracts AWS, Azure, GCP, and OCI networking differences. Use cases span multi-cloud transit networking (the foundational entry point), zero trust network segmentation, egress cost optimization, FQDN-based firewall policy, M&A infrastructure integration, FAA/HIPAA/PCI-DSS compliance workloads, and AI workload isolation. Regulated industries — financial services, healthcare, aviation, and insurance — disproportionately appear in Aviatrix's public reference base, likely because compliance requirements create strong pull toward a vendor-neutral, auditable networking layer. Aviatrix claims 10% of Fortune 500 companies as customers, a figure cited on its financial services solutions page. Geographic coverage spans North America, Europe (GN in Denmark, HAPEV in Germany, Aegon in the Netherlands, Amundi in France), Asia-Pacific (Yara global, IHG global), and the Middle East — though reviewers note limited in-country support staff in the GCC region. The ACE (Aviatrix Certified Engineer) certification program acts as a pipeline builder, with 8,366 registered community members as of the run date, creating a practitioner base that evangelizes the platform internally within prospective enterprise accounts.[CU005, CU006, CU007, CU008, CU009, CU010]

Customer Segmentation by Vertical, Buyer, and Use Case
Segment / VerticalPrimary Buyer / UserCore Use CaseRepresentative ScaleRevenue / Strategic ValueEvidence Gap
Financial Services (banks, insurers, asset managers)Cloud architect, CISO, Head of InfrastructureMulti-cloud transit, zero trust segmentation, PCI/GDPR compliance1,000–200,000 employees; $500M–$882B revenueHighest ACV; compliance requirements create strong lock-inNRR and renewal rates undisclosed; competitor displacement unknown
Hospitality and RetailHead of Infrastructure, IT architectMulti-region multicloud networking, guest-facing app availabilityLarge hotel chains (6,000+ properties), global retailersHigh strategic value; SLA-critical, large cloud footprintsNo published contract length or renewal data for these buyers
Aviation / TransportationSenior Network Engineer, CloudOpsHybrid cloud zero trust, FAA compliance, operational telemetryRegional carrier (240+ aircraft, 100+ destinations)Moderate ACV; mission-critical uptime requirementsRegulatory compliance depth (FAA) not independently verified
Healthcare and Life SciencesDevSecOps, DevOps Engineer, CTOHIPAA-compliant data exchange, multi-VPN management, cloud-native PHI protectionMid-size pharmacy platforms, healthcare analytics startupsLower ACV vs. FS; compliance-driven purchaseNo published churn or renewal data; SOC2/HIPAA audit artifacts not public
Agriculture and IndustrialDirector of DevOps, Director of Farm DataMulticloud operational consistency, day-2 automation, WAN integrationGlobal crop nutrition (Yara, revenue ~$16B)Moderate ACV; longer sales cycles due to operational complexityNo outcome metrics (cost savings, latency) disclosed for this segment
AI-Native / Cloud-Native SoftwareCo-CEO, CTO, infrastructure leadAgentic AI workload security, data sovereignty, microsegmentationEarly-stage startups scaling to enterpriseLow initial ACV; high expansion potential if AI workloads scaleEarliest-stage case study (Across AI 2026); durability unproven
Media / TelecomSenior Network Engineer, Cloud ArchitectMulticloud connectivity, legacy OCI workload migration, FireNet integrationGlobal satellite operator (Inmarsat)Moderate ACV; complex multi-vendor environmentNo published churn or contract renewal data

Segments derived from published case studies and PeerSpot industry research data; no official revenue-by-segment breakdown is disclosed by Aviatrix.

[CU005, CU006, CU008, CU009, CU012]
FU001: Aviatrix Customer Journey Map — Segments, Touchpoints, and Expansion Loops

Maps the enterprise buyer's path from initial discovery through multicloud deployment expansion, annotated with evidence from named customer case studies.

Journey stages inferred from case study narratives and community data; no official customer journey funnel conversion metrics are disclosed by Aviatrix.

[CU009, CU010, CU011, CU038, CU039, CU040]

6.2 Adoption Trajectory and Growth Evidence

Aviatrix self-reports 500+ enterprise customers across its website and press materials, a figure cited consistently since at least mid-2024 and confirmed in the May 2024 "Building an Iconic Business" press release and the 2025 Deloitte Technology Fast 500 announcement. No precise customer count update was found for 2026, leaving the 500+ figure as the most recent public data point. Third-party estimates by Latka place ARR at approximately $63.9M as of October 2024, growing roughly 81% year-over-year from $35.3M in 2023, which is consistent with a customer base expanding at double-digit pace. Aviatrix has been named to the Deloitte Technology Fast 500 for four consecutive years (2022–2025), corroborating sustained revenue growth rather than a one-year spike. Vendr procurement data shows a median annual contract value (ACV) of approximately $194,034, with a range of $153,513 to $798,362, reflecting the consumption-based model where spend scales with gateway counts and cloud resource usage. Monthly list pricing ranges from $2,500 to $15,000 depending on tier. These ACVs indicate a mid-to-large enterprise buying pattern consistent with six-to-twelve-month procurement cycles and multi-stakeholder sign-off. Community growth signals complement the revenue trajectory. The Aviatrix community (community.aviatrix.com) shows 8,366 registered members, 969 topics, and 1,355 replies, with ACE certifications continuing to be awarded at a visible pace. The ACE program is described by the company as "the industry's leading multicloud networking and security certification," and it functions both as a demand-generation motion and as a retention lever by building deep platform expertise inside customer engineering teams. Aviatrix's Azure Marketplace listing and prior AWS Marketplace presence extend procurement optionality through cloud provider committed-spend programs, reducing friction for cloud-native buyers.[CU001, CU003, CU004, CU013, CU014, CU015]

Customer Growth and Adoption Trajectory
MetricValueDateSourceConfidenceImplicationMissing Denominator
Enterprise customer count500+ (self-reported)May 2024 / currentAviatrix press releases and websiteMedium — company-claimed, not independently verifiedConfirms large-enterprise market penetration; exact count undisclosedNo breakdown by contract status, active vs. churned, or region
Fortune 500 penetration~10% of Fortune 500Current (June 2026)Aviatrix financial services solutions pageLow-medium — company-claimed, not audited~50 Fortune 500 accounts if accurate; credibility boost for enterprise salesWhich Fortune 500 companies? Revenue from this cohort unknown
Estimated ARR~$63.9M (Oct 2024)October 2024Latka third-party estimateLow — third-party estimate, no company confirmation81% YoY growth; pace of customer vs. expansion unclearGross-to-net expansion split not available
Deloitte Technology Fast 5004th consecutive year inclusionNovember 2025Deloitte / Aviatrix press releaseHigh — third-party verifiedSustained revenue growth > 50% CAGR over 4 years confirmedRevenue CAGR percent not disclosed by Deloitte or Aviatrix
Median ACV$194,034 per yearCurrentVendr procurement dataMedium — based on buyer-reported dealsEnterprise average spend confirms B2B SaaS with long sales cyclesNo quartile breakdown or trend data
ACE community members8,366 registered membersJune 2026community.aviatrix.com live statsHigh — directly observable from public community pageLarge practitioner community suggests broad enterprise touchpointsCertification pass rate and active vs. inactive members not tracked
Monthly pricing range$2,500–$15,000/monthCurrentAviatrix pricing pageMedium — list pricing, not contracted pricingImplies ACV of $30K–$180K+ depending on tierDiscounting terms and marketplace incentives not published

All customer count and ARR figures are company-claimed or third-party estimated; no audited financial disclosures exist. ARR estimate is from Latka as of October 2024.

6.3 Named Customer Proof and Case Studies

Aviatrix publishes at least 14 named case studies on its website as of the run date, covering a broad range of industries, geographies, and use cases. All cited deployments are described as production environments rather than pilots. The evidence quality is moderate: outcomes include quantified metrics for a subset of customers (Republic Airways reduced MTTR from days to under one hour; Aegon reduced tunnel setup from hours to seconds; HAPEV deploys new workloads in under one hour via IaC) while many other case studies offer qualitative outcomes only. Customer executives are named and quoted in all cases, providing reference quality above a logo-only claim. The case studies are published by Aviatrix and carry company-controlled framing; no independent third-party audit of outcomes was found. Review site data from PeerSpot and TrustRadius provides some corroboration through uncontrolled enterprise user reviews, with PeerSpot yielding an 8.0/10 consensus across large-enterprise users. The newest case study identified (Across AI, an agentic AI startup) was published in 2026 and concerns AI workload security — a freshness signal consistent with the company's strategic pivot toward the "Containment Era" and AI security use cases. The named customer set skews toward Global 2000 and Fortune 500 organizations: AB InBev is the world's largest brewer with 80% of infrastructure in the cloud; IHG operates 6,000+ hotels in 100+ countries; Aegon holds $882B in revenue and 31.7M customers worldwide; Amundi manages more than €2 trillion in assets. This reference base strengthens the enterprise narrative but leaves the SMB and mid-market segments underdocumented. There are no public case studies from North American telecom, federal government, or major tech-sector buyers, which are potential concentration or coverage gaps.[CU017, CU018, CU019, CU020, CU021, CU022]

Named Customer Proof Table
CustomerSegment / IndustryDeployment / Use CaseProduction vs. PilotQuantified OutcomeEvidence Limitation
Republic AirwaysAviation / Hybrid cloudCNSF zero trust — hybrid cloud + on-prem unified fabricProductionMTTR days→<1 hr; +150 Mbps encrypted throughput; same-day regional deployCase study published by Aviatrix; FAA compliance depth not independently audited
AB InBevCPG / Hybrid multicloudTransit networking, CIDR NAT for M&A IP conflicts, Cost APIsProductionM&A integration unblocked; team size held constant; cost forecasting improvedNo latency, cost, or throughput numbers quantified; qualitative only
IHG Hotels & ResortsHospitality / MulticloudAWS+GCP transit backbone + Equinix edge mesh for 100+ country operationsProductionGlobal expansion simplified; business-critical app availability improvedNo uptime SLA data; Equinix partnership scope not independently detailed
Better (fintech)Financial services / MulticloudCloud Firewall + Distributed Cloud Firewall for egress and complianceProductionCompliance requirements met (PCI/security); egress costs reducedNo quantified egress cost savings; CISO quote only
AegonFinancial services / AWS + AzureMulti-cloud transit + HPE + segmentation; 3-4 click tunnel provisioningProductionTunnel setup: hours to seconds; team size not increased despite scaleM&A source-of-truth for IP overlap not independently verified
AmundiAsset management / Azure hybridMulti-region transit, FQDN filtering, ExpressRoute hybrid, packet captureProductionMulti-region Asia expansion enabled; client onboarding acceleratedNo client onboarding time metrics quantified
HAPEVPension / Hybrid (AWS + Azure)Secure datacenter edge + IaC for hybrid cloudProductionNew workload deployment <1 hr via IaC; backup times substantially reducedGerman pension regulatory compliance specifics not detailed
YaraAgriculture / Multicloud (AWS + multi-CSP)Cloud-agnostic transit networking + day-2 operationsProductionDay-2 ops simplified; multi-CSP onboarding acceleratedNo cost, latency, or throughput metrics disclosed
GN (GN Store Nord)Audio / Medical tech / AzureAzure transit + FireNet + centralized visibility + Terraform IaCProductionM&A integration supported; team of 2 managing full cloud backboneCurrently single-cloud (Azure); multicloud migration in evaluation
InmarsatSatellite / Telecom / MulticloudTransit + FireNet + Palo Alto Prisma integration + OCI spoke gatewaysProductionLegacy OCI connectivity resolved; troubleshooting acceleratedLegacy Oracle workload migration depth and timeline not disclosed

All case studies are published and hosted by Aviatrix; outcomes are customer-reported and company-curated. No independent audit of claimed outcomes was found.

[CU017, CU018, CU019, CU020, CU021, CU022]
FU003: Customer Proof Quality Matrix — Evidence Assessment by Named Account

Rates each named customer on evidence quality, outcome specificity, production confirmation, and customer-side seniority of the reference.

Evidence quality ratings assigned by analyst based on presence of quantified outcomes vs. qualitative narrative; "High" requires at least one quantified metric, "Medium" requires named executive quote with outcome claim, "Low" has named quote only.

[CU017, CU018, CU019, CU020, CU021, CU022]

6.4 Review Site Sentiment and Adoption Friction

Independent review platforms present a moderately positive but friction-aware picture. PeerSpot gives Aviatrix an 8.0/10 aggregate rating from nine in-depth reviews, with large enterprise buyers (500+ employee organizations) disproportionately represented. Recurring praise themes are multi-cloud provider support, centralized topology and visibility, VPN high-throughput bundling, CIDR overlap resolution, and Terraform module consistency. TrustRadius yields a lower 7.1/10 from nine reviews, with reviewers specifically citing missing VPN admin-down controls, limited IPS customization, alert flooding, and manual update overhead. Pricing is the most consistent friction point across all platforms. Multiple PeerSpot reviewers describe Aviatrix as "a pretty expensive solution" and note the mandatory bundling of support with the license ("you can't buy the product without support"). Vendr data corroborates this: median ACV of $194K puts Aviatrix well above typical SMB and mid-market networking software spend. The consumption-based model creates budget unpredictability for customers scaling gateway counts rapidly. Onboarding complexity and a steep learning curve are the second most common friction source: reviewers note that users unfamiliar with multi-cloud networking concepts require dedicated training before realizing value. This is consistent with the ACE program's existence as a formal prerequisites-building track. GCC regional support is cited as inadequate by at least one PeerSpot reviewer based in the UAE, who found no local Aviatrix staff for in-person technical guidance. A January 2025 critical CVE (CVE-2024-50603) in the Aviatrix Controller was actively exploited in the wild by attackers deploying cryptominers and backdoors — creating a material customer patching burden and a credibility risk during the company's zero trust marketing push.[CU029, CU030, CU031, CU032, CU033, CU034]

Retention, Repeat Usage, and Satisfaction
MetricValue / StatusSegmentConfidenceDiligence Ask
Net Revenue Retention (NRR)Not disclosedAll segmentsUnknown — no public dataRequest audited NRR for the last 4 quarters from CFO / investor dataroom
Gross Revenue Retention (GRR) / Logo ChurnNot disclosedAll segmentsUnknown — no public dataRequest logo retention cohort data; identify if 500+ figure is net of churn
Contract LengthNot disclosed; likely annual subscription with renewalEnterprise accountsLow — inferred from ACV and "yearly licensing fee" PeerSpot quoteConfirm whether multi-year contracts are available; what % of ARR is multi-year
Customer Satisfaction (PeerSpot)8.0 / 10 overall; large enterprise segment dominantLarge enterprise (50% of reviewers)Medium — 9 in-depth reviews; not statistically representativeSolicit more enterprise reference calls; prioritize FS and healthcare verticals
Customer Satisfaction (TrustRadius)7.1 / 10 overallMid-to-large enterpriseLow-medium — 9 reviews onlyDetermine if TrustRadius score diverges systematically from PeerSpot by segment
Expansion Evidence (qualitative)Multiple case studies show use-case expansion beyond initial deploymentEnterprise accounts (Aegon, IHG, AB InBev, Amundi)Low — company-curated case studies only; no NRR confirmationVerify expansion through independent buyer reference conversations
ACE Certification Stickiness8,366 community members; ongoing badge awards visible on community pageTechnical champions at enterprise accountsMedium — directly observable community statsCorrelate ACE certification density with renewal rate (not yet publicly available)

NRR, GRR, and churn are all undisclosed; all retention and satisfaction data in this table is either not available or low-confidence third-party estimates.

6.5 Retention, Expansion, and Concentration Risks

Aviatrix has not disclosed any public NRR, GRR, churn, cohort, or contract-renewal metrics. This is the single largest diligence gap in the customer analysis. Without NRR data, it is impossible to verify whether the reported 500+ customer count represents healthy durable relationships or a combination of new-logo growth masking elevated churn. The 81% ARR growth estimate (Latka, 2024) is consistent with a high-growth trajectory but provides no signal on net retention vs. new-logo composition. The land-and-expand model is evidenced qualitatively: Aegon expanded from basic VPC connectivity to enterprise-grade distributed firewalling; IHG extended from AWS to GCP and added Equinix edge fabric; AB InBev continuously uncovered new use cases ("as the AB InBev team explored additional Aviatrix capabilities, the team continued to uncover additional use-cases"). The ACE certification program with 8,366 community members also functions as a retention moat — engineers certified on the platform have meaningful switching costs. However, all expansion evidence comes from company-published case studies, and the degree of multi-product adoption (e.g., combined CNSF + DCF + HPE uptake) is not independently verified. Customer concentration risk is unknown. The public reference base is dominated by Global 2000 accounts; whether one or several of these represent a disproportionate revenue share is impossible to determine from public data. The partner channel (AWS Marketplace, Azure Marketplace, Equinix, WWT, Presidio) adds buying pathways but also introduces dependency on cloud provider committed-spend programs that could shift under contract renegotiation. Geographic concentration toward North America and Europe, with limited Middle East and APAC field coverage, constrains expansion into high-growth cloud markets.[CU035, CU036, CU037, CU038, CU039, CU040]

Expansion and Concentration Risk
Expansion Driver / Risk FactorMechanismConcentration RiskSeverityDiligence Path
Land-and-expand motionCustomers start with transit networking, then add DCF, CNSF, HPE, and compliance featuresLow if broad; unknown actual multi-product attach rateMedium — positive driver offset by unknown NRRAsk for multi-product attach rate and average product count per customer at renewal
ACE certification ecosystem8,366+ community members create internal champions; switching cost builds with depthConcentration risk: single platform dependence for engineersLow (positive) — reduces churn riskTrack ACE certification growth rate year-over-year; correlate with renewal rate
Top customer concentrationUnknown; Global 2000 reference set suggests a few large accounts may dominate ARRHigh risk if top 5 customers represent >30% of ARRHigh — no public disclosure; cannot be evaluatedRequest top-10 customer revenue concentration from dataroom
Cloud marketplace dependencyAWS and Azure Marketplace listings create committed-spend procurement channelProvider policy changes (fee structures, marketplace exclusivity) could shift costsMedium — provider leverage increases over timeConfirm what percentage of new ARR flows through marketplace vs. direct sales
Geographic concentrationNorth America and Europe dominate named customer base; GCC and APAC underrepresentedRevenue at risk if NA/EU cloud spending slows; expansion upside in underpenetrated marketsMedium — limits TAM realization and exposes revenue to regional macro shiftsRequest geographic ARR breakdown; assess go-to-market investment in APAC/GCC
Channel partner dependency (Presidio, WWT, Equinix)Named on financial services solutions page; act as influencers and implementation partnersLoss of key partner could reduce referral pipelineLow-medium — diversified partner set reduces single-partner riskConfirm which percentage of deals are influenced vs. sourced by channel partners

Top-customer concentration and multi-product attach rate are unknown; all severity assessments are based on observable patterns from public case study data.

Channel and Procurement Characteristics
Channel / Route to MarketRoleEvidenceBuyer FrictionCustomer Profile
Direct enterprise salesPrimary revenue channel; enterprise account executives and SEsNamed case studies, $194K median ACV, multi-stakeholder sign-off required6–12+ month procurement cycle; InfoSec, Networking, Finance sign-off typicalLarge enterprise (>1,000 employees); multi-cloud architecture teams
AWS MarketplaceCloud marketplace procurement; reduces PO complexity for AWS-committed buyersAviatrix listed on AWS Marketplace; prior chapter evidence of active listingAWS Marketplace fees (3–5%); still requires internal champion and POCAWS-primary buyers with EDP (Enterprise Discount Program) commitments
Azure MarketplaceCloud marketplace procurement; Azure MACC spend draw-downLive listing on marketplace.microsoft.com as of June 2026Azure Marketplace contract terms; MACC allocation politicsAzure-primary or Microsoft-ecosystem buyers; Aegon, GN (Azure users) fit profile
Channel / VARs (Presidio, WWT)Implementation and referral partners; geography-specific coverageNamed on aviatrix.ai financial services solutions pagePartner margin expectations; co-sell coordination overheadBuyers preferring SI/VAR-led implementations; regulated industries with compliance mandates
ACE practitioner communityBottom-up technical demand creation; ACE-certified engineers become internal sponsors8,366 community members; ongoing ACE badge awards on community.aviatrix.comLong bottom-up cycle before executive sponsor engagement; requires ACE ROI articulationNetwork engineers and cloud architects at enterprise accounts; self-qualified leads

Channel mix percentages are not publicly disclosed; channel roles inferred from public partner references, marketplace listings, and community data.

[CU003, CU014, CU015, CU040]
FU002: Aviatrix Adoption and Deployment Funnel — Discovery to Expansion

Illustrates the enterprise discovery-to-deployment-to-expansion path for Aviatrix, highlighting where evidence exists and where gaps remain.

Community member count is directly observed; customer count is company-claimed; all null values represent undisclosed metrics. Funnel conversion rates are unknown.

[CU001, CU003, CU013, CU015]

6.6 Exhibits

Chapter 07

07Risks

7.1 Strategic and Competitive Risks

Aviatrix's primary strategic risk is hyperscaler commoditization of its core transit-networking use case. AWS Cloud WAN provides a managed wide-area network service connecting branch offices, data centers, and VPCs with only a few clicks and centralised policy management—directly overlapping Aviatrix's transit networking value proposition. Azure Virtual WAN offers a full-mesh, hub-and-spoke managed architecture integrating routing, encryption, site-to-site VPN, and ExpressRoute, with auto-scaling and built-in Azure Firewall integration. Google Network Connectivity Center adds Partner Cross-Cloud Interconnect for AWS and Azure, enabling organisations to use GCP as a WAN backbone—squeezing the multicloud networking niche that Aviatrix pioneered. AWS Transit Gateway and Network Firewall remain the baseline competing stack for single-cloud AWS environments, offering free-tier integration and native scaling that Aviatrix must overcome on price-performance justification. Cisco Multicloud Defense and Palo Alto Prisma Cloud are established enterprise alternatives in the cloud firewall segment, with Cisco carrying existing enterprise relationships that Aviatrix's newer channel program must displace. Wiz's platform expands into detection and response capabilities while maintaining a large developer ecosystem, creating a credible adjacent threat from the CNAPP direction. The CEO-led pivot from networking to security adds a second layer of strategic risk: expanding the competitive landscape to include SASE vendors, CNAPP players, and zero-trust vendors who were previously only partial overlaps. The company risks being caught between its original networking identity and a crowded security market before the pivot is fully executed. [CR001, CR002, CR003, CR004, CR005, CR006]

Partner and Dependency Risk Register
DependencyCounterpartyRoleConcentrationFailure ScenarioSeverityMitigationResidual Exposure
AWS API and Transit GatewayAmazon Web ServicesUnderlying network fabric for majority of deploymentsVery HighAWS deprecates Aviatrix-used API endpoints or bundles competing capability into TGW free tierCriticalMulti-cloud architecture reduces single-cloud lock-in; Terraform provider abstracts some changesAWS Cloud WAN directly competes; any API friction would accelerate customer evaluation of native alternatives
Azure APIs and Virtual WANMicrosoft AzureUnderlying network fabric for Azure multi-cloud deploymentsHighAzure tightens firewall policy APIs or bundles DCF-equivalent into Azure Firewall PremiumHighAzure Virtual WAN integration; platform abstractionAzure Firewall premium and Virtual WAN already offer overlapping transit + security controls
AWS Marketplace and Azure MarketplaceAmazon / MicrosoftPrimary customer acquisition and billing channelHighMarketplace policy changes, fee structures, or vendor removalMedium-HighDual-marketplace presence; direct sales channel maintainedNo disclosed fallback revenue mix if marketplace terms worsen
Channel Partners (VARs, ISVs, CSPs)Multiple resellers and integratorsIndirect sales and service deliveryMediumNew channel program underperforms; CRO transition disrupts partner relationshipsMediumNew CRO Ken Horner (ex-Cloudflare) with partner program expertiseProgram is newly launched; no public performance data available

Dependency concentration ratings are analyst judgments based on deployment patterns described in public documentation and customer evidence. No contract terms between Aviatrix and hyperscalers are publicly available. Severity reflects platform impact if dependency fails or is withdrawn.

[CR001, CR002, CR003, CR004, CR035, CR037]
FR001: Risk Heatmap — Likelihood vs. Impact

Risks positioned by analyst-assessed likelihood (rows) and investment-impact severity (columns); cell values name the specific risk driver.

Likelihood rows from top: Low, Medium, High, Near-Certain. Ratings are analyst judgments based on public evidence and comparable SaaS risk profiles; not model-generated probabilities.

[CR001, CR007, CR008, CR016, CR021, CR029]
FR002: Risk Transmission Map — How Risks Cascade to Investment Outcomes

Directed acyclic graph showing causal pathways from root-cause risks through intermediate impacts to investment-thesis outcomes.

[CR001, CR007, CR016, CR021, CR023, CR030]

7.2 Security and Technical Risks

CVE-2024-50603, a CVSS 10.0 unauthenticated remote code execution flaw in the Aviatrix Controller, was disclosed in January 2025 and immediately weaponised in the wild. Wiz tracked multiple active incidents, finding approximately 3% of cloud enterprise environments run Aviatrix Controller and that 65% of those have a lateral movement path to administrative cloud control plane permissions. Active exploitation deployed XMRig cryptocurrency miners and the Sliver command-and-control framework, with researchers noting likely data exfiltration via enumerated cloud permissions. CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on January 16, 2025, requiring Federal Civilian Executive Branch agencies to patch by February 6, 2025. A public proof-of-concept was available upon disclosure. Aviatrix issued a hot patch in early November 2024 and permanent fixes for supported Controller versions 7.1 and 7.2 on December 19, 2024; customers on unsupported versions were exposed for the full window. Beyond the specific CVE, the Controller's central role in policy enforcement creates an inherent single-point-of-failure risk: compromise or downtime of the Controller affects policy enforcement and visibility for all managed workloads and clouds. AWS Cloud environments have been documented as allowing Aviatrix Controller privilege escalation by default, which amplifies the blast radius of any future Controller compromise. The platform's agentless architecture—while an operational strength— relies entirely on hyperscaler API stability; provider-side API changes, deprecations, or quota restrictions can silently break connectivity or enforcement policies. The steep implementation complexity documented in G2 and TrustRadius customer reviews increases the probability of operational misconfiguration that could open lateral movement paths or policy gaps. [CR007, CR008, CR009, CR010, CR011, CR012]

Operational and Security Risk Register
Failure ModeLikelihoodSeverityMitigation MaturityResidual ExposureUnresolved Gap
Controller compromise / unauthenticated RCE (CVE-2024-50603 class)Medium (patched but historical exploit occurred)CriticalPartial — patch issued, CISA mandate applied; end-of-support versions still existCustomers on EOL versions; AWS privilege escalation by default not universally hardenedNo public patch rate attestation; legacy-version exposure unquantified
Controller single point of failure — policy outage or downtimeLow-MediumHighPartial — HA configurations documented; failover not independently testedSingle control plane governs all policy; prolonged outage blocks workload traffic enforcementHA test results and SLA documentation not publicly available
Hyperscaler API breaking changes / deprecationMediumHighLow — Aviatrix publishes release notes but no documented API stability SLA from AWS / Azure / GCPSilent policy gaps or routing failures upon cloud provider API changesConfirm API-change monitoring, automated regression tests, and response SLA with vendor
Implementation complexity and misconfigurationMedium-High (G2/TrustRadius reviews cite steep learning curve)Medium-HighPartial — ACE certification program, professional services offeredCustomer misconfigurations create unmonitored east-west traffic pathsNo public data on misconfiguration incident rates or post-deployment audit practices
AI workload security (AgentGuard) — early access executionMedium (product is early access as of 2026)MediumLow — early access; no production track recordCompetitive window closes if GenAI security requirements solidify before Aviatrix GARoadmap commitment to GA timeline and customer pilot results not publicly disclosed

Failure modes ordered by severity. Likelihood ratings are analyst assessments; no Aviatrix-published incident rate data is available for private-company operations. CVE-2024-50603 likelihood reflects post-patch environment; pre-patch likelihood was Near-certain given public PoC availability.

[CR007, CR008, CR009, CR010, CR013, CR029]

7.3 Leadership, Governance, and Execution Risks

Aviatrix underwent a CEO transition in July 2023 when founder Steve Mullaney— who built the company from scratch to a $2 billion valuation—handed leadership to Doug Merritt, the former president and CEO of Splunk. At Splunk, Merritt grew annual recurring revenue from approximately $100 million to nearly $3 billion over six years. The strategic competence is well-documented, but the Aviatrix pivot is structurally different: Merritt is repositioning the company in a crowded security market rather than scaling an already-dominant analytics platform. His departure from Splunk followed a $1 billion Silver Lake private equity investment in 2021, and he has not previously completed an organic growth trajectory in a directly competitive security category. Aviatrix hired several senior leaders in 2024-2025—CRO Ken Horner (ex-Cloudflare, where he drove ~100% YoY enterprise growth for two consecutive years), CMO Scott Leatherman, and multiple VPs—indicating that significant leadership churn accompanied the pivot. The BankInfoSecurity report from July 2025 confirms that Merritt rebuilt the leadership team specifically with cybersecurity expertise, conceding that the prior team was not optimally configured for the new security direction. While the incoming bench is experienced, the simultaneous replacement of CRO, CMO, and multiple functional VPs represents elevated execution risk at the GTM layer, particularly with a new channel partner program simultaneously being launched. Key-person risk also centers on Merritt himself: without a Chief Operating Officer listed publicly, operational continuity risk is elevated if he were to depart. [CR014, CR015, CR016, CR017, CR018, CR038]

People and Execution Risk Register
Role / FunctionDependency or GapLikelihoodSeverityMitigationDiligence Path
CEO (Doug Merritt)Key-person dependency; strategy pivot owner; no public COO successionLowCriticalBoard-level succession planning expected but not confirmedConfirm board succession plan; understand equity/incentive structure and lock-in period
CRO (Ken Horner) — go-to-market executionNewly appointed from Cloudflare; no track record in cloud networking security verticalMediumHighHorner's Cloudflare enterprise success is documented; Aviatrix market differsReview pipeline metrics and partner program uptake; request 90-day GTM review
Founder departure (Steve Mullaney)Loss of founder-CEO vision, customer relationships, and internal culture-setterCompleted (departed July 2023)Medium (ongoing cultural/retention overhang)Merritt framed culture continuity in public statementsReview employee Glassdoor sentiment and attrition rates post-transition
Security product leadershipPivot requires executives with deep security domain expertise; Merritt recruited from Google and CiscoMediumHighNew hires in place as of mid-2025; knowledge transfer to Aviatrix context in progressIdentify tenure and retention of newly hired security product leaders; assess technical bench depth

Likelihood and Severity are analyst assessments. Aviatrix does not publish org chart detail, attrition rates, or equity plan structure. Row ordering reflects severity of investment-thesis impact if risk materialises.

[CR014, CR015, CR016, CR017, CR018, CR038]
FR003: Dependency Map — Critical Platform and Capital Dependencies

Key operational, financial, and go-to-market dependencies of Aviatrix and the failure scenarios each introduces.

[CR001, CR002, CR003, CR034, CR035, CR043]

7.4 Financial and Valuation Risks

Aviatrix is a private-undisclosed company with no public financial statements or investor disclosures. Its last confirmed external funding event—$200 million led by TCV at a $2 billion valuation—was announced in September 2021. Only a single SEC Form D exempt offering notice (filed November 2019, for a prior raise) is publicly accessible; no subsequent Form D amendments are filed publicly for the Series E or any later rounds. This means the company's current ARR, burn rate, gross margin, cash position, and investor covenants are entirely unknown from public sources. Third-party analyst services (Sacra, CBInsights, GetLatka, GrowJo) publish estimates of Aviatrix's ARR but do so without access to audited financials and carry explicit disclaimers about accuracy. The private SaaS valuation environment deteriorated sharply between 2021 and 2024, with typical compression of 40–60% from 2021 peak multiples; Aviatrix's $2 billion book valuation is therefore at meaningful downside risk on any secondary market transaction or next fundraise unless ARR growth has been exceptional. Revenue concentration is also unknown: the company discloses 500+ enterprise customers including 10% of Fortune 500, but does not break out revenue by customer or vertical, making concentration risk unquantifiable without diligence access. The combination of financial opacity, unverified ARR, and a strategic pivot increases uncertainty for any prospective investor or acquirer attempting to underwrite the thesis. [CR019, CR020, CR021, CR022, CR023, CR033]

7.5 Regulatory, Legal, and Compliance Risks

Aviatrix navigates an increasingly demanding regulatory environment across three primary vectors. First, CISA's Known Exploited Vulnerabilities catalog placed CVE-2024-50603 on the federal patch mandate list, requiring FCEB agencies to remediate by February 6, 2025—exposing Aviatrix to potential loss of federal enterprise relationships if customers on supported versions were not patched in time. Second, Aviatrix's customers in regulated verticals (financial services, government, healthcare) increasingly require NIST SP 800-207 Zero Trust Architecture alignment, FedRAMP authorization for government cloud deployments, and EU GDPR/NIS2 compliance for European operations. Aviatrix's trust center claims SOC 2 compliance but does not publicly surface the audit scope or Type II attestation report, creating a transparency gap that enterprise procurement teams must close through direct inquiry. Third, the CSA Cloud Controls Matrix defines security requirements that cloud service providers must demonstrate to enterprise customers—Aviatrix's competitive position depends on continuous alignment with evolving CCM versions. No known regulatory enforcement actions, IP litigation, or class-action filings have been identified against Aviatrix as of June 2026, but the CVE exploitation campaign creates latent liability risk if customers can demonstrate that delayed disclosure or insufficient patch notification contributed to damages. Aviatrix's SEC Form D (2019) shows Delaware incorporation with a Santa Clara, CA headquarters—standard for a venture-backed company—but the absence of any publicly filed follow-on funding documents after the $200M Series E limits regulatory and investor transparency. [CR024, CR025, CR026, CR027, CR028, CR040]

Regulatory / Legal Risk Register
Rule / CaseJurisdictionStatusLikelihoodSeverityMitigationResidual ExposureDiligence Path
CISA KEV CVE-2024-50603 federal patch mandateUnited StatesActive (patched versions released; FCEB deadline Feb 6 2025)HighCriticalPatch to v7.1.4191 / v7.2.4996; restrict Controller internet accessCustomers on End-of-Support versions remain exposed; no public attestation of patch coverageConfirm customer patch coverage via support telemetry; request exception list
NIST SP 800-207 Zero Trust Architecture complianceUnited States (Federal/Enterprise)Ongoing requirement; Aviatrix claims alignment but no independent attestationHighHighArchitecture alignment documented in Aviatrix platform materials; CISA ZT maturity model referencedNo third-party attestation of NIST 800-207 conformance in procurement contextRequest ZT compliance mapping document and independent assessment during diligence
GDPR / EU NIS2 data sovereigntyEuropean UnionOngoing; Aviatrix DPA / sub-processor agreements not publicly visibleMediumHighStandard SaaS GDPR DPA expected; Controller data-residency options unclearEU enterprise customers may face procurement delays if data flows not mappedRequest DPA terms, sub-processor list, and data residency documentation
FedRAMP authorization for US government cloudUnited States (Federal)Not yet FedRAMP authorized (not on FedRAMP marketplace as of 2026-06-23)LowHighNone confirmed; FedRAMP path would require significant compliance investmentBlocks direct federal cloud deployments; government customers must use 3rd-party authorized wrappersClarify FedRAMP roadmap and whether existing FCEB deployments rely on agency ATOs
Latent CVE liability — customer damages from exploitation campaignUnited States (civil)No known litigation filed as of June 2026; exploitation occurred Jan 2025LowMediumAviatrix worked with affected customers; proactive patch notification documentedRisk of class action or individual claims if customers prove delayed disclosure or inadequate notificationReview customer communications timeline; confirm indemnification language in MSAs

Rows ordered by severity. FedRAMP status and litigation risk based on public sources as of 2026-06-23; private company legal history is not publicly disclosed. GDPR/NIS2 row reflects European customer exposure, not confirmed enforcement actions. Likelihood and Severity assessments are analyst judgments derived from public evidence.

[CR007, CR008, CR024, CR025, CR026, CR027]
Mitigation and Kill Criteria
RiskMonitorable TriggerThreshold / EventAction Implication
Controller security CVE (repeat)CISA KEV catalog additions for Aviatrix productsSecond CVSS ≥ 9.0 Aviatrix CVE added to KEV within 18 months of CVE-2024-50603Thesis break — structural security design flaw; reassess investment position
Hyperscaler feature parityAWS / Azure public announcements of native multicloud firewall or zero-trust networkingAWS or Azure GA of zero-trust workload enforcement equivalent to Aviatrix DCF at no incremental costThesis stress — accelerate evaluation of Aviatrix differentiation and pricing power
Strategic pivot failureARR growth and win/loss rate in security vs. networking use casesARR growth below 30% YoY for two consecutive quarters, or security ACV below 50% of new bookingsReassess whether pivot is succeeding before next capital event
Leadership attritionPublic announcements of departures for CEO, CRO, or CPO within 12 months of hireTwo or more C-suite or VP departures within one year of appointmentGovernance concern — request board-level explanation and succession plan
Financial runway shortfallFundraising announcements, bridge rounds, or down-round press coverageAny public indication of down round or capital constraintImmediate diligence on cash position, ARR, and investor covenants

Kill criteria are analyst-defined thresholds based on publicly observable signals. Aviatrix does not publish ARR, win/loss ratios, or financial disclosures. Thresholds should be calibrated with Aviatrix management during formal diligence.

[CR007, CR008, CR016, CR017, CR021, CR023]

7.6 Exhibits

Chapter 08

08Valuation

8.1 Financing History and Current Valuation Context

Aviatrix completed six disclosed funding rounds totaling approximately $346M–$414M (sources vary) between 2015 and 2022. The defining event was the September 2021 Series E: $200M raised at a $2 billion post-money valuation, co-led by TCV (with TCV General Partner Tim McAdam joining the board) and joined by Insight Partners and Tiger Global alongside existing investors CRV, General Catalyst, and Greenspring Associates. At the time, Aviatrix claimed $15.7M ARR (April 2021 per Latka), implying a Series E entry multiple of approximately 127x ARR — extreme even by peak-ZIRP standards and difficult to reconcile with any forward-growth model unless ARR was significantly understated. No new primary equity round has been announced in the 4.5+ years since the Series E. The funding gap is ambiguous: it may indicate capital efficiency and internal cash generation, difficulty accessing new capital on acceptable terms, or deliberate patience waiting for better IPO conditions. As of June 23, 2026, Forge's pre-IPO platform lists Aviatrix (AVIA.PVT) with no current "Last Matched Price," indicating secondary-market illiquidity. Yahoo Finance and PM Insights reference a Forge price of $3.48/share as of June 22, 2026. Using the Forge-reported shares outstanding of 11,806,794 for one preferred class (likely incomplete versus fully-diluted share count), and cross-referencing with the $411M implied valuation derived elsewhere, the fully-diluted share count is estimated at approximately 118M shares. EquityZen separately reports total funding of $414M and 550+ customers, while Tracxn and Crunchbase report $346M and various figures. These discrepancies reflect normal data aggregator variance for private companies and do not indicate material discrepancies in the financing record. The SEC Form D accession 0001792033-19-000002 (November 2019) confirms Aviatrix Systems, Inc. as a Delaware corporation with a business address at 2901 Tasman Drive, Suite 109, Santa Clara, CA 95054 and a $46M Series C offering. No S-1 or comparable IPO filing appears in SEC EDGAR as of June 2026, confirming Aviatrix remains in private status. [CV001, CV002, CV003, CV004, CV005, CV006]

Aviatrix Historical Financing Rounds
RoundDateAmountPost-Money ValuationLead Investor(s)Implied ARR Multiple
Series ASep 2015$10MNot disclosedFormation 8N/A — pre-revenue stage
Series BJan 2017$15MNot disclosedCRV, Formation 8N/A — early revenue stage
Series COct 2019$46MNot disclosedCRV~6–12x (estimated $5–8M ARR at close)
Series DFeb 2021$75MNot disclosedGeneral Catalyst~5–10x (estimated $10–15M ARR at close)
Series ESep 2021$200M$2,000MTCV, Insight Partners, Tiger Global~127x (Latka $15.7M ARR Apr 2021 anchor)
Secondary (Forge/Yahoo)Jun 2026 (last signal)N/A~$411M impliedOpen secondary market~6–7x (Latka $64M ARR Oct 2024 anchor)
Total Raised (primary)~$346M–$414MMultiple (see above)

Funding amounts and dates from Tracxn, Crunchbase, and EquityZen; sources vary slightly. Post-money valuation disclosed only for Series E. ARR multiples for early rounds are estimated from Latka data points and should be treated as illustrative. Secondary pricing from Yahoo Finance / Forge as of June 22–23, 2026; shares outstanding used for implied valuation derived from cross-referencing multiple sources.

[CV001, CV002, CV003, CV004, CV006, CV008]

8.2 Public Comparable Set and Market Multiple Analysis

Aviatrix operates at the intersection of cloud networking and network security, placing it in a comparable set that spans pure-play cloud security vendors (Zscaler, CrowdStrike), broad cybersecurity platforms (Palo Alto Networks, Fortinet), and infrastructure-adjacent networking/identity plays (Cloudflare, Okta). As of June 2026, the publicly observable EV/revenue multiples span a wide range reflecting divergent growth profiles and market narratives. Zscaler (ZS), the most direct functional analog as a cloud-native security vendor, trades at approximately 6.6x trailing-twelve-months revenue — a severe compression from its October 2025 peak P/S ratio of 18.2x (per Macrotrends historical data). Zscaler's market cap has declined approximately 55% year-over-year, driven by slower growth outlook and AI-disruption concerns. Its FY2025 10-K (SEC filing, September 2025) confirms $2,673M revenue (23.3% growth) and continued net losses of $41.5M. Palo Alto Networks (PANW) commands a 22.4x multiple on its platform-consolidation premium and strong ARR of $3.5B+. CrowdStrike (CRWD, 34.5x) and Cloudflare (NET, 34.9x) trade at high multiples on superior growth rates (21-32%). Fortinet (FTNT, 15.3x) benefits from diversified hardware-software model with positive earnings. Okta (OKTA, 6.9x) trades at a discount reflecting slower growth and identity market saturation. The relevant valuation band for Aviatrix — a mid-scale private company with uncertain ARR growth and incomplete financials — centers on the 5–10x range, reflecting a peer-company blend of the slower-growth comps (ZS, OKTA, FTNT) with a private-company discount of 20–35% versus comparable public peers. Damodaran's January 2025 dataset confirms a median EV/Sales of 9.01x for EBITDA-positive software companies and 9.56x for Internet software firms, consistent with this range. DealMatrix benchmarks the Privacy and Security sector at a median EV/Sales of approximately 7.3x. [CV011, CV012, CV013, CV014, CV015, CV016]

Comparable Valuation Table
Company (Ticker)Product FocusMarket Cap (June 2026)TTM RevenueApprox. EV/RevenueRelevance to AviatrixLimitation as Comp
Zscaler (ZS)Cloud-native zero-trust security$20.9B$3.17B~6.6xHigh — cloud-native enterprise security, SaaS subscription model, no hardwareMultiple severely compressed (–55% YoY); growth decelerated to 23%; not profitable on GAAP basis.
Palo Alto Networks (PANW)Broad cybersecurity platform (NGFW + cloud + SOC)$237.7B$10.6B~22.4xHigh — enterprise security, cloud security module overlaps Aviatrix use cases10x Aviatrix's scale; platform breadth commands structural premium; GAAP profitable.
CrowdStrike (CRWD)Endpoint + identity + cloud security platform$175.5B$5.09B~34.5xMedium — different product (endpoint vs. networking), but similar SaaS model and buyerPremium multiple reflects high growth (21.7%) and Falcon platform lock-in; not directly comparable.
Cloudflare (NET)Edge networking + zero-trust + DDoS + AI gateway$81.2B$2.33B~34.9xMedium — networking/security hybrid; closest to Aviatrix's network-centric approachHigher-growth (29.9%), consumer+enterprise mix, and platform optionality drive premium vs. Aviatrix.
Fortinet (FTNT)NGFW + SD-WAN + FortiOS security fabric$108.4B$7.11B~15.3xMedium-Low — on-premises/hybrid hardware-software; different delivery modelGAAP profitable ($1.85B net income); hardware component and slower growth (14.2%) limit SaaS comparability.
Okta (OKTA)Cloud identity and access management$20.6B$3.0B~6.9xLow-Medium — different product (identity vs. networking), but similar buyer and SaaS modelSlowest growth (11.7%) and identity-market headwinds compress multiple; signals risk for slower-growth Aviatrix scenarios.

Market cap and TTM revenue from StockAnalysis.com as of June 2026, sourced from S&P Global Market Intelligence. EV/Revenue calculated as market cap ÷ TTM revenue (approximate proxy; true EV would subtract cash/add debt). YoY market cap change reflects trailing 12 months.

[CV011, CV012, CV013, CV014, CV015, CV016]
FV002: Valuation Sensitivity — EV/ARR Multiple vs. ARR

Illustrates how enterprise value shifts across a 3x–10x EV/ARR multiple range at three ARR scenarios ($70M bear, $85M base, $95M bull), with the Forge secondary-implied $411M and Series E $2B marked for reference.

All ARR values are third-party estimates. Multiple range derived from public cybersecurity peer set with 20–35% private discount. Series E $2B is a benchmark mark, not a current investable price.

[CV031, CV032, CV033, CV034]

8.3 Private Market Signals, ARR Framework, and Uncertainty Disclosure

Two structural challenges define this valuation analysis: (1) Aviatrix does not publicly disclose financial results, making all ARR and revenue figures third-party estimates; and (2) the secondary market for Aviatrix shares is illiquid, making secondary prices unreliable as a precision valuation tool. These limitations are material and must be front-of-mind when interpreting any scenario range. The best available ARR anchor is Latka's $63.9M estimate for October 2024 (with a prior point of $35.3M in November 2023, implying ~81% YoY growth). Growjo's $135M algorithmic estimate is likely upward-biased. Using the Latka trajectory and applying a more conservative 25–35% growth rate to mid-2026 yields an estimated ARR of $85–97M. Aviatrix's strategic pivot from multicloud networking to cloud network security introduces additional uncertainty: ARR recognition patterns may shift as product packaging changes. The SaaS Capital Index (SCI) provides important market context. Its Q1 2026 analysis confirmed decade-plus lows in ARR multiples as AI existential-risk narratives dominated market sentiment, with ARRG multiples (ARR multiple divided by growth rate) still above prior lows, suggesting further vulnerability if growth decelerates. Private SaaS companies typically trade at a 20–35% discount to public comparables of similar growth and scale, reflecting liquidity premium, information asymmetry, and preference overhang. Applying this to the public comp EV/revenue range of 6–10x (for similar-profile peers) yields a private-market-comparable range of approximately 4–8x ARR for Aviatrix. The Forge/Yahoo secondary price ($3.48/share → $411M) is broadly consistent with the base scenario, but the absence of recent matched trades signals extreme illiquidity. Secondary prices for companies with heavy preference stacks (Series E at $2B) can be structurally misleading: preferred shareholders with liquidation preferences may extract most of the enterprise value at any exit below $2B, leaving secondary markets to price common/junior preferred in a structurally disadvantaged position. [CV023, CV024, CV025, CV027, CV028, CV029]

FV003: Valuation / Return Range — Scenario Outcomes

Low-to-high enterprise value and implied Series E investor return across bull, base, and bear scenarios, illustrating the challenging return profile for Series E holders versus secondary buyers.

Ranges are based on estimated ARR × EV/ARR multiple scenarios. Return is for hypothetical Series E investor assuming $200M entry at $2B post-money. Does not model preference waterfall or dilution; actual per-share returns require full cap table analysis.

[CV031, CV032, CV033, CV035, CV036]

8.4 Scenario Analysis and Valuation Ranges

Three scenarios are modeled using ARR as the primary value driver and EV/ARR as the multiple. All scenarios use third-party-estimated ARR inputs and should be treated as analytical constructs, not confirmed projections. The bull case reflects successful execution of the cloud security pivot, strong ARR growth to ~$95M by mid-2026, and a premium 8–10x multiple driven by sector re-rating and scarcity value as a private cloud security pure-play. This implies a valuation of $760M–$950M. Achieving this scenario requires sustained 25%+ growth, margin improvement, and improved market sentiment toward cloud security multiples. The base case — most likely given available evidence — assumes $85M ARR (in-line with conservative extrapolation from Latka) and a 5–7x multiple reflecting current SaaS capital market conditions, yielding $425M–$595M. This range brackets the Forge-implied $411M, which represents the lower bound given illiquidity discounts. The bear case assumes ARR growth deceleration to $70M (potentially reflecting disruption from AI-native networking tools, hyperscaler feature encroachment, or execution risk during the security pivot) and further multiple compression to 3–4x, yielding $210M–$280M. This scenario is triggered by competitive displacement or market conditions continuing to deteriorate. Sensitivity analysis reveals that multiple is the dominant driver: moving from 4x to 8x at $85M ARR shifts valuation from $340M to $680M. ARR uncertainty is secondary but material: a $20M ARR miss at 6x multiple costs $120M in value. The investment return profile is unfavorable at any price near the $2B Series E: Series E investors would need a $10B+ exit (5× return) to achieve institutional hurdle rates, requiring Aviatrix to reach $1B+ ARR at 8–10x multiples — a multi-decade trajectory under current growth assumptions. Secondary buyers at $411M face more realistic return math but remain exposed to preference-stack dilution. [CV031, CV032, CV033, CV034, CV035, CV036]

Bull / Base / Bear Scenario Table
ScenarioARR Assumption (mid-2026)Multiple Range (EV/ARR)Implied Valuation RangeKey RiskProbability Signal
Bull~$95M (30–35% YoY growth from Oct 2024 Latka anchor)8–10x (cloud security premium; sector re-rating)$760M–$950MRequires sustained growth and SaaS multiple recovery; PANW/CRWD competition intensifying.Low-to-medium; dependent on macro/sentiment recovery and confirmed ARR growth.
Base~$85M (20–25% YoY growth; conservative extrapolation)5–7x (current mid-comp peer range, private discount applied)$425M–$595MExecution risk on security pivot; preference overhang limits common equity upside.Medium; broadly consistent with Forge secondary-implied $411M at the lower bound.
Bear~$70M (growth stall or disruption scenario)3–4x (distressed/down-round market or hyperscaler displacement)$210M–$280MHyperscaler encroachment, AI-native networking tools, or further SaaS multiple compression.Low-to-medium; would likely trigger a strategic process or down-round primary.

All ARR inputs are third-party estimated with no direct company disclosure. Multiple ranges derived from public cybersecurity comparable set (ZS 6.6x, FTNT 15.3x, PANW 22.4x) with 20–35% private discount applied. Scenarios are analytical constructs, not forecasts.

[CV031, CV032, CV033, CV034, CV035]

8.5 Investment Stance, Diligence Asks, and Thesis-Break Triggers

The investment stance on Aviatrix is Hold/Watch — not actionable as a new investment at any price near the Series E mark, and requiring significant evidence accumulation before a secondary purchase at the ~$411M level becomes compelling. The thesis rests on genuine product differentiation in cloud-agnostic multicloud networking/security, a large addressable market, and a strong early customer base (550+ enterprises). The anti-thesis centers on the $2B preference overhang, unconfirmed financials, sector multiple compression, and execution risk from a mid-stage product strategy pivot. The recommendation logic flows from five factors: (1) Market/Proof — the cloud security market is large and growing, Aviatrix has verifiable customer proof, but scale remains unconfirmed; (2) Product/Moat — multicloud-native architecture is defensible but increasingly challenged by PANW, Cisco, and hyperscalers; (3) Financials — ARR estimates suggest moderate growth but the $200M raise with limited financial transparency is a red flag; (4) Risks — competitive, execution, and preference-overhang risks are high; (5) Valuation — secondary at $411M is consistent with base case but not a discount, and the $2B entry is undefendable. The final diligence asks center on confirming ARR ($80–100M target range), gross margin (should be 70%+ for SaaS), net retention rate (>110% for strong SaaS), preference stack details, board composition, and any M&A approaches or strategic process. Thesis-break triggers include ARR below $60M (suggesting growth reversal), confirmed hyperscaler feature encroachment displacing core Aviatrix use cases, or a down-round primary raise below $500M pre-money. Exit readiness is low: Aviatrix lacks the $150M+ ARR scale, public comparable margins, and clean preference waterfall structure necessary for an imminent IPO. A 2027–2028 IPO window is possible if growth continues and markets recover, but relies on multiple favorable conditions. M&A remains the more likely exit path in the 2026–2028 horizon, at $400M–$700M unless scale substantially improves. [CV039, CV040, CV041, CV042, CV043, CV044]

Recommendation Summary Table
DimensionJudgmentRationaleEvidence QualityAction Implication
Investment StanceHold / WatchSecondary at ~$411M is base-case consistent but not discounted; $2B entry is undefendable.Medium — ARR unconfirmedDo not buy at Series E mark; reassess if confirmed ARR >$100M emerges.
ConfidenceLow–MediumAll financial data is third-party estimated; no public disclosure of ARR or margins.Low — private opacityRequire audited financials or credible management disclosures before conviction.
Risk RatingHighPreference overhang, sector compression, execution pivot risk, and illiquid secondary market.Medium — corroborated across sourcesSize conservatively; any entry above $500M pre-money requires strong ARR evidence.
Valuation StanceFairly-valued to Over-valued at Series E; Base-case at secondaryBase range $425M–$595M; Series E $2B requires $250–333M ARR at current multiples.Medium — scenario range based on public comp setSecondary at $400–500M is investable only with confirmed ARR; avoid Series E secondary paper.

All judgments are based on third-party estimated ARR and publicly observable comparable multiples as of June 2026. Aviatrix has not disclosed financial results publicly.

[CV031, CV032, CV033, CV034, CV035, CV036]
Thesis / Anti-Thesis Table
Argument TypeArgumentWhat Would Change the View
ThesisCloud-agnostic multicloud networking/security architecture is defensible: enterprises with 3+ cloud environments need a vendor-neutral control plane that hyperscalers cannot neutralize.Hyperscalers expand native cross-cloud management with comparable Aviatrix feature parity at lower cost, or a major security vendor acquires the category.
ThesisAviatrix's pivot to cloud network security aligns with the fastest-growing segment of enterprise security spend, potentially expanding TAM and justifying higher multiples.Pivot stalls: ARR growth decelerates below 15%, indicating the networking-to-security transition is not resonating with buyers.
Anti-ThesisThe $2B Series E valuation embedded assumptions of hyperscale ARR growth that have not materialized at the expected rate; the preference overhang makes common equity nearly worthless at any realistic near-term exit.New primary round at $2B+ pre-money, or confirmed $200M+ ARR at strong margins, would force a reassessment.
Anti-ThesisSaaS sector multiple compression — exacerbated by AI existential risk narratives in Q1 2026 — creates a structural headwind: even strong ARR growth will not restore ZIRP-era multiples, and Aviatrix needs those multiples to justify its last primary mark.Sector re-rating (ZS/CRWD multiples return to 15x+), combined with demonstrated profitability and ARR scale, would make the $2B a recoverable mark over a 5–7 year horizon.

All thesis/anti-thesis arguments are synthesized from publicly available competitor, market, and financial data. ARR figures are third-party estimated.

[CV039, CV040, CV023, CV025, CV046]
Thesis-Break and Kill Triggers Table
TriggerThreshold / EventTransmission to ThesisAction Implication
ARR Growth ReversalConfirmed ARR below $60M or YoY growth below 10%Destroys base scenario; forces multiple compression to 3x or below; $210M or less enterprise valueTrigger strategic review; flag for M&A fire-sale risk or down-round primary.
Hyperscaler DisplacementAWS, Azure, or GCP launches native multicloud networking feature set displacing Aviatrix's gateway architectureErodes TAM; competitive moat weakens; NRR contracts; valuation to bear case or belowExit secondary positions; monitor quarterly product announcements from all three hyperscalers.
Down-Round Primary Capital RaiseNew equity round at pre-money valuation below $500MConfirms insider assessment of value below Series E; signals preference structure restructuring likelyImmediate reassessment; down-round indicates distress or significant value destruction.
SaaS Sector Re-Rating ReversalZS and peer median EV/Revenue falls below 4x (from 6.6x today)Compresses Aviatrix base case below $340M; at that point M&A at <$500M becomes the only liquidity pathHedge with sector index put or reduce exposure to late-stage private SaaS.
Management Team DepartureCEO Steve Mullaney or CTO departure without strategic successor planExecution risk on security pivot; customer confidence at risk; accelerates competitive threatsDemand management transition clarity before any investment decision.

Thresholds are illustrative and should be calibrated to confirmed ARR data once available from primary sources.

[CV032, CV033, CV034, CV038, CV043]
Final Diligence Asks Table
TopicMissing EvidenceWhy It MattersOwner / Diligence Path
Confirmed ARR and Growth RateAviatrix has not publicly disclosed ARR, revenue, or growth rate; only third-party estimates ($64–135M range) are available.ARR is the single most important valuation driver; a $30M ARR miss shifts base-case enterprise value by $150–210M.Management disclosure in a formal diligence process; request audited annual financials or management-prepared financial statements.
Gross Margin and Cost StructureNo public data on gross margin, OpEx breakdown, or path to profitability.Gross margin below 65% would disqualify SaaS premium multiples; profitability timeline affects dilution needs.Request income statement data: cost of revenue, R&D, S&M, G&A, and any operating profit metrics.
Net Revenue Retention (NRR) RateNo disclosed NRR; customer expansion or churn patterns are unknown.NRR > 120% would support high-multiple scenario; NRR < 100% signals contraction risk.Request cohort analysis or ARR bridge (new ARR, expansion, churn) by vintage.
Cap Table and Preference WaterfallLiquidation preference structure for Series A–E is not publicly disclosed; preference multiple and participation rights unknown.Preference overhang determines common stock value in any exit below $2B; critical for secondary buyers.Request cap table with preference terms, anti-dilution provisions, and board observer rights.
IPO or Strategic Process StatusNo S-1, IPO roadshow, or confirmed M&A process as of June 2026; exit timeline is entirely opaque.Without an exit catalyst, illiquidity discount is severe; secondary investors face indefinite hold periods.Direct management inquiry; monitor SEC EDGAR for any S-1, Form 8-A, or investment banker engagement announcements.

Diligence asks reflect the absence of any public financial disclosure by Aviatrix as a private company. All items are required before any conviction investment recommendation.

[CV030, CV038, CV041, CV044, CV045]
FV001: Recommendation Logic Flow

Chain from market/proof, product/moat, financials, risks, and valuation inputs to the Hold/Watch investment recommendation for Aviatrix.

Recommendation logic is qualitative synthesis of all prior chapter evidence; node weights are not formally calibrated.

[CV031, CV032, CV033, CV039, CV040]
FV004: Investment KPIs — IC-Ready Scoring

Investment committee-ready scoring across market opportunity, product proof, competitive moat, financial economics, risk profile, valuation, and evidence quality.

KPI scores are qualitative analyst judgment on a 1–10 scale. Not a quantitative model output. Intended as an IC discussion framework, not a definitive rating.

[CV039, CV040, CV042, CV046]

8.6 Exhibits

Disclaimer

This report is for informational purposes only and is not investment advice.

Evidence index

Claims
IDStatementConfidenceSources
CO001 Aviatrix is headquartered in Santa Clara, California. High SO001, SO009
CO002 Aviatrix was founded in 2014. Medium SO003
CO003 The company name 'Aviatrix' means 'female pilot' and honors the company's female founder. Medium SO002
CO004 Aviatrix's primary platform is the Cloud Native Security Fabric (CNSF), which provides cloud network security at the workload level. High SO001, SO011, SO016
CO005 Aviatrix is trusted by more than 500 of the world's leading enterprises globally. High SO002, SO006, SO012
CO006 Aviatrix's customer base includes approximately 10% of the Fortune 500. Medium SO006
CO007 Aviatrix closed a $200 million Series E financing round in September 2021. High SO003, SO005, SO020
CO008 Aviatrix's Series E valued the company at $2 billion, achieving unicorn status. High SO003, SO005, SO020
CO009 Aviatrix's Series E financing round was led by TCV (Technology Crossover Ventures). High SO003, SO020
CO010 Doug Merritt became CEO and President of Aviatrix effective July 6, 2023. High SO003, SO004
CO011 Doug Merritt served as CEO of Splunk from 2015 to 2021, during which Splunk's ARR grew from approximately $100 million to nearly $3 billion. High SO004, SO005, SO007
CO012 Steve Mullaney served as Aviatrix CEO from 2019 to July 2023, during which the company achieved a $2 billion valuation. High SO003, SO004
CO013 Steve Mullaney previously served as CEO of Nicira, which was acquired by VMware in 2012, before joining Aviatrix in 2019. Medium SO003
CO014 Mullaney described his leadership sweet spot as the $1M–$100M stage and acknowledged Doug Merritt was better suited for the $100M–$1B stage, facilitating the CEO succession. High SO003, SO004
CO015 Ken Horner joined Aviatrix as CRO, having previously driven nearly 100% year-over-year enterprise growth for two consecutive years at Cloudflare. Medium SO006
CO016 Scott Leatherman serves as Aviatrix's CMO, with prior experience at Veritone, Interana (acquired by Twitter), and SAP. Medium SO006
CO017 Varsha Vig serves as Aviatrix's CHRO, previously at Paxos, Lyft, McDonald's, and Compass. High SO004, SO005
CO018 Chris McHenry serves as Chief Product Officer at Aviatrix as of June 2026. High SO013, SO004
CO019 Nick Sturiale, Managing Partner at Ignition Partners, serves on Aviatrix's board and states he has been involved in 100+ startups. High SO002, SO018
CO020 Aviatrix's GitHub organization AviatrixSystems has 39+ public repositories, including Terraform providers, Kubernetes firewall charts, and ACE certification labs, with active commits as of June 2026. Medium SO009
CO021 Aviatrix operates the ACE (Aviatrix Certified Engineer) Program, described by the company as the industry's leading multicloud networking and security certification. High SO002, SO010, SO015
CO022 The Aviatrix Distributed Cloud Firewall (DCF) was launched in 2023 and won a Cybersecurity Excellence Award. High SO004, SO013
CO023 Aviatrix was named to the inaugural Fortune Cyber 60 list following its DCF launch. Medium SO004
CO024 In June 2026, Aviatrix announced integration of its Cloud Native Security Fabric with Microsoft Agent Control Specification, enabling single-policy-file AI agent governance across AWS, Azure, Google Cloud, and Kubernetes. High SO013, SO010
CO025 The Microsoft ACS integration was unveiled at Microsoft Build 2026 and is available to all Aviatrix customers at no additional cost through an Early Access program. High SO013, SO010
CO026 Aviatrix's physical address is 2901 Tasman Drive, Santa Clara, CA 95054. Medium SO009
CO027 A July 2025 interview with CEO Merritt reveals that customers were already choosing Aviatrix primarily for security rather than networking, indicating the pivot was reactive to customer feedback. Medium SO007
CO028 To execute the security pivot, Merritt restructured Aviatrix's leadership team by recruiting executives with deep cybersecurity expertise from Google and Cisco. Medium SO007
CO029 Aviatrix had approximately 350 employees at the time of the July 2023 CEO transition. Medium SO003
CO030 Aviatrix received early-stage venture backing from Ignition Partners in pre-Series E rounds including Series B and/or C. Medium SO002, SO018
CO031 Aviatrix's target buyers include cloud security teams, cloud architects, network engineering teams, and FinOps practitioners. High SO011, SO014
CO032 Aviatrix's mission is to empower companies to work efficiently, securely, and with modern networking capabilities across multicloud environments. High SO002, SO001
CO033 As of June 2026, Aviatrix's newsroom lists 462+ news items, reflecting extensive public communications since founding. High SO010, SO013
CO034 The Cloud Native Security Fabric enforces policy at the workload level rather than at a central transit firewall, enabling universal policy propagation in subseconds and limiting blast radius to a single workload. High SO011, SO013
CO035 Aviatrix operates a remote-first, globally distributed workforce culture. Medium SO014
CO036 Aviatrix's annual recurring revenue (ARR) and profitability are not publicly disclosed; the company is a private entity with no SEC filing obligations. Medium
CO037 Aviatrix was recognized by Deloitte Fast 500 as a fast-growing company, based on company-reported recognition in press release content, though the Deloitte Fast 500 page was inaccessible during fetching. Low SO023
CO038 Aviatrix's cloud security solutions target enterprises in regulated industries including financial services, healthcare, manufacturing, retail, and software. High SO011, SO012
CO039 92% of organizations are multi-cloud, each with unique and incompatible security tools—a market condition Aviatrix's CNSF is designed to address. Medium SO011
CO040 Aviatrix's customers page features AB InBev, IHG Hotels & Resorts, Republic Airways, and Better as named reference customers. High SO012, SO017
CM001 MarketsandMarkets projects the global cloud security market at USD 34.37 billion in 2026, growing to USD 59.34 billion by 2031 at a CAGR of 11.5%. Medium SM001
CM002 MarketsandMarkets estimates the cloud security market at USD 30.60 billion in 2025, growing to USD 34.37 billion in 2026, reflecting approximately 12% annual growth. Medium SM001
CM003 Within the cloud security market, the CNAPP (cloud-native application protection platform) segment is expected to register the highest sub-category CAGR of 14.6% from 2026 to 2031 (MarketsandMarkets). Medium SM001
CM004 North America is expected to account for the largest share (32.2%) of the global cloud security market in 2026 (MarketsandMarkets). Medium SM001
CM005 Grand View Research estimates the global cloud security market at USD 35.84 billion in 2024, projected to reach USD 75.26 billion by 2030 at a CAGR of 13.3%. Medium SM002
CM006 Large enterprises accounted for more than 74% of cloud security market revenue share in 2024 (Grand View Research). Medium SM002
CM007 The Thales Cloud Security Study 2024 found that 44% of enterprises reported cloud security incidents and 14% experienced data breaches in the past year (cited by Grand View Research). Medium SM002
CM008 The hybrid cloud deployment segment within cloud security is expected to grow at a CAGR of 13.7% from 2025 to 2030, driven by business continuity and cross-environment monitoring needs (Grand View Research). Medium SM002
CM009 The global network security market is expected to grow from USD 84.50 billion in 2025 to USD 119.70 billion by 2030 at a CAGR of 7.2% (MarketsandMarkets, December 2025). Medium SM004
CM010 The global Zero Trust Security market is projected to reach USD 78.7 billion by 2029 at a CAGR of 16.6% (MarketsandMarkets, July 2024). Medium SM004
CM011 The global Zero Trust Architecture market is projected to reach USD 38.5 billion by 2028 at a CAGR of 17.3% (MarketsandMarkets, November 2023). Medium SM004
CM012 The global SASE market is expected to reach USD 68.06 billion by 2030 from USD 19.19 billion in 2026, at a CAGR of 28.8% from 2026 to 2032 (MarketsandMarkets, June 2026). Medium SM005
CM013 The global Security Service Edge (SSE) market is expected to grow from USD 6.08 billion in 2024 to USD 23.01 billion by 2030 at a CAGR of 24.8% (MarketsandMarkets, March 2025). Medium SM005
CM014 89% of organizations reported using multi-cloud in Flexera's 2024 State of the Cloud Report, up from 87% the prior year. Medium SM003
CM015 61% of large enterprises (10,000+ employees) use multi-cloud security tools according to Flexera's 2024 State of the Cloud Report. Medium SM003
CM016 Managing cloud spending has been the top challenge for organizations two consecutive years (2023 and 2024), with over 29% of organizations spending more than USD 12 million annually on public cloud (Flexera 2024). Medium SM003
CM017 NIST Special Publication 800-207, Zero Trust Architecture, was published in August 2020 and defines the authoritative federal zero trust framework including seven core tenets emphasizing resource-level access enforcement on a per-session basis. High SM006, SM012
CM018 Unit 42's 2026 Global Incident Response Report (750+ investigated cases) found identity weaknesses were exploited in 89% of investigations, and identity-based techniques drove 65% of initial access events (Palo Alto Networks). Medium SM007
CM019 Unit 42's 2026 Global Incident Response Report found that 87% of attacks involved multiple attack surfaces (endpoints, cloud, SaaS, identity, network) simultaneously (Palo Alto Networks). Medium SM007
CM020 The fastest intrusions in Unit 42's 2026 dataset moved from initial access to data exfiltration in 72 minutes; AI-assisted attack simulations reached approximately 25 minutes (Palo Alto Networks). Medium SM007
CM021 More than two-thirds of organizations reported implementing zero trust policies across their enterprises in a 2024 TechTarget Enterprise Strategy Group survey (cited by IBM). Medium SM010
CM022 A 2021 U.S. Executive Order and OMB Memorandum M-22-09 (January 2022) directed all U.S. federal civilian agencies to adopt zero trust architecture with specific technical milestones. High SM012, SM010
CM023 CISA's Zero Trust Maturity Model Version 2.0 covers five pillars (identity, devices, networks, applications/workloads, data) and three cross-cutting capabilities, aligned to OMB M-22-09 (CISA). High SM012, SM010
CM024 ZTNA enforces one-to-one encrypted connections at the application layer using hidden IP addresses, replacing VPN's network-layer implicit trust model and preventing lateral movement (Cloudflare). Medium SM009
CM025 ZTNA can be deployed as agent-based (client software on endpoints) or service-based / cloud-delivered, enabling application-specific access without exposing the broader network (Cloudflare). Medium SM009
CM026 The global multi-cloud networking market is projected to reach USD 7.6 billion by 2027 at a CAGR of 22.5%, and the enterprise networking market overall is projected at USD 193.77 billion by 2030 at 9.2% CAGR (MarketsandMarkets). Medium SM013
CM027 IBM frames zero trust as a security strategy for modern multicloud networks, focusing on individual connection-level verification between users, devices, applications, and data rather than network-perimeter enforcement (IBM). Medium SM010
CM028 Zero trust as a framework was introduced by Forrester analyst John Kindervag circa 2010; major enterprise frameworks include NIST SP 800-207, CISA ZTMM, and Forrester's Zero Trust eXtended model (IBM citing Forrester history; NIST SP 800-207 corroborates). Medium SM010, SM006
CM029 Cisco defines network security as implemented through coordinated layers — firewalls, IDS/IPS, network segmentation, VPNs, and DDoS protection — applying a defense-in-depth principle (Cisco). Medium SM011
CM030 Cisco identifies emerging quantum computing capabilities as a threat that will render traditional security protocols obsolete and require transition to post-quantum cryptography (PQC) protocols, creating a long-horizon security architecture risk (Cisco). Medium SM011
CM031 Zscaler describes zero trust as a cloud-era security model with the core principle of "never trust, always verify," replacing the traditional castle-and-moat perimeter model (Zscaler). Medium SM008
CM032 CISA defines zero trust as a collection of concepts designed to minimize uncertainty in enforcing accurate, least-privilege per-request access decisions, representing a shift from location-centric to data-centric security (CISA). Medium SM012
CM033 Asia Pacific is expected to be the fastest-growing cloud security region at a CAGR of 15.0% from 2025 to 2030, driven by digital government initiatives and rising cybersecurity awareness (Grand View Research). Medium SM002
CM034 GDPR, CCPA, HIPAA, SOX, and FedRAMP are cited as key regulatory compliance drivers compelling cloud security investments in healthcare, banking, and government sectors (Grand View Research). Medium SM002
CM035 Multi-cloud and hybrid cloud adoption trends are the primary driver of demand for cloud security solutions providing seamless visibility, compliance, and threat management across diverse infrastructure types (MarketsandMarkets). Medium SM001
CM036 DevSecOps and cloud-native application development trends require integrating security into the application development lifecycle, increasing demand for scalable cloud security solutions (MarketsandMarkets). Medium SM001
CM037 Aviatrix's CRO and CMO press release (February 2025) stated the company has 500+ enterprise customers including 10% of the Fortune 500, with strong VAR, ISV, and CSP partner networks, and positions for "sustained hyper growth" (Aviatrix company-claimed). Medium SM014
CM038 NIST SP 800-207 establishes that all enterprise resources must be authenticated and authorized regardless of network location, access is determined on a per-session basis, and enterprises must assume no implicit trust in their networks (NIST). Medium SM006
CM039 Palo Alto Networks' 2025 State of Cloud Security Report (2,800 respondents across 6 industries and 10 countries) found 97% of organizations prioritize consolidating their cloud security footprint and 89% believe cloud and SOC security must be fully integrated (Palo Alto Networks). Medium SM015
CM040 Aviatrix's CMO Scott Leatherman cited IP address exhaustion, Azure NAT gateway policy changes, and infrastructure modernization as the top customer challenges driving Aviatrix adoption (Aviatrix via PRNewswire, February 2025). Medium SM014
CP001 Alkira provides Network Infrastructure-as-a-Service (NIaaS) and Global Backbone-as-a-Service as a direct cloud networking competitor to Aviatrix, supporting AWS, Azure, GCP, and Oracle Cloud Infrastructure (OCI) from a unified cloud-native platform. High SP001, SP002
CP002 Alkira claims its platform delivers a 96% reduction in cloud setup time and 47% reduction in network management time compared to manual configuration approaches. Medium SP001
CP003 Alkira's platform includes a drag-and-drop interface, integrated ZTNA, and next-generation firewall capabilities embedded within its NIaaS offering. Medium SP001, SP002
CP004 Alkira claims up to 40% lower total cost of ownership versus alternatives in its competitive positioning materials. Low SP001
CP005 Alkira's ecosystem integrates with Cisco SD-WAN, Palo Alto Networks, Fortinet NGFW, F5, Splunk, ServiceNow, and other enterprise tools, mirroring Aviatrix's partner ecosystem strategy. Medium SP001
CP006 Alkira offers both consumption-based and commitment-based pricing, with charges driven by network element size, connectors, NGFW instances, and egress—in contrast to Aviatrix's subscription model. Medium SP001
CP007 Prosimo's product scope, current funding status, and go-to-market strategy could not be independently verified during this research run because the prosimo.io domain was inaccessible. Low
CP008 Cisco Multicloud Defense uses a single SaaS control plane to manage security policy across public and private cloud environments, eliminating inefficient point solutions. Medium SP003
CP009 Cisco Multicloud Defense provides ingress, egress, and east-west protection—stopping inbound threats, blocking command-and-control, data exfiltration, and preventing lateral movement—in a mode directly competing with Aviatrix's Distributed Cloud Firewall. Medium SP003
CP010 Cisco Multicloud Defense automates underlying cloud network constructs and integrates natively with Infrastructure-as-Code (IaC) tools for greater agility and flexibility. Medium SP003
CP011 Palo Alto Networks' Prisma Cloud analyzes 1 trillion events per 24-hour period to deliver cloud visibility and uses Precision AI to detect 1.5 million new attacks every day. Medium SP011
CP012 Palo Alto Networks Prisma Cloud covers the full application lifecycle from code development through cloud runtime, with AI-powered risk prioritization and automated guided remediation. Medium SP011
CP013 Palo Alto Networks Prisma SASE claims to be the industry's most comprehensive SASE solution, delivering security for users, applications, data, and devices on a multicloud architecture. Medium SP012
CP014 Fortinet holds the #1 position in network firewalls worldwide with more than 50% global market share, backed by patented ASIC-based processing technology. Medium SP017
CP015 FortiGate NGFWs include built-in ZTNA capabilities and SD-WAN integration, enabling Fortinet to offer an end-to-end security and connectivity solution. Medium SP017
CP016 Fortinet supports quantum-safe cryptography including post-quantum IPsec VPNs and NIST-approved post-quantum cryptography algorithms, differentiating from software-only NIaaS approaches in high-assurance environments. Medium SP017
CP017 AWS Transit Gateway connects thousands of Amazon VPCs across AWS accounts and regions without requiring manual peering connections or routing table management, and supports inter-region peering for shared DNS, Active Directory, and IPS/IDS services. High SP004, SP005
CP018 AWS Network Firewall provides a managed, cloud-native firewall service for VPCs, positioned as a direct built-in substitute for organizations operating AWS-centric deployments without multicloud requirements. Medium SP005
CP019 Azure Firewall is a managed cloud-native network security service providing managed policy enforcement, and Azure Virtual WAN offers global hub-and-spoke network connectivity as Azure-native substitutes for third-party multicloud networking tools. High SP006, SP007
CP020 Google Cloud's hierarchical firewall policies enable Cloud Next Generation Firewall (Cloud NGFW) enforcement at the VPC level, providing a cloud-native policy layer for GCP-centric deployments. High SP008, SP025
CP021 Hyperscaler-native networking solutions (AWS TGW, Azure vWAN, GCP Cloud Router) are single-cloud only and cannot natively manage cross-cloud topology, creating the operational problem that Aviatrix and Alkira solve for multicloud enterprises. Medium SP004, SP006, SP008
CP022 Cato Networks' SASE converges SD-WAN, cloud network, and Security Service Edge functions (FWaaS, CASB, DLP, SWG, ZTNA) into a unified cloud-native service delivered from a globally distributed architecture. Medium SP009
CP023 Cato Networks' SASE architecture is identity-driven, cloud-native, and globally distributed, covering all enterprise edges including on-premises data centers, branch offices, and individual users—positioning Cato as an alternative to layered overlay approaches. Medium SP009
CP024 Netskope One Private Access delivers universal ZTNA via the Netskope One Platform, combining SSE, SASE, and converged gateway services on the NewEdge global network. Medium SP010
CP025 Zscaler claims Zscaler Private Access (ZPA) is the world's most deployed ZTNA solution, capable of replacing legacy VPN and VDI with AI-powered user-to-app segmentation. Medium SP013
CP026 According to Zscaler's own research, 91% of organizations are concerned that VPNs compromise their security and 56% of organizations suffered one or more VPN-related attacks in 2023-2024. Medium SP013
CP027 Zscaler ZPA provides AI-powered workload-to-workload segmentation and app segmentation, offering granular east-west control that partially overlaps with Aviatrix's microsegmentation and Distributed Cloud Firewall capabilities. Medium SP013
CP028 Wiz's cloud and AI security platform is trusted by more than 50% of Fortune 100 companies and integrates with 200+ tools covering infrastructure, AI models, data, and application-layer security across cloud environments. Medium SP016
CP029 Wiz focuses on cloud security posture management (CSPM) and AI application security at the visibility and risk-prioritization layer rather than enforcing network-level traffic policy, making it adjacent rather than directly competitive with Aviatrix at the data plane. Medium SP016
CP030 Illumio was named a 2024 Forrester Wave Leader in Microsegmentation and earned a 4.8 out of 5 star rating based on 59 reviews in the 2026 Gartner Peer Insights VOC Report for Network Security Microsegmentation. Medium SP014
CP031 Illumio's breach containment platform enforces zero-trust segmentation using an AI security graph across hybrid and multi-cloud environments at the workload level rather than the network routing layer. Medium SP014
CP032 On PeerSpot, Aviatrix is rated 8.0 out of 10 and ranked #3 in Software Defined Networking, most commonly compared to Cisco ACI, with 50% of users in large enterprises and 16% from financial services firms. Medium SP015
CP033 Aviatrix's cloud-native security fabric positions it as an orchestration layer that integrates with partner NGFWs (Palo Alto, Fortinet, Check Point) for traffic inspection, creating co-sell dynamics with vendors that also compete against it. Medium SP001, SP015
CP034 Aviatrix's Distributed Cloud Firewall deploys enforcement natively in the cloud data plane, avoiding traffic hairpin to an external firewall appliance, which differentiates it from incumbent NGFW overlay approaches such as Cisco Multicloud Defense. Medium SP003, SP015
CP035 PeerSpot users compare Aviatrix against Cisco ACI, Meraki SD-WAN, and Megaport, indicating that the competitive set in buyers' minds extends beyond pure multicloud networking to SD-WAN and interconnect services. Medium SP015
CP036 Aviatrix's primary competitive moat is its cloud-neutral, provider-agnostic control plane embedded in customer multicloud topology; replacing it requires coordinated reconfiguration across VPCs, VNets, route tables, firewall domains, and BGP peering configurations. Medium SP001, SP002, SP003
CP037 Hyperscaler-native networking tools are steadily improving their cross-account, cross-region management capabilities, which raises the threshold at which enterprises need a third-party overlay and represents a displacement risk for Aviatrix at the low end of its market. Medium SP004, SP005, SP006, SP007, SP008
CP038 Palo Alto Networks' platform consolidation strategy (unifying SD-WAN, SASE, cloud security, and NGFW under one Cortex/Prisma umbrella) creates a displacement risk for Aviatrix in accounts where Palo Alto already holds a dominant platform position. Medium SP011, SP012
CP039 Alkira competes directly with Aviatrix on NIaaS and multicloud networking management with overlapping feature sets; Alkira's consumption-based pricing may create a lower initial perceived cost in competitive evaluations. Medium SP001, SP002
CP040 The switching cost for Aviatrix customers is high once multicloud networking topology is deployed, because migration requires coordinated reconfiguration across VPCs, VNets, routing tables, security policies, and operational runbooks. Medium SP001, SP004, SP015
CP041 Zscaler's market positioning argues that traditional network-centric security creates unnecessary attack surface, which if accepted by enterprise security buyers, challenges the premise of Aviatrix's network-first architecture for east-west enforcement. Medium SP013
CP042 Cato Networks includes a Global Cloud Network with global backbone routing as part of its SASE platform, directly overlapping with Alkira's Global Backbone-as-a-Service and Aviatrix's multicloud transit capabilities. Medium SP009
CP043 Cisco's Hybrid Mesh Firewall strategy combines on-premises hardware (Secure Firewall 4200 Series) with cloud-native Multicloud Defense under a unified policy management layer, providing coverage breadth that Aviatrix cannot match without third-party NGFW integration. Medium SP003
CP044 Aviatrix's integration with Palo Alto, Fortinet, and Cisco creates a co-sell advantage today but is a structural vulnerability: if any partner develops its own native multicloud transit fabric, the integration becomes a competitive entry point rather than a differentiator. Medium SP001, SP011
CP045 Wiz and Aviatrix are both sold to cloud security buyers, creating budget competition in consolidated-platform deals where investment in Wiz's broad CSPM platform may displace budget for Aviatrix's multicloud networking layer. Low SP016, SP014
CP046 Fortinet's more than 50% global market share in network firewalls and its FortiGuard AI/ML security services give it substantial distribution and renewal leverage in accounts where Aviatrix might seek to displace on-premises NGFW with cloud-native enforcement. Medium SP017
CP047 Hyperscaler-native transit and firewall services are typically priced on a pay-per-use basis included in or bundled with existing cloud committed-spend agreements, making the effective incremental cost near-zero for cloud-committed enterprises evaluating Aviatrix. Medium SP004, SP005, SP006, SP007
CI001 Latka estimates Aviatrix ARR reached approximately $63.9M as of October 2024, based on its proprietary data-compilation methodology; this figure is not confirmed by Aviatrix. Medium SI001
CI002 Latka estimates Aviatrix ARR reached approximately $35.3M as of November 2023, representing a prior reference point for the growth trajectory. Medium SI001
CI003 The implied year-over-year ARR growth from $35.3M (Nov 2023) to $63.9M (Oct 2024) is approximately 81%, derived from Latka estimates. Medium SI001
CI004 Latka estimates Aviatrix ARR was approximately $15.7M as of April 2021, providing a historical anchor for the compound growth trajectory. Low SI001
CI005 Aviatrix was named to the 2025 Deloitte Technology Fast 500, marking its fourth consecutive year on the list; Deloitte Fast 500 eligibility requires at least $5M in current-year revenues and 50%+ fiscal-year growth from 2021 to 2024. High SI005, SI024
CI006 Aviatrix raised $200M in a Series E funding round on September 8, 2021, led by TCV, establishing a post-money valuation of $2 billion. High SI004, SI003, SI014
CI007 Aviatrix enterprise pricing ranges from approximately $2,500 to $15,000 per month as of June 2026 across two documented tiers (Basic and Enterprise), per CostBench. Medium SI009, SI006
CI008 The median enterprise buyer pays approximately $194,034 per year for Aviatrix software according to Vendr's buyer-side benchmarking data. Medium SI008
CI009 Market benchmarks document approximately $0.14 per hour per gateway (~$102/month) and ~$0.16/hour per VPC attachment (~$117/month) as unit-level cost observations for Aviatrix. Low SI009, SI008
CI010 CostBench documents at least two hidden cost categories beyond Aviatrix's list price — implementation fees and training — estimated to add 15–23% to the total contract value. Medium SI009
CI011 Aviatrix's pricing page does not publish specific list prices; both Basic and Enterprise tiers require contacting sales for a custom quote. Medium SI006
CI012 Series E new investors were TCV (lead), Insight Partners, and Tiger Global; existing investors CRV, Formation 8, General Catalyst, Greenspring Associates, Ignition, Liberty Global Ventures, Meritech Capital, and TrueBridge Capital Partners also participated. High SI004, SI003
CI013 Tracxn records Aviatrix's Series A ($10M, Sep 2015) as the first external equity round, led by Formation 8 and Ignition Partners. Medium SI002
CI014 Tracxn records Aviatrix's Series B as $15M raised in January 2017 with investors CRV, Formation 8, and Ignition Partners. Medium SI002
CI015 Tracxn records the Series C as $46M raised in October 2019, led by CRV, with Formation 8, Liberty Global Ventures, and Ignition Partners participating. Medium SI002, SI017
CI016 Tracxn records the Series D as $75M raised in February 2021, led by General Catalyst, with Greenspring Associates, Meritech, TrueBridge, CRV, Liberty Global Ventures, Formation 8, and Ignition Partners participating. Medium SI002
CI017 Tracxn reports Aviatrix's total capital raised at approximately $346M across six rounds; Yahoo Finance and Sacra report $383.09M, reflecting possible discrepancies in treatment of sub-rounds or convertible instruments. Medium SI002, SI013, SI012
CI018 Aviatrix publicly reports 500+ enterprise customers including approximately 10% of the Fortune 500 (approximately 50 Fortune 500 companies) as of early 2025. Medium SI018, SI022
CI019 Aviatrix's revenue model is structured as a subscription SaaS model with annual enterprise contracts and per-gateway unit pricing within a software-defined platform. Medium SI006, SI023, SI009
CI020 Aviatrix generates revenue from at least five streams: subscription gateway software, professional services, premium support, training/certification (ACE program), and channel/marketplace listings. Low SI019, SI021, SI006
CI021 Growjo estimates Aviatrix's current annual revenue at approximately $135M, based on algorithmic extrapolation; this figure is not company-confirmed and carries high uncertainty. Low SI007
CI022 The Series E $200M round of September 2021 more than doubled Aviatrix's valuation within approximately six months of the Series D, according to the official press release. Medium SI004
CI023 As of June 2026, no new primary equity funding round has been publicly announced for Aviatrix in over four years since the September 2021 Series E. Medium SI002, SI013, SI024
CI024 The Forge secondary market price for Aviatrix (AVIA.PVT) was $3.48 per share as of June 22, 2026, per Yahoo Finance/Forge Data. Medium SI013
CI025 The Forge secondary market model implies Aviatrix's estimated valuation at approximately $411M as of June 22, 2026, based on a proprietary model incorporating primary funding data and secondary market transactions. Medium SI013
CI026 The Forge-implied valuation of ~$411M represents a roughly 79% markdown from the $2B Series E valuation, consistent with post-2021 SaaS multiple compression. Medium SI013, SI010
CI027 Aviatrix appointed Ken Tinsley as Chief Financial Officer in 2025, as confirmed in the Deloitte Fast 500 press release dated November 2025. Medium SI005
CI028 Aviatrix's Series E was co-led by TCV; as part of the deal, TCV General Partner Tim McAdam joined Aviatrix's Board of Directors. Medium SI004
CI029 Ken Horner was appointed CRO in early 2025, joining from Cloudflare where he led approximately 100% year-over-year enterprise growth for two consecutive years. Medium SI018
CI030 Aviatrix's go-to-market channels include direct enterprise sales, value-added resellers (VARs), independent software vendors (ISVs), and cloud service providers (CSPs). Medium SI018, SI019
CI031 Aviatrix's pricing page offers no public price list; pricing requires contacting sales for both Basic and Enterprise tiers, consistent with an enterprise sales-led motion. Medium SI006, SI009
CI032 Growjo estimates Aviatrix has approximately 521 employees as of 2025–2026, with approximately 24% year-over-year employee growth. Low SI007
CI033 The Forge-implied valuation of ~$411M on approximately $64M estimated ARR (2024) yields an implied EV/ARR of approximately 6.4x — above the 3.8x private security SaaS median (DealMatrix) but below the 7.0x public SaaS median (SaaS Capital). Low SI013, SI011, SI010
CI034 Aviatrix discloses no gross margin, NRR, CAC, LTV, burn rate, or cash position; these metrics are private for all private companies without public disclosure obligations. Medium SI012, SI015, SI016
CI035 The SaaS Capital Index showed a median ARR valuation multiple of 7.0x for public B2B SaaS companies as of early 2025, down approximately 60% from its 2021 peak. Medium SI010
CI036 The DealMatrix benchmark for the Privacy and Security sector reported a median EV/Sales multiple of approximately 3.8x as of Q1 2025. Medium SI011
CI037 Using Latka's 2024 ARR estimate of $63.9M and Aviatrix's $2B Series E valuation, the implied EV/ARR multiple at that mark is approximately 31x, reflecting peak-2021 SaaS valuations. Medium SI001, SI004, SI010
CI038 Revenue per employee is estimated at approximately $259K per year (Growjo), using the $135M estimated ARR divided by 521 estimated employees; this is below the ~$300K threshold associated with efficient enterprise SaaS. Low SI007
CI039 Aviatrix's software-defined gateway deployment model, which runs in customer cloud environments rather than as managed infrastructure, is expected to support gross margins in the 65–80% range typical for similar cloud security SaaS vendors. Low SI010, SI011, SI023
CI040 Public cloud security SaaS comparables (Zscaler, Cloudflare) report non-GAAP gross margins of approximately 75–81%, providing a sector proxy for Aviatrix's undisclosed margins. Medium SI010, SI011
CI041 Aviatrix's cost structure is likely dominated by engineering R&D and enterprise sales and marketing, consistent with the pattern for pre-profitability B2B SaaS companies at similar scale and stage. Low SI007, SI019
CI042 Professional services implementation costs may compress blended gross margins if bundled in ARR or if revenue recognition for implementation is accelerated; this cannot be assessed without audited financials. Low
CI043 Aviatrix's pivot from multicloud networking to cloud network security in 2024–2025 may affect revenue mix, ARR composition, and gross margin profile; the financial impact of this strategic shift is not publicly quantifiable. Low SI020, SI005
CI044 The SEC Form D filed November 4, 2019 (accession 0001792033-19-000002) confirms Aviatrix Systems, Inc. is incorporated in Delaware, based in Santa Clara, California, with CIK 0001792033; the filing corresponds to the Series C offering dated October 21, 2019. High SI017, SI002
CI045 Aviatrix's Deloitte Fast 500 eligibility criteria confirm that revenues exceeded $5M in current-year measurement and that fiscal-year growth from 2021 to 2024 exceeded 50%, providing an independent floor on reported revenue growth. Medium SI005
CI046 The absence of a new primary funding round since September 2021 is publicly verifiable and is ambiguous: it could indicate cash-flow self-sufficiency or avoidance of a down-round. Medium SI002, SI013, SI024
CI047 The total funding-to-ARR efficiency ratio for Aviatrix is approximately 18–19% ($64M ARR / $346M raised), below the 25–35% threshold that characterizes capital-efficient enterprise SaaS. Low SI001, SI002
CI048 All ARR figures for Aviatrix in the public domain are third-party estimates (Latka, Growjo, Compworth); Aviatrix has not publicly confirmed or denied any specific ARR figure, making any revenue-based underwriting dependent on data room access. Medium SI001, SI007, SI015
CE001 Aviatrix Cloud Native Security Fabric (CNSF) is the flagship platform umbrella comprising two product lines: Zero Trust for Workloads and Zero Trust for Networking. High SE001, SE003
CE002 CNSF embeds zero trust enforcement directly into the cloud network fabric, brokering identity-aware, one-to-one workload communication across AWS, Azure, GCP, and OCI. High SE002, SE003
CE003 CNSF operates agentlessly—no SDK changes, no kernel modules, and no application rewrites are required for deployment. High SE004, SE003
CE004 The CNSF architecture uses a central Aviatrix Controller for policy management and cloud API integration, spoke gateways for inline enforcement, and CoPilot for cross-cloud visibility and compliance reporting. High SE005, SE002
CE005 In CNSF's Containment Architecture, policy is auto-propagated to every workload at deploy time across all supported clouds, enforcing governance at the workload boundary rather than at a shared egress point. Medium SE002, SE005
CE006 Aviatrix positions the current security era as 'The Containment Era,' describing containment as the architectural successor to detection-first security models. High SE001, SE002
CE007 Aviatrix's official documentation is hosted at docs.aviatrix.com; as of June 2026 the production platform version is 9.0. High SE015, SE014
CE008 Distributed Cloud Firewall (DCF) provides inline L4-L7 enforcement at spoke gateways without hairpinning traffic through a centralized firewall appliance. High SE005, SE002
CE009 DCF's SmartGroups enable identity-based workload policies that span AWS, Azure, and GCP with a single policy definition, enforced consistently across clouds. High SE005, SE003
CE010 DCF supports WebGroups for north-south internet egress control including FQDN-based filtering and full URL-path-level control. High SE005, SE003
CE011 All DCF policies are managed as code through Terraform and CI/CD pipelines, enabling version control, peer review, and automated deployment. Medium SE005, SE024
CE012 DCF uses Cloud Asset Inventory (CAI) for continuous workload discovery, including VMs, containers, serverless functions, and managed services—including ephemeral resources legacy tools miss. Medium SE005
CE013 High Performance Encryption (HPE) uses a patented multi-tunnel, multi-core architecture achieving 100+ Gbps hybrid throughput and up to 1 Tbps+ cloud-to-cloud using parallel tunnels and ECMP. High SE008, SE003
CE014 HPE delivers software-defined encryption replacing hardware VPNs and scales elastically with cloud compute; standard AWS or Azure VPN gateways are limited to approximately 1.25 Gbps per tunnel. Medium SE008
CE015 HPE includes a Crypto-Agility Engine designed for seamless algorithm upgrades including post-quantum cryptography (PQC) readiness. Medium SE008, SE007
CE016 Workload Threat Visibility (WTV) transforms Aviatrix NAT Gateways into security sensors providing unified cross-cloud outbound visibility, exposing malicious destinations and reducing NAT cost and complexity. Medium SE009
CE017 Aviatrix also offers an Aviatrix Cloud Firewall and Secure Datacenter Edge product line focused on high-performance perimeter protection for datacenter and edge workloads. Medium SE013, SE014
CE018 CoPilot provides a centralized cross-cloud visibility, monitoring, policy visualization, and compliance-reporting layer on top of the distributed CNSF enforcement fabric. High SE002, SE007
CE019 AgentGuard's Shadow AI Discovery capability is in early access as of June 2026, with a claimed 15-minute time-to-first-value for discovering all AI agents in a cloud environment. Medium SE006
CE020 AgentGuard discovers AI agents, MCP servers, and LLM endpoints via VPC Flow Logs, DNS logs, and Cloud Asset Inventory analysis—without requiring SDK instrumentation or code changes. Medium SE006, SE012
CE021 AgentGuard covers AI agent frameworks including Strands, LangChain, and AutoGen, and supports LLM providers: OpenAI, Anthropic, Bedrock, Vertex, Cohere, and Mistral. High SE006, SE004
CE022 AgentGuard's Deep AI Observability and Advanced AI Guardrails capabilities are on the product roadmap for Q3 2026; they are not yet generally available. Medium SE006
CE023 On June 4, 2026, Aviatrix announced it is one of the first multicloud network-layer enforcement substrates for the Microsoft Agent Control Specification (ACS), available at no additional cost to existing customers. High SE010, SE014
CE024 The ACS integration uses a single .guardrails.yaml policy file compiled into an Aviatrix DCF custom resource definition, deployable via GitHub Actions, Argo, Flux, or any CI runner. Medium SE010
CE025 The ACS integration creates two enforcement planes for AI agents: the Microsoft Agent Control SDK (in-process) and the Aviatrix CNSF (network-layer), both governed by the same .guardrails.yaml policy file. Medium SE010
CE026 Aviatrix joined OISF as a consortium member on June 8, 2026, contributing 556 purpose-built Suricata rules for AI-specific threat categories and multicloud reference architectures to the open-source community. High SE011, SE017
CE027 Suricata has been embedded in the Aviatrix platform as its core IPS engine since initial integration, performing inline deep packet inspection, TLS decryption, and custom rule matching. High SE011, SE017
CE028 Aviatrix's OWASP-referenced threat model cites the OWASP Top 10 for Agentic Applications and peer-reviewed by over 100 security researchers, published December 2025, as the formal taxonomy for AI agent risks. High SE010, SE020, SE021
CE029 CNSF delivers audit-ready compliance telemetry supporting HIPAA 2025, PCI DSS 4.0, DORA, NIS2, and CISA ZTMM 2.0 frameworks through CoPilot reporting and HPE encryption. Medium SE003, SE007
CE030 CVE-2024-50603 (CVSS 10.0) is an unauthenticated remote code execution vulnerability in the Aviatrix Controller caused by API endpoints failing to sanitize user-supplied input, allowing OS command injection. High SE018, SE019
CE031 CVE-2024-50603 was actively exploited in January 2025 to deploy XMRig cryptominers and the Sliver C2 framework; CISA added it to the Known Exploited Vulnerabilities catalog on January 16, 2025. High SE018, SE022
CE032 Wiz reported that 3% of cloud enterprise environments have Aviatrix Controller deployed, and 65% of those environments have a default lateral movement path to administrative cloud control plane permissions on AWS. High SE018, SE019
CE033 Aviatrix issued a hot patch for CVE-2024-50603 in early November 2024 covering versions down to 6.7 (including end-of-support releases), and released permanent fixes for versions 7.1.4191 and 7.2.4996 on December 19, 2024—prior to public PoC availability. High SE018, SE022
CE034 Aviatrix's Trust Center lists 5 audits and certifications (SOC 2, ISO 27001, TISAX, GDPR, CCPA), 30 additional documents, 15 policies, and 2 pentest reports. High SE016, SE014
CE035 CNSF is deployed as software-defined overlays inside customer-owned VPCs and VNets with no hardware appliances, no network re-architecture, and no application changes required. High SE004, SE003
CE036 The Aviatrix Controller automates provisioning, tunnel orchestration, policy enforcement, key management, and lifecycle operations across the entire multi-cloud deployment. Medium SE008, SE005
CE037 Aviatrix CNSF supports AWS, Azure, GCP, OCI, and on-premises Kubernetes; the platform is available on AWS Marketplace and Azure Marketplace with a 30-day free trial for Aviatrix Enterprise. High SE003, SE010
CE038 A single Terraform provider (AviatrixSystems/aviatrix on registry.terraform.io) enables infrastructure-as-code automation combining network and application CI/CD pipelines. Medium SE024, SE005
CE039 Unlike native cloud security groups or managed firewalls (AWS Network Firewall, Azure Firewall, GCP VPC Firewall), Aviatrix CNSF defines policy once and enforces it consistently across all supported clouds without per-cloud tooling. Medium SE002, SE005
CE040 Aviatrix's Containment Architecture enforces at every workload on every path, while chokepoint security (traditional NGFW/transit firewall) only governs traffic routed through the inspection point. Medium SE002
CE041 AgentGuard inverts the traditional developer-first AI security model: security teams deploy it network-side without requiring developer compliance or SDK adoption. Medium SE006
CE042 Aviatrix offers a free Workload Attack Path Assessment tool for breach-chain visualization and risk discovery, available before any deployment commitment. High SE004, SE003
CU001 Aviatrix self-reports serving 500+ enterprise customers globally as of May 2024, confirmed consistently across its website and press materials. High SU001, SU016
CU002 Aviatrix claims that approximately 10% of Fortune 500 companies use its platform, as stated on its financial services solutions page. Medium SU018
CU003 The Aviatrix community portal (community.aviatrix.com) shows 8,366 registered members, 969 topics, and 1,355 replies as of June 2026, with ACE certifications continuing to be awarded visibly. Medium SU019
CU004 Aviatrix describes the ACE (Aviatrix Certified Engineer) program as "the industry's leading multicloud networking and security certification," used for demand generation and customer stickiness. Medium SU015, SU016
CU005 PeerSpot research data shows that large enterprise organizations (500+ employees) account for approximately 50% of professionals researching Aviatrix on the platform. Medium SU020
CU006 Financial services firms account for 16% of all Aviatrix product views on PeerSpot, making it the single largest industry vertical represented. Medium SU020
CU007 Aviatrix's primary buyer persona is enterprise cloud architects, senior network engineers, and DevOps leads at organizations managing connectivity across two or more cloud providers (AWS, Azure, GCP, OCI). Medium SU020, SU001
CU008 PeerSpot data shows that manufacturing companies, outsourcing firms, retailers, construction companies, healthcare organizations, and insurance companies are among Aviatrix's secondary industry verticals. Medium SU020
CU009 Aviatrix customers are predominantly located in North America and Europe, with named accounts in the US, Netherlands (Aegon), Germany (HAPEV), France (Amundi), Denmark (GN), UK (Inmarsat), Norway (Yara), and globally deployed at IHG Hotels and AB InBev. Medium SU003, SU004, SU007, SU009, SU010, SU011, SU012
CU010 Multi-cloud transit networking and connectivity across two or more cloud service providers is the foundational entry-point use case for Aviatrix enterprise deployments. Medium SU001, SU020
CU011 Beyond transit networking, Aviatrix customers use the platform for zero trust network segmentation, egress cost optimization, FQDN-based firewall policy, M&A infrastructure integration, and AI workload isolation. Medium SU002, SU003, SU006, SU010
CU012 Regulated industries — including financial services (PCI DSS, GDPR), healthcare (HIPAA), aviation (FAA), and insurance — disproportionately appear in Aviatrix's published customer reference base, likely due to compliance requirements driving demand for a vendor-neutral, auditable networking layer. Medium SU002, SU005, SU010, SU013
CU013 Aviatrix has been named to the Deloitte Technology Fast 500 for four consecutive years (2022, 2023, 2024, 2025), confirmed by the November 2025 press release and the Deloitte Fast 500 listing. High SU017, SU024
CU014 Third-party estimates (Latka) place Aviatrix's ARR at approximately $63.9M as of October 2024, representing approximately 81% year-over-year growth from $35.3M in 2023. Low SU025
CU015 Vendr procurement data shows the median annual contract value for Aviatrix enterprise buyers is approximately $194,034 per year, with a range from approximately $153,513 to $798,362. Medium SU023
CU016 Aviatrix monthly list pricing ranges from $2,500 to $15,000 per month depending on tier, as published on its pricing page. Medium SU001
CU017 Republic Airways reduced mean time to resolution (MTTR) for network issues from days to under one hour after deploying Aviatrix Cloud Native Security Fabric. Medium SU005
CU018 Republic Airways increased hybrid cloud encrypted throughput by approximately 150 Mbps while maintaining full encryption using Aviatrix CNSF and High-Performance Encryption. Medium SU005
CU019 Republic Airways accelerated regional cloud deployments from multi-day timelines to same-day provisioning after deploying Aviatrix CNSF and IaC automation. Medium SU005
CU020 IHG Hotels & Resorts deployed Aviatrix across AWS and GCP to create an enterprise cloud networking backbone for its global operations spanning 6,000+ hotels in 100+ countries, confirmed as a production deployment. Medium SU004
CU021 Anheuser-Busch InBev (AB InBev), the world's largest brewer, uses Aviatrix to manage 80% of its infrastructure in the public cloud across multiple cloud service providers and on-premises systems. Medium SU003
CU022 Better (a US fintech homeownership platform) uses Aviatrix Cloud Firewall and Distributed Cloud Firewall as its primary egress perimeter for compliance with financial services regulatory requirements across AWS and Azure. Medium SU002
CU023 Aegon (financial services, $882B revenue, 31.7M customers) reports reducing network tunnel provisioning time from hours to seconds — "3-4 clicks" — after deploying Aviatrix multicloud transit. Medium SU010
CU024 HAPEV (a German pension provider managing 1M+ accounts) reports that its DevOps team can configure infrastructure for new workloads in under one hour using Aviatrix IaC capabilities. Medium SU009
CU025 Amundi Technology, managing >€2 trillion in assets for Europe's largest asset manager, uses Aviatrix for multi-region Azure hybrid cloud expansion, FQDN filtering, and client onboarding acceleration in production. Medium SU007
CU026 Yara, a global crop nutrition company with ~$16B revenue, uses Aviatrix across all public cloud providers for cloud-agnostic multicloud networking and day-2 operations management in production. Medium SU008
CU027 PeerSpot rates Aviatrix 8.0 out of 10 overall, based on nine in-depth enterprise reviews, with the large enterprise segment accounting for approximately 50% of researchers. Medium SU020
CU028 PeerSpot enterprise user reviews report approximately 30–40% reduction in network management effort and approximately 50% increase in deployment speed after adopting Aviatrix, though these figures are self-reported by individual reviewers. Low SU020
CU029 TrustRadius rates Aviatrix 7.1 out of 10 based on nine reviews, a notably lower score than PeerSpot, with specific complaints about missing VPN admin controls, limited IPS customization, alert flooding, and manual update overhead. Medium SU021
CU030 Multiple PeerSpot enterprise reviewers describe Aviatrix as "a pretty expensive solution" that mandates bundled support with the license, making it inaccessible without an annual support contract. Medium SU020
CU031 Reviewers on PeerSpot and TrustRadius consistently cite a steep learning curve for users unfamiliar with multi-cloud networking concepts, with onboarding complexity requiring dedicated training before realizing product value. Medium SU020, SU021
CU032 CVE-2024-50603, a critical vulnerability in the Aviatrix Controller, was actively exploited in production customer environments in January 2025 to deploy cryptominers and backdoors in customer cloud infrastructure. Medium SU026
CU033 At least one PeerSpot reviewer based in the UAE reports that Aviatrix has very limited local presence in the GCC market (UAE, Qatar, Kuwait, Saudi Arabia), making in-person or regional technical support unavailable. Low SU020
CU034 A TrustRadius reviewer at a systems engineering firm with 200–500 employees reports that direct support from the Aviatrix team was lacking and did not meet needs, though other reviewers rate support more positively. Low SU021
CU035 Aviatrix has not publicly disclosed NRR, GRR, logo churn, or cohort retention metrics as of the run date; all retention KPIs are entirely absent from public investor-facing or press materials. High SU025, SU016
CU036 No public data exists on customer revenue concentration; it is unknown what share of Aviatrix ARR is held by its top 5 or top 10 accounts. Medium SU025
CU037 Aviatrix contract length and multi-year renewal terms are not publicly disclosed; the only available signal is the PeerSpot reference to "yearly licensing fee," implying annual subscription structure. Low SU020
CU038 The ACE certification program creates platform stickiness by building deep Aviatrix expertise inside enterprise customer engineering teams, increasing switching costs as certified engineers become internal infrastructure champions. Medium SU015, SU019
CU039 Multiple named customers show documented use-case expansion beyond initial transit networking: Aegon expanded to distributed firewalling; IHG extended to GCP and added Equinix edge integration; AB InBev added Cost APIs and observability after initial connectivity deployment. Medium SU003, SU004, SU010
CU040 Aviatrix names AWS, Azure, Equinix, Megaport, WWT, and Presidio as key partners for financial services customers, providing both technical integration pathways and go-to-market co-sell routes. Medium SU018, SU027
CU041 The Azure Marketplace listing of the Aviatrix Controller as of June 2026 enables enterprise procurement through Microsoft Azure committed-spend programs (MACC), reducing friction for Azure-primary buyers. Medium SU027
CR001 AWS Cloud WAN provides a managed wide-area network service with centralised dashboard and global networking capabilities that directly overlaps Aviatrix's cloud transit networking use case. High SR001, SR019
CR002 Azure Virtual WAN offers a full-mesh hub-and-spoke managed networking service integrating routing, encryption, VPN, ExpressRoute, and Azure Firewall, competing with Aviatrix's multi-cloud networking and security capabilities. High SR002, SR021
CR003 Google Network Connectivity Center enables cross-cloud connectivity including Partner Cross-Cloud Interconnect for AWS and Azure, competing with Aviatrix's multi-cloud networking use cases. High SR003, SR008
CR004 AWS Transit Gateway and Network Firewall form a competitive baseline stack for single-cloud AWS environments that Aviatrix must displace with a price-performance or capability argument. High SR019, SR020, SR004
CR005 Cisco Multicloud Defense and Palo Alto Networks Prisma Cloud are established enterprise-grade alternatives to Aviatrix in the cloud firewall and multi-cloud security segments, both with larger enterprise installed bases. High SR022, SR023
CR006 Wiz's cloud security platform has expanded into detection, response, and workload protection capabilities that partially overlap with Aviatrix's Distributed Cloud Firewall, creating an adjacent competitive threat from the CNAPP direction. Medium SR024
CR007 CVE-2024-50603 is a CVSS 10.0 critical unauthenticated remote code execution vulnerability in the Aviatrix Controller, allowing attackers to inject OS commands via unsanitized API endpoints. High SR010, SR009, SR011
CR008 CISA added CVE-2024-50603 to its Known Exploited Vulnerabilities (KEV) catalog on January 16, 2025, mandating Federal Civilian Executive Branch agencies to apply fixes by February 6, 2025. High SR011, SR009, SR010
CR009 Wiz researchers found that approximately 3% of cloud enterprise environments run Aviatrix Controller, and 65% of those deployments have a lateral movement path to administrative cloud control plane permissions. Medium SR009
CR010 Active exploitation of CVE-2024-50603 in January 2025 included deployment of XMRig cryptocurrency miners and the Sliver command-and-control framework for persistence and likely data exfiltration via enumerated cloud permissions. Medium SR009
CR011 A public proof-of-concept exploit for CVE-2024-50603 was made available upon disclosure in January 2025, materially lowering the barrier to exploitation. Medium SR009, SR010
CR012 Aviatrix issued a hot patch for CVE-2024-50603 in early November 2024 and permanent fixes for Controller versions 7.1 (v7.1.4191) and 7.2 (v7.2.4996) on December 19, 2024. Medium SR009, SR015
CR013 When deployed in AWS cloud environments, Aviatrix Controller allows privilege escalation by default, amplifying the blast radius of any Controller compromise. Medium SR009
CR014 Aviatrix founder CEO Steve Mullaney departed on July 6, 2023, having built the company from founding to a $2 billion valuation over four years as CEO. High SR013, SR016
CR015 Doug Merritt, former president and CEO of Splunk where he grew ARR from approximately $100 million to nearly $3 billion over six years, became Aviatrix CEO, president, and chairman in July 2023. High SR013, SR016
CR016 Under Doug Merritt, Aviatrix has strategically pivoted its primary value proposition from cloud networking abstraction to cloud network security, as confirmed by BankInfoSecurity reporting in July 2025. High SR012, SR016
CR017 Aviatrix hired multiple new senior leaders in 2024-2025 including CRO Ken Horner (ex-Cloudflare), CMO Scott Leatherman, and VPs across revenue operations, strategic accounts, growth marketing, and business value. High SR014, SR016
CR018 CRO Ken Horner previously drove nearly 100% YoY enterprise growth for two consecutive years at Cloudflare, but his ability to replicate this in the cloud network security vertical under a new CEO and revised strategy is unproven. Medium SR014
CR019 Aviatrix has filed only one SEC Form D exempt offering notice (November 2019, for a prior round), and no publicly accessible Form D amendments exist for the $200 million 2021 Series E or any subsequent fundraising. High SR005, SR030
CR020 Aviatrix's last publicly confirmed valuation is $2 billion, set at the September 2021 Series E funding round led by TCV; no subsequent valuation has been publicly disclosed. High SR028, SR027
CR021 Private SaaS company valuations compressed approximately 40–60% from 2021 peak multiples by 2023–2024; Aviatrix's $2B 2021 book valuation is at meaningful downside risk on any secondary transaction or next fundraise absent exceptional ARR growth. Medium SR017, SR018, SR027
CR022 Third-party analyst services (Sacra, CBInsights, GetLatka, GrowJo) publish Aviatrix ARR estimates without access to audited financials, carrying explicit disclaimers about accuracy. Medium SR017, SR018, SR029, SR031
CR023 Aviatrix's burn rate, cash position, gross margin, and capital runway are entirely unknown from public sources, as the company is a private-undisclosed entity with no public financial statements. Medium SR005, SR030, SR017
CR024 CISA's cybersecurity framework and zero trust maturity model represent evolving enterprise requirements that Aviatrix must track to maintain procurement eligibility in regulated enterprise and government segments. Medium SR007, SR033
CR025 The Cloud Security Alliance Cloud Controls Matrix (CCM) defines baseline security controls that cloud service and networking providers must demonstrate to enterprise customers seeking vendor security assurance. Medium SR006
CR026 Aviatrix's trust center claims security commitment and SOC 2 compliance, but no third-party-audited Type II attestation report or compliance scope is publicly accessible for enterprise procurement review. Medium SR015
CR027 GDPR and EU data sovereignty rules create compliance complexity for Aviatrix deployments in European enterprise environments, particularly regarding Controller data residency and sub-processor obligations. Low SR006, SR033
CR028 Aviatrix Systems, Inc. is incorporated in Delaware and headquartered in Santa Clara, CA, as confirmed by its 2019 SEC Form D filing; no subsequent Form D amendments are publicly accessible for later funding rounds. High SR030, SR005
CR029 Aviatrix's agentless architecture relies entirely on hyperscaler API stability; provider-side API changes, deprecations, or quota restrictions can silently break connectivity or enforcement policies without advance notice. Medium SR001, SR002, SR003
CR030 Aviatrix's pivot from networking to security expands its total addressable competition to include SASE vendors, CNAPP players, and zero-trust networking vendors who were previously only partial overlaps. Medium SR012, SR022, SR023, SR024
CR031 Customer reviews on G2 and TrustRadius document a steep learning curve and complex implementation for Aviatrix's platform, creating potential adoption risk and increased probability of customer misconfiguration. Medium SR025, SR026
CR032 Aviatrix's ACE (Aviatrix Certified Engineer) program is designed to address the cloud network security skills gap, but dependence on ACE-certified practitioners creates a potential implementation bottleneck in enterprise deployments. Low SR015
CR033 Aviatrix discloses 500+ enterprise customers including 10% of Fortune 500 but does not disclose revenue concentration by customer or vertical, making concentration risk unquantifiable without direct diligence access. Medium SR014, SR013
CR034 The Aviatrix Controller is a single centralised control plane that governs policy enforcement across all managed workloads; prolonged Controller downtime or compromise would affect enforcement and visibility for all connected clouds and workloads. Medium SR009, SR015
CR035 Aviatrix's go-to-market model relies on a new channel partner program involving VARs, ISVs, and CSPs; the program is newly launched under CRO Ken Horner and its performance has not been publicly reported. Low SR014
CR036 Aviatrix's AgentGuard AI workload security product was in early access as of 2026, representing a high-execution-risk strategic bet in the rapidly evolving AI governance security segment. Low SR015
CR037 AWS Transit Gateway pricing and feature evolution has continued to reduce the price-performance gap with Aviatrix's overlay networking for single-cloud AWS environments, as AWS VPC pricing is measured by the hour and per-GB data processed. Medium SR004, SR019
CR038 The transition from a founder-led networking startup to a security-focused enterprise company under a new CEO represents a material strategic pivot with execution risk that is not yet evidenced by public performance data. Medium SR012, SR013, SR016
CR039 AWS VPC NAT Gateway is priced at $0.045 per hour plus data processing charges; customers use this baseline cost as the floor when evaluating Aviatrix's incremental value for multi-cloud environments. High SR004, SR019
CR040 NIST SP 800-207 Zero Trust Architecture alignment is a table-stakes requirement for Aviatrix to maintain credibility in regulated enterprise and federal government procurement processes. Medium SR032, SR033
CR041 Aviatrix's CVE-2024-50603 exploit campaign highlighted that Controller internet exposure and default AWS privilege escalation were enabling factors, indicating that baseline configuration hardening was not universally applied by customers. Medium SR009
CR042 Gartner and enterprise analyst guidance identifies multicloud governance and cost overruns as key risk factors for enterprises, a dynamic that creates both demand for and scrutiny of vendors like Aviatrix operating in the multicloud management space. Medium SR008, SR034
CR043 Aviatrix's customer acquisition relies materially on AWS Marketplace and Azure Marketplace channel listings, creating dependency on marketplace policies, billing structures, and availability for a portion of its enterprise pipeline. Low SR001, SR021
CR044 BankInfoSecurity (July 2025) reports that Merritt recruited executives with deep cybersecurity and product expertise from Google and Cisco to execute the security pivot, implicitly acknowledging the prior leadership team was not optimally configured for the new strategic direction. Medium SR012
CR045 No known regulatory enforcement actions, material IP litigation, or class-action filings have been publicly identified against Aviatrix as of June 2026, though the CVE-2024-50603 exploitation campaign creates latent customer liability risk. Medium SR005, SR030, SR009
CR046 Aviatrix must demonstrate NIST SP 800-207 and CISA Zero Trust Maturity Model alignment to maintain enterprise and government procurement eligibility, both of which are continuing requirements rather than one-time certifications. Medium SR032, SR033, SR007
CV001 Aviatrix raised $200M in its Series E funding round on September 8, 2021, at a $2 billion post-money valuation, co-led by TCV with participation from Insight Partners and Tiger Global. High SV019, SV021, SV027, SV028
CV002 Tim McAdam, General Partner at TCV, joined Aviatrix's Board of Directors as part of the Series E investment, affirming TCV's lead position. High SV019, SV028
CV003 Aviatrix's total primary funding is reported at approximately $346M–$414M across six rounds by various data sources (Tracxn $346M, EquityZen $414M, Forge $383M, Crunchbase mid-range), with variance reflecting normal data aggregator discrepancies. Medium SV020, SV013, SV009, SV029
CV004 Aviatrix's primary equity rounds include: Series A $10M (Sep 2015), Series B $15M (Jan 2017), Series C $46M (Oct 2019), Series D $75M (Feb 2021), and Series E $200M (Sep 2021), totaling approximately $346M in primary capital. Medium SV020, SV029, SV025
CV005 No new primary equity funding round for Aviatrix has been publicly announced in over 4.5 years since the September 2021 Series E as of June 2026, representing an unusually long gap for a company at this stage. Medium SV009, SV013, SV020, SV029
CV006 Forge's pre-IPO platform page for Aviatrix shows a Forge Price Date of 06/23/2026 with no 'Last Matched Price' (displayed as '--'), indicating current secondary market illiquidity for Aviatrix shares. Medium SV009
CV007 EquityZen reports Aviatrix's total funding at $414M and indicates that more than 550 customers worldwide leverage Aviatrix as of its most recently available data. Medium SV013
CV008 Yahoo Finance and PM Insights reference a Forge secondary market price of $3.48 per share for Aviatrix (AVIA.PVT) as of June 22, 2026. Medium SV015, SV016
CV009 At $3.48/share and an estimated 118 million fully-diluted shares, the implied Aviatrix enterprise valuation as of June 2026 is approximately $411M, representing a ~79% decline from the $2B Series E post-money valuation. Medium SV015, SV016, SV009
CV010 PM Insights lists Aviatrix in its secondary market data coverage but does not provide a verified bid or ask with meaningful depth, indicating limited secondary market liquidity for investors seeking meaningful position sizes. Medium SV015
CV011 Zscaler (ZS) as of June 2026 has a market cap of approximately $20.90B (down ~55.4% YoY) and TTM revenue of $3.17B (+24.6%), implying an approximate EV/revenue multiple of 6.6x. Medium SV001, SV002
CV012 Palo Alto Networks (PANW) as of June 2026 has a market cap of approximately $237.72B (up ~80.9% YoY) and TTM revenue of $10.61B (+19.5%), implying an approximate EV/revenue multiple of 22.4x. Medium SV003, SV004
CV013 CrowdStrike (CRWD) as of June 2026 has a market cap of approximately $175.45B (up ~52.1% YoY) and TTM revenue of $5.09B (+23.2%), implying an approximate EV/revenue multiple of 34.5x. Medium SV005, SV030
CV014 Cloudflare (NET) as of June 2026 has a market cap of approximately $81.21B (up ~37.1% YoY) and TTM revenue of $2.33B (+31.6%), implying an approximate EV/revenue multiple of 34.9x. Medium SV006
CV015 Fortinet (FTNT) as of June 2026 has a market cap of approximately $108.44B (up ~36.9% YoY) and TTM revenue of $7.11B (+15.7%), implying an approximate EV/revenue multiple of 15.3x. Medium SV007
CV016 Okta (OKTA) as of June 2026 has a market cap of approximately $20.62B (up ~11.5% YoY) and TTM revenue of $3.0B (+11.7%), implying an approximate EV/revenue multiple of 6.9x. Medium SV008
CV017 Zscaler's SEC 10-K filing (September 11, 2025) confirms revenue of $2,673.1M in fiscal year 2025 (ended July 31, 2025), $2,167.8M in fiscal 2024, and $1,617.0M in fiscal 2023, with year-over-year growth of 23% and 34% respectively. High SV012, SV002
CV018 Zscaler's FY2025 10-K reports net losses of $41.5M (FY2025), $57.7M (FY2024), and $202.3M (FY2023), with over 9,400 customers as of July 31, 2025, including approximately 40% of the Forbes Global 2000. High SV012, SV001
CV019 Zscaler's market cap declined approximately 55% year-over-year as of June 2026, driven by slower growth outlook and concerns about AI-driven disruption to zero-trust security demand, contrasting with PANW (+80.9%) and CRWD (+52.1%) performance. Medium SV001, SV003, SV005
CV020 Zscaler's P/S ratio reached 18.17x on October 31, 2025, then compressed to below 7x by June 2026 (implied by $20.9B market cap / $3.17B TTM revenue), representing a contraction of greater than 60% in 8 months. Medium SV010, SV001
CV021 47 analysts polled by S&P Global assign Zscaler a consensus 'Buy' rating with an average 12-month price target of $193.05, implying 49% upside from the June 2026 price near $124. Medium SV001
CV022 Damodaran's January 2025 dataset reports a median EV/Sales multiple of 9.01x for Software companies with positive EBITDA (77 firms), and 9.56x for Internet Software firms, providing a reference baseline for software valuation multiples. High SV014, SV023
CV023 The SaaS Capital Index (SCI) median ARR multiple reached decade-plus lows in Q1 2026 as markets priced in AI as an existential threat to the SaaS business model, compressing valuations across both AI-native and traditional SaaS companies. High SV011, SV022
CV024 The SCI median ARR growth rate declined from more than 30% in 2021 to the low teens by 2025, while ARR multiples remained range-bound 2022–2025, creating accumulating valuation vulnerability that materialized in Q1 2026. High SV011, SV022
CV025 The ARRG multiple (SCI ARR multiple divided by median growth rate) remained above prior lows after Q1 2026's selloff, suggesting the sector remains exposed to further valuation vulnerability if SaaS growth rates continue to decelerate. Medium SV011
CV026 DealMatrix benchmarks the Privacy and Security sector at a median EV/Sales multiple of approximately 7.3x, consistent with the lower end of the public comp set and appropriate for Aviatrix's scale and growth profile. Medium SV023
CV027 Latka estimates Aviatrix ARR at approximately $63.9M as of October 2024, up from $35.3M in November 2023, implying approximately 81% year-over-year growth — a high growth rate that may reflect early TAM expansion effects. Medium SV017
CV028 Growjo estimates Aviatrix annual revenue at approximately $135M using algorithmic extrapolation from employee count and industry benchmarks; this figure is materially higher than Latka's ARR estimate and has lower reliability. Low SV018
CV029 Extrapolating from Latka's $63.9M ARR (October 2024) at a 25–30% annualized growth rate to June 2026 (approximately 20 months), Aviatrix's estimated ARR would be in the range of $85–97M — used as the base scenario anchor. Low SV017, SV024
CV030 All ARR and revenue figures for Aviatrix in the public domain are third-party estimates or algorithmic derivations; Aviatrix has not publicly disclosed any financial metric, creating material uncertainty in any valuation scenario. High SV017, SV018, SV024, SV025
CV031 Bull scenario: $95M ARR × 8–10x EV/ARR multiple = $760M–$950M enterprise valuation, requiring successful execution on the security pivot, sustained ARR growth, and a sector multiple recovery toward historical medians. Low SV017, SV023, SV011
CV032 Base scenario: $85M ARR × 5–7x EV/ARR multiple = $425M–$595M enterprise valuation, consistent with current market multiples for comparable private cloud security companies and broadly bracketing the Forge-implied $411M. Medium SV017, SV011, SV022, SV023
CV033 Bear scenario: $70M ARR × 3–4x EV/ARR multiple = $210M–$280M enterprise valuation, reflecting potential ARR growth stall, hyperscaler competitive displacement, and further sector multiple compression. Low SV017, SV011
CV034 To justify the $2B Series E valuation at current market multiples of 6–8x EV/ARR, Aviatrix would need to achieve $250–333M in ARR — approximately 3–5x above current third-party-estimated ARR levels. Medium SV017, SV022, SV023
CV035 Series E investors face an approximate paper mark-to-market loss of $1.6 billion (79%) based on the Forge-implied secondary valuation of ~$411M versus the $2B Series E post-money price; preferred liquidation preferences likely protect senior capital in any structured exit. Medium SV009, SV015, SV019
CV036 At a base-case exit range of $425M–$595M, Series E preferred holders would likely recover capital plus limited return, while common stock and junior preferred holders would receive minimal or no proceeds depending on the preference waterfall structure. Medium SV019, SV027, SV028
CV037 An M&A exit at 5–8x estimated ARR (~$85M) would imply an acquisition price of $425M–$680M, a range potentially attractive to strategic acquirers such as Cisco, Palo Alto Networks, or a hyperscaler seeking multicloud security capabilities. Low SV023, SV003, SV017
CV038 IPO readiness for a private cloud security company typically requires demonstrated ARR at $150M+ scale, near-positive or positive operating margins, stable or improving growth rates, and a clean preference structure; Aviatrix's current estimated metrics fall short of most of these thresholds. Medium SV011, SV012, SV022
CV039 Aviatrix's cloud-agnostic multicloud networking and security architecture represents a defensible product niche: enterprises with three or more cloud environments require a vendor-neutral control plane that hyperscalers are structurally limited in providing neutrally. Medium SV013, SV024, SV031
CV040 Aviatrix's transition from multicloud networking to cloud network security is strategically coherent given TAM expansion, but introduces revenue recognition uncertainty, potential customer confusion, and increased competitive surface area versus established security vendors. Medium SV031, SV024, SV013
CV041 The $200M Series E at a $2B post-money valuation creates a large liquidation preference overhang that materially discounts the economic value of common stock and junior preferred shares relative to the headline enterprise value. Medium SV019, SV027, SV028
CV042 Aviatrix's capital efficiency ratio — estimated ARR of ~$64M divided by total primary funding of ~$346M — is approximately 18–19%, below top-quartile SaaS benchmarks of 40%+ ARR efficiency, indicating high capital consumption per revenue dollar. Low SV017, SV020, SV022
CV043 The 4.5+ year gap without a new primary funding round signals either adequate internal cash generation, deliberate waiting for better market conditions, or potential difficulty accessing capital at the $2B valuation anchor — the last interpretation is consistent with secondary market pricing. Medium SV009, SV013, SV020
CV044 No S-1, Form 8-A, or other public offering filing has been detected in SEC EDGAR searches as of June 2026, confirming that Aviatrix remains in private status with no imminent public offering on the regulatory record. High SV026, SV009
CV045 The Forge IPO page for Aviatrix shows no 'Last Matched Price' as of June 23, 2026, indicating that secondary market liquidity has dried up and current pricing signals should be treated with high uncertainty. Medium SV009
CV046 The approximately 79% markdown from the $2B Series E to the ~$411M Forge-implied secondary valuation materially exceeds the typical 30–50% compression observed for comparable late-stage tech secondaries, suggesting a combination of ZIRP-era overpricing, sector multiple contraction, and company-specific execution uncertainty. Medium SV009, SV015, SV011, SV022
Sources
IDPublisherTitleQuote
SO001 Aviatrix Cloud Network Security | Runtime Protection for AI & Multicloud | Aviatrix® Aviatrix — Cloud Network Security | Runtime Protection for AI & Multicloud
SO002 Aviatrix Cloud Network Innovation Leader | About Aviatrix Aviatrix means female pilot — a trailblazer pushing boundaries. Our name honors our female founder and spirit of innovation.
SO003 Aviatrix (via CRN coverage) Former Splunk CEO Merritt Becomes Aviatrix's New Leader; Mullaney Exits In 2021, Mullaney was instrumental in ushering Aviatrix through $200 million in growth funding led by investment firm TCV, valuing the company at $2 billion.
SO004 Aviatrix Aviatrix® Building an Iconic Business with New Leadership and Vision Merritt joined Aviatrix in June 2023 following a six-year tenure as CEO and President of Splunk.
SO005 PR Newswire Aviatrix® Building an Iconic Business with New Leadership and Vision Revenues grew from the equivalent of $100 million in Annual Recurring Revenue (ARR) to nearly $3 billion in ARR.
SO006 PR Newswire Aviatrix Appoints New CRO and CMO, Bolstering Leadership Team as Cloud Network Security Market Demand Escalates Trusted by more than 500 of the world's leading enterprises, our cloud networking platform... with 10% of the Fortune 500.
SO007 BankInfoSecurity (ISMG) Aviatrix Pivots Investment From Networking to Cloud Security "What I kept finding was, 'Hey, really interesting networking capability that you give to us. But we really chose you for your security capability.'" — Doug Merritt, Aviatrix CEO
SO008 Crunchbase Aviatrix - Crunchbase Company Profile & Funding Trusted by more than 500 of the world's leading enterprises.
SO009 GitHub Aviatrix Systems — GitHub Organization 2901 Tasman Dr. Santa Clara, CA 95054
SO010 Aviatrix Cloud Network Innovation News & Updates — Aviatrix Newsroom Showing 12 of 462 News
SO011 Aviatrix The Containment Platform for Every Cloud Workload | Aviatrix® Platform 92% of organizations are multi-cloud, each with unique, incompatible security tools.
SO012 Aviatrix Aviatrix Customer Success | 500+ Enterprise Customers 500+ Enterprise Customers Trust Aviatrix for Their Cloud Networking & Security
SO013 Aviatrix Aviatrix Extends Microsoft Agent Control Specification for AI Trusted by more than 500 of the world's leading enterprises.
SO014 Aviatrix Cloud Network Security Careers | Aviatrix We're building something transformational — and we're doing it together.
SO015 Aviatrix Index — Aviatrix Documentation Welcome to the comprehensive documentation for Aviatrix's cloud networking platform.
SO016 Aviatrix Cloud Native Security Fabric — See and Stop What's Already Inside | Aviatrix Traditional security guards the door. But attackers are already inside. Control what happens between your workloads.
SO017 Aviatrix Cloud Network Architecture & Implementation Use Cases | Aviatrix Solutions You can't solve cloud challenges with yesterday's tools.
SO018 Ignition Partners Ignition Partners Portfolio
SO019 AWS Marketplace AWS Marketplace: Search Results for Aviatrix
SO020 TechCrunch Aviatrix raises $200M at a $2B valuation for its cloud networking and security platform
SO021 TCV Aviatrix — TCV Investments
SO022 CRN 10 Hottest Cloud Computing Startups Of 2023
SO023 Deloitte Deloitte Technology Fast 500 Winners
SO024 Fortune Fortune Cyber 60 Ranking
SO025 G2 Aviatrix Reviews on G2
SM001 MarketsandMarkets Cloud Security Market Report 2026-2031, by Type, Geo, Tech "The cloud security market is projected to reach USD 59.34 billion by 2031 from USD 34.37 billion in 2026, at a CAGR of 11.5%."
SM002 Grand View Research Cloud Security Market Size And Share | Industry Report, 2030 "The global cloud security market size was estimated at USD 35.84 billion in 2024 and is projected to reach USD 75.26 billion by 2030, growing at a CAGR of 13.3% from 2025 to 2030."
SM003 Flexera Flexera 2024 State of the Cloud Report: Cloud computing trends "Respondents saw a slight increase in multi-cloud usage, up from 87% last year to 89% this year. Sixty-one percent of large enterprises use multi-cloud security."
SM004 MarketsandMarkets Network Security Market, Zero Trust Architecture Market, and Zero Trust Security Market Forecasts "The network security market is expected to grow from USD 84.50 billion in 2025 to USD 119.70 billion by 2030, at a CAGR of 7.2%."
SM005 MarketsandMarkets SASE Market and Security Service Edge (SSE) Market Forecasts "The SASE market is expected to reach USD 68.06 billion by 2030 from USD 19.19 billion in 2026, exhibiting a CAGR of 28.8%."
SM006 National Institute of Standards and Technology (NIST) NIST Special Publication 800-207: Zero Trust Architecture "Zero trust (ZT) is the term for an evolving set of cybersecurity paradigms that move defenses from static, network-based perimeters to focus on users, assets, and resources."
SM007 Palo Alto Networks What is Zero Trust? Definition, Principles, and Strategy "Unit 42's 2026 Global Incident Response Report: Identity weaknesses were exploited in 89% of investigations. Identity-based techniques drove 65% of initial access."
SM008 Zscaler What Is Zero Trust? Definition, Principles and Architecture "Zero trust is a cloud-era security model: never trust, always verify. It replaces network trust with continuous, least-privilege checks per request using identity, behavior, and device posture."
SM009 Cloudflare What is Zero Trust Network Access (ZTNA)? "ZTNA is similar to the software-defined perimeter (SDP) approach to controlling access. In ZTNA, connected devices are not aware of any resources on the network other than what they are connected to."
SM010 IBM What Is Zero Trust? | IBM "According to a 2024 TechTarget Enterprise Strategy Group report, more than two thirds of organizations say that they are implementing zero trust policies across their enterprises."
SM011 Cisco What Is Network Security? "Emergence of quantum computing capabilities will render traditional security protocols obsolete and require complex transition to post-quantum cryptography (PQC) protocols."
SM012 CISA (Cybersecurity and Infrastructure Security Agency) Zero Trust Maturity Model | CISA "Zero trust provides a collection of concepts and ideas designed to minimize uncertainty in enforcing accurate, least privilege per-request access decisions in information systems and services in the face of a network viewed as compromised."
SM013 MarketsandMarkets Multi-Cloud Networking and Enterprise Networking Market Forecasts "The global Multi-Cloud Networking market size is projected to reach USD 7.6 billion by 2027, at a Compound Annual Growth Rate (CAGR) of 22.5% during the forecast period."
SM014 Aviatrix (via PR Newswire) Aviatrix Appoints New CRO and CMO, Bolstering Leadership Team as Cloud Network Security Market Demand Escalates "Aviatrix is solving the biggest challenges facing enterprises today, like IP exhaustion, Azure NAT gateway policy changes, and infrastructure modernization with zero trust cloud networking."
SM015 Palo Alto Networks 2025 Cloud Security Research Report (State of Cloud Native Security) "97% of orgs prioritize consolidating their cloud security footprint. 89% of orgs say cloud and application security must be fully integrated with the SOC."
SM016 Palo Alto Networks What Is Cloud Network Security? "Containerized next-generation firewalls stop malware from entering and spreading within the cluster, while also preventing malicious outbound connections used in data exfiltration and command and control (C2) attacks."
SM017 BankInfoSecurity Aviatrix Pivots Investment from Networking to Cloud Security
SM018 Aviatrix Cloud Native Security Fabric (CNSF)
SM019 Aviatrix Solutions
SM020 Aviatrix Platform
SM021 Aviatrix Customers
SM022 Aviatrix Aviatrix — Cloud Network Security
SM023 Deloitte Technology Fast 500 Winners
SM024 Fortune Cyber 60 Ranking
SM025 G2 Aviatrix Reviews
SM026 Aviatrix (via PR Newswire) Aviatrix Building an Iconic Business with New Leadership and Vision
SP001 Alkira Cloud Networking Across AWS, Azure and GCP Alkira claims 96% reduction in cloud setup time, 47% reduction in network management time, and up to 40% lower total cost of ownership, and supports AWS, Azure, GCP, and OCI with a drag-and-drop interface.
SP002 Alkira Home - Alkira Network Infrastructure-as-a-Service
SP003 Cisco Systems Cisco Multicloud Defense Simplify security and gain multidirectional protection across any public or private cloud to block inbound attacks, lateral movement, and data exfiltration using a single solution.
SP004 Amazon Web Services Network Gateway - AWS Transit Gateway Build, deploy, and manage applications across thousands of Amazon VPCs without having to manage peering connections or update routing tables.
SP005 Amazon Web Services Network Firewall, Cloud Firewall - AWS Network Firewall
SP006 Microsoft Azure Azure Firewall – Cloud Network Security Solutions
SP007 Microsoft Azure Virtual WAN - Microsoft Azure
SP008 Google Cloud Hierarchical firewall policies - Cloud Next Generation Firewall - Google Cloud Documentation
SP009 Cato Networks SASE: What is Secure Access Service Edge? SASE converges SD-WAN, a Cloud Network, and Security Service Edge (SSE) functions, including FWaaS, CASB, DLP, SWG, and ZTNA, into a unified, cloud-native service.
SP010 Netskope Netskope One Private Access | Universal ZTNA solution
SP011 Palo Alto Networks Prisma Cloud | Comprehensive Cloud Security Prisma Cloud analyzes 1T events every 24 hours to deliver unparalleled visibility and uses Precision AI to detect 1.5M new attacks every day.
SP012 Palo Alto Networks Prisma SASE
SP013 Zscaler Transforming secure access with Zscaler Private Access (ZPA) 91% of organizations are concerned that VPNs compromise their security; 56% of organizations suffered one or more VPN-related attacks in 2023-2024.
SP014 Illumio Breach Containment & AI Cloud Detection and Response | Illumio Illumio Named a 2024 Forrester Wave Leader in Microsegmentation. Illumio is named a Customers' Choice in the 2026 Gartner Peer Insights VOC Report for Network Security Microsegmentation with a 4.8 out of 5 star rating based on 59 reviews.
SP015 PeerSpot Aviatrix Reviews, Competitors and Pricing Aviatrix is the #3 ranked solution in top Software Defined Networking. PeerSpot users give Aviatrix an average rating of 8.0 out of 10. Aviatrix is popular among the large enterprise segment, accounting for 50% of users.
SP016 Wiz Wiz Cloud and AI Security Platform | Wiz Trusted by more than 50% of Fortune 100 companies. Wiz AI-APP provides end-to-end visibility and protection for cloud and AI systems across development, infrastructure, data, and runtime.
SP017 Fortinet Next Generation Firewall (NGFW) - FortiGate FortiGate is the most deployed network firewall with over 50% of global market share. FortiGate NGFWs include built-in ZTNA capabilities and SD-WAN integration.
SP018 Gartner Peer Insights Cloud Networking Services Reviews - Gartner Peer Insights
SP019 PeerSpot Alkira Reviews - PeerSpot
SP020 PeerSpot Cisco Meraki SD-WAN vs Aviatrix - PeerSpot Comparison
SP021 Gartner Gartner for Information Technology Leaders
SP022 Alkira Alkira Cloud Networking - Product Overview
SP023 Amazon Web Services AWS Transit Gateway - Use Cases and Features
SP024 Microsoft Azure Azure Firewall Premium Features
SP025 Google Cloud GCP Cloud NGFW Firewall Policy Overview
SI001 Latka Aviatrix Systems Revenue 2024: $63.9M Est. ARR In 2024, Aviatrix Systems's revenue reached $63.9M. The company previously reported $35.3M in 2023. Since its launch in 2013, Aviatrix Systems has shown consistent revenue growth.
SI002 Tracxn Aviatrix — Funding Rounds and Investors Aviatrix has raised a total of $346M over 6 funding rounds: 1 Seed, 2 Early-Stage and 3 Late-Stage rounds. Aviatrix's largest funding round so far was a Series E for $200M in Sep 2021.
SI003 Insight Partners Aviatrix Raises $200 Million in Funding Led by TCV, Elevating Valuation to $2 Billion This Series E funding raises Aviatrix's valuation to $2 billion, which has more than doubled in six months since the previous round.
SI004 Aviatrix Aviatrix Raises $200 Million in Funding Led by TCV, Elevating the Cloud Networking Leader's Valuation to $2 Billion Aviatrix, the leader in cloud networking and network security, today announced it has raised $200 million in growth funding led by TCV. This Series E funding raises Aviatrix's valuation to $2 billion, which has more than doubled in six months since the previous round.
SI005 Aviatrix Aviatrix Named One of North America's Fastest-Growing Companies on the 2025 Deloitte Technology Fast 500 This marks Aviatrix's fourth consecutive year on the prestigious list, underscoring its continued momentum as a leader in cloud network security. Guided by Chief Executive Officer Doug Merritt and newly appointed Chief Financial Officer Ken Tinsley, Aviatrix continues to scale its operations.
SI006 Aviatrix Aviatrix Pricing Page
SI007 Growjo Aviatrix: Revenue, Competitors, Alternatives Aviatrix's estimated annual revenue is currently $135M per year. Aviatrix has 521 Employees. Aviatrix grew their employee count by 24% last year.
SI008 Vendr Aviatrix Systems Software Pricing and Plans 2025: See Your Cost Median buyer pays $194,034 per year.
SI009 CostBench Aviatrix Pricing 2026: 2 Plans from $2,500–$15,000/month Aviatrix costs $2.5K to $15K per month as of June 2026, with 2 plans available. Pricing depends on your chosen tier, contract length, and negotiated discounts. There are at least 2 documented hidden costs beyond list price.
SI010 SaaS Capital 2025 Private SaaS Company Valuations We begin 2025 with the SCI median valuation multiple standing at 7.0 times current run-rate annualized revenue.
SI011 Venionaire DealMatrix Privacy and Security Valuation Multiples As of 31 March 2025, the Privacy and Security sector benchmark was an EV/Sales multiple of about 3.8× and an EV/EBITDA multiple of about 18.6× (median across six regions).
SI012 Sacra Aviatrix funding, news and analysis Funding $383.09M. Founded 2014. Headquarters Santa Clara, CA.
SI013 Yahoo Finance (Forge Data) Aviatrix (AVIA.PVT) Valuation, History and News PVT - Private Company Price USD 3.4800. Forge Price as of Jun 22, 2026. Estimated Valuation 411.03M. Latest Funding Date Sep 8, 2021. Total Amount Raised 383.09M.
SI014 The SaaS News Aviatrix Raises $200 Million in Series E The round, which raised the company's valuation to $2 billion, was led by TCV with participation from new investors Insight Partners and Tiger Global, and existing investors CRV, Formation 8, General Catalyst, Greenspring Associates, Ignition, Liberty Global Ventures, Meritech Capital and TrueBridge Capital Partners.
SI015 PM Insights Aviatrix Valuation
SI016 CB Insights Aviatrix Stock Price, Funding, Valuation, Revenue and Financial Statements
SI017 U.S. Securities and Exchange Commission (SEC EDGAR) Aviatrix Systems, Inc. Form D — Notice of Exempt Offering of Securities (Series C) Aviatrix Systems, Inc. Incorporated in Delaware. Business location: Santa Clara, CA. Signed by Stephen Mullaney, President and CEO, 2019-11-04. Offering item 06b.
SI018 PR Newswire Aviatrix Appoints New CRO and CMO, Bolstering Leadership Team as Cloud Network Security Market Demand Escalates With a customer base of 500+ that includes 10% of the Fortune 500 and strong VAR, ISV, and CSP partners, Aviatrix is poised for sustained hyper growth.
SI019 PR Newswire Aviatrix Building an Iconic Business with New Leadership and Vision
SI020 BankInfoSecurity (ISMG) Aviatrix Pivots Investment From Networking to Cloud Security While Aviatrix began with a networking abstraction layer across clouds, customer feedback made it clear that their security functionality was the primary attraction.
SI021 Aviatrix Customer Stories
SI022 Aviatrix About Aviatrix
SI023 Aviatrix Aviatrix Homepage
SI024 Crunchbase Aviatrix — Company Funding and Investors
SI025 G2 Aviatrix Reviews — Enterprise Customer Feedback
SE001 Aviatrix Cloud Network Security | Runtime Protection for AI & Multicloud | Aviatrix
SE002 Aviatrix Cloud Native Security for Multicloud & AI | Aviatrix Platform CNSF is the embedded enforcement fabric that makes Zero Trust a reality.
SE003 Aviatrix Aviatrix Products – Unified Zero Trust Security Across All Clouds CNSF delivers audit-ready compliance with HIPAA 2025, PCI DSS 4.0, DORA, NIS2, and CISA ZTMM 2.0.
SE004 Aviatrix Aviatrix Zero Trust Workloads Solution for Cloud Native Security
SE005 Aviatrix Distributed Cloud Firewall (DCF) for the Modern Cloud | Aviatrix Distributed Inline Enforcement at Source: Enforces full L4-L7 inspection directly at the source of traffic, dropping unauthorized connections at the first hop.
SE006 Aviatrix AgentGuard: Network-Native AI Security | Aviatrix Shadow AI Discovery is in early access. Network Enforcement is available today via Zero Trust for AI Workloads. Deep AI Observability and Advanced AI Guardrails ship Q3 2026.
SE007 Aviatrix Aviatrix Zero Trust Networking Solution for Cloud Native Security
SE008 Aviatrix High-Performance Encryption for Multicloud Security | Aviatrix HPE scales to 100+ Gbps hybrid throughput and up to 1 Tbps+ cloud-to-cloud using parallel tunnels and ECMP.
SE009 Aviatrix Workload Threat Visibility: See What's Leaving Your Cloud | Aviatrix
SE010 Aviatrix Microsoft Agent Control Specification: AI Agent Security Guide | Aviatrix Aviatrix's Cloud Native Security Fabric is the first multicloud enforcement substrate for the Microsoft Agent Control Specification.
SE011 Aviatrix Contain. Detect. Eliminate. Aviatrix Deepens Its Investment in the Full Model (OISF blog) The platform now ships 556 purpose-built Suricata rules covering AI-specific threat categories: prompt injection and jailbreak detection, sensitive data leakage, malicious tool usage, data exfiltration, agent-to-agent threats, and malicious file uploads.
SE012 Aviatrix Aviatrix Zero Trust for AI Workloads
SE013 Aviatrix Cloud Network Architecture & Implementation Use Cases | Aviatrix
SE014 Aviatrix Aviatrix Newsroom — Cloud Network Innovation News & Updates
SE015 Aviatrix Aviatrix Documentation — Index
SE016 Aviatrix Aviatrix Systems, Inc. Security Profile — Trust Center Audits and Certifications (5): SOC 2, ISO 27001, TISAX, GDPR, CCPA.
SE017 Open Information Security Foundation (OISF) OISF Consortium Membership Levels and Benefits
SE018 The Hacker News Hackers Exploit Aviatrix Controller Vulnerability to Deploy Backdoors and Crypto Miners Around 3% of cloud enterprise environments have Aviatrix Controller deployed, out of which 65% of them demonstrate a lateral movement path to administrative cloud control plane permissions.
SE019 NIST National Vulnerability Database NVD — CVE-2024-50603
SE020 OWASP Foundation OWASP Top 10 for Large Language Model Applications
SE021 OWASP GenAI Security Project LLM Top 10 — OWASP Gen AI Security Project
SE022 CISA Known Exploited Vulnerabilities Catalog | CISA
SE023 Help Net Security Aviatrix — Help Net Security Coverage 2026
SE024 HashiCorp / Terraform Registry Aviatrix Terraform Provider — registry.terraform.io
SE025 Aviatrix Aviatrix Blog — Cloud Network Technical Blog & Insights
SE026 PeerSpot Aviatrix Reviews 2026
SU001 Aviatrix Aviatrix Customer Success — 500+ Enterprise Customers 500+ Enterprise Customers Trust Aviatrix for Their Cloud Networking & Security
SU002 Aviatrix Better Financial Secures Cloud Data with Egress — Aviatrix Customer Story "Without Aviatrix, Better would simply not be able to meet our security and compliance requirements." — Ali Khan, CISO, Better
SU003 Aviatrix AB InBev Streamlines Multicloud Management — Aviatrix Customer Story "The Aviatrix Control Plane is one of the key features we value because of the visibility it provides across the entire environment." — Manaswinee Mohanty, Director of DevOps, AB InBev
SU004 Aviatrix IHG Powers Global Hotel Operations with Multicloud Architecture "Having a partner like Aviatrix helps the team to be successful." — Eric Norman, Head of Infrastructure, Architecture and Innovation, IHG Hotels & Resorts
SU005 Aviatrix Republic Airways Turns Its Hybrid Cloud Network into a Zero Trust Security Fabric "We can spin up connectivity in a new region in under one day and have a full environment ready to go." — Brent Fowler, Senior Network Engineer, Republic Airways
SU006 Aviatrix Across AI Delivers Secure Enterprise AI Agents with Aviatrix CNSF "Aviatrix is foundational. It allows us to focus on building value at the application and agent layers." — Nilou Salehi, Co-CEO, Across AI
SU007 Aviatrix Amundi Streamlines Hybrid Cloud Network Security "Aviatrix has been a key enabler to bring on-prem network engineers into the public cloud and is the glue that holds the DevOps and Network teams together." — Thomas Mouilleseaux, Global Head of IT Network, Amundi
SU008 Aviatrix Yara Secures Multicloud Network Security "Aviatrix makes both deployment automation and day-two operations much simpler than native cloud networking." — David Van Damme, Director of Farm and Field Data, Yara
SU009 Aviatrix HAPEV Manages Multicloud Security Environment "With the Aviatrix IaC capabilities, our DevOps team can configure the infrastructure for new workloads in less than an hour." — Radu Alexa, Network & Security Engineer, HAPEV
SU010 Aviatrix Aegon Simplifies Multicloud Security & Network Management "Working with a small team to deliver what we are doing today would not have been possible if we had not implemented Aviatrix." — Glynis Coutee, Head of Infrastructure, Aegon
SU011 Aviatrix GN Gains Complete Azure Network Visibility "With Aviatrix, we can make decisions based on business considerations — Our infrastructure doesn't hold us back." — Søren Stentoft Hansen, Director of IT Security & Network, GN
SU012 Aviatrix Inmarsat Implements Secure Multicloud Architecture "The Aviatrix solution provides us a scalable, repeatable way to design where new pods of connectivity can be onboarded in minutes." — Sheldon Parsons, Senior Network Engineer, Inmarsat
SU013 Aviatrix PipelineRx Secures Healthcare Data Exchange "Aviatrix gave us simple, scalable, centralized management capabilities for all our VPNs and all our data." — Darren Lombardi, DevOps Engineer, PipelineRx
SU014 Aviatrix Socially Determined Enhances Healthcare Data Security "With Aviatrix, we can resolve problems faster. This lets us service our internal teams and help them get products out faster." — Min Pummalee, Senior DevSecOps Technical Specialist, Socially Determined
SU015 Aviatrix Aviatrix Certified Engineer (ACE) Program: Get Certified Now!
SU016 Aviatrix Aviatrix Building an Iconic Business with New Leadership and Vision "Trusted by more than 500 of the world's leading enterprises, our cloud networking platform creates the visibility, security, and control needed to adapt with ease."
SU017 Aviatrix Aviatrix Named One of North America's Fastest Growing Companies — Deloitte 2025 "Being recognized as one of North America's fastest-growing companies reflects our relentless focus on securing the cloud for our customers."
SU018 Aviatrix Cloud Security for Financial Services — Aviatrix Solutions 500+ Enterprises Trust Aviatrix — Including 10% of the Fortune 500
SU019 Aviatrix Community The Cloud Network — Aviatrix Community Portal Community Stats: 969 Topics, 1,355 Replies, 8,366 Members
SU020 PeerSpot Aviatrix Reviews, Competitors and Pricing — PeerSpot "Aviatrix is a pretty expensive solution. Users have to pay a yearly licensing fee for the solution and the support. You can't buy the product without support."
SU021 TrustRadius Aviatrix Reviews & Ratings 2026 — TrustRadius "Updates take too much manual work." / "It lacks ways to admin-down an established site-to-site VPN connection."
SU022 G2 Aviatrix Reviews — G2
SU023 Vendr Aviatrix Systems Software Pricing & Plans 2025 — Vendr Median buyer pays $194,034 per year
SU024 Deloitte Deloitte Technology Fast 500 Winners
SU025 Sacra Aviatrix Company Profile — Sacra Research
SU026 The Hacker News Hackers Exploit Aviatrix Controller Vulnerability to Deploy Cryptominers and Backdoors Hackers actively exploited CVE-2024-50603 in Aviatrix Controller, deploying cryptominers and backdoors in customer cloud environments.
SU027 Microsoft Aviatrix Controller — Azure Marketplace
SR001 Amazon Web Services AWS Cloud WAN – Managed Wide Area Network Service AWS Cloud WAN provides a central dashboard for making connections between your branch offices, data centers, and Amazon VPCs—building a global network with only a few clicks.
SR002 Microsoft Azure Documentation Azure Virtual WAN Overview Azure Virtual WAN is a networking service that brings many networking, security, and routing functionalities together to provide a single operational interface.
SR003 Google Cloud Documentation Network Connectivity Center (NCC) Overview NCC supports Partner Cross-Cloud Interconnect for Amazon Web Services (AWS) (Preview), enabling cross-cloud connectivity using Google Cloud as the backbone.
SR004 Amazon Web Services Amazon VPC Pricing NAT Gateway is charged on an hourly basis. For this region, the rate is $0.045 per hour.
SR005 U.S. Securities and Exchange Commission EDGAR Full-Text Search — Aviatrix Systems Form D Filings EDGAR search returns one Aviatrix Systems, Inc. Form D filing (November 2019, Reg D item 06B); no subsequent Form D amendments are publicly accessible for later funding rounds.
SR006 Cloud Security Alliance Cloud Controls Matrix (CCM) The CCM helps you align with industry-accepted security standards (including ISO, NIST, PCI, and DSS), fulfilling multiple requirements in one streamlined process.
SR007 Cybersecurity and Infrastructure Security Agency No-Cost Cybersecurity Services & Tools CISA has curated a database of no-cost cybersecurity services and tools as part of our continuing mission to reduce cybersecurity risk across U.S. critical infrastructure partners and state, local, tribal, and territorial governments.
SR008 Gartner Gartner for IT Leaders — Multicloud and CIO Priorities 2026
SR009 The Hacker News Hackers Exploit Aviatrix Controller Vulnerability to Deploy Backdoors and Crypto Miners Cloud security firm Wiz said it's currently responding to "multiple incidents" involving the weaponization of CVE-2024-50603 (CVSS score: 10.0), a maximum severity bug that could result in unauthenticated remote code execution.
SR010 NIST National Vulnerability Database NVD — CVE-2024-50603 CVE-2024-50603 scored CVSS 10.0 (Critical); affected Aviatrix Controller versions prior to 7.1.4191 and 7.2.4996.
SR011 Cybersecurity and Infrastructure Security Agency Known Exploited Vulnerabilities Catalog CISA added CVE-2024-50603 to the KEV catalog on January 16, 2025, requiring Federal Civilian Executive Branch agencies to apply fixes by February 6, 2025.
SR012 BankInfoSecurity (ISMG) Aviatrix Pivots Investment From Networking to Cloud Security While Aviatrix began with a networking abstraction layer across clouds, customer feedback made it clear that their security functionality was the primary attraction, said CEO Doug Merritt.
SR013 Aviatrix (via CRN) Former Splunk CEO Merritt Becomes Aviatrix's New Leader; Mullaney Exits Merritt will succeed Steve Mullaney, who for the past four years has built Aviatrix into an industry-defining enterprise cloud networking and network security company.
SR014 PR Newswire Aviatrix Appoints New CRO and CMO, Bolstering Leadership Team Ken Horner has joined Aviatrix as its new Chief Revenue Officer (CRO), coming from leading technology companies including Cloudflare, Flexera, Splunk, HP, and Cisco.
SR015 Aviatrix Aviatrix Trust Center At Aviatrix, security is our highest priority. We are deeply committed to protecting our customers' data, ensuring the security of our products, and upholding the highest standards of operational excellence.
SR016 PR Newswire Aviatrix: Building an Iconic Business with New Leadership and Vision Doug Merritt was named CEO, president and chairman of Aviatrix as the company enters a new phase of growth focused on cloud network security.
SR017 Sacra Aviatrix Funding, News & Analysis
SR018 CB Insights Aviatrix Stock Price, Funding, Valuation, Revenue & Financial Statements
SR019 Amazon Web Services AWS Transit Gateway
SR020 Amazon Web Services AWS Network Firewall
SR021 Microsoft Azure Azure Virtual WAN
SR022 Cisco Cisco Multicloud Defense
SR023 Palo Alto Networks Prisma Cloud
SR024 Wiz Wiz Platform
SR025 G2 Aviatrix Reviews
SR026 TrustRadius Aviatrix Reviews
SR027 Tracxn Aviatrix Funding and Investors
SR028 Aviatrix Aviatrix Raises $200 Million in Funding Led by TCV Aviatrix raises $200 million in Series E funding at a $2 billion valuation, the round led by TCV with participation from Insight Partners and others.
SR029 GetLatka Aviatrix Systems — Revenue, Customers, and Growth Data
SR030 U.S. Securities and Exchange Commission Aviatrix Systems Inc. — SEC Form D (Exempt Offering, 2019) Aviatrix Systems, Inc., incorporated in Delaware, headquartered in Santa Clara CA 95054, filed Regulation D exempt offering notice (item 06B) on November 4, 2019.
SR031 GrowJo Aviatrix — Revenue and Employee Count Estimates
SR032 NIST NIST SP 800-207: Zero Trust Architecture
SR033 Cybersecurity and Infrastructure Security Agency Zero Trust Maturity Model
SR034 Gartner Gartner Peer Insights — Cloud Networking Services Reviews
SV001 StockAnalysis (S&P Global Market Intelligence data) Zscaler (ZS) Stock Price & Overview Market Cap: 20.90B -55.4%; Revenue (ttm): 3.17B +24.6%
SV002 StockAnalysis (S&P Global Market Intelligence data) Zscaler (ZS) Financials & Income Statement FY 2025 Revenue: 2,673; Revenue Growth (YoY): 23.31%
SV003 StockAnalysis (S&P Global Market Intelligence data) Palo Alto Networks (PANW) Stock Price & Overview Market Cap: 237.72B +80.9%; Revenue (ttm): 10.61B +19.5%
SV004 StockAnalysis (S&P Global Market Intelligence data) Palo Alto Networks (PANW) Financials & Income Statement FY 2025 Revenue: 9,222; Revenue Growth (YoY): 14.87%
SV005 StockAnalysis (S&P Global Market Intelligence data) CrowdStrike Holdings (CRWD) Stock Price & Overview Market Cap: 175.45B +52.1%; Revenue (ttm): 5.09B +23.2%
SV006 StockAnalysis (S&P Global Market Intelligence data) Cloudflare (NET) Stock Price & Overview Market Cap: 81.21B +37.1%; Revenue (ttm): 2.33B +31.6%
SV007 StockAnalysis (S&P Global Market Intelligence data) Fortinet (FTNT) Stock Price & Overview Market Cap: 108.44B +36.9%; Revenue (ttm): 7.11B +15.7%
SV008 StockAnalysis (S&P Global Market Intelligence data) Okta (OKTA) Stock Price & Overview Market Cap: 20.62B +11.5%; Revenue (ttm): 3.00B +11.7%
SV009 Forge Global Aviatrix IPO: Investment Opportunities & Pre-IPO Valuations — Forge Series E Valuation, Sep 2021: $2B; Total Funding: $383.09MM; Forge Price Date: 06/23/2026; Last Matched Price: --
SV010 Macrotrends Zscaler Price to Sales Ratio 2016–2025 | ZS 2025-10-31 P/S ratio: 18.17; 2026-02-17 stock price: 172.59
SV011 SaaS Capital Four early 2026 SaaS trends SaaS valuations hit decade-plus lows in Q1 2026 as markets priced in AI as an existential threat.
SV012 U.S. Securities and Exchange Commission (SEC) Zscaler, Inc. Annual Report on Form 10-K for Fiscal Year Ended July 31, 2025 Revenue increasing from $1,617.0 million in fiscal 2023 to $2,167.8 million in fiscal 2024 to $2,673.1 million in fiscal 2025
SV013 EquityZen Invest In Aviatrix Stock | Buy Pre-IPO Shares | EquityZen Total Funding: 414M; More than 550 customers worldwide reportedly leverage Aviatrix
SV014 Aswath Damodaran — NYU Stern School of Business Value/Sales Ratios by Industry — January 2025 Software (77 firms): EV/Sales 9.01 (positive EBITDA firms); Software (Internet): EV/Sales 9.56
SV015 PM Insights Aviatrix — Private Market Insights and Secondary Price Data AVIA.PVT $3.48 per share (June 22, 2026 per PM Insights/Forge cross-reference)
SV016 Yahoo Finance Aviatrix (AVIA.PVT) — Private Shares on Yahoo Finance AVIA.PVT last price $3.48 (June 22, 2026)
SV017 Latka (via GetLatka) Aviatrix ARR Revenue Data Aviatrix ARR $63.9M as of October 2024; $35.3M as of November 2023
SV018 Growjo Aviatrix — Revenue Estimate and Employee Data Growjo estimates Aviatrix current annual revenue at approximately $135M
SV019 Aviatrix (official company press release) Aviatrix Closes $200 Million Series E at $2 Billion Valuation Aviatrix today announced it has closed a $200 million Series E funding round at a $2 billion post-money valuation
SV020 VentureBeat Aviatrix Raises $200 Million in Series E Funding Aviatrix has raised $200 million in Series E funding at a $2 billion post-money valuation
SV021 The SaaS News Aviatrix Raises $200 Million in Series E Aviatrix raised $200 million in Series E at a $2 billion post-money valuation
SV022 SaaS Capital Private SaaS Company Valuations — ARR Multiple Benchmarks Median ARR multiple for private B2B SaaS companies 7.0x (SCI as of late 2024)
SV023 DealMatrix Privacy and Security Industry Valuation Multiples Median EV/Sales multiple for Privacy and Security sector: approximately 7.3x
SV024 Sacra Aviatrix — Private Company Revenue and Business Analysis
SV025 CB Insights Aviatrix Systems — Financials and Funding Overview
SV026 U.S. Securities and Exchange Commission (SEC EDGAR) Aviatrix Systems Inc. Form D — Notice of Exempt Offering of Securities Aviatrix Systems, Inc. — Delaware corporation, 2901 Tasman Drive, Santa Clara CA 95054
SV027 TCV (Technology Crossover Ventures) Aviatrix Series E Investment Announcement — TCV Portfolio
SV028 PR Newswire Aviatrix Raises $200 Million in Series E Funding Aviatrix today announced $200 million in Series E funding at a $2 billion post-money valuation
SV029 Crunchbase Aviatrix — Organization Funding and Investor Data
SV030 StockAnalysis (S&P Global Market Intelligence data) CrowdStrike Holdings (CRWD) Financials & Income Statement FY 2026 Revenue: 4,812; Revenue Growth (YoY): 21.71%
SV031 Bank Info Security Aviatrix Pivots Investment from Networking to Cloud Security