The model is swappable. The map is not.
The largest AI companies are rebuilding themselves around Palantir's playbook. We read every Palantir shareholder letter since 2020 to work out what a security graph should take from it, and what it should refuse to copy.
Within the last year and a half, the largest AI companies in the world converged on the same plan: hire forward-deployed engineers, embed them inside customers, and get trusted access to the context that turns model output into decisions. One of them even named its enterprise platform after the product it is imitating.
The company being imitated is Palantir. An essay published this month, "Forward Deployed" (The Diff, also published in Arena), argues that the labs are copying the form without the substance, building what it calls "Palantir Cargo Cults." Its sharpest line is worth keeping in view: "it's relatively easy to distill frontier models, but... almost impossible to distill institutions."
We build Setu, which derives a live map of what an attacker can reach from the security data an organisation already holds. That is an ontology in all but name: typed identities, assets and relationships, resolved from dozens of sources into one graph. So we read all of Palantir's shareholder letters from 2020 to 2026 and asked a narrow question. What should a security product take from twenty years of building ontologies for institutions, and what should it refuse to copy?
Here is what we took.
1. The model is necessary. It is not sufficient.
Palantir's August 2024 letter makes the argument in one image. Language models "may be able to flawlessly mimic Goethe, but without more, add little value." They are "wild animals, whose power... must be tamed and harnessed." By February 2026 the claim is sharper: "The models must be tethered to objects in the real world, and it is that tether... that we have built."
Security teams are learning the same thing the hard way. Point a language model at raw SOC data and it will read a vendor's "persistence score" as evidence of persistence, and a CVE association as proof of exploitation. The words are right and the meaning is wrong, which is the most dangerous kind of error because it survives review.
Our answer has been to make the graph carry the meaning, not the model. Every score the assistant can read arrives with a note on how it was computed and what it does not mean. Every entity a narrative names must exist in the evidence, or the narrative is rejected. The model itself is interchangeable, and in air-gapped deployments it runs on the customer's own hardware. The same letters observe that model vendors "swap places every six months." If that is true, the durable asset is the map and its rules, not the model reading them.
2. A map you cannot act on is a report
The most persistent idea in the letters is that the ontology exists to reach a decision. In April 2023 the stated goal is "to move from mere research and investigation to concrete action." In May 2024 the platform is described as infrastructure for "write-back functions, data lineage tracking, large language models, and... the handoff between human and algorithmic agents."
This is where we have to be precise about where Setu stands. Today Samyoga reads and reasons. It is not an execution layer, and we say so on our thesis page. Anything that changes a customer system is staged for a named person to approve, and autonomy is granted one action at a time, never globally.
What the letters clarified for us is the shape of the next step. An action should be a typed object in the same graph as the things it acts on. It should declare which pattern in the graph it is legal against, how much authority it needs, what reverses it, and what change in the graph it promises. That turns "isolate this host" from a button into a claim that can be checked before and after it runs. It is the part of the ontology idea we are building now, and we will write about it when it works on a real network rather than before.
3. Deployment work has to compound, or you are a consultancy
Palantir's 2020 listing letter dismisses custom tools because they "often only work briefly, if at all." The May 2022 letter talks about decomposing its platforms, and notes that one of its four products "was once an internal set of tools." The most revealing line comes in November 2025, explaining why the company kept its headcount small: "an army of bright minds... would have obscured the platform's weaknesses."
That is the real discipline behind the forward-deployed engineer. The essay puts the incentive plainly: "the person making specific promises is also the one who has to make those promises come true." But the engineer is only valuable if the pain they absorb in one customer becomes product for the next.
For a young company this is the whole ballgame. Every security deployment is messy in its own way: an unusual firewall format, a legacy rule set, a CMDB that disagrees with everything. We treat each of those as a test of whether the product generalises. A new log format should become a mapping the next customer gets for free. An imported rule set should become an importer, not a script. We now use AI to draft those mappings, with deterministic gates deciding whether they ship. The question we ask of every engagement is simple: will the next customer be easier because of this one?
4. Days, not quarters
In February 2024 Palantir reported that it had run "fewer than 100 commercial pilots in 2022" and "over 500 bootcamps" the next year, short engagements where customers used the software on their own data. Organisations that had spent "hundreds of millions of dollars in lackluster or failed data integration projects are now seeing results in days."
Security buyers are worn out on long proofs of concept that end in a slide deck. The equivalent of a bootcamp for a reachability product is obvious. Connect one identity source and one telemetry source, and within days show the actual paths an attacker could take to the assets that matter most, on the customer's own data, with the evidence attached. If a product cannot produce something true about your environment in a week, a longer pilot is unlikely to change that.
5. Sovereignty is the moat, not the compliance box
The letters return again and again to one commercial principle. In 2022: the value "is a result of the software itself, not the information or data of those who use it." In the second quarter of 2026, contrasting itself with AI labs that want their partners' data: "We have always declined, and will continue to decline, entering into a parasitic relationship with our partners." Its customers, it says, "have declined to become vassal states of the language labs."
The essay makes the same point with a better analogy. Palantir is closer to TSMC than to a model lab: "TSMC may help you manufacture your chips, but they will never, ever compete with your design." The customer owns the result.
For security data this is not a philosophical preference. It is the product. A graph of who can reach what inside an organisation is among the most sensitive artefacts it will ever produce. Setu is built so that the graph stays inside the customer's boundary: in its own datacentre or a sovereign cloud region, fully air-gappable, with no cross-border transfer because there is no transfer. We think every vendor asking for this level of access should be able to say, in writing, what it will never do with it.
6. Governance is a feature
It would be easy to read Palantir's history as a story about data integration. The letters tell a different one. In April 2023: "Access controls alone, however, are not sufficient." Granular controls are "essential not only to the efficacy of the systems themselves but to their adoption." In February 2026, "granular permissioning" and "functional audit logs" are presented as the software's answer to the uninvited ear of the state.
The essay describes the original design choice the same way: purpose-based access and full accountability, rather than the ability to find anything about anyone.
AI makes this more pressing, not less. An assistant that can query a security database is a new user with broad reach and no judgment of its own. Ours runs with read-only access to an explicit set of tables, can only propose changes for a human to approve, and every step is recorded. For a CISO, "who can see what, and can you prove it" is a buying criterion, and we treat it as one.
7. Paid for value, not volume
The August 2026 letter draws the line bluntly: "We are paid, and have always aspired to be paid, as a derivative of value creation... We do not get paid for clicks or tokens or chats."
The security market mostly prices the opposite way. When a product is paid by the gigabyte ingested, the vendor earns more when the customer logs more, whether or not anything got safer. We think a product that claims to reduce exposure should eventually be measured on the exposure it reduces. That is an open question for us, not an announcement, but it is the right question.
What we are not copying
The job title. The essay's warning about cargo cults applies to startups at least as much as to labs. Hiring people called forward-deployed engineers does not create the thing that made them work, which is trust, and deployment work that compounds.
The horizontal ambition. Palantir builds ontologies for entire enterprises and sells to the chief executive. Setu is deliberately narrow: identities, assets and the paths between them, for the people responsible for defending them. A fixed, opinionated security schema is an advantage in a domain where everyone's data looks different but the attack paths rhyme.
The twenty-year runway. The letters admit early years when bespoke delivery "weighed on our ability to expand," and call that period a "necessary interregnum." That was survivable with a decade of government anchor contracts. A young security company does not get an interregnum. The discipline has to exist from the first customer.
The certainty. The letters are written with great confidence. The essay notes that the map "never fully matches the territory," and that the job is to keep it "always getting less wrong." That sentence describes a security graph better than anything in the letters. Ours is wrong in places, it says where, and every week it should be less wrong than the week before.
The short version
Distill the letters and the essay into one sentence for security and you get this: the model is swappable, the map is not, and the map is only worth having if you can act on it without giving away the thing that makes it yours.
Sources: Palantir Technologies shareholder letters, August 2020 to August 2026, published at palantir.com/newsroom/letters. "Forward Deployed," The Diff, September 21, 2026, and Arena, September 18, 2026. Samyoga has no affiliation with Palantir or with either publication, and neither has reviewed this post.
Setu Research
Setu Security Research