Cockroach Labs
High-quality distributed database franchise with a demanding private-market price
Cockroach Labs looks like a real late-stage infrastructure winner candidate, but the current private-market price appears stretched relative to public evidence on revenue and efficiency.
Cover facts
Company profile
Cockroach Labs is a New York-based infrastructure company founded in 2015 and built around CockroachDB, a PostgreSQL-compatible distributed SQL database sold as fully managed cloud and enterprise software. Public evidence shows unusually strong customer proof across payments, order management, fraud, gaming, and internal database-platform workloads, along with continued secondary-market interest in 2026. The central diligence tension is that company quality looks real while current financial disclosure remains too sparse to underwrite valuation with high conviction.
- Website
- www.cockroachlabs.com
- Founded
- 2015-01-01
- Founders
- Spencer Kimball, Ben Darnell, Peter Mattis
- Founding location
- New York, NY
- Headquarters
- New York, NY
- Product
- Cockroach Labs sells CockroachDB Cloud, self-hosted CockroachDB Enterprise, and related support and migration capabilities for globally distributed, resilient transactional workloads.
- Customers
- Enterprises and technically sophisticated software teams running mission-critical, multi-region, compliance-sensitive, or high-availability applications.
- Business model
- Subscription and consumption-based database revenue spanning managed cloud, enterprise software, support, and migration-led expansion.
- Stage
- late-stage private
- Funding status
- Series F in December 2021 raised $278M at a $5B valuation; 2026 secondary indicators imply roughly a $6.9B mark without disclosed new primary capital.
Executive summary
Top strengths
- Strong product and customer proof in mission-critical distributed transactional workloads.
- Premium reference customers such as DoorDash, Netflix, Route, Riskified, Form3, and Hard Rock support relevance and switching-cost durability.
- Continued secondary-market interest and a sustained premium narrative suggest the market still views Cockroach as a differentiated late-stage asset.
- PostgreSQL compatibility plus multi-region resilience and portability create a credible strategic wedge in a large infrastructure category.
Top risks
- Public financial disclosure is too thin to verify current ARR, NRR, gross margin, concentration, or runway at the present price.
- Distributed-database correctness, upgrade discipline, and support intensity create meaningful operational and execution risk.
- The customer mix appears high quality but skewed toward sophisticated accounts that may require longer sales cycles and heavier post-sale support.
- Current implied valuation looks rich relative to public software-infrastructure comp multiples unless hidden metrics are substantially stronger than public anchors.
Open gaps
- Current 2025-2026 ARR or revenue run rate and segmented net retention / gross retention.
- Gross margin, support-cost intensity, and whether support-heavy deployments dilute operating leverage.
- Customer concentration and the revenue share of top enterprise accounts.
- Cash balance, burn, runway, and any primary financing plans beyond secondary liquidity.
Contents
01Company Overview
1.1 Identity, product scope, and current positioning
Cockroach Labs positions itself as an infrastructure company solving a narrow but painful problem: how to run transactional databases that stay online through node, zone, and even regional failures without forcing application teams to manually shard or redesign around brittle failover patterns. Accessible public materials consistently place the company in New York and date the company to 2015, while its official product surfaces emphasize a PostgreSQL-compatible, cloud-native distributed SQL database rather than a proprietary developer experience. The product stack is no longer one thing. In 2026 the company markets fully managed CockroachDB Cloud, self-hosted Enterprise, migration tooling, and support, and it monetizes across Basic, Standard, and Advanced cloud tiers. That tiering matters because it shows Cockroach Labs is trying to capture both bottoms-up experimentation and regulated production workloads from the same platform. The public trust and security materials reinforce the same go-to-market message: resilience plus compliance plus operator simplicity. The strongest identity signal is therefore not raw scale; it is the company’s insistence that transactional correctness, multi-region resilience, and PostgreSQL familiarity can coexist in one system-of-record product for modern apps.[CO001, CO002, CO003, CO004, CO005, CO006]
| metric | value / status | date | confidence | gap |
|---|---|---|---|---|
| Founded | 2015 | 2015 | high | |
| Headquarters | New York, New York | 2026-07-20 | high | |
| Current stage | Private / Series F | 2026-07-20 | high | |
| Last primary round | $278M Series F at $5B valuation | 2021-12-16 | high | |
| Total raised | $633M | 2021-12-16 | high | |
| 2026 secondary price signal | $7.79 per share on Nasdaq Private Market | 2026-07-02 | medium | Secondary pricing is not the same as a new primary round. |
| Notice secondary price signal | $8.18 per share | 2026-07-20 | medium | Marketplace listing rather than a priced financing. |
| 2023 revenue / ARR | $128.3M | 2023-12-31 | medium | Latest public financial figure surfaced by an aggregator, not by management in 2026. |
| Headcount estimate | ~715 employees | 2025-11-28 | medium | Third-party estimate; official 2026 headcount undisclosed. |
| Customer scale evidence | 200+ customers in 2021 plus named 2026 enterprise deployments | 2026-07-20 | medium | Current official customer count not publicly disclosed. |
| Open-source signal | Public GitHub repo and historical 22k+ stars | 2026-07-20 | medium | Current star count changes over time; 2021 figure was official. |
| Cloud availability | AWS, GCP, Azure; BYOC and self-hosted options | 2026-07-20 | high | |
| Security posture | SOC 2, ISO 27001/27017/27018, PCI DSS, HIPAA-ready claims | 2026-07-20 | high | Certification scope depends on plan and deployment mode. |
| Board disclosure | Not publicly disclosed in accessible sources | 2026-07-20 | medium | Requires management or data-room diligence. |
Mixes official company statements, marketplace pricing indicators, and third-party estimates. Null or gap text indicates information not publicly disclosed with sufficient precision.
[CO001, CO004, CO005, CO006, CO007, CO008]Cockroach Labs links a PostgreSQL-compatible distributed SQL core to managed cloud delivery, compliance tooling, and customer proof in outage-sensitive verticals, with secondary-market pricing as the main unresolved investor signal.
[CO002, CO004, CO005, CO006, CO007, CO012]1.2 Capital formation, private-market signals, and scale markers
The last primary financing remains the December 2021 Series F, when Cockroach Labs raised $278 million at a $5 billion valuation and said lifetime funding had reached $633 million. That round is stale by growth-software standards, but it remains the cleanest official valuation anchor because it comes directly from the company and names an elite investor roster led by Greenoaks. What changed after that is not a new primary round but a more visible secondary market. Nasdaq Private Market and Notice both showed mid-2026 share prices in the high-single-digit range, and PM Insights surfaced a June 2026 premium to the 2021 round that implies a much higher enterprise mark than the official $5 billion headline. Those signals confirm liquidity and investor interest, but they do not solve the core diligence problem: public revenue evidence is still thin. GetLatka’s 2023 ARR figure of $128.3 million and 2025 headcount estimate around 715 employees suggest a business with meaningful scale, yet the company’s 2026 momentum release still avoids hard financial disclosure. The resulting picture is a company large enough to matter, clearly still private, and plausibly worth more on secondary desks than in its last primary round, but still not transparent enough for underwriters to treat those marks as equivalent to a fresh priced financing.[CO008, CO009, CO010, CO011, CO012, CO013]
| person | role | background | founder-market fit or functional coverage | key-person dependency |
|---|---|---|---|---|
| Spencer Kimball | CEO and co-founder | Most visible public executive across funding, product, and resilience messaging | Owns company narrative across fundraising, product direction, and enterprise positioning | high |
| Sailesh Munagala | Chief Financial Officer | Publicly named in the 2026 momentum update as a senior leadership addition | Adds finance leadership as Cockroach Labs matures beyond pure founder-led product selling | medium |
| Public co-founder roster beyond Kimball | Partially disclosed | Accessible public sources clearly center Kimball, but do not cleanly expose the full current founder roster | Founder continuity is relevant to infrastructure-company credibility but is not fully transparent here | medium |
| Board and governance roster | Undisclosed in accessible sources | Public evidence does not expose the current board composition or observer seats | Governance opacity matters more once secondary trading becomes active | medium |
This leadership table intentionally distinguishes clearly disclosed executives from governance areas that remain opaque in accessible sources.
[CO021, CO022, CO035, CO020]| stakeholder | role | control or economic importance | diligence ask |
|---|---|---|---|
| Greenoaks | Lead investor in Series F | Led the last official priced round at the $5B valuation anchor | Clarify board seat, ownership, and any tender or liquidity restrictions. |
| Benchmark | Early investor and visible long-term backer | Represents continuity from the company’s earliest financing periods into late-stage scale | Confirm current stake and governance rights post-Series F. |
| Tiger Global | Growth investor in Series F syndicate | Signals crossover-fund appetite at the peak of 2021 infrastructure pricing | Assess appetite for future insider support or secondary liquidity. |
| Nasdaq Private Market | Secondary liquidity venue | Publishes an estimated share price and facilitates employee/investor transfers for eligible sellers | Understand bid-ask depth, transfer approval rules, and buyer concentration. |
| Notice.co / other private-market aggregators | Secondary market intelligence layer | Provides indicative private-share pricing but not the certainty of a fresh financing | Reconcile quoted per-share values against 409A marks or actual tender documents. |
| Employees and option holders | Potential sellers in private liquidity programs | Active secondary trading can affect retention, morale, and dilution expectations | Request option-pool size, refresh-grant policy, and any current liquidity windows. |
This table focuses on stakeholders shaping valuation and control rather than trying to reconstruct a complete cap table from public crumbs.
[CO008, CO009, CO010, CO012, CO013, CO014]Cockroach Labs progressed from a 2015 founding to a $5B Series F in 2021, then into a 2026 phase defined by secondary-market price discovery, enterprise customer proof, and a resilience-led AI narrative.
Customer milestones use publication timing of public case studies as the dated anchor rather than the original internal go-live date.
[CO001, CO008, CO010, CO019, CO023, CO024]Cockroach Labs combines strong enterprise deployment proof with limited public financial disclosure and a valuation context shaped more by secondary trading than by a fresh primary round.
Mixes company statements, marketplace pricing, and third-party estimates; figures are directionally useful but not equivalent to a fresh audited company disclosure.
[CO008, CO010, CO012, CO013, CO015, CO016]1.3 Leadership concentration and governance visibility
Leadership visibility is unusually concentrated around Spencer Kimball. He remains the public executive attached to the 2021 financing materials and the 2026 momentum narrative, which is helpful for coherence but also creates key-person concentration. The company did signal bench-building by adding Sailesh Munagala as chief financial officer in the 2026 momentum update, which is the most notable publicly visible executive addition in the accessible source set. Beyond that, public governance disclosure is thin. Readily accessible company and third-party profiles do not clearly expose the current board roster, protective provisions, or detailed cap-table structure. That does not imply governance weakness, but it does mean outside investors must infer a lot from the financing syndicate rather than from direct governance documents. The practical implication is that Cockroach Labs now looks like a founder-led late-stage infrastructure company with credible institutional backing but limited public transparency on board composition and investor control. That is acceptable for a private unicorn, but it remains a diligence gap because governance strength matters more once a company begins trading actively in the secondary market and positioning itself as a long-duration enterprise platform.[CO021, CO022, CO035, CO008, CO009]
| date | event | type | amount / status | participants | implication |
|---|---|---|---|---|---|
| 2015 | Cockroach Labs founded | founding | Company inception | Spencer Kimball and early engineering team | Begins the distributed SQL thesis for a cloud-first world. |
| 2021-12-16 | Series F announced | financing | $278M at $5B valuation; $633M total raised | Greenoaks plus late-stage syndicate | Official valuation anchor for every later pricing discussion. |
| 2021-12-16 | Serverless adoption milestone disclosed | scale | 10,000+ new Serverless users | Cockroach Labs | Shows bottoms-up developer funnel emerging alongside enterprise sales. |
| 2021-12-16 | Cloud penetration milestone disclosed | scale | 50%+ customers on Dedicated | Cockroach Labs | Confirms managed-cloud monetization was becoming central by 2021. |
| 2024 | Booking.com migrates order platform use case publicly | customer | ~20TB order platform | Booking.com | Adds marquee travel proof for mission-critical workloads. |
| 2024 | Netflix fleet case study published | customer | 380+ clusters, 160+ production | Netflix | Validates multi-team internal platform usage at hyperscale. |
| 2025 | State of Resilience study published | market | 1,000 enterprise survey respondents | Cockroach Labs + Wakefield Research | Reinforces resilience-led narrative and regulatory relevance. |
| 2026-02 | CockroachDB v26.1 security/compliance release | product | Expanded security and compliance controls | Cockroach Labs | Signals emphasis on regulated workloads and identity-aware access. |
| 2026-05 | Public advisories include privilege escalation and data-integrity issues | adverse | Multiple security and correctness advisories | Cockroach Labs | Reminds investors that distributed-database trust depends on disclosure and patch discipline. |
| 2026 | Momentum release highlights AI-scale resilience and partner expansion | go-to-market | Throughput up to 50%; OEM relationship with IBM; CFO appointment | Cockroach Labs | Positions the company for another phase of enterprise expansion without a fresh primary round. |
Milestones intentionally combine financing, product, customer, and adverse disclosures so later chapters can reuse one chronology of record.
[CO001, CO008, CO010, CO018, CO019, CO023]1.4 Customer proof, resilience credibility, and adverse signals
Cockroach Labs’ strongest non-financial proof point is the quality of its named customer set. Booking.com uses CockroachDB for a roughly 20 TB order platform spanning multiple European regions; SumUp says it migrated a core payments system serving more than 4 million merchants; Form3 runs a multi-cloud payments backbone across AWS, GCP, and Azure; and Netflix reports a fleet of more than 380 CockroachDB clusters. Those are not vanity logos. They are high-availability workloads in payments, travel, and media where correctness and outage tolerance actually matter. This customer evidence supports the company’s 2026 positioning around AI-scale resilience and always-on operations. At the same time, the adverse record is not empty. Cockroach Labs openly publishes technical advisories, and the 2026 list includes privilege-escalation issues, partial-index corruption, live-data-deletion edge cases, and backup-integrity problems. The status page also shows the company is willing to expose cloud incidents publicly. Netting it out, the company has genuine enterprise proof and unusually strong resilience credentials, but those strengths coexist with the ordinary reality of operating a complex distributed database: the product surface is large, bugs happen, and trust depends on disclosure discipline as much as on architecture.[CO023, CO024, CO025, CO026, CO027, CO028]
02Market Analysis
2.1 Market boundary and category logic
Cockroach Labs should not be sized against the entire universe of databases. Its product is a distributed SQL database marketed for cloud-native, mission-critical transactional applications that need resilience, multi-region availability, and PostgreSQL familiarity. That means the cleanest category anchor is distributed SQL, with broader cloud-database and distributed-database figures used only as boundary checks. The included spend is application-facing transactional data infrastructure: production OLTP clusters, resilience upgrades, cloud database operations, migrations off legacy relational estates, and adjacent compliance-heavy modernization work. Excluded spend includes data warehouses, search engines, pure document stores, and developer tooling categories that do not directly replace a transactional system of record. This boundary matters because a very broad “database TAM” can make the opportunity look gigantic while saying almost nothing about the spend Cockroach Labs can actually win. The status-quo alternative is also stronger than in younger software categories. Teams can stay on PostgreSQL, stay on Aurora, use application-level sharding, or select a hyperscaler-native system such as Spanner. The market is therefore not created by awareness alone; it opens when buyers feel enough outage, scale, compliance, or geo-distribution pain to justify migration effort. That framing keeps later valuation work honest: Cockroach Labs is selling into a valuable but highly contested modernization decision, not into unclaimed greenfield demand.[CM001, CM002, CM003, CM018, CM033]
| segment/category | included spend | excluded spend | buyer/payer | relevance |
|---|---|---|---|---|
| Distributed SQL databases | Global transactional clusters, resilience upgrades, managed SQL operations, schema-compatible migrations | Analytics warehouses, search engines, document databases | Platform engineering / CTO / CIO | Best-fit core market lens for Cockroach Labs. |
| Broader distributed databases | Transactional and some non-transactional distributed data infrastructure | Single-node databases and unrelated developer tooling | Architecture and infrastructure leadership | Useful sanity-check market but broader than company scope. |
| Cloud database market | Managed database services across SQL, NoSQL, and multiple deployment models | Pure on-prem legacy support contracts | Cloud platform owners and finance sponsors | Outer-bound adjacency rather than precise addressable market. |
| Status-quo PostgreSQL estates | Self-managed OLTP, extension-heavy installs, app-side sharding | Purpose-built globally consistent distributed SQL features | Engineering managers and DBAs | Primary do-nothing alternative. |
Defines what is in-scope before using any market-size figure.
[CM001, CM002, CM003, CM033]| option | why buyers choose it | why it is not the same market | implication for Cockroach Labs |
|---|---|---|---|
| Self-managed PostgreSQL | Familiarity and extension ecosystem | Lacks native distributed-SQL posture for multi-region resilience | Biggest inertia source and migration starting point. |
| Amazon Aurora PostgreSQL | Managed experience inside AWS | Often optimized for one-cloud convenience over cross-cloud portability | Competes hardest where buyers want minimal change. |
| Google Spanner | Strong architecture for Google Cloud shops | Ties buyers more tightly to hyperscaler and different ecosystem choices | Powerful competitor in large strategic deals. |
| Document or analytics databases | May solve adjacent data problems | Do not directly replace transactional SQL systems of record | Should stay out of core TAM claims. |
Status-quo substitutes matter because most buyers can delay migration by accepting narrower architecture tradeoffs.
[CM002, CM003, CM018, CM020, CM021]2.2 Sizing lenses and where they disagree
Public sizing evidence spans three nested but non-identical markets. DataIntelo's distributed-SQL estimate is the best narrow fit because it explicitly matches Cockroach Labs' architectural category. Business Research Insights provides a broader distributed-database lens, while Coherent Market Insights captures the much larger cloud-database umbrella. These are useful together precisely because they disagree: the range shows the uncertainty created when category boundaries widen. The resulting lesson is that investors should not treat one headline TAM as settled fact. A $26B cloud-database estimate may be directionally helpful for long-run adjacency, but it is not the same as the addressable pool for distributed SQL. Conversely, an estimate below $5B for distributed databases may still miss the specific value premium of globally consistent SQL workloads. Using multiple lenses preserves contradiction rather than laundering it into fake precision. This also limits public SAM and SOM work. Without a disclosed customer count, conversion funnel, or region-by-workload mix, an outsider cannot responsibly derive a company-specific serviceable market. The right diligence stance is to preserve the failed sizing path and ask management for segmentation they actually use internally. In other words, market numbers are useful here as boundary conditions, not as a substitute for actual company operating data.[CM004, CM005, CM006, CM007, CM026, CM031]
| publisher | year | geography | value | CAGR | methodology | confidence | limitation |
|---|---|---|---|---|---|---|---|
| DataIntelo | 2025/2034 | global | $7.2B to $24.8B | 14.7% | Distributed SQL category estimate | medium | Methodology is summarized, not fully transparent. |
| Coherent Market Insights | 2026/2033 | global | $26.0B to $73.0B | 15.9% | Broader cloud database market | medium | Too broad to use as company SAM. |
| Business Research Insights | 2026/2035 | global | $4.48B to $9.96B | 10.5% | Distributed database market | medium | Not limited to distributed SQL. |
| Internal diligence implication | 2026 | n/a | Use distributed SQL as base lens | n/a | Choose nested-market framing | high | Requires management help for true SAM/SOM. |
These lenses are intentionally nested rather than blended because the categories are not interchangeable.
[CM004, CM005, CM006, CM007, CM031, CM035]| issue | evidence | why it changes valuation work | interim conclusion |
|---|---|---|---|
| Category mismatch | Cloud database vs distributed SQL vs distributed database estimates diverge sharply | Different boundaries can inflate TAM by several multiples | Use nested lenses, not one blended estimate. |
| Methodology opacity | Analyst pages summarize results more than methods | Hard to verify segment inclusion and deployment assumptions | Treat figures as directional, not precise. |
| Missing public SAM | No public workload-fit segmentation from company | Cannot isolate capture zone from external data alone | Ask management for internal segmentation. |
| Missing public SOM | No customer count or win-rate disclosure | Cannot support credible share assumptions | Avoid market-share precision in public-only model. |
This register preserves contradictions instead of collapsing them into one headline TAM.
[CM007, CM026, CM031, CM032, CM035]Shows why the narrow distributed-SQL lens is the best base case while broader lenses remain useful boundary checks.
The three market layers use different source methodologies and years; the figure is a framing device, not a mathematically additive funnel.
[CM004, CM005, CM006, CM007, CM031, CM033]Point market estimates are shown as degenerate ranges to make the disagreement visible without implying false precision.
Each published estimate is a point figure represented as a range with equal low/high bounds; the last row is interpretive rather than numeric.
[CM007, CM026, CM035]2.3 Buyer map, adoption drivers, and gating constraints
The economic buyer for CockroachDB is rarely a lone developer. Database transformations that justify this product usually involve platform teams, database specialists, security/compliance owners, and an executive sponsor willing to fund migration work in exchange for lower outage risk or better geographic scale. Daily users are engineers, but the payer is often the leader accountable for resilience, cloud architecture, or a regulated launch schedule. The adoption triggers in public evidence are consistent: multi-region growth, inability to tolerate downtime, migration away from brittle sharding, and demand for compliance or locality controls. PostgreSQL compatibility helps because it narrows organizational switching cost relative to a net-new database model. Customer cases reinforce that the first workload is usually a painful one—a payment flow, booking path, fraud-control service, or other latency-sensitive system—before broader standardization follows. Constraints are equally important. Migration is expensive, operational behavior changes in distributed systems are non-trivial, and any correctness advisory or public incident can slow enterprise conviction. Competition also compresses urgency: Aurora, Spanner, TiDB, YugabyteDB, Neon, and PlanetScale all give buyers some way to postpone or reshape the problem. That makes the market valuable, but not frictionless. The adoption path is therefore less like a standard software upgrade and more like a board-visible reliability project that earns budget only when the pain is concrete.[CM008, CM009, CM010, CM011, CM012, CM013]
| segment | buyer | user | payer | workflow | budget owner | adoption trigger |
|---|---|---|---|---|---|---|
| Financial services / payments | CTO or platform VP | DB engineers and app teams | Engineering / transformation budget | Ledger, payments, risk, regulated systems | CIO / CTO | Resilience plus compliance requirements. |
| Travel / booking | Platform leader | SRE and app engineers | Engineering budget | Reservation and inventory systems | VP Engineering | Global traffic spikes and downtime sensitivity. |
| Fraud / commerce infrastructure | Security or data-platform leader | Application engineers | Product + engineering | Fraud decisioning and checkout infrastructure | CTO / GM | Need low latency and no single-region failure mode. |
| Media / streaming / consumer platforms | Infrastructure leadership | Database and backend teams | Platform budget | User state, catalog, and global session data | VP Infrastructure | Scale plus multi-region reach. |
| AI application platforms | Architecture leader | Platform and data engineers | Innovation / platform budget | Operational stores adjacent to vector workflows | CTO | Need transactional core plus new AI features. |
Buyer and payer roles are inferred from product positioning plus public customer case studies, not from disclosed pipeline data.
[CM010, CM011, CM012, CM013, CM016, CM027]| driver/constraint | direction | timing | implication | diligence ask |
|---|---|---|---|---|
| Multi-region resilience demand | positive | current | Supports premium value story for mission-critical apps | Measure how many new wins explicitly cite outage avoidance. |
| PostgreSQL compatibility | positive | current | Reduces switching cost and expands developer relevance | Request migration conversion data from PostgreSQL-heavy accounts. |
| Compliance and data sovereignty | positive | current | Opens regulated workloads and larger deal sizes | Request regulated-industry pipeline mix and sales cycle length. |
| AI/vector feature expansion | positive but emerging | current | May widen product relevance without changing core wedge | Measure actual AI-linked production deployments. |
| Migration complexity | negative | current | Slows conversion and raises proof burden | Request professional-services intensity and time-to-production. |
| Correctness advisories / trust scrutiny | negative | current | Can slow adoption if resilience promise looks fragile | Request incident review process and referenceability after events. |
Positive and negative forces are mixed because the same resilience narrative that creates demand also raises trust scrutiny.
[CM014, CM015, CM016, CM017, CM024, CM025]| alternative | pricing posture | buyer appeal | pressure on Cockroach Labs |
|---|---|---|---|
| Aurora | Consumption-based managed service | Familiar SQL plus AWS-native operations | Reduces urgency for AWS-centric teams. |
| Spanner | Premium hyperscaler service | Global scale with Google-managed operations | Sets high architectural benchmark in strategic cloud deals. |
| Neon / PlanetScale | Low-friction serverless entry | Cheap experimentation and developer-led evaluation | Can intercept smaller or earlier-stage workloads. |
| TiDB / YugabyteDB | Distributed SQL alternatives | Open-source or multi-mode evaluation path | Raises feature-by-feature comparison burden. |
Pricing posture is qualitative because direct apples-to-apples workload pricing is not publicly normalized.
[CM019, CM021, CM022, CM023]| stage | lead role | proof required | friction point |
|---|---|---|---|
| Problem recognition | CTO / platform VP | Outage pain, geo-scale need, compliance requirement | Internal priority may still be low. |
| Technical evaluation | Platform / database team | Compatibility, performance, failover behavior | Benchmark skepticism and migration effort. |
| Pilot workload | Application team + SRE | One painful workflow proves value | Operational learning curve. |
| Standardization | Engineering leadership | Reference win and platform economics | Broader migration backlog and org capacity. |
Stages describe the most credible public adoption pattern, not a disclosed official sales process.
[CM013, CM014, CM015, CM024, CM034]Maps representative segments to their most plausible public buyer, user, and payer roles.
Roles are inferred from customer stories and product positioning rather than from disclosed org charts.
[CM011, CM013, CM028, CM034]The adoption path usually starts with a painful reliability or geo-scale need, then expands after a first production proof point.
This is a generalized flow inferred from multiple public case studies rather than a disclosed company sales methodology.
[CM014, CM015, CM024, CM034]03Competitors
3.1 Competitive set: status quo, hyperscalers, and true distributed-SQL peers
Cockroach Labs does not sell into a blank market. The first and often strongest competitor is the status quo: teams can keep running PostgreSQL, add replicas, and postpone a migration altogether. That matters because PostgreSQL remains broadly popular and portable, which lowers the organizational urgency to adopt a heavier distributed system even when CockroachDB may be architecturally cleaner for global workloads. The next layer of competition comes from hyperscalers. Aurora, Spanner, and AlloyDB each offer a procurement shortcut: the buyer can stay inside AWS or Google Cloud, reuse commercial relationships, and adopt a managed service without introducing a standalone database vendor. For many enterprise accounts that organizational convenience is itself a feature, even before product differences are considered. Only after those two layers does the buyer get to the most direct distributed-SQL peer set: YugabyteDB, TiDB, and in selected cases CockroachDB-versus-Spanner decisions. PlanetScale, Vitess, Neon, and SingleStore widen the decision set further by offering lower-friction developer entry, sharded MySQL, serverless Postgres, or hybrid transactional-plus-analytical positioning. The practical lesson is that Cockroach Labs is competing less for generic “database spend” than for a narrow class of correctness-sensitive workloads where multi-region resilience is painful enough to justify migration.[CP001, CP002, CP003, CP005, CP008, CP010]
| competitor | category | scale / ownership signal | target segment | differentiation | limitation |
|---|---|---|---|---|---|
| PostgreSQL | Status quo / open source | Community-led OSS ecosystem | General OLTP and broad developer use | Lowest lock-in and broadest tooling familiarity | No native active-active multi-region write path in core project |
| Amazon Aurora | Incumbent managed relational service | AWS-native managed service | AWS shops wanting managed PostgreSQL/MySQL compatibility | Procurement ease, serverless option, replicas, Global Database | AWS-only footprint and multi-part pricing |
| Google Spanner | Global-consistency incumbent | Google-managed distributed database | Large GCP-first global applications | Strong consistency at global scale with managed operations | High lock-in and complex replica-based pricing |
| AlloyDB | Managed PostgreSQL performance path | Google Cloud managed product | PostgreSQL users wanting more performance and AI features on GCP | 100% PostgreSQL-compatible positioning with read pools and AI story | Still tied to Google environment and node-style pricing |
| PlanetScale / Vitess | Sharded MySQL / low-friction cloud DB | Commercial platform on top of Vitess | Teams optimizing developer speed or MySQL scale-out | Cheap entry, HA clusters, BYOC option, proven sharding control plane | MySQL/Vitess lineage limits direct PostgreSQL overlap |
| Neon | Serverless Postgres | Commercial managed Postgres platform | Developer-led apps and agents needing fast starts | Scale-to-zero, branching, separate compute and storage | Less about global active-active transactional semantics |
| YugabyteDB | Direct distributed PostgreSQL peer | Open-source plus commercial support motion | Mission-critical cloud-native OLTP with portability goals | Multi-master distributed PostgreSQL and open-source lock-in story | Very similar pitch creates head-to-head displacement risk |
| TiDB | Distributed SQL with HTAP angle | PingCAP-managed or self-managed | Teams combining transactions with real-time analytics | MySQL compatibility, decoupled compute and storage, HTAP framing | Weaker PostgreSQL migration story |
| SingleStore | Adjacent real-time data platform | Managed cloud DBaaS | Real-time apps mixing SQL, JSON, vector, and analytics | Hybrid transactional plus analytical breadth and strong performance claims | Not a clean PostgreSQL system-of-record substitute for every workload |
| MongoDB Atlas | Adjacent modern app substitute | Managed document database platform | Builders favoring schema flexibility and modern app tooling | Strong modern-app and AI brand | Document model is not a drop-in relational substitute |
Profiles focus on public ownership, platform posture, and target segment rather than trying to reconstruct exact private funding for every rival.
[CP001, CP002, CP005, CP008, CP010, CP012]Positions the main alternatives on deployment freedom versus bundled operational simplicity using evidence-backed ordinal placement.
Axis values are ordinal placements derived from public product, pricing, and deployment descriptions rather than from a disclosed benchmark score.
[CP002, CP005, CP008, CP010, CP015, CP017]3.2 Capability overlap: where Cockroach still stands out and where rivals are catching up
Capability overlap is real, but it is uneven. CockroachDB’s clearest proposition remains the combination of PostgreSQL compatibility, distributed ACID behavior, active-active multi-region design, and deployment freedom across clouds or self-hosted environments. That package is still relatively unusual, especially when compared with standard PostgreSQL and Aurora, which remain easier to adopt but less natively distributed. The catch is that important parts of the pitch are no longer unique. AlloyDB uses the PostgreSQL label while adding managed performance and AI features on Google Cloud. Yugabyte markets distributed PostgreSQL with open-source and multi-cloud language very close to Cockroach’s core story. TiDB sells strong consistency plus horizontal scale but through a MySQL-compatible lens. PlanetScale, Vitess, and Neon do not match Cockroach on every correctness or multi-region dimension, but they can win the early project or single-team decision by lowering operational friction and starting cost. This means feature breadth alone is not a moat. Buyers can increasingly assemble a shortlist in which each vendor wins a different slice of the tradeoff: portability, hyperscaler convenience, serverless developer velocity, open-source lock-in avoidance, or multi-model data handling. Cockroach Labs still looks strongest when the workload needs global transactional correctness without accepting one-cloud lock-in, but the company now has to prove that need rather than assume it.[CP004, CP009, CP014, CP015, CP017, CP020]
| criterion | CockroachDB | PostgreSQL | Aurora | Spanner / AlloyDB | Yugabyte | PlanetScale / Neon / TiDB |
|---|---|---|---|---|---|---|
| PostgreSQL compatibility | Strong core positioning | Native baseline | High but AWS-shaped | Mixed: AlloyDB strong, Spanner partial PG interface | Strong in YSQL posture | Mixed: Neon strong, PlanetScale/TiDB weaker |
| Active-active multi-region writes | Core positioning | Weak in core project | Limited / topology-dependent | Strong for Spanner, weaker for AlloyDB | Strong competitive overlap | Generally weaker or not central |
| Cloud agnosticism | Strong | Strong | Weak | Weak to moderate | Strong | Moderate |
| Open-ecosystem / lock-in comfort | Moderate | Strong | Weak | Weak | Strong | Mixed |
| Developer entry friction | Moderate | Low if staying put | Low inside AWS | Moderate to high | Moderate | Low for Neon and PlanetScale |
| Analytics / multi-model adjacency | Moderate | Moderate | Moderate | Growing via AI and read scale | Moderate | Strong for TiDB and SingleStore |
| AI / vector marketing intensity | Rising | Low in core project | Limited in these sources | High | High | High |
Matrix uses evidence-backed ordinal labels rather than pretending every feature is directly comparable across architectures and deployment models.
[CP004, CP009, CP010, CP014, CP015, CP017]Shows where the main alternatives concentrate strength rather than pretending every product optimizes for the same job.
[CP010, CP014, CP015, CP017, CP020, CP021]3.3 Pricing, lock-in, and moat durability
Pricing models show why the competitive danger comes from more than one direction. Aurora, Spanner, and AlloyDB mostly monetize through enterprise-style infrastructure constructs such as instances, nodes, replicas, storage, and network replication. That suits steady-state production workloads and enterprise purchasing norms, but it also produces multi-line-item bills and topology-dependent costs. By contrast, Neon and PlanetScale make entry cheaper and more developer-friendly with free or low-cost starting points and usage-based expansion. SingleStore and some TiDB offers sit between those poles, mixing managed service economics with workload-sensitive usage or cloud packaging. These pricing differences reinforce the lock-in landscape. Open-source or open-ecosystem options such as PostgreSQL, Vitess, Yugabyte, and TiDB can calm buyer anxiety about irreversible platform dependence. Aurora and the Google stack trade some of that freedom for procurement ease and adjacent cloud integration. PlanetScale’s and Neon’s strength is not that they are perfect substitutes for CockroachDB; it is that they can intercept workloads before buyers ever conclude they need Cockroach-level distribution semantics. The resulting moat is therefore conditional, not absolute. Cockroach Labs does not own distributed-database ideas, AI messaging, or PostgreSQL familiarity by itself. Its moat comes from proving that a cloud-agnostic, correctness-first, multi-region PostgreSQL system is materially better for a subset of mission-critical applications than staying on the status quo or taking the bundled hyperscaler path. That can be durable, but only if migration tooling, customer proof, and sales focus keep the company ahead of direct peers such as Yugabyte while defending against the cheaper pilot experiences offered by Neon and PlanetScale.[CP006, CP007, CP011, CP012, CP013, CP016]
| competitor | entry model | scale model | contract / hidden-cost signal | implication for Cockroach Labs |
|---|---|---|---|---|
| PostgreSQL | Free OSS software | Infrastructure + labor | HA and tooling assembled separately | Hardest status-quo option to dislodge on cost alone |
| Aurora | On-demand or serverless ACUs | Instance + storage + I/O + replica + Global DB costs | Region-specific commitments and replicated write I/O | Wins when buyer wants AWS convenience more than portability |
| Spanner | Processing units / nodes | Compute + storage + backups + replication + bandwidth | Replica counts and minimum billing windows matter | Strong but enterprise-shaped global scale option |
| AlloyDB | Provisioned managed cluster | vCPU + memory + storage + backup + networking | HA uses two nodes; CUDs improve economics | Targets serious PostgreSQL workloads already on GCP |
| PlanetScale | Starts at $5/mo Postgres or low-cost HA | Resource-based monthly pricing plus enterprise add-ons | BYOC shifts infra cost into buyer account | Intercepts developer pilots cheaply |
| Neon | Free tier and paid CU-hour usage | Usage-based compute + storage + history storage | Autoscaling and branching change realized cost shape | Makes serverless Postgres pilots very easy |
| Yugabyte / TiDB | Free OSS plus managed cloud offers | Cluster-size or managed-service growth | Commercial support decisions determine real cost | Direct portability pitch without hyperscaler lock-in |
| SingleStore | On-demand usage | Credits + storage + optional Flow CDC charges | Ingestion-heavy use cases can raise cost quickly | Competes where real-time AI/analytics breadth matters |
Pricing rows simplify vendor calculators into the billing primitives most relevant to buyer behavior and acquisition friction.
[CP005, CP006, CP007, CP008, CP011, CP012]| moat claim | threat | severity | why it is real | mitigation / diligence ask |
|---|---|---|---|---|
| PostgreSQL familiarity feeds migration into CockroachDB | The same familiarity supports staying on PostgreSQL or choosing Aurora/AlloyDB instead | high | Status quo and managed-Postgres options keep organizational change low | Ask management for concrete displacement data by source database |
| Cloud-agnostic distribution is differentiated | Spanner, AlloyDB Omni, Yugabyte, and BYOC offers narrow that gap for many accounts | high | Several rivals now sell portability or hybrid stories publicly | Test whether buyers actually need cross-cloud writes or just cloud procurement flexibility |
| Distributed SQL is hard to build | Yugabyte and TiDB already offer credible distributed alternatives and Vitess/PlanetScale can satisfy many scale problems earlier | high | Conceptual uniqueness has already eroded | Request win/loss detail against Yugabyte, TiDB, PlanetScale, and Aurora |
| AI-era database relevance will widen demand | AI and vector claims are now common across AlloyDB, Yugabyte, TiDB, and SingleStore | medium | Public messaging shows AI positioning is category-wide | Separate real customer usage from marketing narrative |
| Enterprise proof should defend pricing | Hyperscaler bundling and low-friction serverless pilots can still undercut acquisition cost | medium | Distribution power and cheap entry matter before architecture does | Inspect sales-cycle data by competitor class |
| Migration tooling creates stickiness | Public evidence does not prove exact competitive win rates or conversion economics | medium | Outsiders cannot quantify whether tooling meaningfully changes close rates | Ask for pipeline conversion by migration path and deployment target |
Risk register focuses on whether the moat survives real buyer behavior, not whether CockroachDB is technically impressive in isolation.
[CP026, CP028, CP029, CP030, CP032, CP033]Evidence-weighted scorecard of Cockroach Labs’ competitive durability versus the current alternative set.
[CP019, CP028, CP029, CP030, CP033, CP035]3.4 Exhibits
04Financials
4.1 Monetization architecture spans developer funnel, production clusters, and high-touch services
Cockroach Labs does not sell one clean SKU. Its monetization stack deliberately spans a low-friction developer funnel, provisioned cloud production plans, and a set of enterprise service layers that help customers migrate and operate the database. The Basic plan is the clearest self-serve hook: usage-based request-unit billing with a meaningful free allowance makes it easy to start without a heavy commitment. Standard and Advanced then convert that initial funnel into explicit infrastructure spend, with Standard selling provisioned vCPU capacity plus usage line items and Advanced monetizing dedicated nodes, storage, and in some cases IOPS. The model becomes more interesting once support and migration are included. Public support pages show that Cockroach Labs sells tiered subscriptions, charges an additional percentage fee for enterprise cloud support, and bundles technical advisory, named success coverage, and root-cause analysis into higher tiers. Migration documentation and MOLT tooling make clear that the company expects many large customers to arrive through replacement projects, not only through brand-new greenfield applications. That is a good sign for monetizable customer depth, but it also means the business is not purely software-automatic. A meaningful share of value creation appears tied to solution engineering, migration expertise, and enterprise operational trust. Financially, Cockroach looks more like a hybrid of cloud infrastructure recurring revenue and high-touch enterprise delivery than like a simple freemium database utility.[CI001, CI002, CI004, CI009, CI012, CI013]
| stream | billing unit | customer type | what drives expansion | implication |
|---|---|---|---|---|
| Basic cloud | Request units + storage with free allowance | Developers and small workloads | More request load and stored data | Functions as top-of-funnel and lightweight usage monetization |
| Standard cloud | Provisioned vCPU-hours plus usage line items | Production cloud workloads | Higher reserved capacity, storage, backups, CDC, transfer | Looks like recurring infrastructure revenue with expansion levers |
| Advanced cloud | Per-node compute, storage, IOPS, plus usage items | Enterprise and regulated workloads | More nodes, larger nodes, replicas, security features, support | Highest likely ACV but also most bespoke delivery |
| Self-hosted enterprise | License / subscription style commercial motion | Customers needing their own environment | More clusters, support, and architectural scope | Preserves enterprise monetization outside Cockroach-managed cloud |
| Support subscriptions | Tiered service subscription; cloud enterprise fee percent | Operators of production workloads | Higher severity coverage and enterprise operations needs | Adds sticky service revenue and strengthens retention |
| Professional services / migration | Project or scoped-service engagement | Replacement and modernization projects | Migration complexity and workload criticality | Improves close rates but adds delivery cost |
Rows summarize the public monetization surfaces visible in pricing, support, deployment, and migration materials.
[CI001, CI002, CI004, CI009, CI012, CI013]| plan / lever | public billing mechanic | customer behavior encouraged | hidden or variable cost signal | financial implication |
|---|---|---|---|---|
| Basic | Usage-based RUs with free monthly allowance | Prototype and bursty trial usage | RU bundle absorbs backups and transfer | Helpful acquisition funnel, less transparent margin by small account |
| Standard compute | Provisioned vCPU-hours billed on reserved capacity | Capacity planning and long-lived production use | Overprovisioning buffer can create slack spend | Supports predictable recurring revenue |
| Standard storage / CDC / transfer | Usage-based line items | Expansion as workloads grow or globalize | Cross-region traffic and watched data can surprise buyers | Creates post-land expansion revenue |
| Advanced nodes | Per-node compute and storage | Enterprise architecture planning and regional design | AWS IOPS and security add-ons raise complexity | Higher ACV and more bespoke commercial motion |
| Enterprise support | Subscription layer with cloud support surcharge | Operational trust and faster response expectations | Service intensity can grow with cloud consumption | Adds recurring revenue but also service cost |
| Migration services | High-touch engagement around replacement projects | Complex cutovers and database consolidation | Labor-intensive delivery and sales engineering | Raises CAC but also win probability for large deals |
Pricing mechanics are simplified from documentation into the commercial behaviors they most likely drive.
[CI002, CI003, CI004, CI009, CI010, CI013]Shows how Cockroach Labs converts a low-friction cloud entry point into higher-value production infrastructure and service revenue.
[CI001, CI002, CI004, CI009, CI012, CI014]4.2 Public unit-economics signals are strongest on pricing mechanics, not on efficiency disclosure
The best public financial evidence is mechanical rather than complete. Cockroach Labs explains exactly how Standard and Advanced customers are billed, what a 40 percent capacity buffer looks like, when cross-region pricing applies, and which expansion levers sit outside base compute. That matters because it tells investors where revenue can expand after initial adoption: backup retention, watched-data CDC, cross-region transfer, additional replicas, and dedicated enterprise support all layer on top of the cluster itself. But the same public clarity reveals why unit economics are hard to underwrite from outside. Standard bills reserved capacity rather than realized usage, which can be good for revenue predictability but can also create customer slack or optimization pressure. Advanced is even more bespoke, with region-, provider-, security-, and sometimes IOPS-sensitive pricing. Those line items may produce attractive net expansion in mature accounts, yet they also create gross-margin sensitivity to infrastructure mix and multi-region traffic. The visible GTM motion reinforces that ambiguity. MOLT, migration services, and consultative support help Cockroach close hard replacement projects, but they also imply customer-acquisition and implementation costs that are not separately disclosed. Public evidence therefore supports a view that Cockroach has multiple monetization levers, but it does not support precise CAC, payback, or margin modeling.[CI005, CI006, CI007, CI008, CI010, CI011]
| economic area | public signal | likely revenue driver | likely cost driver | confidence |
|---|---|---|---|---|
| Developer funnel | Basic free usage and request-unit billing | Conversion from trial to production | Free-tier support and absorbed infrastructure | medium |
| Standard cloud production | Reserved vCPU capacity with 40% buffer guidance | Recurring compute reservation | Cloud infra even when customers underutilize reserved capacity | medium |
| Advanced enterprise | Per-node pricing with security and IOPS variation | Larger regulated or multi-region accounts | Dedicated infra and support intensity | medium |
| Support subscriptions | Tiered SLA with named services and cloud support surcharge | Operational add-ons and retention | Skilled support labor and incident management | medium |
| Migration toolkit | Schema conversion, load, replication, verify, failback | Large modernization programs | Solution engineering and services effort | medium |
| Expansion usage | Backups, CDC watched data, cross-region transfer | Workload growth after deployment | Cloud egress, storage, and operational complexity | medium |
This table is inferential because public sources describe billing mechanics far more precisely than margin outcomes.
[CI006, CI008, CI013, CI014, CI015, CI026]Traces customer workload growth into billable expansion levers while highlighting where public margin disclosure stops.
[CI006, CI010, CI013, CI014, CI026, CI027]Maps the visible revenue levers against likely delivery cost and disclosure clarity.
[CI001, CI013, CI014, CI026, CI029, CI035]4.3 Traction and capital context are real, but today’s underwriting inputs remain sparse
Cockroach Labs is not a tiny company waiting for first proof. The 2021 Series F announcement disclosed strong ARR growth, a sharp cloud-revenue acceleration, and more than 200 customers with over half already on Dedicated. Third-party aggregation later surfaced a 2023 ARR or revenue figure of 128.3 million dollars and a 2025 headcount estimate around 715 employees. Those datapoints support the view that Cockroach is operating at meaningful late-stage scale. What is missing is what investors most want right now: fresh revenue, burn, cash balance, gross margin, retention, and efficiency data. The 2026 momentum release emphasizes product and partner progress without publishing updated financials. Secondary pricing suggests ongoing investor interest and a valuation above the 2021 primary round, but secondary activity does not inject fresh operating cash or settle the runway question. The result is a financial story with strong qualitative signals and weak precision. Revenue quality looks promising because the product sits in mission-critical infrastructure, cloud mix improved early, and support or migration services appear monetizable. Yet the absence of current financial statements means the path to profitability and the adequacy of the 2021 capital base still have to be inferred rather than demonstrated. That is enough to justify continued diligence, not enough to underwrite with high conviction.[CI018, CI019, CI020, CI021, CI022, CI023]
| signal | public value | date | what it tells us | limitation |
|---|---|---|---|---|
| Last primary financing | $278M Series F at $5B valuation | 2021-12-16 | Large late-stage balance-sheet raise and valuation anchor | Stale as an operating-funding indicator |
| Official lifetime funding | $633M | 2021-12-16 | Company had meaningful capital cushion entering 2022 onward | No public cash balance today |
| Secondary valuation signal | ~$6.9B implied | 2026-06 | Investors still assign premium private-market value | No new cash enters company |
| Private-market liquidity | Active pricing on Nasdaq Private Market and Notice | 2026-07 | Not obviously frozen or distressed | Liquidity for holders is not runway disclosure |
| Headcount proxy | ~715 employees | 2025-11-28 | Suggests a substantial operating cost base | Third-party estimate only |
| 2026 financial disclosure | No updated ARR, burn, or cash metrics public | 2026-07-20 | Core underwriting gaps persist | Prevents precise runway judgment |
Capital adequacy can only be triangulated from funding history, secondary pricing, and scale proxies because current balance-sheet disclosure is absent.
[CI020, CI021, CI022, CI023, CI024, CI025]| metric | best public value | source quality | why it matters | diligence ask |
|---|---|---|---|---|
| Current ARR / revenue | $128.3M for 2023 | third-party aggregator | Needed for growth and valuation precision | Request 2024 and 2025 ARR with cloud mix |
| Gross margin | Not publicly disclosed | missing | Determines infrastructure software quality | Ask for cloud gross margin by plan |
| Burn / runway | Not publicly disclosed | missing | Needed to assess financing dependency | Request cash balance, burn, and runway assumptions |
| NRR / GRR | Not publicly disclosed | missing | Needed to prove durability of expansion-led model | Request cohort and renewal metrics |
| CAC / payback | Not publicly disclosed | missing | Needed to judge consultative GTM efficiency | Request fully loaded acquisition and deployment cost metrics |
| Support / services mix | Qualitatively visible but not numerically disclosed | partial | Needed to separate software margin from services margin | Request revenue mix by cloud, license, support, and services |
The gap list is the real underwriting blocker: public evidence shows how Cockroach sells, but not enough of how efficiently it sells.
[CI020, CI022, CI035, CI036, CI038]Brackets the few public financial anchors and shows where the 2026 evidence set stays thin.
[CI013, CI020, CI021, CI023, CI024, CI025]4.4 Exhibits
05Product & Technology
5.1 Product definition and SKU map
CockroachDB’s product definition is more concrete than “distributed SQL.” Public materials consistently frame it as a transactional system-of-record database for always-on, cloud-native applications that need PostgreSQL familiarity, resilience, and global scale at the same time. That workflow orientation matters because it separates CockroachDB from both pure analytical systems and from document or multi-model platforms that solve different jobs. The product surface is also broader than a single engine. Cockroach Labs sells managed cloud, self-hosted enterprise software, migration tooling, and support around the same database core. Basic or serverless-style entry points are there to reduce trial friction, while Standard and Advanced are structured for progressively more demanding production and regulated workloads, procurement paths, and security expectations in enterprise accounts. This module map reveals the company’s strategic intent: use familiarity and easy starts to get into the workflow, then expand into higher-value production, compliance, and migration work. The product story is therefore not only about feature count. It is about turning a hard replacement category into a platform decision that can begin small and still scale into a mission-critical control plane.[CE001, CE002, CE003, CE026, CE027, CE031]
| module / SKU | deployment form | primary buyer need | notable capability | evidence status |
|---|---|---|---|---|
| Basic / serverless entry | Managed cloud | Fast start and low-friction experimentation | Usage-based entry into distributed SQL | publicly visible |
| Standard | Managed cloud | Production workloads with provisioned capacity | Provisioned multi-region cluster planning | publicly visible |
| Advanced | Managed cloud | Regulated or high-control production | Dedicated nodes, deeper security and compliance | publicly visible |
| Enterprise self-hosted | Customer environment | Control, portability, and own-environment operations | Full feature surface outside Cockroach-managed cloud | publicly visible |
| MOLT toolkit | CLI / migration tooling | Replacement of legacy databases | Schema conversion, load, replication, verify | publicly visible |
| Support / services | Operational overlay | Faster issue resolution and migration help | Dedicated Slack, advisory, performance tuning | publicly visible |
The module map focuses on what customers buy or use, not on every internal packaging nuance.
[CE002, CE003, CE024, CE031]| workflow or use case | why Cockroach fits | best plan / module | operational tradeoff |
|---|---|---|---|
| Always-on OLTP | Strong consistency plus multi-active resilience | Standard or Advanced | Requires capacity and locality planning |
| Global consumer application | Regional by row/table plus survival goals | Advanced | Cross-region traffic and compliance choices matter |
| Modernization off legacy relational estate | PostgreSQL compatibility plus MOLT migration path | Enterprise + MOLT | Cutover and schema conversion still require discipline |
| Regulated workload | CMEK, compliance posture, row-level security, identity integration | Advanced | Security features add setup and governance work |
| AI-semantic search near operational data | Built-in vector indexing with distributed storage semantics | Standard / Advanced | Feature set is still maturing and vendor-authored |
| Developer evaluation or prototyping | Low-friction managed start | Basic / serverless | Does not prove enterprise production fit by itself |
Use-case mapping translates database features into the actual jobs a buyer wants completed.
[CE001, CE003, CE009, CE015, CE019, CE020]Connects customer-facing product modules to the underlying database core and service layers.
[CE001, CE002, CE003, CE024, CE031]5.2 Core architecture and deployment model
CockroachDB’s technical identity starts in its architecture. The database accepts SQL on any node, converts those statements into key-value operations, and then coordinates them over distributed ranges replicated across the cluster. Ranges split as data grows, writes flow through Raft quorum, and locality metadata plus range placement lets the system optimize for resiliency and geography without asking the application to manage shards itself. Multi-region controls are not an afterthought. The documentation exposes explicit abstractions for primary regions, table localities, super regions, secondary regions, and survival goals. That gives customers a way to trade latency, compliance, and resilience in SQL-visible terms rather than only in network topology diagrams. Cluster virtualization extends this direction by separating control and data planes through system and virtual clusters, which matters for physical cluster replication, resource isolation, and more governable operational models. This is the layer that is hardest for customers to recreate themselves. PostgreSQL familiarity is relatively easy to understand; what is difficult is combining that familiarity with multi-region topology, consistent replication, portability, low-touch operations, and newer AI-ready indexing in one product. That is where the underlying architecture still looks differentiated.[CE004, CE005, CE006, CE007, CE008, CE009]
| layer | what it does | public evidence | why it matters |
|---|---|---|---|
| SQL layer | Accepts SQL on any node and plans distributed execution | Architecture overview | Keeps the product relational and familiar |
| KV storage | Translates SQL state into distributed key-value ranges | Architecture overview | Enables elastic splitting and rebalancing |
| Replication layer | Replicates ranges via Raft quorum | Architecture overview | Drives consistency and survivability |
| Multi-region abstractions | Adds regions, localities, super regions, secondary regions, survival goals | Multi-region overview | Makes geography and resilience configurable in product terms |
| Cluster virtualization | Separates control plane and data plane into system and virtual clusters | Cluster virtualization overview | Supports more isolated operational topologies |
| Vector indexing layer | Stores partitioned vector index structures in ranges | C-SPANN materials | Extends product into AI-native search without a separate engine |
This table abstracts implementation layers into operating concepts relevant to buyers and operators.
[CE004, CE005, CE006, CE008, CE011, CE015]Shows the path from migration or prototype to regulated multi-region operation.
[CE003, CE008, CE020, CE024, CE035]Maps the main product dependencies that make CockroachDB powerful but operationally non-trivial.
[CE006, CE008, CE011, CE016, CE019, CE022]5.3 Trust, quality, and operational controls
The product’s maturity story is as much about control surfaces as it is about raw performance. Security and trust materials describe a stack that includes encryption, compliance programs, identity integration, CMEK, row-level security, and responsible-disclosure processes. Release 26.1 pushes that further with Azure compliance participation, automatic user provisioning, JWT and OIDC role synchronization, and native FIPS 140-3 support—signals that the company is courting regulated enterprises, not only growth startups. Operational transparency is visible in the open. Cockroach Labs publishes technical advisories, a responsible-disclosure policy, and a public incident history. That transparency is a strength, but it also confirms the ordinary reality of a complex distributed database: the system is powerful enough that bugs, security issues, and nuanced operational edge cases are inevitable. Trust therefore depends on response quality, repeatable tooling, and platform discipline, not on pretending the architecture is simple. The same tension appears in the broader product breadth. Migrations, CDC, multi-region settings, vector indexing, AI-agent governance, virtualization, and resilience benchmarking all increase product value for serious buyers. They also raise the operational surface area. For customers, the right question is not whether CockroachDB is technically rich—it clearly is—but whether the richness reduces net complexity for the target workload or simply moves complexity into a more centralized platform. The public materials make a strong case that resilience is deeply productized; they do not erase the need for careful operations, measured rollout discipline, and knowledgeable operators.[CE019, CE020, CE021, CE022, CE023, CE024]
| control area | public control | why buyer cares | remaining caveat |
|---|---|---|---|
| Identity and access | JWT / OIDC role sync, automatic user provisioning, LDAP/AD lineage | Reduces manual security operations | Configuration still matters |
| Encryption and key management | CMEK and encryption controls | Supports regulated-cloud deployments | Cloud-specific setup complexity remains |
| Compliance posture | HIPAA, PCI, SOC 2, ISO, FIPS messaging | Shortens enterprise security review | Scope differs by plan and cloud |
| Data sovereignty | Regional by row, super regions, jurisdiction pinning | Supports domicile rules | Tradeoffs with latency and topology must be chosen carefully |
| Disclosure discipline | Responsible disclosure policy and advisories | Signals maturity and transparency | Also exposes recurring bug surface |
| Incident visibility | Public cloud incident history | Shows operational accountability | Confirms non-zero outage risk |
Trust posture combines product controls and operational disclosure rather than only compliance badges.
[CE019, CE020, CE021, CE022, CE023, CE034]| area | 2025-2026 public signal | stage or maturity cue | strategic implication |
|---|---|---|---|
| Throughput improvements | 25.2 cites 50% average throughput gain across nine workloads | recent release claim | Performance remains a central roadmap axis |
| Buffered writes | Preview in 25.2 with 15-40% cited gains | preview | Still improving write path efficiency |
| Vector indexing | Preview in 25.2 plus deeper C-SPANN internals | preview but strategically important | AI-search use cases are becoming first-class |
| Row-level security | GA in 25.2 | generally available | Better tenant isolation for regulated apps |
| Identity-aware access | 26.1 JWT and OIDC automation | recent release | Strengthens enterprise security posture |
| FIPS / compliance / Azure support | 26.1 compliance and native FIPS support | recent release | Pushes deeper into regulated workloads |
Roadmap signals are vendor-authored release notes, so they show direction and maturity cues more reliably than they prove customer-level outcomes.
[CE013, CE014, CE015, CE017, CE019, CE020]Separates mature core capabilities from newer expansion surfaces inside the product.
[CE015, CE019, CE022, CE024, CE025, CE031]5.4 Exhibits
06Customers
6.1 The customer base is broad in logos but concentrated in mission-critical use cases
Cockroach Labs has no shortage of named customer proof. The public customer page spans financial services, retail, software, media, gaming, manufacturing, and gambling, while legacy official disclosures already pointed to more than 200 customers and tens of thousands of deployed clusters back in 2021. That combination matters because it shows both breadth and age: this is not a product still waiting for first serious references. But the more important pattern is not raw logo count. It is workload type. Across the visible roster, CockroachDB is repeatedly used for order management, payments, fraud screening, device control planes, gaming metadata, shipment tracking, and sportsbook ledgers. These are operational systems where downtime, incorrect writes, or regional failure would immediately harm revenue or customer experience. That concentration cuts both ways. It is strong evidence that CockroachDB has found buyers with real pain and real budgets. It also suggests the product is best suited to technically demanding customers who value resilience, consistency, and topology control enough to absorb the complexity of a distributed database. In other words, the roster looks more like an enterprise-infrastructure customer book than a broad, lightweight SMB utility base. That pattern is attractive for ACV and retention, but less obviously supportive of mass-market volume or frictionless self-serve breadth.[CU001, CU002, CU003, CU004, CU005, CU006]
| vertical | named examples | core workload | why it matters |
|---|---|---|---|
| Banking & fintech | Form3, SumUp, unnamed Fortune 50 banks | Payments, scheme connectivity, regulated transaction processing | Shows fit for correctness-sensitive regulated workloads |
| Retail & eCommerce | Shipt, Route, Riskified | Payments, fraud, order and shipment data | Proves operational demand under always-on consumer traffic |
| Travel | Booking.com | Reservation order management | Demonstrates complex global transaction orchestration |
| Media & streaming | Netflix | Device platform and workflow orchestration | Shows adoption by elite internal platform teams |
| Gaming & betting | Hard Rock Digital, Superbet, Netflix gaming | State-sensitive betting and gaming control planes | Supports regulatory and multi-region positioning |
| Software / technology platforms | DoorDash internal DBaaS, Route platform services | Internal developer platforms and operational control planes | Suggests expansion beyond single app deployments |
Vertical coverage emphasizes named or reasonably inferable production segments rather than every logo on the marketing site.
[CU001, CU006, CU014, CU021, CU024, CU029]| source | public datapoint | what it supports | caveat |
|---|---|---|---|
| Series F press release | 200+ customers; tens of thousands of clusters | Meaningful historical commercial base | Stale by 2026 |
| Series F blog | 50%+ of customers on Dedicated | Managed-cloud adoption depth | Also historical |
| Customers page | Five-page roster across many industries | Breadth of named proof | No exact count or spend |
| Apps Run The World | Directional deployment list and enterprise examples | Independent breadth corroboration | Methodology not fully transparent |
| ReadyContacts | 226-company marketed list | Directional account universe | Lead-gen source, not audited disclosure |
| Momentum release | Enterprise and partner expansion emphasis | Ongoing commercial activity | No fresh paying-customer count |
The table separates logo breadth from exact customer-count precision.
[CU002, CU003, CU004, CU005, CU040]Shows the recurring path from painful incumbent database problem to expansion inside demanding enterprise accounts.
This is an analyst-synthesized customer journey based on repeated patterns across public case studies, not a disclosed lifecycle funnel from Cockroach Labs.
[CU001, CU006, CU024, CU029, CU032, CU034]6.2 The strongest references show deep production adoption, not lightweight pilots
The named case studies are unusually concrete. DoorDash runs CockroachDB as an internal service at around 1.2 million peak queries per second, 300-plus clusters, and roughly 1.9 petabytes of data. Netflix operates more than 380 clusters and has expanded usage into device management, workflow orchestration, and gaming. Route powers more than 1 billion orders, while Booking.com, Form3, Shipt, Riskified, and Hard Rock all describe business-critical transaction flows rather than side projects. This matters because it reduces a common diligence concern in infrastructure software: references that look impressive on paper but represent small pilots or non-critical shadow deployments. Here, the public stories point to source-of-truth systems, payment engines, customer-facing order flows, and internal database platforms. Those are harder workloads to win, govern, and far harder workloads to displace once running successfully. The recurring theme is that CockroachDB often enters through a difficult architectural problem—global transactions, regulatory locality, or legacy database bottlenecks—and then becomes more central over time. Several stories also show deployment expansion after the initial decision, whether through more clusters, more regions, more nodes, or broader internal self-service. The references therefore indicate not only adoption but operational trust after adoption inside demanding environments. That gives the customer evidence real weight.[CU007, CU008, CU009, CU010, CU011, CU012]
| customer | public scale signal | workload type | signal quality |
|---|---|---|---|
| DoorDash | 1.2M peak QPS; 300+ clusters; 1.9PB; ~900 changefeeds | Internal DB platform | high but vendor-authored |
| Netflix | 380+ clusters; 160+ prod; 60+ multi-region | Internal DBaaS and control planes | high but vendor-authored |
| Route | 1B+ orders; 13,000 brands; 52TB | Order and shipment data | medium-high |
| Riskified | 10,000+ online TPS; 99%+ retention | Fraud transaction system | medium-high |
| Shipt | 1-2M payment transactions/day; four regions | Distributed payment system | medium |
| Hard Rock Digital | Peak ~100 nodes x 32 vCPUs | Multi-region sportsbook | medium |
| Form3 | 700 TPS; strict P99 latency SLAs | Multi-cloud payments engine | medium |
| Booking.com | Order Platform around 20TB | Reservation order management | medium |
Scale signals are normalized from case-study claims and should be read as indicative, not audited.
[CU004, CU009, CU012, CU016, CU019, CU021]| metric or signal | value / status | segment | confidence | diligence ask |
|---|---|---|---|---|
| Riskified retention | 99%+ customer retention | Fraud / eCommerce | medium | Confirm whether figure is logo retention or revenue retention and how current it is |
| Route support ROI | Positive qualitative ROI from paid support | ECommerce platform | medium | Request renewal and support attach rates |
| Zero-downtime migrations | Repeated qualitative signal across Riskified, DoorDash, SumUp | Migration-heavy enterprise buyers | medium | Request migration success rate and time-to-value data |
| Public NRR / GRR | Not disclosed | Whole portfolio | high | Request NRR, GRR, churn, and renewal by segment |
| Customer concentration | Not disclosed | Whole portfolio | high | Request top-10 and top-20 customer revenue share |
| Independent satisfaction coverage | Thin for production accounts | Whole portfolio | medium | Request reference calls and third-party review distributions |
Retention evidence is mostly anecdotal or customer-specific rather than portfolio-wide.
[CU019, CU023, CU037, CU039, CU040, CU041]Evidence-availability funnel from historical customer-base disclosure to the smaller set of deeply quantified public references.
Stages mix different evidence bases and are not a true commercial conversion funnel; the figure is meant to show how public evidence narrows from broad customer claims to a small set of richly described reference accounts.
[CU018, CU024, CU028, CU035, CU041]Qualitatively compares reference quality, outcome specificity, retention visibility, and deployment maturity across flagship customers.
Ratings are analytical judgments based on public source depth and independence, not a vendor-disclosed scoring system.
[CU019, CU023, CU038, CU039, CU040, CU041]6.3 Customer quality looks strong, but count precision and independence remain weaker
From an investor perspective, the customer story is strongest on quality, not precision. Riskified’s 99+ percent retention, Route’s support ROI, and repeated examples of zero-downtime migrations or multi-region survival all support the idea that CockroachDB can become sticky once embedded. These are good signals for expansion and long-lived revenue. What public evidence does not provide is a clean 2026 answer to how many paying customers Cockroach Labs has right now, what net retention looks like, or how customer spend is distributed across self-serve versus large enterprise accounts. Official customer-count disclosures are old, while third-party customer databases are helpful but methodologically weak. The prudent conclusion is therefore constructive but not naive. Cockroach Labs appears to have high-value customers with meaningful switching costs and visible post-sale support engagement. However, the public proof set still relies heavily on company-authored success stories, so customer depth is easier to verify than customer breadth, retention quality, or cohort economics. Investors should view the customer chapter as strong evidence of fit in hard accounts, not as a substitute for real cohort disclosure or concentration analysis. The missing inputs are mostly commercial, not technical, which is still a meaningful diligence distinction.[CU013, CU017, CU020, CU023, CU031, CU037]
| customer | starting point or constraint | why Cockroach won | post-land implication |
|---|---|---|---|
| Platform standardization | DoorDash and Netflix turn CockroachDB into an internal service, increasing expansion room within large accounts | Can create very large wallet share once approved | Also creates dependence on a small number of sophisticated flagship accounts |
| Regulated geography expansion | Form3 and Hard Rock expand where compliance and locality matter | Supports high ACV in payments and betting | Sales cycles may lengthen and deployment help may rise |
| Migration-led land motion | Riskified, Booking.com, DoorDash, and SumUp show replacement projects as entry points | Can unlock durable system-of-record placements | Migrations may require heavy support and solution engineering |
| Managed-service adoption | 2021 disclosure that 50%+ of customers were on Dedicated | Improves cloud expansion potential | Current cloud mix is undisclosed |
| Support attachment | Route and Hard Rock describe meaningful vendor support value | Can increase expansion and renewal durability | May pressure service cost if support intensity is high |
| Customer concentration | No public concentration data | Large reference accounts may be economically important | Request concentration and cohort data directly |
Expansion potential is visible, but concentration and attach-rate precision remain missing from public evidence.
[CU003, CU023, CU035, CU037, CU038, CU041]Illustrative retention curves because Cockroach Labs does not publicly disclose actual retention cohorts.
Cockroach Labs discloses no cohort retention data. These curves are illustrative thought tools to frame how much value depends on actual renewal and expansion behavior, not company-specific measurements.
[CU039, CU040, CU041, CU044]6.4 Exhibits
07Risks
7.1 The largest near-term risks are operational correctness and version discipline
The public advisory record makes one point impossible to ignore: CockroachDB’s core challenge is not proving that the architecture works in principle, but keeping a very ambitious distributed database safe across many versions, workloads, and deployment patterns. The 2026 advisories alone span privilege escalation, partial index corruption, live-data deletion, and silent import or backup failure scenarios. Even when many of these bugs are rare and patched quickly, they directly target the trust assumptions customers care most about in a system of record. The operating model compounds that risk. Cockroach Labs’ own production and upgrade documentation emphasizes topology discipline, replication health, backup verification, hotspot-aware schema design, load balancing, and release-finalization awareness. This is mature documentation, but it also shows that resilience is conditional on customer execution. The database removes some application-layer burden while creating a different burden in operations engineering. That leaves the company exposed to a classic infrastructure challenge: if correctness defects or upgrade mistakes hit a flagship account, the damage can travel quickly from support load into renewal risk and brand reputation. Operational excellence is therefore not a nice-to-have for Cockroach Labs. It is the product. The main risk is not one catastrophic unknown, but the compounding effect of many small operational failures in a database customers expect to trust completely.[CR001, CR002, CR003, CR004, CR005, CR006]
| failure mode | likelihood | severity | mitigation maturity | residual exposure | unresolved gap |
|---|---|---|---|---|---|
| Privilege escalation or auth-control defects | low-medium | high | Patchable, documented | moderate | Need evidence of patch adoption across customer base |
| Data corruption or live-data deletion bug | low | very high | Patchable but severe | material | Need incident frequency and customer impact history |
| Silent backup / import failure modes | low-medium | high | Documented mitigations exist | material | Need proof of backup-validation practice in large accounts |
| Hotspots and poor workload design | medium | medium-high | Well documented but customer-dependent | moderate | Need evidence of pre-sales workload qualification discipline |
| Upgrade or support-policy drift | medium | medium-high | Strong documentation | moderate | Need visibility into version distribution across installed base |
| Cloud or control-plane incident handling | low-medium | medium-high | Public status page and SLA structure | moderate | Incident-history detail is still thin publicly |
Rows are ordered by residual severity rather than by raw likelihood alone.
[CR001, CR002, CR003, CR004, CR005, CR007]Qualitatively scores the major risk clusters by likelihood, severity, mitigation maturity, and residual exposure.
[CR001, CR013, CR018, CR031, CR036, CR042]7.2 Regulated customers raise the economic value of the product and the severity of failure
Cockroach Labs increasingly sells into payments, banking, and betting use cases where the database does not merely store information; it helps satisfy legal, operational-resilience, and location-control requirements. DORA raises the bar for financial-sector ICT risk management, incident reporting, testing, and third-party oversight, while sportsbook and gaming deployments can inherit state-locality and Wire Act logic that force bespoke topology decisions. That is strategically attractive because these are high-value workloads with large switching costs. But it is also dangerous because failure is judged against a tougher standard. Customers in regulated sectors will expect proof of release discipline, incident transparency, data handling controls, and clear contractual boundaries. The company’s own legal materials reinforce that shared-responsibility model: customers must secure their accounts, follow best practices, and accept meaningful limitations around beta services, service continuity, and remediation. In practice, this means Cockroach’s push upmarket is also a push into higher-severity consequences. The more the company wins mission-critical regulated accounts, the less room it has for ambiguous outages, weak documentation, or sloppy version policy. That asymmetry is especially important: success in the best customer segments also raises the cost of every future mistake.[CR016, CR017, CR018, CR019, CR020, CR021]
| rule / obligation | jurisdiction / scope | risk to Cockroach | likelihood | severity | mitigation | residual exposure | diligence path |
|---|---|---|---|---|---|---|---|
| DORA ICT resilience and third-party oversight | EU financial entities and their providers | Higher diligence burden, incident expectations, and audit pressure in fintech / banking accounts | medium | high | Maintain strong controls and customer-facing compliance evidence | material | Request regulated-customer audit outcomes and control mappings |
| Wire Act and state-locality betting requirements | US sportsbook / gaming deployments | Bespoke topologies and legal-compliance failure risk for gaming customers | medium | high | Use locality-aware architecture and deployment guidance | material | Request legal/compliance playbooks for betting customers |
| Cloud terms and website terms | All cloud customers and site users | Service suspension, modification, or termination rights may create procurement friction | medium | medium | Negotiate enterprise terms and clarify SLA remedies | moderate | Review enterprise MSAs and top-customer contract exceptions |
| Privacy and cross-border transfer obligations | Global users, especially GDPR / UK / California contexts | Data-handling scrutiny and contract overhead for privacy-sensitive buyers | medium | medium | Provide DPA / privacy controls and region design guidance | moderate | Review DPA adoption and privacy-incident history |
This register focuses on external rules or contracts that can create material customer or vendor obligations.
[CR018, CR019, CR020, CR021, CR022, CR023]| dependency | counterparty | role | concentration / lock-in issue | failure scenario | severity | mitigation | residual exposure |
|---|---|---|---|---|---|---|---|
| Public-cloud infrastructure | AWS / GCP / Azure | Hosts customer clusters or adjacent services | Portability does not remove hyperscaler dependence | Regional outage, pricing change, or service degradation affects customers | high | Multi-region design and multi-cloud patterns | material |
| Object storage and backup targets | Cloud storage providers | Backups / imports / exports | Storage-layer issues can surface as data-protection risk | Intermittent backend failures create incomplete backup or import results | high | Validation, restore testing, and patched releases | material |
| Managed Kubernetes or cloud control planes | Cloud vendors | Operational substrate in some deployments | Can add another control layer outside Cockroach | Control-plane degradation slows customer recovery or expansion | medium | Architecture review and fallback planning | moderate |
| Customer account and support teams | Cockroach Labs internal org | Knowledge transfer and operational guidance | High-touch deployments may depend on tribal knowledge | Support understaffing or turnover increases churn risk | medium | Codify playbooks and automate more operations | moderate |
The company is less partner-dependent than an API wrapper, but still meaningfully exposed to infrastructure and service dependencies.
[CR016, CR017, CR023, CR033, CR040]Maps the external dependencies that shape Cockroach Labs risk even when the product promises portability.
[CR018, CR020, CR023, CR033, CR042]7.3 Commercial risk comes from selective fit, support intensity, and limited public visibility
Cockroach Labs does not appear to face a simple “nobody needs this” risk. The bigger commercial question is how wide the truly attractive buyer pool is. PostgreSQL remains free and deeply familiar, while Aurora and Spanner can look operationally simpler for buyers comfortable with cloud lock-in. That means Cockroach often wins when the workload is especially demanding—global transactions, multi-region survivability, or compliance-sensitive portability—but may face more friction in mainstream relational opportunities. Customer stories suggest that many wins are migration-led and support-heavy. That can create durable system-of-record placements and strong ACVs, but it can also lengthen sales cycles and raise service costs. Independent critique around hidden implementation cost points in the same direction. If expansion economics are strong, this trade can still work. Public sources simply do not disclose enough to prove that today. That opacity matters. Without fresh retention, concentration, margin, or runway disclosure, investors can see the outline of the risk map but not its exact weights. The right stance is therefore selective optimism paired with hard diligence on customer concentration, support intensity, and release-related incident history. If those hidden metrics are strong, many visible risks look manageable; if they are weak, the same visible risks become thesis-threatening very quickly.[CR028, CR029, CR030, CR031, CR032, CR034]
| role / function | dependency or gap | likelihood | severity | mitigation | diligence path |
|---|---|---|---|---|---|
| Support and solutions engineering | Complex accounts may require deep hands-on help | medium | high | Invest in automation and playbooks | Ask for support staffing ratios and escalation metrics |
| Product / release engineering | Correctness bugs can create outsized trust damage | medium | very high | Patch discipline and strong QA | Request bug-severity and patch-latency dashboards |
| GTM / enterprise sales | Selective-fit workload can lengthen cycles | medium | medium-high | Focus ICP and partner leverage | Request sales-cycle and win-rate data by segment |
| Finance / leadership | Opacity around burn, margin, and concentration limits underwriting | medium | medium-high | Improve disclosure in diligence | Request board pack metrics and scenario analyses |
| Customer success | Expansion depends on renewal and adoption management | medium | high | Formalize customer-health scoring | Request renewal playbooks and churn postmortems |
Execution risk is concentrated where human expertise substitutes for product simplicity.
[CR016, CR017, CR031, CR032, CR036, CR037]| risk | monitorable trigger | threshold / event | action implication |
|---|---|---|---|
| Correctness / security bug risk | Severity-1 or widespread advisory pattern | Multiple major supported-release defects with real customer impact | Escalate technical diligence or pause investment |
| Version-policy / support drift | High installed-base exposure to unsupported or innovation releases | Meaningful share of revenue on unsupported paths | Demand remediation plan before conviction |
| Support-intensity risk | Rising support burden without margin proof | Support costs scaling faster than ARR in enterprise segment | Pressure gross-margin assumptions |
| Customer concentration risk | Top-account dependence discovered in diligence | Top 10 customers represent outsized revenue share | Haircut valuation and seek contract durability proof |
| Competitive simplification risk | Losses to Aurora / Postgres in core ICP | Win rates weaken outside extreme use cases | Reassess TAM and sales-efficiency assumptions |
| Regulated-account incident risk | High-profile outage in fintech or betting customer | Customer-visible service or correctness failure in regulated workflow | Treat as thesis-threatening event |
Each row pairs a visible risk with a practical diligence or monitoring threshold.
[CR038, CR039, CR040, CR041, CR042]Shows how technical or contractual issues can flow into customers, support costs, retention, and valuation.
[CR032, CR039, CR040, CR041, CR042]7.4 Exhibits
08Valuation
8.1 Current price signals imply a premium valuation with limited public financial support
The most concrete valuation anchors are straightforward: Cockroach Labs last raised primary capital at a $5 billion valuation in late 2021, and secondary-market indicators in mid-2026 imply something closer to $6.9 billion. Those prices are not trivial achievements. They signal that the market continues to view Cockroach as a serious late-stage infrastructure asset rather than as a fading private round. The problem is what public numbers can actually support. The clearest revenue anchor still comes from a third-party 2023 estimate of about $128.3 million. Even if investors generously test a $170-200 million revenue range for 2025-2026, the implied revenue multiples remain very high. That means the current price already assumes meaningful hidden progress on revenue scale, retention, or margin quality. Public evidence therefore supports direction, but not enough precision to make the price feel conservative. In other words, the public market is not being asked whether Cockroach is good. It is being asked whether the company is good enough, large enough, and efficient enough to justify a premium multiple despite incomplete disclosure. That is a much harder question. The investment problem is therefore mostly one of valuation discipline rather than of company identification or simple awareness.[CV001, CV003, CV004, CV005, CV006, CV007]
| recommendation | confidence | risk rating | valuation stance | decision implication |
|---|---|---|---|---|
| Continue diligence / do not chase price | medium | high | full to demanding | Company quality is real, but current public evidence does not clearly support aggressive entry pricing |
| Positive on company quality | high | medium-high | premium justified in principle | Customer proof and product depth support staying engaged |
| Negative on cheapness | high | high | not obviously undervalued | Need better private metrics before treating current price as attractive |
| Conditional bullishness only with stronger data | medium | medium | bull case requires hidden upside | Revenue, retention, and margin proof would change the stance |
The recommendation separates enthusiasm for the company from enthusiasm for the current implied price.
[CV038, CV039, CV042]| scenario | assumptions | valuation / return logic | key risks | probability signal |
|---|---|---|---|---|
| Bull | Revenue materially above $200M, strong NRR, good gross margin, concentrated support burden under control | Current secondary price can be justified or modestly beaten | Execution still matters, but quality proves out | possible but not proven |
| Base | Revenue has grown but not enough to erase opacity discount; customer quality strong | Value clusters around mid-single-digit billions, near or somewhat below current secondary marker | Current price already embeds much of the good news | most defensible publicly |
| Bear | Growth slower, retention weaker, or support intensity heavier than hoped | Value falls toward lower public-comp range and current secondary price is too rich | Opacity masks fragile economics | cannot be ruled out |
| Upside unlock | New primary round or public-style disclosure proves metrics | Premium multiple can compress less than feared | Requires data not public today | depends on diligence success |
Scenario logic is structured around what current hidden metrics would have to look like, not around arbitrary narratives.
[CV033, CV034, CV035, CV036, CV037, CV039]Illustrates how aggressively the implied revenue multiple falls as assumed revenue rises.
[CV008, CV009, CV010, CV011, CV012]8.2 Public comps support a premium for quality, but not an open-ended premium
Public software and database comps provide an uncomfortable reality check. MongoDB and Confluent trade around ten times revenue, Snowflake near twenty times, and Elastic meaningfully lower. Against that backdrop, Cockroach’s implied secondary multiple looks rich even under optimistic revenue tests. For the current price to resemble Snowflake-like public premium territory, Cockroach would need revenue well above the last public anchor; for it to resemble MongoDB-like territory, it would need dramatically more. That does not mean the valuation is irrational. Cockroach has unusually strong customer proof, real technical depth, and a category story around resilience, portability, and globally distributed transactional workloads. Those qualities deserve a premium to average infrastructure software and likely to weaker database franchises. There is a real difference between a premium asset and an easy entry point, and this chapter argues the company is more clearly the former than the latter. But quality alone cannot eliminate the need for discipline. The company also carries operational complexity, support intensity, and disclosure opacity that argue against paying an unlimited scarcity premium. The fair conclusion is that Cockroach deserves some premium, but current pricing already appears to capture a large share of it. Investors should assume the valuation needs to be earned with stronger private metrics, not merely admired from product quality.[CV013, CV014, CV015, CV016, CV017, CV018]
| argument | what would change the view |
|---|---|
| High-quality distributed database with strong customer proof and durable relevance | Would weaken if current flagship customers show shallow spend, short contracts, or weak expansion |
| Premium valuation is supportable because category quality is scarce | Would strengthen if current revenue is far above the public anchor and NRR is elite |
| Valuation is too full relative to public comps and visible data | Would weaken if private financials show Snowflake-like growth quality or unusually strong margin structure |
| Opacity is the main block to conviction, not product credibility | Would ease with current ARR, margin, retention, and concentration data |
The anti-thesis is primarily about price discipline and missing data, not disbelief in the core product.
[CV021, CV023, CV029, CV038, CV042]| comparable | metric | multiple / valuation / status | relevance | limitation |
|---|---|---|---|---|
| MongoDB | Public market cap / TTM revenue | ~10.2x revenue | Closest public premium database comp | Different product mix and public-company maturity |
| Snowflake | Public market cap / TTM revenue | ~19.9x revenue | Upper-bound data-infrastructure premium reference | Much larger scale and broader analytics positioning |
| Confluent | Public market cap / TTM revenue | ~9.6x revenue | Infra-software comp with platform narrative | Not a database and different gross-margin profile |
| Elastic | Public market cap / TTM revenue | ~3.9x revenue | Lower-bound multiple-compression reference | Search / observability hybrid business |
| Cockroach Labs 2021 primary | $5B on public 2023 anchor | ~39x on $128.3M; ~29x on $170M test | Shows how rich prior private pricing already was | Uses stale public revenue anchor |
| Cockroach Labs 2026 secondary | $6.9B on public anchor / test cases | ~53.8x on $128.3M; ~40.6x on $170M; ~34.5x on $200M | Current private-market reference | Secondary is not broad public clearing price |
Public comp math is approximate and based on July 2026 market-cap and TTM revenue snapshots.
[CV008, CV009, CV010, CV011, CV012, CV013]Shows how company quality, price richness, and missing metrics interact to produce a cautious-but-engaged recommendation.
[CV021, CV023, CV030, CV038, CV042]8.3 The right stance is constructive on company quality and cautious on entry price
The valuation debate therefore comes down to hidden variables. If Cockroach is already well above $200 million in revenue, has strong net retention, contains support cost, and is proving a path toward durable infrastructure margins, the upper end of the private valuation range can make sense. If not, the current secondary price is ahead of what public evidence can underwrite. This is why the recommendation should be conditional rather than binary. The business appears to have the type of customer quality and technical relevance that investors want in a late-stage infrastructure company. But the price is no longer obviously early or forgiving. It is a price that expects good answers to diligence questions that have not yet been answered publicly. A disciplined investor can still like the setup while insisting on better evidence before calling the current entry attractive. The best investment posture is therefore to stay engaged, press hard on current metrics, and avoid confusing admiration for the product with proof that the current valuation is attractive. Cockroach Labs looks investable. It does not yet look cheap. That distinction is exactly what should govern the recommendation at this stage for disciplined investors.[CV024, CV025, CV026, CV027, CV028, CV029]
| trigger | threshold | transmission to thesis | action implication |
|---|---|---|---|
| Revenue well below optimistic private expectations | Current ARR / revenue not convincingly above $200M | Premium-multiple case weakens sharply | Do not underwrite at current secondary price |
| Weak retention or concentration | Subpar NRR or high top-customer dependence | Customer-quality thesis partially breaks | Apply material discount or pause |
| Support-heavy economics | Gross margin and support cost look worse than expected | Operational complexity becomes financial drag | Reduce valuation tolerance |
| Correctness / trust incident | Severe advisory or customer-visible failure in core accounts | Quality premium compresses fast | Reassess thesis immediately |
| Private-market exuberance fades | Secondary demand weakens without new fundamentals | Price support disappears before business proof arrives | Avoid momentum-driven entry |
Triggers focus on the few hidden variables most likely to change valuation quickly.
[CV039, CV040, CV042]| topic | missing evidence | why it matters | owner or diligence path |
|---|---|---|---|
| Current ARR / revenue | 2025-2026 actual revenue run rate | Determines whether current multiple is merely rich or deeply stretched | Finance leadership / board materials |
| Net retention and gross retention | Segmented NRR / GRR | Shows whether premium customer proof converts into durable expansion | FP&A / RevOps |
| Gross margin and support cost | Support / services intensity and cloud gross margin | Tests whether complexity is accretive or margin-dilutive | Finance + support leadership |
| Customer concentration | Revenue share of top 10 / top 20 accounts | High concentration would raise downside risk materially | Finance + sales ops |
| Cash runway and burn | Current cash balance and burn trajectory | Secondary price is not new cash | Finance / CFO |
| Contract protections | Top-customer negotiated SLA / MSA deltas vs standard cloud terms | May reduce some web-term risk assumptions | Legal / sales leadership |
These asks are prioritized in the order most likely to change valuation stance, not merely to fill curiosity gaps.
[CV029, CV030, CV039, CV040, CV041, CV042]Frames a defensible public-evidence valuation band around the current private-market reference.
[CV033, CV034, CV035, CV036, CV037, CV042]IC-style scoring across seven valuation dimensions.
[CV021, CV024, CV029, CV030, CV038, CV042]8.4 Exhibits
Disclaimer
This report-meta artifact is based only on publicly available information reviewed in the Cockroach Labs chapter YAMLs as of 2026-07-20. It is not investment advice. Recommendation and valuation judgments remain sensitive to undisclosed current financial metrics, customer concentration, support-cost intensity, and negotiated enterprise contract terms.
Evidence index
| ID | Statement | Confidence | Sources |
|---|---|---|---|
| CO001 | Cockroach Labs was founded in 2015 and is based in New York, New York. | High | SO014, SO008 |
| CO002 | CockroachDB is a cloud-native distributed SQL database built for high availability, effortless scale, and control over data placement. | High | SO001, SO002, SO024 |
| CO003 | CockroachDB combines a PostgreSQL-compatible SQL interface with distributed architecture, ACID transactions, and migration tooling. | High | SO002, SO002, SO024 |
| CO004 | Cockroach Labs sells fully managed CockroachDB Cloud, self-hosted Enterprise, and support or migration services rather than a single deployment form factor. | High | SO003, SO004, SO005 |
| CO005 | CockroachDB Cloud Basic includes 50 million request units and 10 GiB of storage free each month, while Standard and Advanced tiers target progressively heavier production workloads. | High | SO005, SO003 |
| CO006 | Advanced CockroachDB Cloud clusters support AWS, GCP, and Azure multi-region deployments with an advertised availability target of up to 99.999 percent. | High | SO005, SO003 |
| CO007 | Cockroach Labs states that CockroachDB Cloud Advanced is HIPAA-ready and PCI DSS capable, and the trust materials also cite SOC 2 and ISO certifications. | High | SO007, SO006, SO002 |
| CO008 | Cockroach Labs raised $278 million in Series F financing in December 2021 at a $5 billion valuation. | High | SO008, SO009 |
| CO009 | The Series F round was led by Greenoaks with participation from Altimeter, BOND, Benchmark, Coatue, FirstMark, GV, Index Ventures, J.P. Morgan, Lone Pine, Redpoint, and Tiger Global. | Medium | SO008 |
| CO010 | Cockroach Labs said the Series F round brought lifetime funding to $633 million. | High | SO008, SO014 |
| CO011 | CB Insights labels Cockroach Labs as a Series F company that is still alive and privately held. | Medium | SO014, SO017 |
| CO012 | Nasdaq Private Market estimated Cockroach Labs shares at $7.79 per share on July 2, 2026, confirming active private-market price discovery. | Medium | SO017 |
| CO013 | Notice.co listed Cockroach Labs at roughly $8.18 per share in July 2026, broadly corroborating the high-single-digit secondary pricing range. | Medium | SO016, SO017 |
| CO014 | A PM Insights snapshot surfaced through web search described Cockroach Labs secondary pricing in June 2026 as roughly a 38 percent premium to the 2021 primary round, implying valuation around $6.9 billion. | Low | SO015, SO017, SO016 |
| CO015 | GetLatka reports Cockroach Labs generated $128.3 million of revenue or ARR in 2023. | Medium | SO013 |
| CO016 | GetLatka estimates Cockroach Labs employed about 715 people by November 2025, up from 590 in 2023 and 483 in 2022. | Medium | SO013 |
| CO017 | At the time of the Series F announcement, Cockroach Labs said annual recurring revenue had tripled year over year and cloud revenue had risen 500 percent in the prior quarter. | Medium | SO008 |
| CO018 | The same 2021 announcement said Cockroach Labs had more than 200 customers, tens of thousands of deployed clusters, and more than 50 percent of customers already on CockroachDB Dedicated. | High | SO008, SO009 |
| CO019 | Cockroach Labs said the Serverless beta had already brought in more than 10,000 new users only weeks after launch. | High | SO008, SO009 |
| CO020 | The Series F blog says the company started in 2015 as a small team frustrated by the lack of sophisticated open-source database technology for a cloud-first world. | Medium | SO009 |
| CO021 | Spencer Kimball remains CEO and the most visible public executive voice for Cockroach Labs in both the 2021 funding materials and the 2026 momentum update. | High | SO008, SO010 |
| CO022 | The 2026 momentum release says Cockroach Labs strengthened its leadership team by appointing Sailesh Munagala as chief financial officer. | Medium | SO010 |
| CO023 | The 2026 momentum release positions CockroachDB around AI-scale resilience, claiming throughput improvements of up to 50 percent in release 25.2 and new C-SPANN vector indexing for PostgreSQL-compatible search. | Medium | SO010, SO010 |
| CO024 | The 2026 update also says Cockroach Labs expanded its partner ecosystem, including an OEM relationship with IBM. | Medium | SO010 |
| CO025 | Cockroach Labs cites Form3, Hard Rock Digital, and Shipt among customers in the 2026 momentum release, signaling continued concentration in regulated and always-on workloads. | Medium | SO010 |
| CO026 | Booking.com uses CockroachDB Cloud for an order platform of roughly 20 TB spanning Frankfurt, London, and Ireland, showing relevance for global travel transaction systems. | Medium | SO020 |
| CO027 | SumUp says CockroachDB underpins a global payments platform serving more than 4 million merchants across 36 markets and processed over 1 billion transactions in 2024. | Medium | SO021 |
| CO028 | Form3 describes CockroachDB as the backbone of a multi-cloud payments engine spanning AWS, GCP, and Azure with 100 to 200 millisecond p99 service-level targets and up to 700 TPS. | Medium | SO022 |
| CO029 | Netflix says it now operates more than 380 CockroachDB clusters, including over 160 production clusters and more than 60 multi-region clusters. | Medium | SO023 |
| CO030 | The GitHub repository describes CockroachDB as open source distributed SQL designed for high availability and effortless scale, reinforcing the company’s open-core developer motion. | Medium | SO024 |
| CO031 | The 2021 funding materials cited more than 22,000 GitHub stars and more than 500 open-source contributors, indicating substantial early developer adoption. | Medium | SO008, SO009 |
| CO032 | Stack Overflow’s 2024 developer survey reported PostgreSQL as the most-used database, strengthening Cockroach Labs’ strategic choice to emphasize PostgreSQL compatibility rather than a proprietary query model. | Medium | SO025, SO002 |
| CO033 | Cockroach Labs discloses technical advisories publicly, and the 2026 advisory list includes privilege escalation, partial-index corruption, live-data deletion, and backup-integrity bugs. | Medium | SO011 |
| CO034 | CockroachDB Cloud also maintains a public incident-history page, showing the company chooses transparency on operational events rather than keeping status private. | Medium | SO012 |
| CO035 | Accessible public materials do not clearly disclose the current board roster or full cap-table governance terms, leaving investors without direct evidence on board composition, liquidation preferences, or information rights. | Medium | SO014, SO008, SO015 |
| CM001 | Cockroach Labs should be analyzed inside the narrower distributed-SQL category nested within broader cloud-database and distributed-database markets, because its product is explicitly a distributed SQL database rather than a generic NoSQL or analytics system. | High | SM002, SM018, SM011 |
| CM002 | The company's practical capture zone includes globally distributed OLTP databases, resilience-driven application modernization, and managed transactional database services, but excludes general-purpose analytics warehouses and document stores as primary market definitions. | Medium | SM002, SM003, SM017 |
| CM003 | Status-quo substitutes remain self-managed PostgreSQL, Amazon Aurora PostgreSQL, Google Spanner for hyperscaler buyers, and application-level sharding on incumbent relational databases. | High | SM018, SM014, SM015, SM030 |
| CM004 | DataIntelo publishes a 2025 distributed SQL database market estimate of about $7.2B growing toward roughly $24.8B by 2034 at about 14.7% CAGR, giving the cleanest narrow-category external sizing anchor. | Medium | SM011 |
| CM005 | Coherent Market Insights places the broader cloud database market around $26.0B in 2026 and about $73.0B by 2033 at roughly 15.9% CAGR, which is directionally useful but much broader than Cockroach Labs' product category. | Medium | SM012 |
| CM006 | Business Research Insights estimates the distributed database market at about $4.48B in 2026 growing to about $9.96B by 2035, a lens narrower than cloud databases but still broader than distributed SQL. | Medium | SM013 |
| CM007 | The spread between roughly $4.5B, $7.2B, and $26.0B market lenses shows why a single generic TAM number would overstate precision for Cockroach Labs. | Medium | SM011, SM012, SM013 |
| CM008 | DataIntelo attributes nearly 59% of distributed-SQL demand to cloud-based deployment models, reinforcing why Cockroach Labs' managed cloud products sit in the growth center of the category. | High | SM011, SM003 |
| CM009 | Coherent Market Insights likewise describes public-cloud deployment as the leading mode in the broader cloud-database market, corroborating the directional cloud bias even if the category definition is broader. | High | SM012, SM003 |
| CM010 | DataIntelo identifies BFSI as the leading distributed-SQL vertical at roughly a quarter of the market, aligning with Cockroach Labs' heavy marketing into financial-services resilience and compliance use cases. | High | SM011, SM005, SM007 |
| CM011 | Official customer evidence also shows travel, commerce, fraud prevention, and media/streaming workloads as credible adjacent verticals through Booking.com, Riskified, and Netflix references. | High | SM006, SM009, SM008 |
| CM012 | Cockroach Labs' 2026 momentum release adds AI to the target-vertical mix, implying category expansion into AI infrastructure workloads rather than only classic payment and booking systems. | High | SM004, SM025 |
| CM013 | The daily user is typically a platform, database, or application-infrastructure engineer, while the economic buyer is an engineering VP, CIO, CTO, or transformation owner sponsoring migration and resilience budgets. | Medium | SM002, SM024, SM006, SM007 |
| CM014 | Adoption usually starts when teams need multi-region writes, survive zonal outages, or remove operational fragility from manual sharding and failover designs. | High | SM002, SM034, SM006, SM007 |
| CM015 | PostgreSQL compatibility matters because PostgreSQL remains the most-used database in Stack Overflow's 2024 survey, and CockroachDB repeatedly positions compatibility as a migration and developer-adoption lever. | High | SM010, SM002, SM024 |
| CM016 | Compliance-sensitive buyers gain another adoption trigger when regulated workloads require data controls, resilience evidence, and auditable security posture. | High | SM005, SM035, SM007 |
| CM017 | AI/vector-search positioning is real but still an extension rather than the company's core historical market wedge, because the stronger public proof remains resilience-heavy transactional workloads. | Medium | SM025, SM036, SM006, SM007 |
| CM018 | Migration tooling is central to category adoption because the practical alternative is not “no database” but staying on PostgreSQL, Aurora, Oracle, or a legacy sharded estate. | High | SM024, SM037, SM038, SM014 |
| CM019 | Pricing pressure comes from hyperscaler databases and newer developer-native serverless products that make entry points cheap even when capabilities are narrower. | High | SM014, SM015, SM021, SM022, SM019, SM020 |
| CM020 | Aurora and PostgreSQL often win when buyers prioritize familiarity and single-cloud optimization over cross-region consistency and cloud portability. | Medium | SM014, SM018, SM031 |
| CM021 | Spanner is a stronger architectural alternative for large Google Cloud-centric deployments but implies hyperscaler dependence that some buyers explicitly want to avoid. | Medium | SM015, SM032 |
| CM022 | Newer serverless SQL products such as Neon and PlanetScale compress evaluation cycles by lowering experimentation cost, even if they do not fully match CockroachDB on resilience and consistency positioning. | Medium | SM022, SM021, SM003 |
| CM023 | TiDB and YugabyteDB matter most where teams want open-source-flavored distributed SQL alternatives rather than hyperscaler-managed databases. | Medium | SM019, SM020, SM033 |
| CM024 | Migration complexity remains a first-order adoption barrier because distributed SQL asks buyers to change database operations, performance expectations, and failure testing discipline rather than only switch vendors. | High | SM013, SM024, SM023 |
| CM025 | The presence of official advisories and public resilience messaging indicates that trust is both a driver and a gating constraint: buyers want resilience, but they scrutinize correctness failures intensely. | High | SM023, SM026, SM005 |
| CM026 | Market reports themselves are a diligence risk because they often bundle incompatible categories, geographies, and methodologies under one headline number. | Medium | SM011, SM012, SM013 |
| CM027 | North America appears to be the leading geography in the available market studies, which is directionally consistent with Cockroach Labs' U.S. headquarters and enterprise go-to-market footprint. | Medium | SM011, SM012, SM001 |
| CM028 | Large-enterprise buyers dominate the economic value pool because multi-region resilience projects usually require cross-team migration effort and executive sponsorship. | Medium | SM012, SM006, SM007 |
| CM029 | SMB adoption is more plausible through serverless and self-serve cloud entry points than through classic field-sold dedicated deployments. | Medium | SM003, SM022, SM021 |
| CM030 | Cockroach Labs' market opportunity is more adoption-timing sensitive than raw-TAM sensitive, because the biggest gating variables are migration urgency, outage pain, and willingness to pay for resilience. | High | SM034, SM026, SM024 |
| CM031 | Public evidence is insufficient to isolate a clean company-specific SAM without making aggressive assumptions about cloud preference, geography, and workload fit. | Medium | SM011, SM012, SM013 |
| CM032 | Public evidence is even less sufficient for SOM because no disclosed conversion funnel, win rate, or live paid-customer count lets an outsider ground market share responsibly. | Medium | SM028, SM029, SM003 |
| CM033 | The most credible market narrative is therefore not “massive generic database TAM,” but “high-value slice of mission-critical cloud-native transactional workloads with expensive failure modes.” | High | SM002, SM005, SM006, SM007 |
| CM034 | Customer examples show that the adoption path often begins in one latency- or resilience-sensitive workflow before expanding into broader platform standardization. | Medium | SM006, SM009, SM027 |
| CM035 | Later valuation work should treat the narrow distributed-SQL estimate as the base lens, the distributed-database estimate as a sanity check, and the cloud-database estimate as an outer bound rather than a core TAM. | Medium | SM011, SM013, SM012 |
| CP001 | Cockroach Labs competes across five distinct buyer choices: staying on PostgreSQL, moving to hyperscaler-managed PostgreSQL, adopting global-consistency distributed SQL, using sharded MySQL-style systems, or choosing adjacent modern data platforms. | Medium | SP008, SP010, SP012, SP017, SP028 |
| CP002 | PostgreSQL is open source, self-hostable anywhere, and backed by a large ecosystem, making it the default status-quo alternative rather than a niche competitor. | High | SP008, SP009 |
| CP003 | The 2024 Stack Overflow survey still lists PostgreSQL among the most popular database technologies, reinforcing that many teams can postpone migration by staying on familiar tooling. | Medium | SP009 |
| CP004 | Cockroach’s own comparison material argues that standard PostgreSQL remains primarily a single-primary architecture with HA, sharding, and failover assembled through extensions or third-party tooling rather than native distributed writes. | Medium | SP004 |
| CP005 | Amazon Aurora is positioned as a managed relational database on AWS with instance, storage, and optional I/O-based billing rather than a cloud-agnostic database layer. | High | SP010, SP011 |
| CP006 | Aurora Serverless prices capacity in ACUs and can scale database capacity automatically, lowering pilot friction for teams that want PostgreSQL compatibility without self-management. | Medium | SP010 |
| CP007 | Aurora Global Database adds cross-region replicated write I/O charges plus region-specific infrastructure, so global resilience on AWS still comes with AWS-native complexity and cost layers. | High | SP011, SP010 |
| CP008 | Google Spanner pricing is multi-component, charging for compute capacity, database storage, backups, cross-region replication, and some network bandwidth. | Medium | SP012 |
| CP009 | Spanner’s multi-region and replica-based pricing model is well suited to large committed GCP workloads but pushes buyers toward Google procurement, topology design, and cross-region cost planning. | Medium | SP012, SP006 |
| CP010 | AlloyDB markets itself as a 100 percent PostgreSQL-compatible managed database with AI features, up to 20 read replicas in a read pool, and a 99.99 percent uptime SLA. | Medium | SP013 |
| CP011 | AlloyDB pricing is built from vCPU, memory, storage, backup-storage, and networking charges, and a high-availability primary instance uses two nodes in-region. | Medium | SP014 |
| CP012 | PlanetScale now spans both Vitess and Postgres motions, with a base plan that starts at 5 dollars per month for single-node Postgres and 15 dollars for a three-node high-availability cluster. | Medium | SP015 |
| CP013 | PlanetScale’s enterprise offering includes single-tenant and bring-your-own-cloud deployment, migration assistance, and upgraded support, which makes it more credible with larger regulated customers than a pure hobby tool would be. | Medium | SP015 |
| CP014 | Vitess is a CNCF-graduated, MySQL-compatible sharding and failover layer that emphasizes transparent sharding, query rewriting, and near-zero-downtime resharding instead of PostgreSQL semantics. | High | SP017, SP016 |
| CP015 | Neon positions itself as a Postgres backend for apps and agents and documents a serverless architecture that separates compute from durable storage via streamed WAL. | High | SP018, SP020 |
| CP016 | Neon’s pricing is usage-based: paid plans bill CU-hours and storage, idle compute can scale to zero, and branching plus history retention change storage economics relative to a conventional managed cluster. | High | SP019, SP020 |
| CP017 | Yugabyte markets itself as an AI-ready distributed PostgreSQL database that is 100 percent open source, multi-master, and built for resilience across zones, regions, and clouds. | Medium | SP021 |
| CP018 | Yugabyte’s commercial motion pairs open-source software with managed or commercial support options, which lowers perceived lock-in relative to hyperscaler-only services. | Medium | SP021, SP022 |
| CP019 | A customer quote on Yugabyte’s homepage says one buyer consolidated Cassandra, Neo4j, Microsoft SQL Server, and CockroachDB systems into one YugabyteDB cluster, which is direct but vendor-authored evidence that Cockroach workloads can be displaced. | Medium | SP021 |
| CP020 | TiDB describes itself as a MySQL-compatible distributed SQL platform that unifies high-volume transactions and real-time analytics in one system with decoupled compute and storage. | Medium | SP023 |
| CP021 | TiDB publicly emphasizes automatic sharding, 99.99 percent availability, strong ACID consistency, and multi-cloud flexibility, which makes it a credible alternative for buyers who prize operational plus analytical consolidation more than PostgreSQL fidelity. | Medium | SP023 |
| CP022 | PingCAP’s cloud packaging spans starter or serverless entry points plus managed and self-managed deployment options, reinforcing a broad funnel from experimentation to enterprise. | Medium | SP024, SP025, SP023 |
| CP023 | SingleStore Helios is a cloud database service with separate compute and storage, vector search, MySQL and MongoDB wire-protocol compatibility, and multi-AZ high-availability positioning. | Medium | SP026 |
| CP024 | SingleStore pricing is explicitly usage-based and can add separate Flow CDC charges on top of compute and storage, which means financial predictability depends heavily on workload shape and ingestion patterns. | Medium | SP027 |
| CP025 | MongoDB Atlas is an adjacent substitute for modern app and AI workloads, but its public messaging centers on document-model agility and modern app builders rather than PostgreSQL-compatible distributed SQL. | Medium | SP028, SP029 |
| CP026 | Review and market-summary surfaces show that buyers evaluating CockroachDB are exposed to a crowded alternative set rather than to one single benchmark rival. | Low | SP030, SP031 |
| CP027 | Cockroach’s strongest direct peer overlap remains with Yugabyte, Aurora, and Spanner because those options all compete on mission-critical transactional workloads rather than only on developer convenience or analytics adjacency. | Medium | SP007, SP005, SP006, SP002 |
| CP028 | Cockroach’s differentiator is not generic “cloud database” branding but the combination of PostgreSQL compatibility, distributed ACID, active-active multi-region design, and cloud-agnostic deployment. | High | SP002, SP004, SP005, SP006 |
| CP029 | That differentiation is narrower than it used to be because AlloyDB, Yugabyte, TiDB, SingleStore, and Neon all now market some mix of performance, AI, vector, or scale features that blunt a simple “modern database” pitch. | Medium | SP013, SP021, SP023, SP026, SP018 |
| CP030 | Hyperscaler products enjoy embedded procurement, support, and adjacent-service bundling, so Aurora, Spanner, and AlloyDB can win on organizational convenience even when Cockroach’s architecture is more portable. | Medium | SP011, SP012, SP013 |
| CP031 | Open-source or source-available ecosystems reduce lock-in anxiety for PostgreSQL, Vitess, Yugabyte, and TiDB relative to AWS-only Aurora or Google-centric Spanner and AlloyDB. | Medium | SP008, SP017, SP021, SP023, SP011, SP012, SP013 |
| CP032 | Switching-cost pressure cuts both ways: PostgreSQL familiarity lowers migration friction into CockroachDB, but the same familiarity also makes “stay on Postgres” or “move to managed Postgres” the easiest no-change answer. | Medium | SP008, SP002, SP010, SP013 |
| CP033 | Low-friction pricing from Neon and PlanetScale means developer-led experiments can start with little commitment, which pressures Cockroach Labs to justify why its heavier distributed model should be adopted before scale pain becomes acute. | Medium | SP019, SP015 |
| CP034 | Enterprise-style node or replica pricing from Spanner, AlloyDB, and Aurora suits steadier production workloads but can look expensive or complex next to simpler free-tier or usage-based serverless offers. | Medium | SP012, SP014, SP010, SP019, SP015 |
| CP035 | The market’s AI narrative is now table stakes: AlloyDB advertises AlloyDB AI, Yugabyte highlights vector indexing for RAG, TiDB frames mixed OLTP and AI workloads, and SingleStore markets vector and real-time AI use cases. | High | SP013, SP021, SP023, SP026 |
| CP036 | Public evidence does not reveal clean win-rate data for Cockroach Labs versus Aurora, Spanner, or Yugabyte, so competitive confidence must rely on product positioning and customer proof rather than on transparent market-share disclosures. | Low | SP005, SP006, SP007, SP003 |
| CP037 | Public evidence also does not cleanly disclose funding or revenue scale for every private competitor in one comparable format, which limits how precise an outsider can make the private-competitive ranking. | Low | SP021, SP018, SP015, SP023 |
| CI001 | Cockroach Labs monetizes multiple layers around the same core database: Basic cloud usage, Standard provisioned clusters, Advanced dedicated clusters, self-hosted enterprise deployment, support subscriptions, and professional or migration services. | High | SI004, SI002, SI003, SI006, SI011 |
| CI002 | CockroachDB Basic is billed purely on usage through request units, and the first monthly spending band equivalent to 50 million request units and 10 GiB of storage is credited back for monthly customers. | High | SI005, SI004 |
| CI003 | On the Basic plan, backups and data transfer are included in request-unit pricing rather than charged as separate line items. | Medium | SI005 |
| CI004 | CockroachDB Standard monetizes production workloads through provisioned vCPU-hours plus usage-based storage, data transfer, backups, and change data capture charges. | High | SI005, SI004 |
| CI005 | For multi-region Standard clusters, the price of the most expensive region is applied to the cluster’s provisioned compute capacity. | High | SI005, SI012 |
| CI006 | Cockroach Labs recommends a 40 percent capacity buffer when planning Standard clusters, which means customers are encouraged to reserve more compute than current observed demand alone would imply. | Medium | SI012 |
| CI007 | CockroachDB Standard is publicly described as well suited for workloads requiring 12 or fewer vCPUs, while Advanced has a minimum production configuration of 3 nodes times 4 vCPUs or 12 total vCPUs. | Medium | SI012 |
| CI008 | CockroachDB Standard is not recommended for analytical or hybrid OLTP/OLAP workloads, which suggests the company protects gross margin and customer fit by steering expensive mixed workloads toward other plans or architectures. | Medium | SI012 |
| CI009 | CockroachDB Advanced monetizes compute and storage on a per-node basis, and on AWS each node can also incur provisioned IOPS charges. | High | SI005, SI004 |
| CI010 | Advanced pricing also varies by region, cloud provider, and whether the Advanced security add-on is enabled, making the enterprise plan materially more configurable and more bespoke than Basic or Standard. | High | SI005, SI004 |
| CI011 | CockroachDB Cloud pricing changed for most customers after contract renewals that began after December 1, 2024, indicating the company has actively revised its monetization architecture rather than leaving older contracts untouched forever. | Medium | SI005 |
| CI012 | Public support pages show Cockroach Labs sells tiered subscriptions, with Enterprise support offering faster response times, a named customer success manager, dedicated Slack, technical advisory services, and root-cause analysis. | Medium | SI006 |
| CI013 | For CockroachDB Cloud customers with Enterprise Subscription support, Cockroach Labs states a 20 percent monthly fee applies based on actual Cloud Credit consumption. | Medium | SI006 |
| CI014 | Cockroach Labs explicitly markets migration assistance and performance tuning through support and professional services, implying a meaningful high-touch component in customer acquisition and expansion. | High | SI006, SI011, SI010 |
| CI015 | The MOLT toolkit covers schema conversion, initial data load, continuous replication, verification, and optional failback across PostgreSQL, MySQL, Oracle, and SQL Server migrations. | High | SI011, SI010 |
| CI016 | Because MOLT is designed for resilient, restartable, and minimal-downtime migrations, Cockroach Labs is optimized for consultative replacement projects rather than for purely impulsive self-serve adoption. | Medium | SI011, SI006, SI008 |
| CI017 | The public deployment-option documentation shows Cockroach Labs supports self-hosted, cloud, on-premises, and enterprise deployment patterns, which broadens its TAM but also broadens delivery complexity. | High | SI008, SI009, SI003 |
| CI018 | The 2021 Series F announcement said Cockroach Labs had tripled annual recurring revenue year over year and grown cloud revenue 500 percent in the previous quarter. | High | SI013, SI014 |
| CI019 | The same financing disclosure said Cockroach Labs had more than 200 customers and that more than 50 percent of customers were already on CockroachDB Dedicated. | High | SI013, SI014 |
| CI020 | GetLatka reports Cockroach Labs generated 128.3 million dollars of ARR or revenue in 2023, which remains the clearest public financial anchor even though it is not a fresh 2026 company disclosure. | Medium | SI016 |
| CI021 | GetLatka also estimates Cockroach Labs employed roughly 715 people by late 2025, giving a rough proxy for the company’s cost base even though the figure is third-party and unaudited. | Medium | SI016 |
| CI022 | The 2026 momentum release emphasizes performance, vector indexing, OEM and partner expansion, and leadership additions, but it does not publish current ARR, burn, or cash-flow metrics. | Medium | SI015 |
| CI023 | Cockroach Labs officially raised 278 million dollars in its Series F and said lifetime funding reached 633 million dollars at that point. | High | SI013, SI014 |
| CI024 | Secondary-market indicators in mid-2026 imply valuation around 6.9 billion dollars, but those signals do not add operating cash to the balance sheet the way a new primary round would. | Medium | SI018, SI020, SI019 |
| CI025 | Nasdaq Private Market and Notice together show that private-market liquidity exists for Cockroach Labs shares, which reduces distress concerns but does not answer runway, burn, or dilution questions. | Medium | SI020, SI019, SI021 |
| CI026 | Cloud bills can expand after adoption through storage, backup, changefeed, and cross-region data transfer charges, so the economic model is not only about provisioned compute. | High | SI005, SI012 |
| CI027 | On Standard, billing is based on capacity reserved rather than actual compute consumed, which can improve performance predictability but also creates slack cost for bursty customers. | Medium | SI005, SI012 |
| CI028 | Basic’s free and usage-based structure is a bottoms-up funnel, while Standard and Advanced are designed to monetize production reliability, multi-region scale, and compliance-sensitive workloads. | Medium | SI004, SI005, SI002, SI003 |
| CI029 | Enterprise support and migration assistance increase the lifetime value of larger customers, but they also imply service-delivery cost and some dependence on skilled solution engineering. | Medium | SI006, SI011, SI003 |
| CI030 | Compared with Aurora and Spanner, Cockroach monetizes a mix of provisioned infrastructure and usage-based line items that looks enterprise-oriented rather than radically cheaper on raw infrastructure alone. | Medium | SI005, SI022, SI023 |
| CI031 | Compared with Neon and PlanetScale, Cockroach’s production plans ask customers to reserve more explicit capacity up front, which likely raises ACV but also increases pilot friction. | Medium | SI004, SI025, SI024 |
| CI032 | The pricing documentation suggests Cockroach Labs can monetize customer growth not just through compute but through backup retention, CDC watched data, and cross-region traffic once workloads become mission critical. | Medium | SI005 |
| CI033 | Clusters running unsupported versions are not eligible for Cockroach Labs’ availability SLA, which ties enterprise supportability to customers staying on recent releases and therefore to an ongoing upgrade program. | Medium | SI007 |
| CI034 | Basic and Standard are automatically upgraded on recent regular releases, while Advanced customers can choose innovation releases and manually drive major-version upgrades, reinforcing that Advanced is built for more controlled enterprise operations. | Medium | SI007 |
| CI035 | Public evidence does not support clean estimates for current gross margin, net retention, CAC, payback, cash balance, or runway, which leaves the true efficiency profile underdetermined even though public database-company filings show the level of disclosure a mature comp can provide. | Low | SI015, SI016, SI017, SI027 |
| CI036 | That absence of burn and cash-balance disclosure means public evidence cannot prove a precise path to profitability, even though mission-critical infrastructure usually has attractive recurring-revenue characteristics. | Low | SI016, SI006, SI029 |
| CI037 | The financial quality that is visible is encouraging: workloads are sticky, support is monetizable, and the company has already shown cloud-mix improvement and large production customers. | Medium | SI013, SI006, SI029 |
| CI038 | The financial verdict is therefore positive on revenue quality but cautious on underwriting: Cockroach Labs looks like a real late-stage infrastructure business with multiple monetization levers, yet public evidence is still too thin to underwrite margin durability or capital adequacy with conviction. | Medium | SI016, SI013, SI005, SI015, SI018 |
| CI039 | A third-party 2026 pricing review argues that migration work, professional services, and cross-region data transfer can push real-world Cockroach spend above the headline entry price, which is directionally consistent with Cockroach’s own multi-line-item billing documentation. | Low | SI028, SI005, SI006 |
| CE001 | CockroachDB is positioned as a PostgreSQL-compatible distributed SQL database for always-on customer experiences rather than as a generic analytics or document platform. | High | SE001, SE002, SE029 |
| CE002 | Cockroach Labs publicly sells multiple deployment forms around that core engine, including managed cloud, self-hosted enterprise, migration tooling, and support. | High | SE003, SE004, SE012 |
| CE003 | The serverless or Basic motion is designed for fast starts and low-friction experimentation, while Standard and Advanced target progressively heavier production, security, and multi-region needs. | Medium | SE005, SE003, SE004, SE014 |
| CE004 | CockroachDB’s architecture documentation says clients can send SQL to any node, which is then translated into key-value operations over distributed ranges. | High | SE016, SE010 |
| CE005 | CockroachDB stores data in contiguous ranges of key-value pairs, automatically splits those ranges as they grow, and replicates them to at least three nodes by default. | Medium | SE016 |
| CE006 | Writes require quorum agreement through the Raft protocol, and the leaseholder or Raft leader coordinates consistent reads and writes for a range. | Medium | SE016 |
| CE007 | CockroachDB was designed to accept reads and writes on all nodes while remaining highly automated and deployable in any environment without platform lock-in. | High | SE016, SE001 |
| CE008 | Multi-region capabilities include primary regions, table localities such as global, regional by table, and regional by row, plus configurable survival goals. | Medium | SE015 |
| CE009 | Super regions and data-domiciling controls are explicitly documented as a way to keep replicas within selected regions for compliance-sensitive deployments. | High | SE015, SE018 |
| CE010 | Secondary regions can be configured to improve failover behavior by pre-positioning leaseholder candidates when a primary region fails. | Medium | SE015 |
| CE011 | Cluster virtualization separates a cluster’s control plane from its data plane and introduces a system virtual cluster plus user virtual clusters with separate administrative boundaries. | Medium | SE017 |
| CE012 | Cockroach Labs documents cluster virtualization as necessary only for physical cluster replication and currently limits a physical cluster to one system virtual cluster and one virtual cluster. | Medium | SE017 |
| CE013 | CockroachDB v25.2 claims roughly 50 percent higher throughput than 24.3 on average across nine workloads. | Medium | SE019 |
| CE014 | The same release describes preview buffered writes that improved performance by roughly 15 to 40 percent in cited tests by reducing round trips and redundant writes. | Medium | SE019 |
| CE015 | CockroachDB added preview vector indexing in 25.2 using Cockroach-SPANN, positioning the database for large-scale semantic search without moving data into a separate specialist store. | High | SE019, SE020 |
| CE016 | The C-SPANN architecture stores vector partitions as self-contained units in CockroachDB ranges so index data can split, merge, and rebalance like ordinary table data. | High | SE020, SE016 |
| CE017 | C-SPANN uses quantization based on RaBitQ and claims roughly a 94 percent reduction in vector size in common cases. | Medium | SE020 |
| CE018 | CockroachDB vector indexes support prefix columns so searches can be partitioned by user or region, aligning vector search with tenancy and data-locality controls. | High | SE020, SE015 |
| CE019 | CockroachDB v26.1 adds expanded HIPAA and PCI participation for Cloud Advanced on Azure, JWT and OpenID Connect role synchronization, automatic user provisioning, unified CMEK management, and native FIPS 140-3 support. | High | SE018, SE023 |
| CE020 | The AI-agent security post frames row-level security, strict authorization, and jurisdiction-based data placement as product controls for zero-trust AI access. | High | SE021, SE018, SE023 |
| CE021 | Trust and security materials also emphasize SOC 2, ISO, HIPAA readiness, PCI capability, and encryption controls as core elements of the product package. | High | SE007, SE006, SE018 |
| CE022 | Cockroach Labs publishes a responsible disclosure policy, technical advisories, and a public cloud incident history, which shows mature quality-control and incident-transparency processes. | High | SE022, SE008, SE009 |
| CE023 | Those same advisories show that the product surface is broad and correctness-sensitive enough to generate real security and data-integrity issues, which is the ordinary downside of a complex distributed database. | Medium | SE008, SE009 |
| CE024 | Migration tooling includes MOLT plus change-data-capture and replication workflows, reinforcing that CockroachDB is built to replace existing transactional systems rather than only to power greenfield applications. | High | SE013, SE012, SE002 |
| CE025 | CockroachDB’s roadmap velocity is visible in the short span between 25.2 performance and vector-indexing updates and 26.1 security and compliance updates. | Medium | SE019, SE018, SE018 |
| CE026 | The product is explicitly cloud-aware across AWS, GCP, and Azure while also supporting self-hosted and hybrid patterns, which is a meaningful differentiator versus one-cloud relational services. | High | SE001, SE003, SE004, SE018 |
| CE027 | PostgreSQL compatibility remains central to the product design, allowing use of familiar SQL tools while avoiding the organizational friction of a wholly new query model. | High | SE002, SE016, SE029 |
| CE028 | Compared with PostgreSQL alone, CockroachDB’s native range replication, multi-active topology, and locality controls are the hardest parts for customers to reproduce themselves. | Medium | SE016, SE015, SE002 |
| CE029 | Compared with Aurora and Spanner, CockroachDB’s main product-tech edge is portability across clouds and self-hosted environments rather than merely offering another managed relational endpoint. | Medium | SE027, SE028, SE001, SE003 |
| CE030 | Compared with Yugabyte and TiDB, CockroachDB leans harder into PostgreSQL familiarity, locality-aware SQL abstractions, and integrated vector or security messaging rather than broader compatibility with MySQL or multi-model workloads. | Medium | SE031, SE032, SE002, SE019, SE018 |
| CE031 | The product breadth is now wide enough to encompass core SQL, multi-region topology, migrations, CDC, compliance, vector indexing, and AI-agent governance in one platform story. | Medium | SE002, SE015, SE013, SE019, SE018, SE021 |
| CE032 | That breadth is a strength for enterprise buyers but also a complexity risk because upgrades, security settings, locality choices, and index behavior all need disciplined operation. | Medium | SE017, SE015, SE008, SE018 |
| CE033 | Developer-signal evidence from the GitHub repository and the PostgreSQL ecosystem helps explain why CockroachDB emphasizes compatibility and operational automation rather than asking users to abandon the relational toolchain. | Medium | SE010, SE029, SE030 |
| CE034 | The public product story increasingly targets regulated and global workloads where row-level security, CMEK, data sovereignty, and multi-region failover are buying criteria rather than nice-to-have features. | Medium | SE018, SE015, SE007 |
| CE035 | The AI-era expansion is not just marketing: CockroachDB now documents billions-scale vector indexing, owner-aware partitioning, and security controls for AI agents in the main product surface. | High | SE020, SE024, SE021, SE019 |
| CE036 | Public sources still cannot fully quantify how CockroachDB’s performance compares with direct rivals on customer-specific workloads, because the strongest performance claims remain vendor-authored rather than independently benchmarked. | Low | SE019, SE001, SE031, SE032 |
| CE037 | The best product-tech verdict is that CockroachDB has evolved from a narrowly distributed-SQL proposition into a broad transactional platform with serious multi-region, compliance, and AI-era credibility. | Medium | SE002, SE015, SE019, SE018, SE020 |
| CE038 | Cockroach Labs continues to make resilience a first-class product theme through explicit performance-under-adversity positioning and outage-focused messaging, reinforcing that reliability is sold as a feature rather than only as an implementation detail. | Medium | SE025, SE026, SE011 |
| CU001 | Cockroach Labs publicly presents CockroachDB as trusted by enterprises across banking and fintech, retail and eCommerce, software and tech, media and streaming, gaming, manufacturing and logistics, and gambling. | High | SU002, SU001 |
| CU002 | The 2021 Series F materials said Cockroach Labs had more than 200 customers and tens of thousands of deployed clusters, establishing a meaningful commercial base well before the 2026 run date. | High | SU004, SU005 |
| CU003 | Those same Series F materials said more than 50 percent of customers were already on CockroachDB Dedicated, implying that managed-cloud adoption had become central to the customer mix early. | High | SU004, SU005 |
| CU004 | Apps Run The World tracks CockroachDB deployments across multiple organizations and geographies, supporting the view that adoption is not limited to a handful of logos even though its counts should be treated as directional. | Medium | SU011, SU002 |
| CU005 | ReadyContacts advertises a 226-company Cockroach Labs customer list and emphasizes vertical and geography slicing, which is useful only as directional third-party evidence rather than as a definitive paying-customer count. | Low | SU012, SU004 |
| CU006 | Cockroach Labs’ visible customer proof is weighted toward mission-critical operational workloads rather than casual departmental apps. | High | SU002, SU003, SU004 |
| CU007 | Booking.com uses CockroachDB for its Order Platform, a highly available order-management system supporting the company’s Connected Trip initiative. | Medium | SU013 |
| CU008 | Booking.com migrated that platform from Cassandra after needing ACID guarantees, CDC, secondary indexes, and lower operational overhead. | Medium | SU013 |
| CU009 | Booking.com says its migrated Order Platform now holds around 20 TB of data on CockroachDB Cloud across multiple European regions. | Medium | SU013 |
| CU010 | Booking.com cites a 99.99998 percent SLI for writes as acceptable for its reservation use case, showing that CockroachDB is used in a high-availability consumer booking workflow. | Medium | SU013 |
| CU011 | Shipt built a distributed payment system on CockroachDB to prioritize correctness, concurrency control, and multi-region availability. | Medium | SU015 |
| CU012 | Shipt publicly describes a deployment with 12 nodes across four regions, about 1 to 2 million payment transactions per day, and a 99.999 percent availability target. | Medium | SU015 |
| CU013 | Shipt explicitly preferred CockroachDB over Spanner because it wanted the option to deploy across multiple clouds rather than accept single-cloud lock-in. | Medium | SU015 |
| CU014 | Form3 uses CockroachDB as the backbone of a managed payments platform serving banks and fintechs across the UK, EU, and US. | Medium | SU016 |
| CU015 | Form3 runs CockroachDB across AWS, GCP, and Azure with a replication factor of three, presenting one of the clearest public examples of true multi-cloud production use. | Medium | SU016 |
| CU016 | Form3 reports strict 100 and 200 millisecond P99 SLAs, about 700 TPS, and customer-local topology placement, indicating that CockroachDB supports latency-sensitive regulated payment flows. | Medium | SU016 |
| CU017 | Form3 says customers such as Lloyds Bank and Nationwide Building Society rely on its platform, indirectly showing that CockroachDB sits beneath major financial-institution workloads. | Medium | SU016, SU023 |
| CU018 | Riskified says it chose CockroachDB to remove a PostgreSQL single-writer bottleneck while preserving PostgreSQL compatibility for a client-facing fraud platform. | High | SU019, SU024 |
| CU019 | Riskified reports 99+ percent customer retention, over 10,000 online transactions per second, and a zero-downtime migration, making it one of the strongest customer-quality proof points in the public set. | High | SU019, SU024 |
| CU020 | Riskified’s story reinforces that security, data integrity, and elasticity matter to customers whose own end users never directly see the database layer. | Medium | SU019 |
| CU021 | Route uses CockroachDB to power always-on data for more than 1 billion orders and says it serves more than 13,000 brands and millions of active app users. | Medium | SU020 |
| CU022 | Route reports about 52 TB of storage and multiple billion-plus-record tables on CockroachDB, supporting the claim that the product can handle large relational operational datasets. | Medium | SU020 |
| CU023 | Route also says paid support delivered unusually strong ROI, a useful signal that support quality can reinforce retention and expansion for sophisticated customers. | Medium | SU020 |
| CU024 | Netflix now operates more than 380 CockroachDB clusters, including over 160 production clusters and more than 60 multi-region clusters, after first offering CockroachDB-as-a-Service internally in 2020. | Medium | SU017 |
| CU025 | Netflix describes CockroachDB as its database solution for applications needing consistency, high availability, and region failover, showing internal standardization beyond a single isolated use case. | Medium | SU017 |
| CU026 | Netflix’s gaming platform uses a 48-node cluster across four regions, illustrating that customer proof extends into newer multi-region entertainment workloads as well as traditional media systems. | Medium | SU017 |
| CU027 | DoorDash publicly operates CockroachDB as a fully abstracted internal database service, with about 2,300 nodes across 300+ clusters, roughly 1.2 million peak QPS, 1.9 petabytes on disk, and close to 900 changefeeds. | Medium | SU021 |
| CU028 | DoorDash’s migration story shows CockroachDB winning a hard production replacement against Aurora Postgres because outages and scaling bottlenecks had become unacceptable. | High | SU022, SU021 |
| CU029 | Hard Rock Digital uses CockroachDB for a multi-region sportsbook that must satisfy state-by-state data residency and availability requirements. | Medium | SU018 |
| CU030 | Hard Rock reports running about 100 database nodes with 32 vCPUs each during NFL peak season, then scaling down to roughly one-third of that footprint afterward without downtime. | Medium | SU018 |
| CU031 | Hard Rock and Form3 both show that regulatory or jurisdictional constraints are recurring purchase drivers, not edge cases, for the CockroachDB customer base. | High | SU018, SU016, SU023 |
| CU032 | The financial-services use-case page says Cockroach Labs has worked with dozens of companies including Fortune 50 banks, supporting the idea that enterprise demand reaches beyond the handful of named case studies. | Medium | SU023 |
| CU033 | SumUp’s story shows CockroachDB supporting a global payments migration where downstream analytics and back-office tools had to remain consistent during cutover. | Medium | SU014 |
| CU034 | Superbet and Hard Rock together indicate that online betting and gaming are repeatable customer segments, not just one-off anecdotes. | Medium | SU025, SU018 |
| CU035 | Across Booking.com, Riskified, DoorDash, and Route, the recurring pattern is migration off legacy relational or adjacent systems into CockroachDB for scale, resilience, and less application-layer complexity. | High | SU013, SU019, SU022, SU020 |
| CU036 | Across Shipt, Form3, Hard Rock, and Netflix, multi-region survivability is sold and used as an operating requirement rather than as optional architecture polish. | High | SU015, SU016, SU018, SU017 |
| CU037 | Multiple customer stories mention direct help from Cockroach Labs account teams, support teams, or professional services, implying that post-sale delivery is part of customer success for complex deployments. | Medium | SU020, SU018, SU019 |
| CU038 | The roster of named customers skews toward sophisticated engineering organizations with platform teams, which likely supports larger contract values but may narrow the accessible buyer pool. | Medium | SU017, SU021, SU016, SU013, SU026 |
| CU039 | Public customer evidence is unusually rich in depth but still mostly vendor-authored, which means the quality of individual stories is stronger than the independence of the overall proof set. | Medium | SU002, SU013, SU016, SU017 |
| CU040 | Public sources do not pin down an exact 2026 paying-customer count, because official figures are stale and third-party databases are inconsistent in method and precision. | Medium | SU004, SU011, SU012, SU007 |
| CU041 | The customer base appears to offer strong expansion potential because many visible workloads are central transaction systems, control planes, or regulated platforms with high switching costs once deployed. | Medium | SU020, SU016, SU017, SU018 |
| CU042 | GetLatka’s late-2025 headcount estimate around 715 employees is consistent with a company large enough to support a substantial enterprise customer base, although it does not itself prove customer count or retention. | Medium | SU007, SU008 |
| CU043 | GitHub and Stack Overflow signals suggest developer familiarity with PostgreSQL and open-source ecosystems remains high, which likely helps Cockroach land customers that want relational tools without abandoning modern distributed architecture. | Medium | SU027, SU028, SU001 |
| CU044 | The best customer verdict is that Cockroach Labs has high-quality reference customers and real production depth across several demanding verticals, but public evidence still leaves exact customer count and independent retention quality less certain than the logo roster implies. | High | SU002, SU004, SU019, SU017, SU020, SU016 |
| CR001 | The 2026 technical-advisory record shows that CockroachDB’s risk surface is not theoretical: public advisories cover privilege escalation, index corruption, live-data deletion, silent import data loss, and backup incompleteness. | High | SR006, SR014 |
| CR002 | A May 2026 advisory disclosed two privilege-escalation vulnerabilities that could let authenticated users gain elevated privileges beyond those assigned to their account. | Medium | SR006 |
| CR003 | An April 2026 advisory disclosed a partial-index corruption bug during backfill on multi-column-family tables under concurrent updates. | Medium | SR006 |
| CR004 | A February 2026 advisory disclosed a race condition between MVCC garbage collection and range splits that could delete live data under rare conditions. | Medium | SR006 |
| CR005 | Another February 2026 advisory said object-storage read failures during AVRO imports could lead to silent data loss without an error being reported to the user. | Medium | SR006 |
| CR006 | The advisory log also includes earlier backup, restore, changefeed, and encryption-related defects, reinforcing that distributed-database correctness is an ongoing operational discipline rather than a solved problem. | Medium | SR006 |
| CR007 | The production checklist says fault tolerance depends on explicit topology choices such as at least three nodes or three regions, uniform locality labeling, and avoiding multiple nodes on one machine, meaning resilience is partly purchased through careful design rather than granted automatically. | High | SR010, SR011 |
| CR008 | The same checklist recommends minimum CPU, RAM, IOPS, and hardware-uniformity practices, implying that under-provisioning or heterogeneous fleets can directly degrade stability and performance. | High | SR010, SR012 |
| CR009 | CockroachDB documents hotspots as bottlenecks that scaling out alone may not solve, including hot rows, index tails, queueing hotspots, and lookback hotspots. | Medium | SR013 |
| CR010 | Hotspot documentation explicitly says some write patterns can limit a distributed cluster to the performance of a single node, which is a meaningful risk for teams expecting effortless horizontal scale. | Medium | SR013 |
| CR011 | Upgrade documentation requires healthy replication, load-balancing, backup validation, review of skipped-release notes, and sometimes manual finalization, showing that version changes carry real operational risk. | High | SR009, SR008 |
| CR012 | Once a major-version upgrade is finalized, the cluster cannot be rolled back to the prior major version. | Medium | SR009 |
| CR013 | Innovation releases have shorter support windows and no Assistance Support phase, which increases the penalty for version drift or poor upgrade timing. | High | SR008, SR009 |
| CR014 | CockroachDB v26.1 is an Innovation release that reaches end of support in 2026, underscoring how quickly customers can fall onto unsupported paths if they standardize on the wrong release. | Medium | SR008 |
| CR015 | The status-history page and advisories together show transparency, but they also confirm the normal reality of a complex database platform: bugs and service incidents are not hypothetical edge cases. | Medium | SR007, SR006 |
| CR016 | Customer stories repeatedly describe direct reliance on Cockroach Labs support or account teams for setup, migration, tuning, or expansion, implying some deployments remain operationally non-trivial even after purchase. | High | SR030, SR033, SR034, SR031 |
| CR017 | Hard Rock says Cockroach Labs helped set up a complicated state-by-state topology, while Route says account-team familiarity improved problem resolution, illustrating real services dependency in sophisticated accounts. | High | SR030, SR034 |
| CR018 | The financial-sector push raises regulatory stakes because DORA imposes ICT risk management, incident reporting, resilience testing, and third-party-risk obligations on financial entities and their providers. | High | SR019, SR023 |
| CR019 | Because Form3 and other financial customers use CockroachDB in payment-critical flows, Cockroach Labs is exposed to more stringent diligence expectations than a generic developer-tool vendor. | Medium | SR031, SR019, SR023 |
| CR020 | Gaming and sportsbook deployments face legal-topology complexity because the Wire Act and state-locality requirements can force bespoke placement and data-residency designs. | High | SR020, SR030 |
| CR021 | Hard Rock’s case study shows that those gaming requirements are not academic: the company needed database gateway nodes in each state and a mix of AWS Regions, Local Zones, and Outposts. | High | SR030, SR020 |
| CR022 | The privacy policy says Cockroach Labs logs device, access, and interaction information and may transfer personal information across borders, which increases data-governance scrutiny for regulated or privacy-sensitive buyers. | Medium | SR018, SR004 |
| CR023 | Cloud terms say customers remain responsible for properly configuring and securing their accounts and associated credentials, leaving meaningful shared-responsibility risk with the customer. | Medium | SR016 |
| CR024 | Cloud terms also say beta services and free offerings can be terminated or suspended at any time, may be incomplete, and receive no indemnification or support. | Medium | SR016 |
| CR025 | Cockroach Labs explicitly disclaims uninterrupted or error-free service in both website and SaaS legal materials, which is standard legally but still matters because the company sells always-on infrastructure. | High | SR015, SR016 |
| CR026 | The SaaS terms allow suspension for nonpayment, suspected risky use, or bankruptcy-like events and allow termination for convenience with notice, giving Cockroach Labs wide contractual control over service continuity. | Medium | SR016 |
| CR027 | The acceptable-use policy restricts penetration testing without prior written consent and sets conditions around public benchmarking, which can slow independent validation and create go-to-market friction in competitive bake-offs. | Medium | SR017 |
| CR028 | PostgreSQL remains a free, mature default with deep ecosystem familiarity, so Cockroach must continually justify complexity, migration cost, and pricing against a strong status-quo alternative. | High | SR026, SR036, SR033 |
| CR029 | Aurora and Spanner create a different kind of competitive risk: for cloud-aligned buyers they may look operationally simpler or more naturally bundled, even if they reduce portability. | Medium | SR024, SR025, SR031, SR025 |
| CR030 | Because many visible customers are sophisticated platform or regulated teams, Cockroach Labs may face TAM and sales-cycle risk if the product remains too complex for mainstream relational workloads. | Medium | SR034, SR032, SR036, SR021 |
| CR031 | Migration-led wins at DoorDash, Riskified, Booking.com, and Form3 show strong product value, but they also imply longer implementation cycles and a heavier need for solution engineering. | High | SR036, SR033, SR035, SR031 |
| CR032 | The combination of support-heavy accounts, regulated workloads, and complex topologies can pressure gross margin if service intensity rises faster than automation. | Medium | SR030, SR034, SR033, SR027 |
| CR033 | Cockroach markets portability, but many public stories still rely on major cloud primitives or managed Kubernetes offerings, so multi-cloud value does not eliminate dependency on hyperscaler economics and outages. | Medium | SR031, SR030, SR011 |
| CR034 | Independent critique emphasizes hidden implementation and optimization costs, supporting the idea that total cost of ownership can be harder than headline pricing suggests. | Medium | SR021, SR003 |
| CR035 | TrustRadius provides only thin independent review depth versus the richness of vendor case studies, leaving external validation of pain points and renewal sentiment underdeveloped. | Low | SR022, SR002 |
| CR036 | Public sources do not disclose current NRR, GRR, customer concentration, burn, or runway, which limits precise risk weighting across commercial, financial, and support dimensions. | Medium | SR027, SR028, SR029 |
| CR037 | Private-company opacity is especially important in this case because many visible strengths—high-quality customers, portability, and resilience—could still mask uneven margin, concentration, or support-cost realities. | Medium | SR027, SR034, SR030, SR031 |
| CR038 | The strongest mitigations are visible and practical: use supported releases, patch aggressively, design topology carefully, validate backups, and test workloads for hotspots before scale forces a redesign. | High | SR008, SR009, SR010, SR013 |
| CR039 | The clearest kill criteria would be evidence of weak renewal economics, major unresolved customer concentration, or a pattern of severe correctness incidents in supported production releases. | Medium | SR006, SR027, SR028 |
| CR040 | Risk transmission is fast in this business: a serious data-integrity event can hit trust, renewals, support load, and valuation simultaneously because the database sits directly inside customer revenue workflows. | High | SR006, SR033, SR035, SR034 |
| CR041 | Competition, complexity, and support intensity are linked risks rather than separate ones: if Cockroach is only clearly superior in the hardest workloads, customer acquisition may remain selective and expensive. | Medium | SR026, SR024, SR021, SR036 |
| CR042 | The best overall risk verdict is that Cockroach Labs’ principal threats are execution and operational-discipline risks rather than existential product disbelief: the product is credible, but the company must keep complex deployments safe, supportable, and economically attractive against simpler alternatives. | High | SR006, SR008, SR016, SR026, SR024, SR030 |
| CV001 | Cockroach Labs raised $278 million in Series F financing in December 2021 at a $5 billion valuation. | High | SV003, SV004 |
| CV002 | The 2021 financing disclosure said lifetime funding had reached $633 million at that point. | High | SV003, SV004 |
| CV003 | Third-party sources in mid-2026 imply secondary-market valuation around $6.9 billion, roughly 38 percent above the last primary round. | High | SV008, SV009, SV010 |
| CV004 | Secondary-market price discovery can validate investor interest, but unlike a new primary round it does not inject fresh operating capital onto the balance sheet. | High | SV008, SV009, SV010 |
| CV005 | GetLatka’s 2023 $128.3 million revenue or ARR estimate remains the clearest public revenue anchor for Cockroach Labs. | Medium | SV006 |
| CV006 | GetLatka’s late-2025 headcount estimate around 715 employees supports the view that Cockroach is operating at meaningful late-stage scale with a substantial cost base. | Medium | SV006, SV007 |
| CV007 | The 2026 momentum release highlights AI-scale resilience, performance, and partner momentum but does not disclose current revenue, margin, or retention metrics. | Medium | SV005 |
| CV008 | At the 2021 $5 billion primary valuation and the 2023 $128.3 million revenue anchor, Cockroach Labs would have traded at about 39x revenue. | Medium | SV003, SV006 |
| CV009 | At the 2026 $6.9 billion secondary marker and the same $128.3 million revenue anchor, Cockroach Labs would imply about 53.8x revenue. | Medium | SV008, SV006 |
| CV010 | Even if Cockroach had reached $170 million of annualized revenue by 2025-2026, the 2021 primary price would still imply roughly 29.4x revenue. | Medium | SV003, SV006 |
| CV011 | At that same $170 million revenue test point, the 2026 $6.9 billion secondary valuation would still imply roughly 40.6x revenue. | Medium | SV008, SV006 |
| CV012 | Even at a more generous $200 million revenue test point, the 2026 secondary marker would still imply about 34.5x revenue. | Medium | SV008, SV006 |
| CV013 | MongoDB’s July 2026 market cap and TTM revenue imply about a 10.2x revenue multiple. | Medium | SV012, SV013 |
| CV014 | Confluent’s July 2026 market cap and TTM revenue imply about a 9.6x revenue multiple. | Medium | SV014, SV015 |
| CV015 | Snowflake’s July 2026 market cap and TTM revenue imply about a 19.9x revenue multiple, representing a premium upper bound for public data-infrastructure software. | Medium | SV016, SV017 |
| CV016 | Elastic’s July 2026 market cap and TTM revenue imply about a 3.9x revenue multiple, illustrating how sharply mature infrastructure multiples can compress. | Medium | SV018, SV019 |
| CV017 | The public comp range from roughly 3.9x to 19.9x suggests that Cockroach’s implied private-market multiple is rich versus current public software infrastructure benchmarks. | Medium | SV012, SV013, SV014, SV015, SV016, SV017, SV018, SV019 |
| CV018 | For a $6.9 billion valuation to look merely Snowflake-like on a 19.9x multiple, Cockroach would need roughly $347 million of annual revenue. | Medium | SV016, SV017, SV008 |
| CV019 | For a $6.9 billion valuation to look MongoDB-like on a 10.2x multiple, Cockroach would need roughly $677 million of annual revenue. | Medium | SV012, SV013, SV008 |
| CV020 | Those thresholds are materially above the last public Cockroach revenue anchor, which is why the current valuation debate turns more on hidden growth and retention quality than on visible numbers. | Medium | SV006, SV008, SV016, SV012 |
| CV021 | Premium customer proof from DoorDash, Netflix, Route, Riskified, Form3, and Hard Rock supports paying more than a generic database-software multiple. | High | SV024, SV025, SV026, SV027, SV028, SV029 |
| CV022 | The product and customer evidence together support a premium to lower-quality infrastructure names because Cockroach sits in mission-critical, high-switching-cost operational systems. | Medium | SV024, SV003, SV025, SV026 |
| CV023 | The main anti-thesis is not lack of product credibility but valuation fullness: public data does not yet prove enough revenue, margin, or retention quality to justify a 30x-plus revenue profile with confidence. | Medium | SV006, SV008, SV020 |
| CV024 | Independent market data frames the distributed-database segment at roughly $4.48 billion in 2026, which makes a $6.9 billion private valuation look aggressive if the company is underwritten only against a narrow category framing. | Low | SV021 |
| CV025 | Broader cloud-database and distributed-SQL market reports indicate that category framing matters enormously; a narrow distributed-database lens is less forgiving than a broad cloud-data-infrastructure lens. | Medium | SV022, SV023, SV021 |
| CV026 | AI-era positioning and partner momentum can help preserve valuation narrative, but without updated financials they do not by themselves de-risk the entry price. | Medium | SV005, SV008 |
| CV027 | Historical growth quality did support a premium earlier: the Series F materials said ARR had tripled year over year and cloud revenue had risen 500 percent in the prior quarter. | High | SV003, SV004 |
| CV028 | The same materials said Cockroach had more than 200 customers and that more than half were already on Dedicated, which supports the idea of improving revenue quality entering 2022. | High | SV003, SV004 |
| CV029 | MongoDB’s 10-K illustrates the level of disclosure a mature public database company provides around revenue, risk, and operations—detail that Cockroach does not yet provide publicly. | Medium | SV020, SV006, SV005 |
| CV030 | Because Cockroach remains private and opaque, the valuation case depends unusually heavily on inference from customer quality, category positioning, and secondary price signals. | Medium | SV006, SV008, SV024 |
| CV031 | Support intensity, migration-heavy sales, and operational complexity deserve some discount versus cleaner self-serve software stories, even if the absolute product quality is high. | Medium | SV025, SV026, SV029, SV030 |
| CV032 | Competition from free PostgreSQL and managed cloud databases also limits how much multiple expansion an investor should assume without evidence of exceptional net retention or margin structure. | Medium | SV031, SV002, SV020 |
| CV033 | A defensible bull case requires Cockroach to show materially higher current revenue than the 2023 public anchor, continued premium customer wins, and evidence that support intensity does not overwhelm economics. | Medium | SV006, SV024, SV025, SV026 |
| CV034 | A defensible bear case is that Cockroach remains a high-quality product with a rich secondary price but insufficient public proof of scale to justify paying above high-teens infrastructure multiples. | Medium | SV008, SV006, SV018, SV019 |
| CV035 | The base case is neither collapse nor euphoria: a high-quality infrastructure company that likely deserves a premium to average software names, but not a blind premium to the best public franchises. | Medium | SV012, SV016, SV024, SV006 |
| CV036 | A reasonable low/base/high valuation frame today is roughly $3.0-4.5B bear, $4.8-6.2B base, and $6.5-8.0B bull, with the current secondary marker sitting in the upper end of what can be defended publicly. | Medium | SV008, SV006, SV016, SV018 |
| CV037 | That range means the $5B primary round can still be defended as strategic late-2021 pricing, but the 2026 secondary marker already prices in meaningful positive hidden information. | Medium | SV003, SV008, SV006 |
| CV038 | The recommendation implied by public evidence is not “avoid the company”; it is “continue diligence, but treat current pricing as full unless private data materially improves the revenue and efficiency picture.” | High | SV024, SV006, SV008, SV020 |
| CV039 | The stance becomes more bullish if diligence confirms revenue well above $200 million, strong net retention, credible margin structure, and limited concentration. | Medium | SV006, SV020, SV008 |
| CV040 | The thesis breaks if hidden data instead shows weak renewal economics, customer concentration, support-heavy gross margin drag, or slower-than-assumed revenue scaling. | Medium | SV006, SV020, SV030 |
| CV041 | The most important diligence asks are current ARR or revenue, NRR and GRR, gross margin, support-cost intensity, cash runway, and customer concentration. | Medium | SV006, SV005, SV020 |
| CV042 | The best valuation stance is that Cockroach Labs is a high-quality late-stage infrastructure asset priced at a demanding level; the company is attractive, but the current public evidence does not make the current secondary price look clearly cheap. | High | SV008, SV006, SV024, SV012, SV016 |