Headquartered in United StatesHeadquarters countrySourced only from this vendor's own published headquarters address (schema.org structured data on their site) — never guessed from domain TLD. Source ↗
Trust profileHow to read thisFive separate questions a buyer actually asks, each answered with its own evidence and a link to the source. There is deliberately no overall score: a single number invites comparison it cannot support, and would mostly reflect how much of Palo Alto Networks we have managed to scan rather than anything about the vendor.
Not checked means we have not looked yet, and is never counted against a vendor. Limited means we did look, but found only one line of evidence — enough to report, not enough to corroborate.
checked 11 of 16 signals
Limited
Independently verified
Has anyone other than the vendor confirmed this?
checked 3 of 4
Nothing here has been confirmed by an independent third party yet.
No third-party certifications found
Profile not claimed by the vendor
Strong
Operating durability
Is this a real, durable business?
checked 3 of 4
How long this vendor has been operating, and who stands behind them.
Domain registered 2005 — 21 years ago
Headquarters: United States
1 public SEC filing(s) — financials are a matter of record
Mixed
Behaviour under stress
What do they do when something goes wrong?
checked 2 of 3
What their public record shows about handling vulnerabilities and outages.
100 published CVE(s) — a public disclosure record exists
10 rated critical
No public status page found
Limited
Disclosure posture
Do they tell you the awkward things unprompted?
checked 2 of 3
How much this vendor volunteers before you have to ask.
No trust center found
No bug bounty or vulnerability disclosure policy found
Data coverage: 20/100What this measures (and doesn't)
Not a quality rating or endorsement — a measure of how much verified, disclosed data we actually have about this vendor. A low score usually means "we don't have much verified information yet," not "this is a bad vendor." Never used to sort or rank vendor lists.
The platform admin controls the formula's weights.
Data coverage profileHow to read thisThe same four components behind the data coverage score above, shaped instead of listed — a vendor strong on verification but thin on buyer feedback looks visibly different from one that's the other way around. Security and feedback plot at the neutral midpoint (50) when there's no data yet (no products tracked, no reviews), matching how the actual score itself treats missing data — not a guess either way.
IntegrationsUI-12 — integration graphDetected from this vendor's own published integration/partner pages by the enrichment loop — each entry links the exact page it was found on. Directional: "integrates with" is claimed by this vendor; "integrated by" is claimed by the other vendor's site. Coverage grows as the scan progresses.
Buyer reviewsUI-14 — verified-buyer reviewsWritten only by domain-verified buyers at other companies, attributed to their company domain (never their identity), and moderated. Buyer-sourced opinion, clearly separate from the neutral catalog facts above — and never an input to search or comparison ordering.
verified buyers only
No buyer reviews yet.
Reputation ratingUI-20 — anonymous ratingA single anonymous 5-star signal from buyers, resellers, and analysts who've engaged with this vendor — separate from the domain-attributed reviews above. No rater identity is ever shown, not even at company level.
anonymous
No ratings in this window yet.
External ratingsUI-22 — third-party ratingsAggregate rating and review count pulled directly from the source site's own published data — never the review text itself, which belongs to that site. Links go to the real page so you can read the actual reviews there.
Security & trust signalsAbout these signalsCertifications are keyword-matched from the vendor's own public pages (each claim links to its source — verify directly before relying on it). Security headers are checked live against the vendor's homepage, re-checked every 90 days. Both are independent, automated signals, not a vendor-submitted or audited claim, and are not blended into a single score.
9 of 9 technical checks completed — not a score, just coverage
CVE severity over timeUI-24 — CVE severity timelineEvery known CVE with a disclosure date and severity, plotted by when it was published — lets you see whether disclosures are trending toward more or less severe, not just a raw count. Same NVD-sourced, name-matched data as the list below.
Known CVEs (100)About this listSourced from the public NVD database, matched by vendor name. This is a name-based match, not exact version tracking — always check the linked NVD record for affected versions before drawing conclusions. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.
A local privilege escalation vulnerability exists in Palo Alto Networks Cortex XDR Agent on the Windows platform that allows an authenticated local Windows user to execute programs with SYSTEM privile…
An authentication bypass vulnerability exists in the GlobalProtect SSL VPN component of Palo Alto Networks PAN-OS software that allows an attacker to bypass all client certificate checks with an inval…
An information exposure through log file vulnerability exists where the password for the configured system proxy server for a PAN-OS appliance may be displayed in cleartext when using the CLI in Palo …
An information exposure vulnerability exists in Palo Alto Networks Panorama software that discloses the token for the Panorama web interface administrator's session to a managed device when the Panora…
An information exposure through log file vulnerability where an administrator's password or other sensitive information may be logged in cleartext while using the CLI in Palo Alto Networks PAN-OS soft…
An information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Palo Alto Networks PAN-OS software when the after-change-detail c…
An insecure configuration of the appweb daemon of Palo Alto Networks PAN-OS 8.1 allows a remote unauthenticated user to send a specifically crafted request to the device that causes the appweb service…
An uncontrolled resource consumption vulnerability in Palo Alto Networks PAN-OS allows for a remote unauthenticated user to upload temporary files through the management web interface that are not pro…
When SSL/TLS Forward Proxy Decryption mode has been configured to decrypt the web transactions, the PAN-OS URL filtering feature inspects the HTTP Host and URL path headers for policy enforcement on t…
When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled (unchecked), improper verification of signatures in PAN-OS …
When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can disclose the pre-logon authentication cookie to a man-in-the-middle attacker on th…
A race condition vulnerability Palo Alto Networks GlobalProtect app on Windows allows a local limited Windows user to execute programs with SYSTEM privileges. This issue can be exploited only while pe…
A cleartext transmission of sensitive information vulnerability in Palo Alto Networks PAN-OS Panorama that discloses an authenticated PAN-OS administrator's PAN-OS session cookie. When an administrato…
Improper restriction of XML external entity reference ('XXE') vulnerability in Palo Alto Networks Panorama management service allows remote unauthenticated attackers with network access to the Panoram…
An improper input validation vulnerability in the configuration daemon of Palo Alto Networks PAN-OS Panorama allows for a remote unauthenticated user to send a specifically crafted registration reques…
An external control of filename vulnerability in the SD WAN component of Palo Alto Networks PAN-OS Panorama allows an authenticated administrator to send a request that results in the creation and wri…
An OS command injection and external control of filename vulnerability in Palo Alto Networks PAN-OS allows authenticated administrators to execute code with root privileges or delete arbitrary system …
A cross-site scripting (XSS) vulnerability exists when visiting malicious websites with the Palo Alto Networks GlobalProtect Clientless VPN that can compromise the user's active session. This issue af…
Under certain circumstances a user's password may be logged in cleartext in the PanGPS.log diagnostic file when logs are collected for troubleshooting on GlobalProtect app (also known as GlobalProtect…
An authentication bypass by spoofing vulnerability exists in the authentication daemon and User-ID components of Palo Alto Networks PAN-OS by failing to verify the integrity of the Kerberos key distri…
…and 80 more
Resources & materials (4)
discovered on their site
Datasheets, whitepapers, and case studies found on paloaltonetworks.com by the enrichment loop. Links open the original documents on the vendor's own site.
Drawn from this vendor's own public materials and authored to keep category questionnaires balanced. Gaps reflect capabilities not emphasized in public materials, not rankings.
Strengths: Cortex XDR correlates endpoint, network, and cloud telemetry with strong analytics and automation.
Gaps:Positioned as an XDR suite; standalone endpoint-only EDR specifics are emphasized less than the broader platform.
Products (35)
Endpoint Detection & Response
3
Cortex XDREDR/XDRAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →
Extended detection and response.
Palo Alto Networks Cortex XDRAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
AI-driven XDR platform for endpoint security with threat prevention and detection
Palo Alto Networks Cortex XSIAMAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
Cortex XSIAMSIEMAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →
AI-driven security operations / SIEM.
Network Firewall (NGFW)
5
Palo Alto Networks Advanced URL FilteringAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
Real-time web threat prevention using ML/DL for URL filtering and phishing
Palo Alto Networks PA-7500AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
Enterprise-scale ML-powered NGFW for data centers and service providers
Palo Alto Networks Software FirewallsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
Software firewalls for multicloud workload protection with Layer 7 threat prevention
Palo Alto Networks Strata Cloud ManagerAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
Palo Alto Networks Strata Network Security PlatformAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
AI-powered network security platform with unified firewall and SASE capabilities
Palo Alto Networks Cortex XSOARAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
SOAR platform for orchestrating security products and automating SOC workflows
Managed Detection & Response (MDR)
2
Palo Alto Networks Unit 42 Managed Detection & ResponseAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
24/7 MDR service built on Cortex XDR with threat hunting and remediation
Palo Alto Networks Unit 42 Managed XSIAMAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
24/7 managed SOC service combining Cortex XSIAM platform with Unit 42 expertise
Attack Surface Management (ASM)
1
Palo Alto Networks Cortex XpanseAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
Active attack surface mgmt solution for discovering & remediating unknown risks
Cloud-Native Application Protection (CNAPP)
3
Palo Alto Networks Cortex Cloud Runtime SecurityAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
Real-time cloud workload protection for VMs, containers, K8s & serverless
Palo Alto Networks Prisma CloudAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
Code to cloud security platform for app lifecycle protection
Prisma CloudCNAPPAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →
Cloud-native application protection platform.
Secure Access Service Edge (SASE/SSE)
6
Palo Alto Networks Prisma AccessAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
Cloud-delivered SASE solution securing users, apps, devices, and data everywhere
Palo Alto Networks Prisma SASEAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
AI-powered SASE platform for securing hybrid workforce and branch networks
Palo Alto Networks Prisma SASE App AccelerationAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
App acceleration for SASE reducing latency and improving performance up to 5x
Palo Alto Networks Prisma SD-WANAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
SD-WAN solution integrated with SASE for branch connectivity and security
Palo Alto Networks SD-WAN for NGFWAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
SD-WAN capabilities integrated with Palo Alto Networks NGFWs
Prisma AccessSASEAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →
Cloud-delivered SASE.
Identity & Access Management
1
IdiraAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
Palo Alto Networks platform securing human, machine, and AI agent identities.
Vulnerability Management
1
Cortex XpanseASMAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →
Attack surface management.
AI / LLM Security
3
Palo Alto Networks AI Access SecurityAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
Secures GenAI app usage with visibility, data protection, and threat defense
Palo Alto Networks Cortex AgentiXAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
Agentic AI platform for building, deploying & governing AI agent workforce
Palo Alto Networks Prisma AIRSAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
Platform securing AI apps, agents, models & data across development lifecycle
Enterprise Browser Security
2
Palo Alto Networks Prisma BrowserAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
SASE-native secure browser for managed and unmanaged devices with data protection
Palo Alto Networks Remote Browser IsolationAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
Remote browser isolation tech protecting against zero-day web threats
Data Loss Prevention
1
Palo Alto Networks Enterprise Data Loss PreventionAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
Enterprise DLP solution protecting sensitive data across networks, clouds, and endpoints
Intrusion Detection and Prevention Systems
2
Palo Alto Networks Advanced DNS SecurityAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
DNS security service that blocks DNS-layer threats in real time
Palo Alto Networks Advanced Threat PreventionAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
IPS with inline AI models to block zero-day exploits and C2 attacks in real time
Medical Device Security
1
Palo Alto Networks Medical Device SecurityAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
Secures medical devices with visibility, risk assessment, and policy enforcement
Cloud Access Security Broker
1
Palo Alto Networks Prisma Access SaaS SecurityAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
SASE-native CASB for SaaS app security, data protection, and threat prevention
Network Sandboxing
1
Palo Alto Networks Advanced WildFireAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
Cloud-based malware prevention engine using ML and sandboxing for file threats