Is CrowdStrike legit?
Short answer: yes, with one big asterisk you deserve to understand before you buy.
Last updated August 7, 2026
CrowdStrike is about as established as a security vendor gets: a Delaware-incorporated, NASDAQ-listed company (CRWD) founded in 2011, a Leader in the Gartner Magic Quadrant for Endpoint Protection seven consecutive times, with twelve SE Labs AAA ratings and ten straight AV-Comparatives awards. The asterisk is July 19, 2024, when a faulty update crashed ~8.5 million Windows machines worldwide, and the Delta lawsuit over it is still in court. Legitimate does not mean flawless; it means real, audited, accountable, and independently tested, and CrowdStrike is all four.
Affiliate disclosure: we earn a commission if you sign up for CrowdStrike through links on this page, at no extra cost to you. Competitor facts come from their own published pages and are date-stamped; the commission does not change the numbers. How we review →
The company, verified
CrowdStrike, Inc. was incorporated in Delaware in August 2011 (the holding company that November), founded by George Kurtz, Dmitri Alperovitch, and Gregg Marston, all ex-McAfee. Warburg Pincus incubated the company; Accel and Alphabet’s CapitalG invested before its June 2019 IPO, the largest pure-play cybersecurity IPO on record per PitchBook. It is remote-first with its designated headquarters in Austin, Texas, and files audited financials with the SEC every quarter.
The validation record
Independent scrutiny is where CrowdStrike is strongest: a Leader in the 2026 Gartner Magic Quadrant for Endpoint Protection (seventh consecutive), Customers’ Choice in the 2026 Gartner Peer Insights Voice of the Customer for both endpoint protection and MDR, a Leader in the 2025 Forrester Wave for MDR, twelve SE Labs AAA ratings since 2018 including 100% detection/protection/accuracy in the 2025 ransomware test, and ten consecutive AV-Comparatives awards. Platform compliance validations include SOC 2, PCI DSS v4.0, HIPAA, and NIST.
The 2024 outage, told straight
On July 19, 2024, a defective Falcon content update sent to Windows sensors caused boot loops on roughly 8.5 million machines: airlines grounded flights, hospitals postponed procedures, broadcasters went dark. It is arguably the largest IT outage ever caused by a security product. Delta Air Lines claims $550 million in losses and sued; in 2025 a Georgia judge ruled Delta’s gross-negligence and computer-trespass claims could proceed, including its allegation that the update was not tested before shipping. The case remains unresolved as we write this. CrowdStrike has since rebuilt its update pipeline with staged rollouts and customer-controlled deployment rings. Buyers should know both halves: the failure was severe and litigated, and the product’s independent test results afterward remain elite.
What the review platforms show
Across the business platforms we aggregate, CrowdStrike’s ratings are remarkably consistent: 4.7 on Gartner Peer Insights (3,108 ratings), 4.6 on G2, 9.0/10 on TrustRadius, 4.7 on Capterra. The outliers are consumer surfaces: Trustpilot (~2/5 across ~18 mostly post-outage reviews) and the Falcon mobile app (2.6 on Google Play). We publish the critical reviews alongside the praise; the pattern is a product professionals rate highly, a mobile app they do not, and a 2024 scar that shows up wherever angry one-off reviews collect.
The caveats that are actually true
From our review corpus, the legitimate knocks: pricing runs high and modules stack; the console takes real time to learn; support responsiveness is inconsistent; the platform is cloud-reliant, a poor fit for air-gapped environments; the mobile app is weak; and BBB accreditation, for whatever it is worth to a B2B software company, is absent. None of these are legitimacy problems. All of them are worth pricing into your decision.
FAQ
Is CrowdStrike a legitimate company?+
Yes. CrowdStrike Holdings, Inc. was incorporated in Delaware in 2011, has traded on NASDAQ as CRWD since June 2019, and protects a large share of the Fortune 500. It was founded by former McAfee executives George Kurtz (CEO) and Dmitri Alperovitch with Gregg Marston, and was backed pre-IPO by Warburg Pincus, Accel, and Alphabet’s CapitalG.
Why is CrowdStrike’s Trustpilot rating so low?+
CrowdStrike’s Trustpilot page holds roughly a 2-out-of-5 score across only about 18 reviews, most posted after the July 2024 outage. It is a tiny, event-driven sample compared to the thousands of verified business reviews on Gartner Peer Insights (4.7 across 3,108 ratings), G2 (4.6), and TrustRadius (9.0/10). We show both because honest context needs both.
What happened with the CrowdStrike outage in 2024?+
On July 19, 2024, a faulty Falcon content update crashed roughly 8.5 million Windows machines worldwide, grounding flights and disrupting hospitals and banks. Delta Air Lines sued, and in 2025 a Georgia court allowed its gross-negligence and computer-trespass claims to proceed; the litigation is unresolved as of August 2026. CrowdStrike overhauled its update deployment process afterward, and its independent test results since remain top-tier.
Is CrowdStrike BBB accredited?+
No. CrowdStrike has a BBB profile (Austin, TX) but is not BBB accredited. That is common for business-to-business software companies, which rarely pursue accreditation, and the profile carries almost no review volume either way.
Is my data safe with CrowdStrike?+
The Falcon platform carries third-party validations including SOC 2, PCI DSS v4.0, HIPAA, and NIST alignment, and the sensor is deployed across governments and most large enterprises. No vendor is beyond risk, and the 2024 outage proved operational risk is real, but on data handling and security certifications CrowdStrike meets the standards regulated buyers require.