A10 Networks: how traffic management became a cybersecurity and AI infrastructure business
Some technology companies are visible every time a consumer opens a laptop or picks up a phone. A10 Networks built its business in a less visible part of computing: the infrastructure sitting between users, applications and the networks carrying enormous volumes of traffic.
That position has changed dramatically since the company was founded in 2004.
A10 began by building technology designed to make application traffic move efficiently through data centres. It subsequently expanded into load balancing, carrier-grade networking, protection against distributed denial-of-service attacks, encrypted-traffic processing, web and API security and, more recently, infrastructure designed for artificial-intelligence workloads.
The progression is easier to understand as a response to one recurring problem: as internet traffic became larger, more encrypted, more distributed and more valuable, keeping that traffic available was no longer enough. It also had to be protected.
By 2026, A10 Networks was describing itself as a provider of secure application and network solutions rather than simply an application-delivery company. Its product portfolio still reflects its networking roots, but cybersecurity and AI infrastructure have become increasingly prominent parts of the story.
A10 started with application-aware networking
A10 Networks was founded in California in 2004 by Lee Chen.
Chen had spent years working in networking and technology before establishing A10. His earlier career included positions at companies including Apple Computer and Foundry Networks, as well as involvement in Centillion Networks.
A10’s own pre-IPO filings describe the company’s original purpose in relatively straightforward terms: it was created to build efficient, application-aware networking performance and security technology.
The company released its first product in 2005.
Its more recognisable application-delivery story began in 2007 with the introduction of the AX Series of Application Delivery Controllers, or ADCs.
An ADC sits in the path between users and application servers.
One of its jobs is load balancing. Instead of allowing every request to hit the same server, an ADC can distribute traffic across multiple systems. That can improve availability and prevent an individual server from becoming overwhelmed.
Modern application delivery involves considerably more than basic load balancing, but that underlying idea explains why the technology became important.
As online banking, ecommerce, software services and large internet platforms became more dependent on always-available applications, the equipment directing traffic into those applications became part of critical infrastructure.
Security arrived early in the AX era
A10 did not remain focused solely on application performance.
According to the company’s 2014 IPO filing, security capabilities were added to the AX Series in 2009.
The following year brought another important expansion.
In 2010, A10 extended the AX family with carrier-grade network address translation technology, commonly known as CGN or CGNAT.
CGNAT became important partly because the internet was running short of freely available IPv4 addresses.
An IPv4 address uses a 32-bit address space. As internet adoption exploded, the finite pool of addresses became increasingly constrained.
Carrier-grade NAT allows service providers to let multiple subscribers share public IPv4 addresses while maintaining the translations necessary to route their traffic correctly.
It is not a permanent replacement for IPv6, which provides a vastly larger address space, but CGNAT has become an important technology for providers managing the long transition between IPv4 and IPv6.
This moved A10 into infrastructure used not only inside enterprise data centres but also within large telecommunications and service-provider networks.
Thunder changed the product identity
A major product transition arrived in May 2013.
A10 launched the Thunder Series, combining application-delivery, networking and security functions on physical and virtual appliances built around the company’s ACOS software platform.
The company’s IPO documentation identified three major workloads at the time: Application Delivery Controllers, Carrier Grade Networking and a Threat Protection System designed to detect and mitigate large-scale distributed denial-of-service attacks.
The older AX family remained part of A10’s portfolio, but Thunder became the name increasingly associated with its major networking platforms.
The timing is significant.
By 2013, internet applications were becoming central to everyday business rather than supplementary services. Mobile traffic was growing, public cloud computing was expanding and organisations were exposing more services directly to the internet.
A traffic-management appliance therefore occupied a strategically useful position: it could see traffic travelling towards important applications and potentially apply both performance and security policies to it.
That overlap between networking and security would become increasingly important to A10’s later strategy.
A10 entered the New York Stock Exchange in 2014
A10 Networks became a publicly traded company in March 2014.
The company sold shares in its initial public offering at $15 each. Its common stock began trading on the New York Stock Exchange under the ticker ATEN on 21 March 2014.
A10’s filings show that 12.5 million shares were initially sold in the offering, including nine million shares sold by the company and 3.5 million sold by existing shareholders. An additional 345,000 shares were subsequently sold by shareholders when the underwriters exercised part of their overallotment option.
Gross proceeds associated with the offering reached approximately $192.7 million, while A10 reported approximately $120.2 million in estimated aggregate net proceeds after the applicable deductions and amounts attributable to selling shareholders.
Going public also made A10’s business considerably easier to examine.
Its SEC filings began providing detailed information about customers, revenue, products and competitive risks rather than relying primarily on marketing descriptions.
At the end of 2013, immediately before the IPO, A10 reported that it had sold products to more than 2,900 customers across 65 countries. Its geographic revenue mix at the time included substantial business in both the United States and Japan.
The founder eventually handed over the CEO role
Lee Chen remained A10’s chief executive from the company’s creation until 2019.
In November 2019, A10 announced that Dhrupad Trivedi would become president and CEO from 2 December that year.
Chen initially remained chairman to assist with the transition.
Trivedi had previously held senior positions at Belden, including responsibility for Tripwire, a cybersecurity software business.
The leadership change coincided with a period in which A10 increasingly presented security as a central part of its identity rather than an additional function surrounding application delivery.
Trivedi subsequently became chair of A10’s board as well as president and CEO. A10’s 2026 proxy statement lists him in all three roles.
A10’s current portfolio still carries its networking DNA
Despite the growing emphasis on security, A10 has not abandoned the networking technologies on which it was built.
Its 2025 annual filing identifies several major infrastructure products.
Thunder ADC handles application delivery and load balancing.
Thunder CGN provides carrier-grade networking functions.
Thunder SSL Insight is designed for processing encrypted traffic so that security systems can inspect traffic that would otherwise remain hidden inside SSL/TLS encryption.
Thunder Convergent Firewall combines several network and security capabilities.
A10 Control, previously known as Harmony Controller, provides centralised management, automation and analytics.
These products are available through combinations of hardware, virtual appliances, software, containers and cloud-oriented deployment models rather than being limited to the dedicated appliances that characterised much of the company’s earlier history.
That evolution reflects how enterprise infrastructure itself has changed.
Applications that once ran primarily inside privately owned data centres can now be distributed across corporate infrastructure, public clouds and edge environments.
The traffic-management problem did not disappear when cloud computing arrived. It became more distributed.
DDoS protection became a major security layer
Distributed denial-of-service attacks attempt to overwhelm services or network infrastructure with traffic or other resource demands.
A10’s involvement in this area dates back well before its present A10 Defend branding.
Its 2014 IPO documentation already described the Threat Protection System as a product intended to identify and mitigate large-scale DDoS attacks.
The modern portfolio expands on that idea.
A10’s current security family includes A10 Defend products for threat intelligence, detection, mitigation and orchestration, alongside web application and API protection.
This is an important distinction when describing A10.
It is not accurate to characterise the company simply as a firewall vendor or simply as a load-balancing company.
Its portfolio spans the point where application delivery, network traffic management and security intersect.
ThreatX Protect pushed A10 further into application security
In February 2025, A10 acquired assets and key personnel associated with ThreatX Protect.
The transaction added web application and API protection capabilities to A10’s security portfolio.
ThreatX Protect included functionality covering web application firewall protection, bot management and API security and was delivered as a software-as-a-service product.
A10 incorporated the technology into its A10 Defend portfolio.
The company did not acquire everything belonging to the former ThreatX business. Its announcement explicitly said that remaining assets would operate separately as Run Security.
That distinction matters because describing the deal simply as “A10 acquired ThreatX” would be broader than the transaction A10 itself announced.
AI infrastructure created another expansion point
Artificial intelligence has introduced a new source of network demand.
Training and operating large AI systems can involve substantial amounts of traffic between processors, storage systems, applications, APIs and users.
For A10, that created an opportunity connected closely to its existing networking and security products.
In June 2025, A10 announced that Microsoft had selected its technology to help protect infrastructure associated with generative-AI workloads.
The announcement said A10 would provide threat-detection and mitigation capabilities for Microsoft’s AI infrastructure.
The safest interpretation is the narrow one supported by the announcement: Microsoft selected A10 for that infrastructure-security role. It should not be expanded into claims that A10 secures all Microsoft AI services or all Azure infrastructure.
TrojAI added security specifically for AI systems
A10’s move into AI security became more explicit in June 2026 when it acquired TrojAI.
TrojAI had developed technology for testing and protecting AI models, applications and agent-based systems.
A10 said the technology provides two principal layers of protection.
The first is red-team testing intended to identify weaknesses before deployment.
The second is runtime protection intended to identify and respond to threats while AI systems are operating.
The acquisition extended A10’s security reach beyond the conventional network perimeter into the behaviour and operation of AI applications themselves.
The A10 AI Gateway arrived in August 2026
A10 took another step into AI infrastructure in August 2026 with the general availability of the A10 AI Gateway.
Rather than being another traditional load balancer, the AI Gateway is designed as a control point between users or applications and the AI models they access.
A10 says it can centralise model routing, cost controls, observability, access policies and governance across AI applications, agents and large language models.
The product can run within a customer’s own environment, including on-premises and private-cloud deployments.
A10 announced general availability on 13 August 2026 after demonstrating the product at Black Hat USA.
The product illustrates how far the company’s definition of “application traffic” has expanded.
In 2007, the AX Series was directing requests towards conventional server applications.
In 2026, A10 is applying the same broad principle of controlling and observing traffic to interactions between software and AI models.
A10 reached record revenue in 2025
A10 reported revenue of $290.6 million for 2025, an increase of 11% from $261.7 million in 2024.
Of that 2025 total, product revenue was approximately $167.1 million and services revenue was approximately $123.5 million.
GAAP net income was $42.1 million.
A10 ended the year with approximately $377.8 million in cash, cash equivalents and marketable securities.
Those figures provide a clearer picture of the company’s scale than broad descriptions such as “networking giant.”
A10 is a global listed technology supplier, but its revenue remains considerably smaller than the largest networking and cybersecurity corporations.
Precision matters in company histories because size and influence are not the same thing.
A specialist can occupy important positions inside telecommunications, cloud and enterprise infrastructure without operating at the revenue scale of the industry’s largest vendors.
Growth continued during the first half of 2026
For the quarter ended 30 June 2026, A10 reported revenue of $80.1 million, up 15.5% from the corresponding quarter a year earlier.
Revenue for the first six months of 2026 reached $155.1 million, compared with $135.5 million during the first half of 2025.
The company reported GAAP net income of $8.9 million for the second quarter and had $357.3 million in cash, cash equivalents and marketable securities at the end of June.
A10 also stated in 2026 that it serves more than 7,000 customers globally. Its corporate material lists approximately 500 employees as of fiscal 2025.
A10 in 2026 is best understood through the traffic it controls
The most interesting part of A10 Networks’ history is not a complete reinvention from one unrelated industry into another.
It is continuity.
The company began by managing application traffic.
It added security as that traffic became more exposed to attacks.
It added carrier-grade networking as internet service providers needed to manage address scarcity and increasingly large subscriber networks.
It expanded DDoS protection as internet availability became economically critical.
It added web and API security as applications moved into cloud environments and APIs became central to modern software.
And it is now moving deeper into AI infrastructure as traffic increasingly flows between applications, agents and large language models.
The technologies have changed, but the strategic location has remained remarkably consistent: A10 wants to operate in the path between valuable applications and the networks or users trying to reach them.
That is a more accurate description of the company’s evolution than treating every new product category as a separate reinvention.
From AX to Thunder to AI
A concise timeline shows the progression:
2004: Lee Chen founds A10 Networks in California.
2005: A10 releases its first product.
2007: The AX Series of Application Delivery Controllers launches.
2009: Security capabilities are added to the AX family.
2010: A10 expands into carrier-grade network address translation.
2013: The Thunder Series launches.
2014: A10 completes its IPO and begins trading on the NYSE under ATEN.
2019: Dhrupad Trivedi succeeds Lee Chen as CEO.
2025: A10 acquires ThreatX Protect assets and expands web application and API security capabilities.
2025: Microsoft selects A10 technology for a defined role protecting mission-critical AI infrastructure.
2026: A10 acquires TrojAI.
2026: The A10 AI Gateway becomes generally available.
2026: First-half revenue reaches $155.1 million.
The result is a company whose products have moved well beyond the load balancers that established its early reputation.
A10 Networks in 2026 combines application delivery, carrier networking, DDoS mitigation, encrypted-traffic processing, web and API protection, centralised network control and an expanding collection of AI security and AI traffic-management technology.
Its next chapter cannot be treated as certain. Acquisitions, AI products and large customer agreements do not guarantee future growth, and competitive technology markets can change rapidly.
What can be stated from the record is more useful: A10 has spent more than two decades extending the same core expertise into new generations of network traffic.
From AX appliances inside data centres to Thunder platforms, cloud deployments and AI gateways, the company has repeatedly followed applications to wherever the traffic moved next.
Sources
This article was checked against A10 Networks’ filings with the US Securities and Exchange Commission, including its 2014 IPO registration documents, subsequent annual and quarterly reports and 2026 proxy statement; A10 Networks investor-relations financial releases; and official A10 Networks announcements concerning its CEO transition, ThreatX Protect transaction, Microsoft engagement, TrojAI acquisition and A10 AI Gateway.
Information checked on 18 September 2026.