Andesite
Also known as: Andesite, Andesite AI, Bionic SOC, The Human+AI SOC
Bionic SOC: a human-AI collaboration platform that automates triage, enrichment, and investigation across 100% of alerts while analysts oversee workflows and own critical decisions. Context-Aware AI consolidates fragmented data silos, Evidentiary AI makes every decision auditable and explainable, and compliance aligns to SOC 2 Type I, NIST 800-53 High, NIST CSF, and the NIST AI RMF, with FedRAMP High in process. Founded by former CIA Special Activities Center director Brian Carbaugh; $38.25M raised from General Catalyst and Red Cell; national security, financial services, and healthcare traction.
Andesite builds the bionic SOC, a human-AI collaboration platform for cyber defense teams that automates triage, enrichment, and investigation across 100% of alerts while analysts oversee the workflows and own the critical decisions. Context-Aware AI aggregates data from across distributed IT environments and consolidates fragmented silos, giving analysts the context and visibility to make informed decisions in actionable output; adaptive automation streamlines workflows spanning threat intelligence to response. Analysts can extract attack techniques (TTPs) from a security bulletin and scan their environment for them in minutes rather than hours or days. The design philosophy is explicit augmentation rather than replacement: the company argues security analysts are irreplaceable for intuitive pattern recognition and creative judgment, and its stated vision is a symbiotic relationship that elevates analysts of every skill level. Evidentiary AI makes every AI-driven decision auditable and explainable with no black boxes, and a secure AI architecture keeps sensitive data within predefined boundaries, never used to train external models. Built-in compliance aligns to SOC 2 Type I, NIST 800-53 (High), NIST CSF, and the NIST AI Risk Management Framework for regulated environments, and the company achieved FedRAMP High In Process designation in January 2026 for public sector work. Founded by former CIA Special Activities Center director Brian Carbaugh with a leadership bench of CIA, NSA-adjacent, JPMorgan, and Salesforce security veterans, and Chris Inglis, the former US National Cyber Director, on its board, Andesite has traction in national security, financial services, and healthcare, with a growing MSSP motion. Within the AI-SOC-analyst cluster, Andesite is the analyst-augmentation entrant with the deepest national-security pedigree and an evidence-first governance story.
Vendor details
Canonical URL
https://andesite.ai
Category
Security / SOC agent
Funding status
Independent McLean, Virginia company founded 2023 by Brian Carbaugh (CEO, former Director of the CIA's Special Activities Center) and Grant Verstandig, incubated by Red Cell Partners' Cyber Practice and General Catalyst; $38.25M total seed funding ($15.25M Apr 2024 + $23M Feb 2025); leadership includes CPO William MacMillan (former CIA CISO, Salesforce SVP InfoSec), CSO Greg Rattray (former JPMorgan Chase CISO), CTO Alex Thaman (ex-Unity, Microsoft); former US National Cyber Director Chris Inglis on the board; traction in national security, financial services, and healthcare
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Connects disparate data sources, security tools, and platforms across the SOC ecosystem, unifying alerts and consolidating fragmented data silos so analysts stop toggling between tools and learning countless query languages. Detailed named-integration lists are not published in retrieved materials; the platform's value proposition is the unified data and investigation layer over whatever stack is present.
Sources & related URLs
Research sources
Capability coverage
5.5 / 14 capabilities · 39%
| Integrations & Tool CallingConnects disparate data sources, security tools, and platforms across the SOC ecosystem, unifying alerts and eliminating tool-toggling; a detailed named-integration list was not retrieved, Andesite launch materials 2026-07-22 | Partial |
|---|---|
| Workflow OrchestrationAutomates triage, enrichment, and investigation across 100% of alerts with agentic AI, with adaptive automation streamlining workflows from threat intelligence to response, IT-Harvest vendor profile and Andesite launch materials 2026-07-22 | Full |
| Knowledge Grounding & RAGContext-Aware AI consolidates fragmented data silos across distributed environments and extracts TTPs from threat intelligence for environment scanning, Andesite launch materials 2026-07-22 | Partial |
| Human Oversight & GuardrailsAnalysts oversee the workflows and own the critical decisions while AI handles triage, enrichment, and investigation; augmentation-not-replacement is the stated design philosophy, IT-Harvest profile and Andesite materials 2026-07-22 | Partial |
| Security, Identity & GovernanceCompliance aligned to SOC 2 Type I, NIST 800-53 (High), NIST CSF, and the NIST AI RMF, with FedRAMP High In Process (Jan 2026) and a secure AI architecture keeping data within predefined boundaries; product-level RBAC not documented, Andesite press materials 2026-07-22 | Partial |
| Observability & AuditabilityEvidentiary AI makes every AI-driven decision auditable and explainable with no black boxes, and there is full visibility into decisions made by the AI systems, AIM Media House and MSSP Alert coverage 2026-07-22 | Full |
| Memory & State PersistenceNo persistent environmental memory, learning store, or state retention documented in retrieved materials, Andesite materials 2026-07-22 | Unable to verify |
| Deployment & Data ResidencySmooth deployment in regulated environments with sensitive data kept within predefined boundaries and never used to train external models, on a FedRAMP High path for public sector, Andesite press materials 2026-07-22 | Partial |
| Prebuilt Agents, Templates & PacksNo prebuilt agent, template, or pack surface documented in retrieved materials, Andesite materials 2026-07-22 | Unable to verify |
| Triggers & Channel CoverageCovers 100% of alerts with automated triage, enrichment, and investigation, supporting both reactive alert handling and proactive threat hunting, IT-Harvest vendor profile 2026-07-22 | Full |
| Model Flexibility & RoutingNo customer-facing model choice or routing documented; the platform's AI is internal to the product, Andesite materials 2026-07-22 | Unable to verify |
| APIs, SDKs & MCP ExtensibilityNo public API, SDK, or MCP surface documented in retrieved materials, Andesite materials 2026-07-22 | Unable to verify |
| Testing, Debugging & OptimizationNo customer-facing testing, evaluation, or optimization capability documented in retrieved materials, Andesite materials 2026-07-22 | Unable to verify |
| Browser & Computer UseNo browser or computer-use capability documented; Andesite operates on unified alert and investigation data, Andesite materials 2026-07-22 | Unable to verify |
Pricing
Contact sales
scope of SOC alert volume and environments under the bionic SOC platform
What is public
The platform capabilities (100% alert coverage, Context-Aware AI, Evidentiary AI, adaptive automation) and compliance alignments (SOC 2 Type I, NIST 800-53 High, NIST CSF, NIST AI RMF, FedRAMP High in process) are public; no plans, tiers, or dollar amounts are disclosed.
Variable cost rationale
Cost scales with alert volume and the number of environments and data sources unified under the platform, growing with organization size and detection coverage.
Sales call required
Yes — required for paid access
Free / trial
Not published
Related vendors
- 7AI — Swarming agentic SOC from the Cybereason founders: sixty plus domain…
- AirMDR — AI-native MDR built around a Virtual Analyst that triages 95% of…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Assail — Autonomous red teaming platform (Ares) whose AI agents discover,…
- Astelia — AI native exposure management platform from Israeli National Red…
- BlinkOps — Agentic security operations platform running a digital workforce of…