Agentic Index
ContraForce vs Qevlar AI (2026)
ContraForce and Qevlar AI both sell heavily to managed security providers, and ContraForce documents more of the grid, 11 of 14 against 8.5. That verdict is the Agentic Index coverage score, graded from each vendor's own published materials.
ContraForce works inside Microsoft Defender XDR and Sentinel, running triage, investigation, response and customer reporting across tenants under each workspace's own procedures, with approval gates on high impact actions and published prices from 249 dollars a month. Qevlar works across more than 50 integrations and reasons in a graph orchestrator rather than a language model, for reproducible tier two and three investigations; it says more than 1,500 organizations run it. On the grid ContraForce is Full on human oversight, knowledge grounding, model choice and workflow orchestration where Qevlar is Partial or None; Qevlar is Partial on memory where ContraForce is None. Choose ContraForce for Microsoft centered delivery with published prices; choose Qevlar for reproducible investigation across mixed stacks.
On the Agentic Index AI SOC ranking, ContraForce clears the bar and Qevlar AI does not. ContraForce documents all five investigation loop capabilities in full; Qevlar AI does not document workflow orchestration in full, nor human oversight and guardrails. 23 of the 85 vendors in the lane clear it. See the AI SOC ranking
This comparison is published by Agentic Index, an independent agentic AI vendor research platform. ContraForce and Qevlar AI are each graded against the same 14 capability Agentic Index taxonomy, from the vendor's own public materials under the Agentic Index verification standard, alongside 955 researched vendors. No vendor pays for placement and no vendor has reviewed this page. How this evidence is graded
Choose ContraForce if
- Your customers run Defender XDR and Sentinel.
- High impact actions should pass an approval gate; ContraForce is Full on oversight and Qevlar Partial.
- Published tier prices help you price your own service.
Choose Qevlar AI if
- Your customers run a mix of SIEMs and EDRs rather than one Microsoft stack.
- Reproducible verdicts from a graph orchestrator matter to your auditors.
- Memory across investigations should be documented; Qevlar is Partial and ContraForce None.
| Feature | C ContraForce |
Q Qevlar AI |
|---|---|---|
| Action & orchestration | ||
|
Integrations & Tool Calling Ability to connect agents to real systems through native integrations, OAuth-authenticated actions, custom tools, APIs, webhooks, or MCP-compatible tools. |
||
|
ContraForceIntegrations & Tool Calling Named integrations cover Microsoft Defender XDR, Microsoft Sentinel, SentinelOne, CrowdStrike, Autotask, ServiceNow, Jira and Azure Lighthouse, and the agent takes response actions in them such as Isolate Endpoint, Reset User Password, Lockout User, Quarantine File, Block Cloud IP and Delete Email. Sourcecontraforce.com/platformread 2026-09-28 |
||
|
Qevlar AIIntegrations & Tool Calling More than 50 API based integrations cover Microsoft Defender, Sentinel and Entra ID, CrowdStrike, Splunk, Elastic, AWS, Okta, Palo Alto, ServiceNow, Jira, Tines and others, with response actions such as blocking a suspicious IP or contacting the user. They span SIEM, SOAR and ticketing, EDR and XDR, email, identity, threat intel, malware sandboxes, cloud and network tools, including Cortex XSIAM and XSOAR, Google SecOps, SentinelOne, Proofpoint, Mimecast, Zscaler and VirusTotal. After an investigation, Qevlar moves to the next action, whether containment for malicious activity, tuning for false positives, or a policy or compliance follow up. SourceQevlar AI, qevlar.com/integrations and qevlar.comread 2026-10-05 |
||
|
Workflow Orchestration Ability to sequence, branch, retry, route, and combine deterministic workflow nodes with autonomous agent steps. |
||
|
ContraForceWorkflow Orchestration Security Delivery Agents run the delivery loop from triage and investigation through response, ticketing and customer reporting. Customers shape the flow, with uploaded response operating procedures setting the containment and remediation steps, settings per severity and classification deciding what runs automatically, and ordered Gamebook run policies blocking, allowing or routing each action. Sourcedocs.contraforce.com/guides/getting-started/configuring-security-delivery-agentsread 2026-09-28 |
||
|
Qevlar AIWorkflow Orchestration A graph based orchestrator, not an LLM, runs each investigation along structured, reproducible paths across the stack and follows the customer's procedures. It connects related activity into a single incident story, maps the full blast radius and moves containment forward. There is no branching, conditions, multiple agents or flow that customers build, and each investigation follows the product's own pipeline. SourceQevlar AI, qevlar.comread 2026-10-05 |
||
|
Triggers & Channel Coverage How agents wake up and where they work: schedules, webhooks, message events, CRM events, inbox events, chat, email, voice, and collaboration tools. |
||
|
ContraForceTriggers & Channel Coverage The On Queue setting runs the agent automatically on every incident of a configured severity, and Agent Shifts set the weekly hours in which it investigates on its own. Manual runs remain available. Sourcedocs.contraforce.com/guides/agent-center/agent-shiftsread 2026-09-28 |
||
|
Qevlar AITriggers & Channel Coverage New alerts from across the security stack start investigations with no analyst initiating them, alerts can be pushed in through POST /alert, and hunts run continuously. A pushed alert is accepted at once with a PENDING status. Hunt queries are written and run across the SIEM and EDR automatically, and the platform works around the clock. SourceQevlar AI, help.qevlar.com SOC Workflow Integration API and qevlar.com/soc-and-vulnerabilityread 2026-10-05 |
||
| Knowledge & context | ||
|
Knowledge Grounding & RAG Ability to ground agent behavior in company data through document ingestion, retrieval, external knowledge APIs, semantic search, or RAG layers. |
||
|
ContraForceKnowledge Grounding & RAG ContraForce grounds the agent in an SOP Knowledge Base, where customers upload classification and response operating procedures as Markdown or text, versioned by re-upload and scoped per workspace, for the agent to draw on in each incident. An Entity Context Graph of the incident's users, devices and IPs sits alongside it. Sourcedocs.contraforce.com/guides/agent-center/operating-proceduresread 2026-09-28 |
||
|
Qevlar AIKnowledge Grounding & RAG Investigations correlate telemetry and threat intelligence from the connected stack and draw on an organizational context of past investigations. For each MSSP client, the provider sets the enrichment and context sources Qevlar uses in every investigation, along with that client's business context. There is no index or graph that Qevlar maintains over the customer's own knowledge. SourceQevlar AI, qevlar.com and qevlar.com/solutions/msspsread 2026-10-05 |
||
|
Memory & State Persistence Ability to persist context across a run, conversation, workflow, user, team, or longer-term memory layer. |
||
|
ContraForceMemory & State Persistence The agent has no memory with a set scope and lifetime, and no context engine or remediation snapshots are described. The SOP Knowledge Base grounds the agent but is not memory. Sourcedocs.contraforce.com/guides/agent-center/operating-proceduresread 2026-09-28 |
||
|
Qevlar AIMemory & State Persistence When analysts override a verdict and add context, Qevlar applies it to future cases, and an organizational context keeps past investigations, so state carries across cases. That knowledge stays in the platform as shared intelligence when analysts move on, and each investigation sharpens the next. Qevlar does not say how widely that store applies or how long it is kept. SourceQevlar AI, qevlar.comread 2026-10-05 |
||
| Control & trust | ||
|
Human Oversight & Guardrails Approval steps, consent checkpoints, escalation rules, structured guardrails, policy constraints, and pause/resume controls. |
||
|
ContraForceHuman Oversight & Guardrails Gamebook run policies are ordered rules that block an action, allow it or send it to an approver first, and high-impact actions such as Isolate Endpoint and Reset User Password sit behind a named approver. Below a confidence threshold, the agent leaves actions to an analyst. Sourcedocs.contraforce.com/guides/getting-started/what-are-gamebooksread 2026-09-28 |
||
|
Qevlar AIHuman Oversight & Guardrails Investigations follow the customer's procedures with analyst control, and analysts can override any verdict and add context. Analysts review alerts judged malicious, confirm the outcome and take the next steps Qevlar suggests. No approval step comes before a response action runs. SourceQevlar AI, qevlar.com and qevlar.com/productread 2026-10-05 |
||
|
Security, Identity & Governance RBAC, SSO, auditability, encryption, least-privilege tool access, compliance posture, and data handling policy. |
||
|
ContraForceSecurity, Identity & Governance SSO and audit logs come on every plan, alongside SOC 2 Type II certification, alignment to ISO 27001:2022, SCIM provisioning on Scale, user roles and permissions and federated least-privilege access. Sourcecontraforce.com/pricingread 2026-09-28 |
||
|
Qevlar AISecurity, Identity & Governance The platform supports SSO integration, with role based access and mandatory MFA on internal and production access, and holds a SOC 2 Type II attestation for the Security criteria. Data is encrypted with AES-256 at rest and TLS 1.2 or higher in transit, with keys held in GCP KMS, and an outside firm runs a penetration test every year. Qevlar does not train its AI models on customer data, and it notifies customers within 72 hours of confirming a personal data breach. SourceQevlar AI, help.qevlar.com Data Privacy and Protection FAQsread 2026-10-05 |
||
|
Observability & Auditability Traces, logs, execution histories, metrics, audit events, and debugging detail for production agent behavior. |
||
|
ContraForceObservability & Auditability Every decision the agent makes, every action it takes and every approval gate is logged with full attribution. Agent Execution History records each run's trigger, incident, source, outcome and prompt, along with cached and completion token counts and USD cost, so each run has its own record. Sourcedocs.contraforce.com/guides/agent-center/agent-execution-historyread 2026-09-28 |
||
|
Qevlar AIObservability & Auditability Every verdict is transparent. Analysts see every step and every observable queried in the investigation, and audit logs are kept for up to 12 months. Full investigation reports can go straight to a SOAR or ticketing system or be read inside Qevlar, and actions can be traced for compliance. SourceQevlar AI, qevlar.com, qevlar.com/solutions/mssps and help.qevlar.com Data Privacy and Protection FAQsread 2026-10-05 |
||
|
Deployment & Data Residency Deployment modes and options, including SaaS, dedicated cloud, VPC, on-prem, hybrid, local runtime, and self-hosting. |
||
|
ContraForceDeployment & Data Residency Deployments run in the US and the UK, with customer data processed and stored only within the assigned regional deployment, a UK-resident stack and Data Zone Standard model deployments offered by region. An EU deployment is planned, and no self-hosted or customer-hosted deployment is offered. Sourcecontraforce.com/platformread 2026-09-28 |
||
|
Qevlar AIDeployment & Data Residency Primary hosting is Google Cloud in Belgium with LLM inference on Azure in Sweden, customer data retained in the EU, and a Bring Your Own Cloud deployment through which customers can choose another region. Bring Your Own Cloud runs on GCP or Azure, and Qevlar can run as SaaS or in a private cloud. Setup goes through APIs and usually takes a few hours, and the fastest so far took 10 minutes. Alert data is deleted 60 days after a contract ends unless agreed otherwise. SourceQevlar AI, help.qevlar.com Data Privacy and Protection FAQs, qevlar.com/product and qevlar.com/solutions/msspsread 2026-10-05 |
||
| Solution readiness | ||
|
Prebuilt Agents, Templates & Packs Ready-made workflows, packaged employees, templates, blueprints, industry solutions, and role-specific agents that reduce time-to-value. |
||
|
ContraForcePrebuilt Agents, Templates & Packs ContraForce ships one prebuilt agent type, the Security Delivery Agent, deployed per workspace, plus a fixed catalog of response actions. Gamebooks are assembled per incident from those actions, with no named template library, and the procedures are the customer's own uploads. Sourcedocs.contraforce.com/guides/getting-started/what-are-gamebooksread 2026-09-28 |
||
|
Qevlar AIPrebuilt Agents, Templates & Packs One platform covers investigation, threat hunting, detection engineering and vulnerability prioritization, and Qevlar sells these as parts of one product, not as separate prebuilt agents or templates. The vulnerability agents, still in preview, blend CVE intelligence with live SOC signal into a contextual severity score, find each asset's owner from ITSM, identity provider and EDR records, and write and run threat hunts across the SIEM and EDR. Qevlar packages the product for phishing, network, identity and cloud alerts, and MSSPs get a separate tenant for each client with its own investigations and settings. SourceQevlar AI, qevlar.com, qevlar.com/soc-and-vulnerability and qevlar.com/solutions/msspsread 2026-10-05 |
||
| Platform extensibility | ||
|
Model Flexibility & Routing Ability to work across multiple foundation models, route tasks to different models, or let buyers bring their own providers and keys. |
||
|
ContraForceModel Flexibility & Routing When creating a Security Delivery Agent, the customer chooses the AI model and deployment type (Global Standard or Data Zone Standard) from the models available in the Agent Center's region, with upgrades to GPT-5.5 and GPT-5.6 depending on runtime support. Sourcedocs.contraforce.com/release-notesread 2026-09-28 |
||
|
Qevlar AIModel Flexibility & Routing Core reasoning runs in Qevlar's graph orchestrator, and LLMs handle narrow tasks such as enrichment and summaries on Azure inference in Sweden. Qevlar chose that single provider, and customers cannot choose a model. Inference stays under EU and EEA processing, and customer data is not used for training. SourceQevlar AI, help.qevlar.com Data Privacy and Protection FAQs and qevlar.comread 2026-10-05 |
||
|
APIs, SDKs & MCP Extensibility Composability layer: stable APIs, SDKs, MCP tool consumption/serving, custom tools, and integration into internal systems. |
||
|
ContraForceAPIs, SDKs & MCP Extensibility Every plan includes a v2 REST API at portal.contraforce.com/api/v2, with service account Basic auth and workspace, cross-workspace and organization scoped endpoints for incidents, gamebooks, tickets, data sources and analytics rules, plus a webhook event reference that includes an agent investigation completed webhook. There is no MCP server. Sourcedocs.contraforce.com/api-reference/endpointsread 2026-09-28 |
||
|
Qevlar AIAPIs, SDKs & MCP Extensibility A REST API at api.qevlar.com with Bearer token auth submits alerts (POST /alert), returns investigation status and results (GET /alert/{id}), and publishes its reference at api.qevlar.com/redoc. A new alert returns an alert ID with a PENDING status, a status check returns IN_PROGRESS, FAILURE or the full results, and rate limits follow the subscription plan. SourceQevlar AI, help.qevlar.com SOC Workflow Integration APIread 2026-10-05 |
||
|
Testing, Debugging & Optimization Testing, debugging, scoring, retries, fallbacks, quality gates, and optimization loops for improving agent workflows before and after deployment. |
||
|
ContraForceTesting, Debugging & Optimization Rollout starts with investigation-only runs before response actions are enabled, and autonomy then expands one Gamebook at a time as verdicts hold up, which works as a dry-run style check on the agent's own output. There is no scored test harness. Sourcedocs.contraforce.com/guides/getting-started/configuring-security-delivery-agentsread 2026-09-28 |
||
|
Qevlar AITesting, Debugging & Optimization Analyst overrides feed later cases. Customers have no evaluation harness, scored test cases, quality gate or optimization loop to run. Qevlar reports a 3 minute average alert investigation and up to 80% of tickets closed automatically, and says MSSPs using it report an average 300% return on investment. SourceQevlar AI, qevlar.com/product and qevlar.com/solutions/mssps; qevlar.comread 2026-10-05 |
||
| Specialist automation | ||
|
Browser & Computer Use Browser, desktop, or remote/local computer control for workflows that cannot be handled through stable APIs alone. |
||
|
ContraForceBrowser & Computer Use The agent acts through API integrations, and browser or computer use is not described. Sourcecontraforce.com/platformread 2026-09-28 |
||
|
Qevlar AIBrowser & Computer Use No agent drives a browser, desktop or remote computer. Investigations and actions run through API integrations, and results can go straight into the team's SOAR or ticketing tool. SourceQevlar AI, qevlar.com and qevlar.com/solutions/msspsread 2026-10-05 |
||
Pricing snapshot
Sourced from the Index pricing dataset · open each vendor's profile for full detail.
| Pricing | C ContraForce |
Q Qevlar AI |
|---|---|---|
|
Entry price Lowest public entry point |
Starter from $249 per month (4 client workspaces), plus a flat rate per incident for each agent run, quoted by ContraForce. | Contact sales; enterprise and MSSP contracts, no public rates |
|
Pricing confidence How public the numbers are |
Public, partial | Contact only |
|
Billing Primary billing axis |
Monthly tier by client workspace allowance, plus a flat rate per Security Delivery Agent run. | enterprise contract (MSSP packaging) |
|
Variable cost Workload / overage exposure |
Medium variable cost | Low variable cost |
|
Free tier / trial Try before you buy |
No free tierTrial
|
No free tierTrial
|
|
Buying motion Self-serve vs sales call |
Mixed | Sales call |
More comparisons with ContraForce or Qevlar AI
Other matchups in security and SOC agents
Not the pairing you were after? These compare a different set of security and SOC agents on the same 14 capabilities.