Agentic Index
Exaforce vs Radiant Security (2026)
Exaforce and Radiant Security both pitch against SIEM cost, each pairing AI investigation with a data layer it runs, and neither publishes a price. That verdict is the Agentic Index coverage score, graded from each vendor's own published materials.
Exaforce is an independent platform with its own data layer, while Radiant's technology now belongs to Cribl. Exaforce's four Exabots detect, triage, investigate and respond over telemetry the platform ingests, with behavioral baselines for every identity and resource, and it closed a 125 million dollar Series B in May 2026. Radiant pairs triage with integrated log management, and Cribl acquired the technology behind the product in August 2026, though Radiant's site still sells it. On the grid Exaforce is Full on knowledge grounding, observability, prebuilt agents and workflow orchestration where Radiant is Partial; Radiant is Full on its API where Exaforce is None. Neither documents deployment and data residency. Choose Exaforce for the deeper documented platform; choose Radiant if the Cribl roadmap is the one you want.
On the Agentic Index AI SOC ranking, Exaforce clears the bar and Radiant Security does not. Exaforce documents all five investigation loop capabilities in full; Radiant Security does not document workflow orchestration in full, nor observability and auditability. 23 of the 85 vendors in the lane clear it. See the AI SOC ranking
This comparison is published by Agentic Index, an independent agentic AI vendor research platform. Exaforce and Radiant Security are each graded against the same 14 capability Agentic Index taxonomy, from the vendor's own public materials under the Agentic Index verification standard, alongside 955 researched vendors. No vendor pays for placement and no vendor has reviewed this page. How this evidence is graded
Choose Exaforce if
- Investigations should reason over behavioral baselines; Exaforce is Full on knowledge and Radiant Partial.
- What the agents did must be observable in full.
- An independent vendor with fresh funding matters to you.
Choose Radiant Security if
- API access is needed; Radiant is Full and Exaforce None.
- You already run Cribl and want the product on that platform.
- Analyst confirmation on each response action is how you work.
| Feature | E Exaforce |
R Radiant Security |
|---|---|---|
| Action & orchestration | ||
|
Integrations & Tool Calling Ability to connect agents to real systems through native integrations, OAuth-authenticated actions, custom tools, APIs, webhooks, or MCP-compatible tools. |
||
|
ExaforceIntegrations & Tool Calling More than 120 integrations ingest and query the customer's sources, and Exabot Respond takes action in them. It quarantines endpoints and emails, isolates hosts, updates security groups, and suspends users, resets MFA and revokes sessions across Okta, Entra ID and AWS, and it acts on tickets in ServiceNow. The count now stands at 130+ integrations across 21 categories, from IaaS, SaaS, identity and code to SIEM, SOAR, MDM, HRIS and crypto infrastructure, and customers can request new ones. Response workflows can also call REST APIs and webhooks and use Perplexity for web search. SourceExaforce, exaforce.com/platform/integrations and /platform/exabot-respond; exaforce.com/platform/exabot-respondread 2026-10-05 |
||
|
Radiant SecurityIntegrations & Tool Calling Data connectors ingest from the customer's tools in categories that include authentication, cloud access security brokers, cloud, endpoint and network logs, email infrastructure and IAM, ICS and OT, messaging apps, password managers, SIEM tools, ticketing systems, security service edge, API protection and an S3 connector, and outgoing webhooks send data on. Response actions run from the case view in CrowdStrike, Microsoft 365 Defender, SentinelOne, Microsoft 365, Okta, Google Workspace, Mimecast, Proofpoint, Netskope and KnowBe4, isolating devices, disabling users, resetting passwords, ending sessions, deleting messages, removing external forwarding rules and blocking IPs, URLs, domains and files. They also start full disk scans in SentinelOne and enroll users in KnowBe4 phishing training. SourceRadiant Security, help.radiantsecurity.ai and /radiant-cases/radiant-cases/response-actionsread 2026-10-06 |
||
|
Workflow Orchestration Ability to sequence, branch, retry, route, and combine deterministic workflow nodes with autonomous agent steps. |
||
|
ExaforceWorkflow Orchestration Teams build response workflows in a visual drag and drop builder with nodes for conditions, actions, approvals, AI reasoning, loops and branching, and can mix autonomous and approved steps in one workflow, beside the Detect, Triage, Investigate and Respond Exabots. Deterministic steps sit beside reasoning nodes that interpret context. SourceExaforce, exaforce.com/platform/exabot-respondread 2026-10-05 |
||
|
Radiant SecurityWorkflow Orchestration Each alert runs through the product's own triage, investigation and case sequence, and response actions launch from the case, on one artifact or in bulk across selected users, IPs and URLs. The audit log mentions automated playbooks, but Radiant describes no branching, multi agent handoff or automation the customer configures. SourceRadiant Security, help.radiantsecurity.ai/radiant-cases/radiant-cases/response-actions-in-cases and /log-management/audit-logs/introduction-to-audit-logsread 2026-10-06 |
||
|
Triggers & Channel Coverage How agents wake up and where they work: schedules, webhooks, message events, CRM events, inbox events, chat, email, voice, and collaboration tools. |
||
|
ExaforceTriggers & Channel Coverage Detections and alerts from ingested telemetry start triage and investigation without a person asking, and response workflows trigger automatically, on a schedule or manually. Analysts can also start work by asking a hypothesis in plain language, and with the managed MDR option, Exaforce analysts and the Exabots run the SOC around the clock. SourceExaforce, exaforce.com/platform/exabot-respond and exaforce.comread 2026-10-05 |
||
|
Radiant SecurityTriggers & Channel Coverage Alerts arriving through data connectors or the custom alerts webhook are triaged and investigated automatically, with no analyst starting the work. Webhook alerts are posted as JSON with a token, enter the triage pipeline and become searchable within several minutes. SourceRadiant Security, help.radiantsecurity.ai/radiant-connectors/ingestion-methods/custom-alerts-webhookread 2026-10-06 |
||
| Knowledge & context | ||
|
Knowledge Grounding & RAG Ability to ground agent behavior in company data through document ingestion, retrieval, external knowledge APIs, semantic search, or RAG layers. |
||
|
ExaforceKnowledge Grounding & RAG A semantic model builds and maintains relationships between the customer's identities, resources and actions as a living map of the environment, over a data platform that ingests and normalizes the customer's security data, with the customer's business context (org structure, policies, roles) layered in. The knowledge model blends technical expertise, curated outside intelligence and awareness of the environment, drawing on LLM reasoning, past decisions and fixed business rules. The data platform covers cloud, SaaS, identity, code and endpoint data. SourceExaforce, exaforce.com/platform/multi-model-airead 2026-10-05 |
||
|
Radiant SecurityKnowledge Grounding & RAG Integrated log management stores the customer's logs with search, query and retention settings, and alerts sent through the custom webhook land in its parsed and alert indexes, where teams can search and investigate them. Radiant says the platform continuously learns the environment, its tooling, behavior and activity to boost accuracy, but it does not say how investigations draw on what it has learned or on the customer's own documentation. SourceRadiant Security, radiantsecurity.ai, help.radiantsecurity.ai/log-management/log-search-and-query and /radiant-connectors/ingestion-methods/custom-alerts-webhookread 2026-10-06 |
||
|
Memory & State Persistence Ability to persist context across a run, conversation, workflow, user, team, or longer-term memory layer. |
||
|
ExaforceMemory & State Persistence The knowledge model draws on historic decisions, user confirmations and outcomes, so state carries across investigations, and the semantic model stores context in a structured form. Exaforce sets out no scope or retention period for that store. SourceExaforce, exaforce.com/platform/multi-model-airead 2026-10-05 |
||
|
Radiant SecurityMemory & State Persistence The platform continuously learns about the environment, its tooling, behavior and activity to boost accuracy, by Radiant's account, but Radiant describes no memory store, what it would keep, its scope or its lifetime. SourceRadiant Security, radiantsecurity.ai and help.radiantsecurity.airead 2026-10-06 |
||
| Control & trust | ||
|
Human Oversight & Guardrails Approval steps, consent checkpoints, escalation rules, structured guardrails, policy constraints, and pause/resume controls. |
||
|
ExaforceHuman Oversight & Guardrails Response workflows can require human approval through Slack, Teams or email before an action runs, with timeouts falling back to safe defaults (pause, rollback or limited containment), and Exaforce calls its responses approved and reversible. Ready made prompts ask users and managers to confirm with buttons, timeouts and automatic escalation, and Exabot Respond is sold as automated action with analyst oversight. SourceExaforce, exaforce.com/platform/exabot-respond and exaforce.comread 2026-10-05 |
||
|
Radiant SecurityHuman Oversight & Guardrails Response actions launched from a case run when an analyst selects the targets, clicks the action and confirms the list of affected artifacts in a confirmation step, and many can be reversed with one click from the action history through the inverse action, such as enabling a user again. Hard deletes and password resets cannot be undone. The platform produces incident specific response plans for that analyst to execute. The audit log separates analyst actions from automated platform actions and playbooks, and Radiant does not say which actions, if any, run without that confirmation. SourceRadiant Security, help.radiantsecurity.ai/radiant-cases/radiant-cases/response-actions-in-cases, /response-actions and /log-management/audit-logs/introduction-to-audit-logsread 2026-10-06 |
||
|
Security, Identity & Governance RBAC, SSO, auditability, encryption, least-privilege tool access, compliance posture, and data handling policy. |
||
|
ExaforceSecurity, Identity & Governance Exaforce names SOC 2 Type 2 and ISO 27001, with PCI DSS and HIPAA support and GDPR alignment. It gives no public detail on SSO, SCIM or roles. The product docs sit behind the app login, and the trust center is at trust.exaforce.com. System status is published at exaforcestatus.com. SourceExaforce, exaforce.com/blogs agentic SOC year in review and exaforce.comread 2026-10-05 |
||
|
Radiant SecuritySecurity, Identity & Governance SAML 2.0 SSO works with Okta, Google and Microsoft Entra ID and is enforced for all users once set, with an emergency bypass through support. Every user is assigned the Admin role, and Radiant names no SCIM provisioning. No compliance attestation is published, and a trust center sits at trust.radiantsecurity.ai. SourceRadiant Security, help.radiantsecurity.ai/manage-radiant/organization-settings/security/set-up-single-sign-on-ssoread 2026-10-06 |
||
|
Observability & Auditability Traces, logs, execution histories, metrics, audit events, and debugging detail for production agent behavior. |
||
|
ExaforceObservability & Auditability Every decision and approval in a response workflow is fully audited, and the team gets full visibility into every decision and action the Exabots take, with investigations shown in case context and explainable anomaly scores. Results come back as clear summaries with supporting evidence, so analysts and auditors see the reasoning behind each answer. SourceExaforce, exaforce.com/platform/exabot-respond and /platform/multi-model-airead 2026-10-05 |
||
|
Radiant SecurityObservability & Auditability Audit logs record who took action, what changed and when, with before and after values, across response actions, alert verdict changes, allow and deny list changes, deleted notes and data connector changes, and they tell analyst actions apart from automated platform actions. Configuration and administrative changes are not yet logged, and Radiant describes no record of the AI's investigation steps and reasoning. SourceRadiant Security, help.radiantsecurity.ai/log-management/audit-logs/introduction-to-audit-logsread 2026-10-06 |
||
|
Deployment & Data Residency Deployment modes and options, including SaaS, dedicated cloud, VPC, on-prem, hybrid, local runtime, and self-hosting. |
||
|
ExaforceDeployment & Data Residency Customers cannot choose a hosting region or run the platform in their own environment, and the login host carries a us label. Self managed means the customer's team runs the SOC on Exaforce's platform, not that the customer hosts the software, and with the managed MDR option Exaforce analysts run it as a 24/7 SOC. The product docs at docs.exaforce.com sit behind the app login, and a trust center runs at trust.exaforce.com. SourceExaforce, exaforce.com and trust.exaforce.comread 2026-10-05 |
||
|
Radiant SecurityDeployment & Data Residency How the product is hosted is not described, and no hosting region, choice of region or customer environment option is published. SourceRadiant Security, radiantsecurity.ai and help.radiantsecurity.ai; trust.radiantsecurity.ai/resourcesread 2026-10-06 |
||
| Solution readiness | ||
|
Prebuilt Agents, Templates & Packs Ready-made workflows, packaged employees, templates, blueprints, industry solutions, and role-specific agents that reduce time-to-value. |
||
|
ExaforcePrebuilt Agents, Templates & Packs Four named prebuilt agents have separate jobs. Exabot Detect, Exabot Triage, Exabot Investigate and Exabot Respond each do their own stage of SOC work. Exabot Respond comes with playbooks for common scenarios, and new ones can be written in natural language. Exaforce also sells the platform as a managed MDR service. SourceExaforce, exaforce.com and /platform/exabot-respondread 2026-10-05 |
||
|
Radiant SecurityPrebuilt Agents, Templates & Packs One AI SOC analyst with incident response and log management around it covers many alert types out of the box, triaging every security alert across endpoint, identity, email, network and cloud. These are parts of one product, with no separate prebuilt agents or templates to adopt. Named customers include Nutcracker Therapeutics, Spellman High Voltage Electronics, Kyowa Kirin and Second Wave Delivery Systems. SourceRadiant Security, radiantsecurity.ai and help.radiantsecurity.airead 2026-10-06 |
||
| Platform extensibility | ||
|
Model Flexibility & Routing Ability to work across multiple foundation models, route tasks to different models, or let buyers bring their own providers and keys. |
||
|
ExaforceModel Flexibility & Routing Exaforce combines its own semantic, behavioral and knowledge models with LLMs from providers it does not name, and customers cannot choose the model. The LLMs act as the reasoning layer and take validated entities and calculated scores as input, which Exaforce says keeps them from hallucinating. The behavioral model learns what normal looks like for every entity and produces explainable anomaly scores. SourceExaforce, exaforce.com/platform/multi-model-airead 2026-10-05 |
||
|
Radiant SecurityModel Flexibility & Routing The models and providers behind Radiant's AI are not disclosed, and no model choice is offered. SourceRadiant Security, radiantsecurity.ai and help.radiantsecurity.airead 2026-10-06 |
||
|
APIs, SDKs & MCP Extensibility Composability layer: stable APIs, SDKs, MCP tool consumption/serving, custom tools, and integration into internal systems. |
||
|
ExaforceAPIs, SDKs & MCP Extensibility There is no public API, SDK or MCP server for the platform, and the product docs at docs.exaforce.com sit behind the app login. Customers who need a source that is not listed can request an integration from the team that builds them. SourceExaforce, exaforce.com/platform/integrationsread 2026-10-05 |
||
|
Radiant SecurityAPIs, SDKs & MCP Extensibility The custom alerts webhook has a published endpoint, a token sent in the authorization header and a JSON body carrying timestamp, alert ID and raw alert fields, for sending alerts from sources without a dedicated connector. Radiant has announced an API for automating operational work, but no API reference beyond the webhook is published. SourceRadiant Security, help.radiantsecurity.ai/radiant-connectors/ingestion-methods/custom-alerts-webhookread 2026-10-06 |
||
|
Testing, Debugging & Optimization Testing, debugging, scoring, retries, fallbacks, quality gates, and optimization loops for improving agent workflows before and after deployment. |
||
|
ExaforceTesting, Debugging & Optimization The Exabots come with no evaluation harness, scored test cases, quality gate or optimization loop. Exaforce claims 90% fewer false positives, 95% less time to investigate, under 30 minutes from alert to response and more than $600K average savings against a traditional SOC stack. SourceExaforce, exaforce.comread 2026-10-05 |
||
|
Radiant SecurityTesting, Debugging & Optimization Claimed results are triage with the quality of a team's best analyst at any scale and response times cut from days to minutes, both Radiant's own figures. Radiant describes no evaluation harness, scored test cases, quality gate or optimization loop the customer runs. SourceRadiant Security, radiantsecurity.ai and help.radiantsecurity.airead 2026-10-06 |
||
| Specialist automation | ||
|
Browser & Computer Use Browser, desktop, or remote/local computer control for workflows that cannot be handled through stable APIs alone. |
||
|
ExaforceBrowser & Computer Use Agents act through integrations, and no Exabot drives a browser, desktop or remote computer. Exabot Investigate hunts without the analyst writing SIEM queries. SourceExaforce, exaforce.comread 2026-10-05 |
||
|
Radiant SecurityBrowser & Computer Use The AI works through data connectors and response actions inside the customer's security and identity tools. Radiant describes no use of a browser, desktop or remote computer. SourceRadiant Security, radiantsecurity.ai and help.radiantsecurity.ai/radiant-cases/radiant-cases/response-actionsread 2026-10-06 |
||
Pricing snapshot
Sourced from the Index pricing dataset · open each vendor's profile for full detail.
| Pricing | E Exaforce |
R Radiant Security |
|---|---|---|
|
Entry price Lowest public entry point |
Contact sales; enterprise contracts, positioned to offset SIEM cost | Contact sales; enterprise contracts with optional integrated log management |
|
Pricing confidence How public the numbers are |
Contact only | Contact only |
|
Billing Primary billing axis |
enterprise contract | enterprise contract |
|
Variable cost Workload / overage exposure |
Medium variable cost | Low variable cost |
|
Free tier / trial Try before you buy |
No free tierTrial
|
No free tierTrial
|
|
Buying motion Self-serve vs sales call |
Sales call | Sales call |
Cribl acquired the technology and intellectual property behind Radiant's AI SOC product in August 2026 and plans to run it as an application on its telemetry platform. Radiant's own site still sells the product and does not mention the deal, so ask who will support the contract and on what roadmap.
More comparisons with Exaforce or Radiant Security
Other matchups in security and SOC agents
Not the pairing you were after? These compare a different set of security and SOC agents on the same 14 capabilities.