Observability — Digital Experience Monitoring

Embrace
User-Focused Observability

The acquisition was announced Jul 21, 2026 and closed Thursday, Aug 27, 2026; deal value was not disclosed. Embrace brings high-fidelity Real User Monitoring for mobile and web, built on OpenTelemetry. Paired with the organically built Synthetics capability, it extends the Palo Alto Networks Observability platform into Digital Experience Monitoring.

Observability Platform → ITOps Compete
Aug 27, 2026
Closed (value undisclosed)
100%
Mobile sessions captured
OTel
Open standard, no lock-in
DEM
New platform surface

Acquisition

The Acquisition — What Actually Closed

Announced Jul 21, 2026. Closed Aug 27, 2026. Value undisclosed. The site's earlier "not yet closed" guidance is retired — you can talk about this as part of the platform now.

Palo Alto Networks announced its intent to acquire Embrace — legally Embrace Mobile, Inc. — on Jul 21, 2026, describing it as a leading provider of user-focused observability. The deal was subject to customary closing conditions and guided to close in fiscal Q1 2027. It closed early, on Thursday, Aug 27, 2026. No purchase price or financial terms were disclosed — and unlike Koi, there is no credible press-reported number to fall back on, so do not offer one.

Two things were announced together, and they are different in kind. Embrace is the acquired Real User Monitoring (RUM) technology for mobile and web. Synthetics is a new capability Palo Alto Networks built organically with the Autonomous Digital Experience Management (ADEM) team, using the company's globally distributed infrastructure to proactively validate application availability and performance from strategic locations worldwide. Together — real users plus synthetic probes — they extend the Observability platform from infrastructure and backend monitoring into Digital Experience Monitoring.

This is the second observability acquisition in eight months, following Chronosphere ($3.35B, closed Jan 29, 2026). The Observability business surpassed $300M ARR in Q3 FY26, and Palo Alto Networks was named a Leader in the Gartner Magic Quadrant for Observability Platforms for the third consecutive year, with the top ranking for Observability Cost Control in the 2026 Gartner Critical Capabilities report (Palo Alto Networks press release).

“To truly understand how their applications are performing, organizations need to see the whole picture — from the moment a user taps or clicks to what exactly happens on the backend. By combining Palo Alto Networks' leading Observability platform with Embrace's innovative Real User Monitoring and the organically developed Synthetic Monitoring capabilities, we'll deliver exactly that. And we're taking it a step further — by linking these capabilities with Cortex AgentiX, organizations will be able to both see and automatically fix issues across their ecosystem. This is what true platformization looks like in practice.”

Lee Klarich — Chief Product & Technology Officer, Palo Alto Networks

Say it right. The umbrella term remains the Palo Alto Networks Observability platform — there is no product called "Cortex Observability", and Embrace is not a Cortex SKU. Embrace keeps its own name in market. Synthetics is organic ADEM-built work, not part of the acquisition — do not credit it to Embrace. And no price was disclosed: if asked, say undisclosed.

Mechanics

How Embrace Works

Auto-instrument the client, capture every session, emit it as OpenTelemetry, and stitch it to the backend trace. That chain is the whole product.

Step 1

Auto-instrument the client

An SDK drops into the app — iOS, Android, React Native, Unity, Flutter for mobile, and a browser agent for web. Instrumentation is automatic: no hand-written spans required to start collecting crashes, ANRs, network calls and performance metrics.

Step 2

Capture 100% of sessions

Not sampled. Every mobile user session is recorded as a session timeline — taps, swipes, clicks, view transitions, network requests, custom events and errors, in order, with full technical context to reproduce the issue.

Step 3

Detect what users feel

Crashes with full user context, ANR detection starting at 1 second, network failures on every API call, JavaScript errors on web, and Core Web Vitals with session context — scored by user and revenue impact rather than raw technical thresholds.

Step 4

Emit as OpenTelemetry

Telemetry leaves the client in OTel format, not a proprietary wire protocol. Embrace is the only frontend-focused vendor in the CNCF. Customers own the data and can route it where they want.

Step 5

Stitch to the backend

Network Spans Forwarding connects a client-side network request to the backend trace in one click — into Chronosphere, Grafana, Honeycomb, Elastic or Datadog. The tap and the failing service call land in the same trace.

Step 6

Alert, dashboard, and query with AI

Impact-based alerting, custom dashboards that mix technical metrics with business KPIs, natural-language filtering in the UI, and an Embrace MCP Server (GA) so agents and LLM workflows can query the data directly.

Capability detail

Mobile RUM
Embrace's core: the most comprehensive mobile monitoring in the market. 100% session capture, automatic instrumentation of crashes, ANRs, network issues and performance metrics, advanced crash reporting with full user context, session replay and user timelines, and network monitoring on all API calls.
Web RUM
Core Web Vitals with session context, user-journey tracking across the whole application, JavaScript error tracking and debugging, custom metrics and business-KPI correlation, and cross-platform journey correlation so a web-to-app handoff stays one story.
ANR detection from 1 second
Application Not Responding events are the most common mobile experience failure that never shows up as a crash. Embrace claims industry-leading detection starting at a 1-second threshold, so short freezes users notice are still captured.
OpenTelemetry-native, CNCF
Built on open standards rather than a proprietary agent format. Embrace positions itself as 100% committed to open, composable observability — no black boxes, no lock-in, customers own their data and can integrate it anywhere.
Network Spans Forwarding
The integration that makes frontend data useful to backend teams: one click connects client-side network requests to a backend observability platform. Existing published integrations include Chronosphere, Grafana, Honeycomb, Elastic and Datadog.
Embrace MCP Server — GA
Launched in beta and now generally available, it exposes Embrace data to AI workflows and agents. Together with the read-only Chronosphere MCP Server, this is the honest answer today when a customer asks how AI agents consume observability context.
SpeedCurve — web performance & synthetics
Embrace acquired SpeedCurve in November 2025, bringing a decade of web performance analytics, JavaScript performance analysis, synthetic testing and investment in WebPageTest. SpeedCurve's work helped define Core Web Vitals; named customers include the BBC, The Guardian, Forbes, Hyatt, Edmunds and Trivago.
Synthetics (organic, ADEM-built)
Not part of the acquisition. Built with the ADEM team on Palo Alto Networks' globally distributed infrastructure to proactively validate application availability and performance from strategic locations worldwide — the "before any user complains" half of Digital Experience Monitoring.

Background

Company Snapshot

Useful for the "who are these people" question from a technical evaluator. Funding and headcount figures are third-party profile data, not Palo Alto Networks disclosures.

Founded / HQ 2016 · Culver City, California
Funding Roughly $79.5M across five rounds — $2.5M seed (2017), $4.5M (2019), $7.5M Series A (2019), $45M Series B (Oct 2021), $20M (Jul 2023)
Investors New Enterprise Associates (NEA), Greycroft, AV8, Eniac, plus operator angels including founders from PagerDuty, Sendbird, LogDNA, Scopely and TestFlight
Scale 51–200 employees; more than 100 organizations on the platform
Named customers Publicly referenced Embrace customers include Hyatt, GOAT, Depop, Dave, ChowNow, TextNow, Cameo, Glo and Apprentice. Heavy concentration in consumer apps, mobile commerce, fintech and mobile gaming — where a bad session is directly lost revenue.
Tuck-in acquisition Acquired SpeedCurve (Nov 2025) for web performance monitoring and synthetics; terms undisclosed. Both product teams were retained.
Legal entity Embrace Mobile, Inc.

Platform Story

How It Fits the Palo Alto Networks Story

Read the stack top to bottom: the user's finger at the top, infrastructure at the bottom, autonomous action at the end. Embrace is the layer that was missing.

Embrace RUMAcquired · closed Aug 27, 2026
What the real end user actually experienced — every mobile and web session, every crash, freeze, failed API call and slow screen, with the session timeline to reproduce it. This is the layer Palo Alto Networks had no answer for before August.
SyntheticsOrganic · built with ADEM
Proactive probing of availability and performance from strategic locations across the globe, on infrastructure Palo Alto Networks already operates. Catches the outage at 2 a.m. when no real user is awake to generate a RUM session.
ADEMExisting · Prisma SASE
Autonomous Digital Experience Management already covers the employee experience path — device, network, SASE, application. Embrace covers the customer experience path. Same question, two very different populations, now under one platform narrative.
ChronosphereAcquired · $3.35B, Jan 29, 2026
Backend, application and infrastructure observability at cloud-native scale, plus the Temporal Knowledge Graph, AI Guided Troubleshooting and the Telemetry Pipeline with its real-time cost control. This is where a forwarded network span from Embrace lands and becomes a full trace.
Cortex XSIAMShipping integration
The Telemetry Pipeline's Cortex XSIAM destination plugin routes security-relevant data into the SOC while high-volume application logs stay where they are, with Federated Search reaching the rest. This is what makes "observability meets security" a shipped claim rather than a slide.
Cortex AgentiXStated direction · not GA
The end state Lee Klarich described: see the broken user experience, trace it to the cause, and have an agent fix it. Treat autonomous find-and-fix across observability as roadmap. Say so before a technical evaluator finds out.

Why Palo Alto Networks is buying observability at all

The strategic logic is the same one behind the Chronosphere deal, extended one layer outward. Security operations and IT operations consume overlapping telemetry, buy from overlapping budgets, and are both being reorganized around AI agents. Owning observability gives Palo Alto Networks the "what is happening" data plane next to its existing "is it safe" data plane — and a second, non-security reason to be in the ITOps buying conversation.

Embrace specifically fixes a gap that was awkward to defend in a competitive evaluation: Chronosphere is excellent from the load balancer inward, but a customer whose complaint is "our app feels slow and we don't know why" was a Datadog or Dynatrace conversation. RUM plus Synthetics closes it, and the DEM framing is what makes the platform comparable to full-suite incumbents rather than a best-of-breed backend tool.

The platformization argument, in one line

Most enterprises pay separately for mobile crash reporting, web performance monitoring, synthetic checks, APM, log analytics and a SIEM — six tools, six contracts, six data silos, and still nobody can trace a customer's abandoned checkout to the service that failed. The Observability platform now covers user experience, proactive validation, backend software and infrastructure in one place, on open standards, with cost control ranked first by Gartner. That is the whole pitch. Fund the move with the consolidation savings, not with a new budget line.

Credibility Check

Shipping vs Roadmap

Say the boundary out loud. The deal closed four days ago as of the start of September — nobody expects a finished merged product, and pretending otherwise is the fastest way to lose a technical evaluator.

Available today

Embrace, as Embrace

The product is real, GA, and buyable — Mobile RUM, Web RUM, session timelines, crash and ANR detection, network monitoring, alerting, dashboards, the MCP Server and SpeedCurve's synthetics. It works standalone and integrates with Chronosphere, Grafana, Honeycomb, Elastic and Datadog via OpenTelemetry.

Sell it: This is not vaporware or a roadmap slide. If the customer's pain is mobile experience, you can start the conversation on the product as it exists today.
Not yet published

Merged console, packaging and SKUs

Palo Alto Networks has not published a unified Observability + Embrace console experience, a combined SKU structure, migration path for existing Embrace contracts, or a date for either. Treat pricing, bundling and single-pane-of-glass questions as open and route them through your Palo Alto contact.

Sell it: Do not invent packaging. "Closed last week, packaging guidance is coming" is a credible answer; a made-up bundle is a lost deal later.
Roadmap

Cortex AgentiX auto-remediation

The "see it and automatically fix it" story is a stated direction in the announcement, and the deep Chronosphere–AgentiX integration was already flagged as planned rather than GA. The working agent paths today are the read-only Chronosphere MCP Server and the Embrace MCP Server.

Sell it: Offer the MCP servers as the concrete answer, then position AgentiX auto-remediation as the reason to pick this platform for the next three years.
Naming

No "Cortex Observability"

The umbrella is the Palo Alto Networks Observability platform. Chronosphere retains its brand, Embrace retains its brand, and Synthetics is an ADEM-built capability. Digital Experience Monitoring (DEM) is the category label for RUM plus Synthetics — do not turn it into a product name either.

Sell it: Getting names right is cheap credibility with an ITOps buyer who already knows this market better than the security buyer does.

Competitive Positioning

Compete — What to Know

RUM is a mature market with entrenched incumbents. Embrace wins on mobile depth, open standards and cost — not on breadth of a single suite. Full domain detail on the ITOps & Observability page.

vs. Datadog RUM & Synthetics

Where we win: Mobile depth — 100% session capture rather than sampling, ANR detection from 1 second, and instrumentation built by and for mobile engineers rather than bolted onto an APM suite. OpenTelemetry-native with customer-owned data, against a proprietary agent estate. And the cost argument is the strongest card in the whole deck: Gartner ranked the platform first for Observability Cost Control in 2026, with customers averaging 89% data-volume optimization.

Where to be careful: Datadog ships one console covering RUM, synthetics, APM, logs and security today. Our equivalent single-pane experience is not published yet. If the customer's primary criterion is "one UI this quarter," concede it and fight on cost trajectory and lock-in instead.

vs. Dynatrace / New Relic

Where we win: Both are strong in enterprise APM and weaker in modern mobile-native experience data. Embrace's frontend-first design plus Chronosphere's schema-agnostic Temporal Knowledge Graph handles heavily custom instrumentation that assumes-a-schema tooling struggles with. Consumption-model transparency is also a live grievance in both installed bases.

Where to be careful: Deep mainframe, .NET and legacy Java estates favour Dynatrace's agent maturity. Do not position DEM as a replacement for that footprint — position it as the customer-experience layer on top.

vs. Sentry, Firebase Crashlytics and other crash tools

Where we win: A crash tool tells you the app died. It does not tell you the user rage-tapped a frozen checkout for eight seconds, watched two API calls time out, and abandoned the cart without ever crashing. Full-session context, ANR-class detection and backend trace linkage are the difference, and Crashlytics is free precisely because it stops there.

Where to be careful: "We already have Crashlytics and it's free" is the most common objection. Do not argue features — ask what percentage of their user-reported issues ever produced a crash report. The gap between that number and 100% is the deal.

vs. doing nothing

The most common real competitor. Mobile and web experience quality is usually owned by an engineering team with no observability budget, measured only by app-store reviews and support tickets. The opening is not a product comparison — it is asking who currently owns the answer when a revenue-generating app is slow, and how long it takes them to get it. In many accounts the honest answer is nobody and days.

Buyer Profile

Who Buys It, and When

Note the buying centre shift: this is usually not the CISO. Expect VP Engineering, Head of Mobile, SRE or platform leadership, with digital or e-commerce leadership as the economic sponsor when revenue is tied to the app.

  • Revenue runs through a mobile app or transactional website — retail, travel, food delivery, fintech, mobile gaming, ticketing. A bad session is a lost order.
  • The customer already has Chronosphere and someone asks "what about the frontend?" — this is the natural expansion motion inside the installed base.
  • Engineering is spending days chasing an issue that reproduces only on certain devices, OS versions or networks, with no session-level evidence to work from.
  • App-store ratings or support-ticket volume are moving in the wrong direction and nobody can attribute the cause to a release, commit or backend service.
  • A Datadog, Dynatrace or New Relic renewal is approaching and the consumption bill has become a board-level line item.
  • The team is standardizing on OpenTelemetry and wants to avoid another proprietary agent estate.
  • Mobile and backend teams are blaming each other with no shared data — Network Spans Forwarding is the specific fix for that political problem.
  • A high-stakes event is coming — Black Friday, a launch, a live sports or ticketing window — and the current answer to "will it hold" is a guess.

Pre-Sales

Scoping Checklist

Collect these before asking for pricing guidance. Packaging under Palo Alto Networks is not published yet, so the sizing conversation runs through your Palo Alto contact.

App Inventory — How many mobile apps and web properties are in scope, and which are revenue-generating versus internal.
Monthly Active Users / Sessions — MAU and session volume per app. This is the primary sizing dimension for RUM in every vendor's model.
Platforms & Frameworks — iOS, Android, React Native, Unity, Flutter, web. Confirms SDK coverage and instrumentation effort.
Incumbent Tooling — Crashlytics, Sentry, Datadog RUM, Dynatrace, New Relic, Instabug or nothing. Capture contract value and renewal date — that date sets the deal clock.
Backend Observability Estate — Whether Chronosphere is already in place, and what else would receive forwarded network spans (Grafana, Honeycomb, Elastic, Datadog).
OpenTelemetry Maturity — Whether the customer has standardized on OTel. If yes, the open-standards argument does most of the selling.
Synthetics Requirement — Number of critical user journeys and geographies to probe proactively, plus any existing synthetic-monitoring contract to displace.
ADEM Overlap — Whether Prisma SASE and ADEM are deployed for employee experience. Determines whether this is one DEM story or two separate conversations.
Data Residency & Privacy — Session capture touches user-behaviour data. Confirm regional storage requirements, retention limits, PII masking rules and who signs off — expect privacy and legal review.
Release Cadence & SDK Approval — How often the app ships and who approves a new SDK in the mobile build. This is the real deployment constraint, not effort.
Buying Centre & Budget — Which team owns the budget: engineering, ITOps, digital or security. This deal usually does not sit in the security line.
Existing Embrace Contract — If the customer is already an Embrace or SpeedCurve customer, note the term and renewal. Migration and co-term guidance is not yet published.

Customer Conversation

Discovery Questions

Open with experience and revenue, not with telemetry. The person who owns the app cares about users abandoning, not about spans.

1

When a customer says your app is slow or broken, how do you find out — and how long does it take you to see what they actually experienced?

2

What percentage of your user-reported issues ever produced a crash report? Everything in the gap is invisible to a crash tool.

3

Do you measure app freezes and ANRs, or only hard crashes? What threshold are you catching them at?

4

Are you sampling sessions or capturing all of them? When the incident is intermittent, which sessions did you not keep?

5

When a mobile issue traces back to a backend service, how do your mobile and platform teams share evidence today?

6

Can you tie a performance regression to a specific release, commit or app version — and how fast did you do it the last time it mattered?

7

Who owns the number that connects app performance to conversion or revenue? Does anyone report it to the business?

8

Have you standardized on OpenTelemetry? How much of your current observability spend is locked into proprietary agents?

9

What is your observability bill this year versus last, and did anyone forecast that increase?

10

Do you validate critical user journeys proactively from outside your network, or do you learn about outages from users?

11

You already run Chronosphere for the backend — who is answering the same questions for the frontend?

12

When a root cause is identified, who fixes it and how long does the handoff take? That is where the AgentiX direction becomes relevant.

Verify It

Sources

Everything on this page traces to one of these. Funding and headcount figures come from third-party profile data, not company disclosures.

Palo Alto Networks — press release, Jul 21, 2026

Primary source. Announcement of intent, strategic rationale, Synthetics as organic ADEM work, the Lee Klarich quote, the $300M+ Observability ARR and Gartner positions, and the update confirming the deal closed Thursday, Aug 27, 2026.

Palo Alto Networks Investor Relations — same release

Investor-relations copy carrying the close-date update. Use this version when an evaluator wants an IR-hosted source.

Embrace — product documentation

Capability detail: 100% session capture, automatic instrumentation, ANR detection from 1 second, session replay and timelines, network monitoring, Web RUM and Core Web Vitals, platform support, and Network Spans Forwarding.

Embrace — company site

OpenTelemetry and CNCF positioning, the open/composable observability stance, MCP Server GA, natural-language filtering, and customer testimonials.

Embrace — SpeedCurve joins Embrace (Nov 2025)

The SpeedCurve tuck-in: web performance analytics, synthetics, WebPageTest, Core Web Vitals lineage, and named SpeedCurve customers.

Embrace — $45M Series B (Oct 2021)

Investor list including NEA, Greycroft, AV8 and Eniac, the 100+ organizations figure, and named customers Hyatt, GOAT, Depop, Dave, ChowNow, TextNow, Cameo, Glo and Apprentice.

Parsers VC — Embrace company profile

Third-party profile data: founded 2016, Culver City HQ, ~$79.5M total funding across five rounds, 51–200 employees. Not a company disclosure — attribute it if challenged.

MarketScreener — transaction record

Confirms the legal entity name, Embrace Mobile, Inc., and the fiscal Q1 2027 close guidance the deal beat.