Agentic Index
Qevlar AI vs Radiant Security (2026)
Qevlar AI and Radiant Security both investigate the alerts a SOC's tools raise and neither publishes a price. That verdict is the Agentic Index coverage score, graded from each vendor's own published materials.
Qevlar is built for reproducible investigations, and Radiant for triage beside a log store. Qevlar is a Paris company whose core reasoning runs in a graph orchestrator rather than a language model, aimed at reproducible tier two and three investigations in about three minutes, and it says it runs at more than 1,500 organizations, many through managed security providers. Radiant pairs triage with integrated log management as a SIEM cost alternative; Cribl acquired the technology behind the product in August 2026, though Radiant's site still sells it. On the grid Qevlar is Full on deployment, observability and security where Radiant is Partial or unknown; Radiant is Full on human oversight, with analyst confirmed response actions, where Qevlar is Partial. Choose Qevlar for reproducible, documented investigation; choose Radiant if analyst sign off on every action and a bundled log store matter most.
On the Agentic Index AI SOC ranking, neither Qevlar AI nor Radiant Security clears the bar, which asks for all five investigation loop capabilities documented in full. Qevlar AI does not document workflow orchestration in full, nor human oversight and guardrails; Radiant Security does not document workflow orchestration in full, nor observability and auditability. 23 of the 85 vendors in the lane clear it. See the AI SOC ranking
This comparison is published by Agentic Index, an independent agentic AI vendor research platform. Qevlar AI and Radiant Security are each graded against the same 14 capability Agentic Index taxonomy, from the vendor's own public materials under the Agentic Index verification standard, alongside 955 researched vendors. No vendor pays for placement and no vendor has reviewed this page. How this evidence is graded
Choose Qevlar AI if
- Investigations should be reproducible, with reasoning in a graph rather than a language model.
- You run or buy through a managed security provider.
- Deployment and security must be documented in full; Qevlar is Full on both.
Choose Radiant Security if
- Every response action should wait for an analyst to confirm it; Radiant is Full on oversight and Qevlar Partial.
- Integrated log management could offset SIEM spend.
- The Cribl transition fits your telemetry plans.
| Feature | Q Qevlar AI |
R Radiant Security |
|---|---|---|
| Action & orchestration | ||
|
Integrations & Tool Calling Ability to connect agents to real systems through native integrations, OAuth-authenticated actions, custom tools, APIs, webhooks, or MCP-compatible tools. |
||
|
Qevlar AIIntegrations & Tool Calling More than 50 API based integrations cover Microsoft Defender, Sentinel and Entra ID, CrowdStrike, Splunk, Elastic, AWS, Okta, Palo Alto, ServiceNow, Jira, Tines and others, with response actions such as blocking a suspicious IP or contacting the user. They span SIEM, SOAR and ticketing, EDR and XDR, email, identity, threat intel, malware sandboxes, cloud and network tools, including Cortex XSIAM and XSOAR, Google SecOps, SentinelOne, Proofpoint, Mimecast, Zscaler and VirusTotal. After an investigation, Qevlar moves to the next action, whether containment for malicious activity, tuning for false positives, or a policy or compliance follow up. SourceQevlar AI, qevlar.com/integrations and qevlar.comread 2026-10-05 |
||
|
Radiant SecurityIntegrations & Tool Calling Data connectors ingest from the customer's tools in categories that include authentication, cloud access security brokers, cloud, endpoint and network logs, email infrastructure and IAM, ICS and OT, messaging apps, password managers, SIEM tools, ticketing systems, security service edge, API protection and an S3 connector, and outgoing webhooks send data on. Response actions run from the case view in CrowdStrike, Microsoft 365 Defender, SentinelOne, Microsoft 365, Okta, Google Workspace, Mimecast, Proofpoint, Netskope and KnowBe4, isolating devices, disabling users, resetting passwords, ending sessions, deleting messages, removing external forwarding rules and blocking IPs, URLs, domains and files. They also start full disk scans in SentinelOne and enroll users in KnowBe4 phishing training. SourceRadiant Security, help.radiantsecurity.ai and /radiant-cases/radiant-cases/response-actionsread 2026-10-06 |
||
|
Workflow Orchestration Ability to sequence, branch, retry, route, and combine deterministic workflow nodes with autonomous agent steps. |
||
|
Qevlar AIWorkflow Orchestration A graph based orchestrator, not an LLM, runs each investigation along structured, reproducible paths across the stack and follows the customer's procedures. It connects related activity into a single incident story, maps the full blast radius and moves containment forward. There is no branching, conditions, multiple agents or flow that customers build, and each investigation follows the product's own pipeline. SourceQevlar AI, qevlar.comread 2026-10-05 |
||
|
Radiant SecurityWorkflow Orchestration Each alert runs through the product's own triage, investigation and case sequence, and response actions launch from the case, on one artifact or in bulk across selected users, IPs and URLs. The audit log mentions automated playbooks, but Radiant describes no branching, multi agent handoff or automation the customer configures. SourceRadiant Security, help.radiantsecurity.ai/radiant-cases/radiant-cases/response-actions-in-cases and /log-management/audit-logs/introduction-to-audit-logsread 2026-10-06 |
||
|
Triggers & Channel Coverage How agents wake up and where they work: schedules, webhooks, message events, CRM events, inbox events, chat, email, voice, and collaboration tools. |
||
|
Qevlar AITriggers & Channel Coverage New alerts from across the security stack start investigations with no analyst initiating them, alerts can be pushed in through POST /alert, and hunts run continuously. A pushed alert is accepted at once with a PENDING status. Hunt queries are written and run across the SIEM and EDR automatically, and the platform works around the clock. SourceQevlar AI, help.qevlar.com SOC Workflow Integration API and qevlar.com/soc-and-vulnerabilityread 2026-10-05 |
||
|
Radiant SecurityTriggers & Channel Coverage Alerts arriving through data connectors or the custom alerts webhook are triaged and investigated automatically, with no analyst starting the work. Webhook alerts are posted as JSON with a token, enter the triage pipeline and become searchable within several minutes. SourceRadiant Security, help.radiantsecurity.ai/radiant-connectors/ingestion-methods/custom-alerts-webhookread 2026-10-06 |
||
| Knowledge & context | ||
|
Knowledge Grounding & RAG Ability to ground agent behavior in company data through document ingestion, retrieval, external knowledge APIs, semantic search, or RAG layers. |
||
|
Qevlar AIKnowledge Grounding & RAG Investigations correlate telemetry and threat intelligence from the connected stack and draw on an organizational context of past investigations. For each MSSP client, the provider sets the enrichment and context sources Qevlar uses in every investigation, along with that client's business context. There is no index or graph that Qevlar maintains over the customer's own knowledge. SourceQevlar AI, qevlar.com and qevlar.com/solutions/msspsread 2026-10-05 |
||
|
Radiant SecurityKnowledge Grounding & RAG Integrated log management stores the customer's logs with search, query and retention settings, and alerts sent through the custom webhook land in its parsed and alert indexes, where teams can search and investigate them. Radiant says the platform continuously learns the environment, its tooling, behavior and activity to boost accuracy, but it does not say how investigations draw on what it has learned or on the customer's own documentation. SourceRadiant Security, radiantsecurity.ai, help.radiantsecurity.ai/log-management/log-search-and-query and /radiant-connectors/ingestion-methods/custom-alerts-webhookread 2026-10-06 |
||
|
Memory & State Persistence Ability to persist context across a run, conversation, workflow, user, team, or longer-term memory layer. |
||
|
Qevlar AIMemory & State Persistence When analysts override a verdict and add context, Qevlar applies it to future cases, and an organizational context keeps past investigations, so state carries across cases. That knowledge stays in the platform as shared intelligence when analysts move on, and each investigation sharpens the next. Qevlar does not say how widely that store applies or how long it is kept. SourceQevlar AI, qevlar.comread 2026-10-05 |
||
|
Radiant SecurityMemory & State Persistence The platform continuously learns about the environment, its tooling, behavior and activity to boost accuracy, by Radiant's account, but Radiant describes no memory store, what it would keep, its scope or its lifetime. SourceRadiant Security, radiantsecurity.ai and help.radiantsecurity.airead 2026-10-06 |
||
| Control & trust | ||
|
Human Oversight & Guardrails Approval steps, consent checkpoints, escalation rules, structured guardrails, policy constraints, and pause/resume controls. |
||
|
Qevlar AIHuman Oversight & Guardrails Investigations follow the customer's procedures with analyst control, and analysts can override any verdict and add context. Analysts review alerts judged malicious, confirm the outcome and take the next steps Qevlar suggests. No approval step comes before a response action runs. SourceQevlar AI, qevlar.com and qevlar.com/productread 2026-10-05 |
||
|
Radiant SecurityHuman Oversight & Guardrails Response actions launched from a case run when an analyst selects the targets, clicks the action and confirms the list of affected artifacts in a confirmation step, and many can be reversed with one click from the action history through the inverse action, such as enabling a user again. Hard deletes and password resets cannot be undone. The platform produces incident specific response plans for that analyst to execute. The audit log separates analyst actions from automated platform actions and playbooks, and Radiant does not say which actions, if any, run without that confirmation. SourceRadiant Security, help.radiantsecurity.ai/radiant-cases/radiant-cases/response-actions-in-cases, /response-actions and /log-management/audit-logs/introduction-to-audit-logsread 2026-10-06 |
||
|
Security, Identity & Governance RBAC, SSO, auditability, encryption, least-privilege tool access, compliance posture, and data handling policy. |
||
|
Qevlar AISecurity, Identity & Governance The platform supports SSO integration, with role based access and mandatory MFA on internal and production access, and holds a SOC 2 Type II attestation for the Security criteria. Data is encrypted with AES-256 at rest and TLS 1.2 or higher in transit, with keys held in GCP KMS, and an outside firm runs a penetration test every year. Qevlar does not train its AI models on customer data, and it notifies customers within 72 hours of confirming a personal data breach. SourceQevlar AI, help.qevlar.com Data Privacy and Protection FAQsread 2026-10-05 |
||
|
Radiant SecuritySecurity, Identity & Governance SAML 2.0 SSO works with Okta, Google and Microsoft Entra ID and is enforced for all users once set, with an emergency bypass through support. Every user is assigned the Admin role, and Radiant names no SCIM provisioning. No compliance attestation is published, and a trust center sits at trust.radiantsecurity.ai. SourceRadiant Security, help.radiantsecurity.ai/manage-radiant/organization-settings/security/set-up-single-sign-on-ssoread 2026-10-06 |
||
|
Observability & Auditability Traces, logs, execution histories, metrics, audit events, and debugging detail for production agent behavior. |
||
|
Qevlar AIObservability & Auditability Every verdict is transparent. Analysts see every step and every observable queried in the investigation, and audit logs are kept for up to 12 months. Full investigation reports can go straight to a SOAR or ticketing system or be read inside Qevlar, and actions can be traced for compliance. SourceQevlar AI, qevlar.com, qevlar.com/solutions/mssps and help.qevlar.com Data Privacy and Protection FAQsread 2026-10-05 |
||
|
Radiant SecurityObservability & Auditability Audit logs record who took action, what changed and when, with before and after values, across response actions, alert verdict changes, allow and deny list changes, deleted notes and data connector changes, and they tell analyst actions apart from automated platform actions. Configuration and administrative changes are not yet logged, and Radiant describes no record of the AI's investigation steps and reasoning. SourceRadiant Security, help.radiantsecurity.ai/log-management/audit-logs/introduction-to-audit-logsread 2026-10-06 |
||
|
Deployment & Data Residency Deployment modes and options, including SaaS, dedicated cloud, VPC, on-prem, hybrid, local runtime, and self-hosting. |
||
|
Qevlar AIDeployment & Data Residency Primary hosting is Google Cloud in Belgium with LLM inference on Azure in Sweden, customer data retained in the EU, and a Bring Your Own Cloud deployment through which customers can choose another region. Bring Your Own Cloud runs on GCP or Azure, and Qevlar can run as SaaS or in a private cloud. Setup goes through APIs and usually takes a few hours, and the fastest so far took 10 minutes. Alert data is deleted 60 days after a contract ends unless agreed otherwise. SourceQevlar AI, help.qevlar.com Data Privacy and Protection FAQs, qevlar.com/product and qevlar.com/solutions/msspsread 2026-10-05 |
||
|
Radiant SecurityDeployment & Data Residency How the product is hosted is not described, and no hosting region, choice of region or customer environment option is published. SourceRadiant Security, radiantsecurity.ai and help.radiantsecurity.ai; trust.radiantsecurity.ai/resourcesread 2026-10-06 |
||
| Solution readiness | ||
|
Prebuilt Agents, Templates & Packs Ready-made workflows, packaged employees, templates, blueprints, industry solutions, and role-specific agents that reduce time-to-value. |
||
|
Qevlar AIPrebuilt Agents, Templates & Packs One platform covers investigation, threat hunting, detection engineering and vulnerability prioritization, and Qevlar sells these as parts of one product, not as separate prebuilt agents or templates. The vulnerability agents, still in preview, blend CVE intelligence with live SOC signal into a contextual severity score, find each asset's owner from ITSM, identity provider and EDR records, and write and run threat hunts across the SIEM and EDR. Qevlar packages the product for phishing, network, identity and cloud alerts, and MSSPs get a separate tenant for each client with its own investigations and settings. SourceQevlar AI, qevlar.com, qevlar.com/soc-and-vulnerability and qevlar.com/solutions/msspsread 2026-10-05 |
||
|
Radiant SecurityPrebuilt Agents, Templates & Packs One AI SOC analyst with incident response and log management around it covers many alert types out of the box, triaging every security alert across endpoint, identity, email, network and cloud. These are parts of one product, with no separate prebuilt agents or templates to adopt. Named customers include Nutcracker Therapeutics, Spellman High Voltage Electronics, Kyowa Kirin and Second Wave Delivery Systems. SourceRadiant Security, radiantsecurity.ai and help.radiantsecurity.airead 2026-10-06 |
||
| Platform extensibility | ||
|
Model Flexibility & Routing Ability to work across multiple foundation models, route tasks to different models, or let buyers bring their own providers and keys. |
||
|
Qevlar AIModel Flexibility & Routing Core reasoning runs in Qevlar's graph orchestrator, and LLMs handle narrow tasks such as enrichment and summaries on Azure inference in Sweden. Qevlar chose that single provider, and customers cannot choose a model. Inference stays under EU and EEA processing, and customer data is not used for training. SourceQevlar AI, help.qevlar.com Data Privacy and Protection FAQs and qevlar.comread 2026-10-05 |
||
|
Radiant SecurityModel Flexibility & Routing The models and providers behind Radiant's AI are not disclosed, and no model choice is offered. SourceRadiant Security, radiantsecurity.ai and help.radiantsecurity.airead 2026-10-06 |
||
|
APIs, SDKs & MCP Extensibility Composability layer: stable APIs, SDKs, MCP tool consumption/serving, custom tools, and integration into internal systems. |
||
|
Qevlar AIAPIs, SDKs & MCP Extensibility A REST API at api.qevlar.com with Bearer token auth submits alerts (POST /alert), returns investigation status and results (GET /alert/{id}), and publishes its reference at api.qevlar.com/redoc. A new alert returns an alert ID with a PENDING status, a status check returns IN_PROGRESS, FAILURE or the full results, and rate limits follow the subscription plan. SourceQevlar AI, help.qevlar.com SOC Workflow Integration APIread 2026-10-05 |
||
|
Radiant SecurityAPIs, SDKs & MCP Extensibility The custom alerts webhook has a published endpoint, a token sent in the authorization header and a JSON body carrying timestamp, alert ID and raw alert fields, for sending alerts from sources without a dedicated connector. Radiant has announced an API for automating operational work, but no API reference beyond the webhook is published. SourceRadiant Security, help.radiantsecurity.ai/radiant-connectors/ingestion-methods/custom-alerts-webhookread 2026-10-06 |
||
|
Testing, Debugging & Optimization Testing, debugging, scoring, retries, fallbacks, quality gates, and optimization loops for improving agent workflows before and after deployment. |
||
|
Qevlar AITesting, Debugging & Optimization Analyst overrides feed later cases. Customers have no evaluation harness, scored test cases, quality gate or optimization loop to run. Qevlar reports a 3 minute average alert investigation and up to 80% of tickets closed automatically, and says MSSPs using it report an average 300% return on investment. SourceQevlar AI, qevlar.com/product and qevlar.com/solutions/mssps; qevlar.comread 2026-10-05 |
||
|
Radiant SecurityTesting, Debugging & Optimization Claimed results are triage with the quality of a team's best analyst at any scale and response times cut from days to minutes, both Radiant's own figures. Radiant describes no evaluation harness, scored test cases, quality gate or optimization loop the customer runs. SourceRadiant Security, radiantsecurity.ai and help.radiantsecurity.airead 2026-10-06 |
||
| Specialist automation | ||
|
Browser & Computer Use Browser, desktop, or remote/local computer control for workflows that cannot be handled through stable APIs alone. |
||
|
Qevlar AIBrowser & Computer Use No agent drives a browser, desktop or remote computer. Investigations and actions run through API integrations, and results can go straight into the team's SOAR or ticketing tool. SourceQevlar AI, qevlar.com and qevlar.com/solutions/msspsread 2026-10-05 |
||
|
Radiant SecurityBrowser & Computer Use The AI works through data connectors and response actions inside the customer's security and identity tools. Radiant describes no use of a browser, desktop or remote computer. SourceRadiant Security, radiantsecurity.ai and help.radiantsecurity.ai/radiant-cases/radiant-cases/response-actionsread 2026-10-06 |
||
Pricing snapshot
Sourced from the Index pricing dataset · open each vendor's profile for full detail.
| Pricing | Q Qevlar AI |
R Radiant Security |
|---|---|---|
|
Entry price Lowest public entry point |
Contact sales; enterprise and MSSP contracts, no public rates | Contact sales; enterprise contracts with optional integrated log management |
|
Pricing confidence How public the numbers are |
Contact only | Contact only |
|
Billing Primary billing axis |
enterprise contract (MSSP packaging) | enterprise contract |
|
Variable cost Workload / overage exposure |
Low variable cost | Low variable cost |
|
Free tier / trial Try before you buy |
No free tierTrial
|
No free tierTrial
|
|
Buying motion Self-serve vs sales call |
Sales call | Sales call |
Cribl acquired the technology and intellectual property behind Radiant's AI SOC product in August 2026 and plans to run it as an application on its telemetry platform. Radiant's own site still sells the product and does not mention the deal, so ask who will support the contract and on what roadmap.
More comparisons with Qevlar AI or Radiant Security
Other matchups in security and SOC agents
Not the pairing you were after? These compare a different set of security and SOC agents on the same 14 capabilities.