Agentic Index
Dropzone AI vs Radiant Security (2026)
Dropzone AI and Radiant Security both triage every alert a SOC raises and both sell through sales, but Dropzone is the broader product and Radiant's future is less settled. That verdict is the Agentic Index coverage score, graded from each vendor's own published materials.
Cribl acquired the technology behind Radiant's AI SOC product in August 2026 and plans to run it on its telemetry platform, while Radiant's site still sells it. Radiant pairs triage with integrated log management offered as a SIEM cost alternative, with response actions an analyst confirms from the case view. Dropzone overlays more than 90 tools, read only by default, adds a threat hunter, and prices by investigation volume. On the grid Dropzone is Full on observability, prebuilt agents, security and workflow orchestration where Radiant is Partial, and Radiant's deployment and data residency could not be established. Choose Dropzone for documented coverage and a settled owner; choose Radiant only if its log store offsets SIEM spend and the Cribl roadmap suits you.
On the Agentic Index AI SOC ranking, Dropzone AI clears the bar and Radiant Security does not. Dropzone AI documents all five investigation loop capabilities in full; Radiant Security does not document workflow orchestration in full, nor observability and auditability. 23 of the 85 vendors in the lane clear it. See the AI SOC ranking
This comparison is published by Agentic Index, an independent agentic AI vendor research platform. Dropzone AI and Radiant Security are each graded against the same 14 capability Agentic Index taxonomy, from the vendor's own public materials under the Agentic Index verification standard, alongside 955 researched vendors. No vendor pays for placement and no vendor has reviewed this page. How this evidence is graded
Choose Dropzone AI if
- Observability, security and orchestration must be documented in full; Dropzone is Full on each and Radiant Partial.
- A vendor with a settled roadmap matters more than a bundled log store.
- Deployment and data residency must be on the record before you sign.
Choose Radiant Security if
- Integrated log management could replace part of your SIEM spend.
- Every response action should wait for an analyst to confirm it from the case view.
- You already run Cribl and want the product on that platform.
| Feature | D Dropzone AI |
R Radiant Security |
|---|---|---|
| Action & orchestration | ||
|
Integrations & Tool Calling Ability to connect agents to real systems through native integrations, OAuth-authenticated actions, custom tools, APIs, webhooks, or MCP-compatible tools. |
||
|
Dropzone AIIntegrations & Tool Calling Dropzone has more than 90 integrations across SIEM, EDR, cloud, identity and email, read only by default. Response Actions run Python that the customer writes in an isolated container with stored secrets injected, to notify external systems, trigger remediation and apply policy actions. Sourcedocs.dropzone.ai/platform/settings/response-actionsread 2026-09-28 |
||
|
Radiant SecurityIntegrations & Tool Calling Data connectors ingest from the customer's tools in categories that include authentication, cloud access security brokers, cloud, endpoint and network logs, email infrastructure and IAM, ICS and OT, messaging apps, password managers, SIEM tools, ticketing systems, security service edge, API protection and an S3 connector, and outgoing webhooks send data on. Response actions run from the case view in CrowdStrike, Microsoft 365 Defender, SentinelOne, Microsoft 365, Okta, Google Workspace, Mimecast, Proofpoint, Netskope and KnowBe4, isolating devices, disabling users, resetting passwords, ending sessions, deleting messages, removing external forwarding rules and blocking IPs, URLs, domains and files. They also start full disk scans in SentinelOne and enroll users in KnowBe4 phishing training. SourceRadiant Security, help.radiantsecurity.ai and /radiant-cases/radiant-cases/response-actionsread 2026-10-06 |
||
|
Workflow Orchestration Ability to sequence, branch, retry, route, and combine deterministic workflow nodes with autonomous agent steps. |
||
|
Dropzone AIWorkflow Orchestration Beyond the agent's own multi step investigation, customers configure what follows it. Response Automations fire on more than 50 triggers, among them an investigation completing with a given status, and run the customer's own code, and versioned custom strategies set priority rules and investigation questions. Sourcedocs.dropzone.ai/platform/settings/response-actionsread 2026-09-28 |
||
|
Radiant SecurityWorkflow Orchestration Each alert runs through the product's own triage, investigation and case sequence, and response actions launch from the case, on one artifact or in bulk across selected users, IPs and URLs. The audit log mentions automated playbooks, but Radiant describes no branching, multi agent handoff or automation the customer configures. SourceRadiant Security, help.radiantsecurity.ai/radiant-cases/radiant-cases/response-actions-in-cases and /log-management/audit-logs/introduction-to-audit-logsread 2026-10-06 |
||
|
Triggers & Channel Coverage How agents wake up and where they work: schedules, webhooks, message events, CRM events, inbox events, chat, email, voice, and collaboration tools. |
||
|
Dropzone AITriggers & Channel Coverage Every alert the connected tools raise starts an investigation, hunts run on a schedule and on new CVEs and campaigns, and response automations fire on more than 50 system triggers. Sourcedropzone.airead 2026-09-28 |
||
|
Radiant SecurityTriggers & Channel Coverage Alerts arriving through data connectors or the custom alerts webhook are triaged and investigated automatically, with no analyst starting the work. Webhook alerts are posted as JSON with a token, enter the triage pipeline and become searchable within several minutes. SourceRadiant Security, help.radiantsecurity.ai/radiant-connectors/ingestion-methods/custom-alerts-webhookread 2026-10-06 |
||
| Knowledge & context | ||
|
Knowledge Grounding & RAG Ability to ground agent behavior in company data through document ingestion, retrieval, external knowledge APIs, semantic search, or RAG layers. |
||
|
Dropzone AIKnowledge Grounding & RAG Investigations query the customer's own tools live through the integrations, and analysts set custom strategies and define normal behavior. Context Memory serves as the persistent store, and no separate maintained index over the customer's documents is described. Sourcedocs.dropzone.ai/platform/settings/custom-strategiesread 2026-09-28 |
||
|
Radiant SecurityKnowledge Grounding & RAG Integrated log management stores the customer's logs with search, query and retention settings, and alerts sent through the custom webhook land in its parsed and alert indexes, where teams can search and investigate them. Radiant says the platform continuously learns the environment, its tooling, behavior and activity to boost accuracy, but it does not say how investigations draw on what it has learned or on the customer's own documentation. SourceRadiant Security, radiantsecurity.ai, help.radiantsecurity.ai/log-management/log-search-and-query and /radiant-connectors/ingestion-methods/custom-alerts-webhookread 2026-10-06 |
||
|
Memory & State Persistence Ability to persist context across a run, conversation, workflow, user, team, or longer-term memory layer. |
||
|
Dropzone AIMemory & State Persistence Context Memory holds institutional facts across investigations. The agent writes to it when analysts change a conclusion, users add notes directly, and it can be reached through the API. Its scope and lifetime are not stated, and Dropzone only advises cleaning it up from time to time. Sourcedocs.dropzone.ai/platform/context-memoryread 2026-09-28 |
||
|
Radiant SecurityMemory & State Persistence The platform continuously learns about the environment, its tooling, behavior and activity to boost accuracy, by Radiant's account, but Radiant describes no memory store, what it would keep, its scope or its lifetime. SourceRadiant Security, radiantsecurity.ai and help.radiantsecurity.airead 2026-10-06 |
||
| Control & trust | ||
|
Human Oversight & Guardrails Approval steps, consent checkpoints, escalation rules, structured guardrails, policy constraints, and pause/resume controls. |
||
|
Dropzone AIHuman Oversight & Guardrails Analysts approve or reopen each investigation in the product and from Slack (/dzapprove, /dzreopen), access to the customer's tools is read only by default, and response actions run only where the customer has configured them. Sourcedocs.dropzone.ai/integrations/tools/slack-chatopsread 2026-09-28 |
||
|
Radiant SecurityHuman Oversight & Guardrails Response actions launched from a case run when an analyst selects the targets, clicks the action and confirms the list of affected artifacts in a confirmation step, and many can be reversed with one click from the action history through the inverse action, such as enabling a user again. Hard deletes and password resets cannot be undone. The platform produces incident specific response plans for that analyst to execute. The audit log separates analyst actions from automated platform actions and playbooks, and Radiant does not say which actions, if any, run without that confirmation. SourceRadiant Security, help.radiantsecurity.ai/radiant-cases/radiant-cases/response-actions-in-cases, /response-actions and /log-management/audit-logs/introduction-to-audit-logsread 2026-10-06 |
||
|
Security, Identity & Governance RBAC, SSO, auditability, encryption, least-privilege tool access, compliance posture, and data handling policy. |
||
|
Dropzone AISecurity, Identity & Governance Access is managed with roles and permissions, and SAML SSO works through Okta, Google Workspace or Microsoft Entra. Dropzone holds SOC 2 Type 2, following a Type 1 audit by Sensiba, and runs a trust center at trustcenter.dropzone.ai. Sourcedropzone.ai/security-privacy-trustread 2026-09-28 |
||
|
Radiant SecuritySecurity, Identity & Governance SAML 2.0 SSO works with Okta, Google and Microsoft Entra ID and is enforced for all users once set, with an emergency bypass through support. Every user is assigned the Admin role, and Radiant names no SCIM provisioning. No compliance attestation is published, and a trust center sits at trust.radiantsecurity.ai. SourceRadiant Security, help.radiantsecurity.ai/manage-radiant/organization-settings/security/set-up-single-sign-on-ssoread 2026-10-06 |
||
|
Observability & Auditability Traces, logs, execution histories, metrics, audit events, and debugging detail for production agent behavior. |
||
|
Dropzone AIObservability & Auditability Each investigation produces an evidence backed report that shows the agent's reasoning, and every response action's output, errors and execution status are logged for auditing. Sourcedocs.dropzone.ai/platform/settings/response-actionsread 2026-09-28 |
||
|
Radiant SecurityObservability & Auditability Audit logs record who took action, what changed and when, with before and after values, across response actions, alert verdict changes, allow and deny list changes, deleted notes and data connector changes, and they tell analyst actions apart from automated platform actions. Configuration and administrative changes are not yet logged, and Radiant describes no record of the AI's investigation steps and reasoning. SourceRadiant Security, help.radiantsecurity.ai/log-management/audit-logs/introduction-to-audit-logsread 2026-10-06 |
||
|
Deployment & Data Residency Deployment modes and options, including SaaS, dedicated cloud, VPC, on-prem, hybrid, local runtime, and self-hosting. |
||
|
Dropzone AIDeployment & Data Residency Each customer gets a dedicated tenant in its own AWS subnet, normally in us-west-2, with optional regional deployments and in-region EU deployment on request for GDPR. The Enterprise plan includes a dedicated single tenant environment. Sourcedropzone.ai/security-privacy-trustread 2026-09-28 |
||
|
Radiant SecurityDeployment & Data Residency How the product is hosted is not described, and no hosting region, choice of region or customer environment option is published. SourceRadiant Security, radiantsecurity.ai and help.radiantsecurity.ai; trust.radiantsecurity.ai/resourcesread 2026-10-06 |
||
| Solution readiness | ||
|
Prebuilt Agents, Templates & Packs Ready-made workflows, packaged employees, templates, blueprints, industry solutions, and role-specific agents that reduce time-to-value. |
||
|
Dropzone AIPrebuilt Agents, Templates & Packs Two agents ship, each doing its own job, the AI SOC Analyst for alert investigation and the AI Threat Hunter for hypothesis driven hunts, with prebuilt hunt packs such as APT29. An AI Threat Intel Analyst is planned. Sourcedropzone.airead 2026-09-28 |
||
|
Radiant SecurityPrebuilt Agents, Templates & Packs One AI SOC analyst with incident response and log management around it covers many alert types out of the box, triaging every security alert across endpoint, identity, email, network and cloud. These are parts of one product, with no separate prebuilt agents or templates to adopt. Named customers include Nutcracker Therapeutics, Spellman High Voltage Electronics, Kyowa Kirin and Second Wave Delivery Systems. SourceRadiant Security, radiantsecurity.ai and help.radiantsecurity.airead 2026-10-06 |
||
| Platform extensibility | ||
|
Model Flexibility & Routing Ability to work across multiple foundation models, route tasks to different models, or let buyers bring their own providers and keys. |
||
|
Dropzone AIModel Flexibility & Routing Dropzone runs on several named LLM services, including Anthropic, Azure OpenAI and Perplexity, and chooses among them itself. Customers cannot choose the model. Sourcedropzone.ai/security-privacy-trustread 2026-09-28 |
||
|
Radiant SecurityModel Flexibility & Routing The models and providers behind Radiant's AI are not disclosed, and no model choice is offered. SourceRadiant Security, radiantsecurity.ai and help.radiantsecurity.airead 2026-10-06 |
||
|
APIs, SDKs & MCP Extensibility Composability layer: stable APIs, SDKs, MCP tool consumption/serving, custom tools, and integration into internal systems. |
||
|
Dropzone AIAPIs, SDKs & MCP Extensibility Developers get a REST API under /app/api/v1 with Api-Key authorization that covers investigations, bulk feedback, user notes, context memory, custom strategies, response actions and system events, with an OpenAPI 3.0.3 spec and a Swagger UI in the product. Sourcedocs.dropzone.ai/apiread 2026-09-28 |
||
|
Radiant SecurityAPIs, SDKs & MCP Extensibility The custom alerts webhook has a published endpoint, a token sent in the authorization header and a JSON body carrying timestamp, alert ID and raw alert fields, for sending alerts from sources without a dedicated connector. Radiant has announced an API for automating operational work, but no API reference beyond the webhook is published. SourceRadiant Security, help.radiantsecurity.ai/radiant-connectors/ingestion-methods/custom-alerts-webhookread 2026-10-06 |
||
|
Testing, Debugging & Optimization Testing, debugging, scoring, retries, fallbacks, quality gates, and optimization loops for improving agent workflows before and after deployment. |
||
|
Dropzone AITesting, Debugging & Optimization Analysts record feedback on investigations singly or in bulk and can reopen a conclusion, reviewing the agent's output after the fact. There is no evaluation harness, scored test set or gate before a strategy change goes live. Sourcedocs.dropzone.ai/apiread 2026-09-28 |
||
|
Radiant SecurityTesting, Debugging & Optimization Claimed results are triage with the quality of a team's best analyst at any scale and response times cut from days to minutes, both Radiant's own figures. Radiant describes no evaluation harness, scored test cases, quality gate or optimization loop the customer runs. SourceRadiant Security, radiantsecurity.ai and help.radiantsecurity.airead 2026-10-06 |
||
| Specialist automation | ||
|
Browser & Computer Use Browser, desktop, or remote/local computer control for workflows that cannot be handled through stable APIs alone. |
||
|
Dropzone AIBrowser & Computer Use The agent queries the customer's tools through their APIs, and driving a browser, desktop or remote computer is not described. Sourcedropzone.airead 2026-09-28 |
||
|
Radiant SecurityBrowser & Computer Use The AI works through data connectors and response actions inside the customer's security and identity tools. Radiant describes no use of a browser, desktop or remote computer. SourceRadiant Security, radiantsecurity.ai and help.radiantsecurity.ai/radiant-cases/radiant-cases/response-actionsread 2026-10-06 |
||
Pricing snapshot
Sourced from the Index pricing dataset · open each vendor's profile for full detail.
| Pricing | D Dropzone AI |
R Radiant Security |
|---|---|---|
|
Entry price Lowest public entry point |
Not published. Plans are priced by investigation volume through sales. | Contact sales; enterprise contracts with optional integrated log management |
|
Pricing confidence How public the numbers are |
Contact only | Contact only |
|
Billing Primary billing axis |
Investigations per year, per AI analyst, sold as an annual subscription. | enterprise contract |
|
Variable cost Workload / overage exposure |
Medium variable cost | Low variable cost |
|
Free tier / trial Try before you buy |
No free tierTrial
|
No free tierTrial
|
|
Buying motion Self-serve vs sales call |
Sales call | Sales call |
Cribl acquired the technology and intellectual property behind Radiant's AI SOC product in August 2026 and plans to run it as an application on its telemetry platform. Radiant's own site still sells the product and does not mention the deal, so ask who will support the contract and on what roadmap.
More comparisons with Dropzone AI or Radiant Security
Other matchups in security and SOC agents
Not the pairing you were after? These compare a different set of security and SOC agents on the same 14 capabilities.