Command Zero
Also known as: Command Zero Throughline
Command Zero is an autonomous AI SOC investigation platform: Agent Zero investigates alerts from a public library of 943 questions over read-only federated data, with customer-set sign-off on verdict types, an ordered audit record of every question and source, living Throughline investigations, and a public API and MCP server.
Command Zero is an autonomous AI SOC investigation platform. Agent Zero investigates security alerts end to end across identity, endpoint, cloud, email and SaaS sources, working from a public library of 943 investigative questions across 33 data sources that teams extend with Custom Questions, and an Agent Validator supervises its verdicts and flags edge cases. The platform connects to customer data through a federated, read-only model with no ingestion or migration.
Customers control which questions the agent may ask, which data sources it may touch and which verdict types require human sign-off; the agent documents findings rather than executing response actions on its own, and analysts run containment from remediation templates. Every investigation records the questions asked, data sources queried and artifacts considered, in order, and a knowledge base of enrichment data, analyst annotations and prior investigations grows with each case.
Throughline, introduced in July 2026, merges related alerts into living investigations that reopen, re-run their questions and re-examine the verdict as new alerts arrive. Since April 2026 a public API (investigations, business context, catalog and schema, remediation) and an MCP server with 25 tools let SOAR playbooks and assistants such as Claude start investigations and run remediation. The platform runs in autonomous and AI-assisted modes and holds SOC 2 Type 2.
Vendor details
Canonical URL
https://www.commandzero.ai
Category
Security / SOC agent
Funding status
Command Zero is independent and headquartered in Austin, Texas, with a presence in Calgary. It was co-founded by CEO Dov Yoran and CTO Dean De Beer, and it took a $10M strategic investment in July 2025 from Okta Ventures, SE Ventures and Crosspoint Capital (company release).
Company status
independent
Use cases & customers
Target customers
Deployment options
Integrations
Command Zero connects read-only to 33 data sources across identity, endpoint, cloud, email and SaaS, including AWS (EC2 and IAM, S3, GuardDuty and EKS), CrowdStrike Falcon, Microsoft Defender for Endpoint, Microsoft 365, Entra ID, GitHub Enterprise, Splunk, Flashpoint and FortiDLP, and imports detection logic from Splunk and CrowdStrike Next-Gen SIEM. A public API and an MCP server with 25 tools let SOAR playbooks, custom hunting frameworks and assistants such as Claude start investigations, add business context and run remediation.
In practice
Your tier 2 and tier 3 work depends on a handful of people who know each tool deeply. Custom Questions encodes that logic into repeatable investigative sequences so any analyst or agent reaches the same conclusion.
You have just acquired a company and have no visibility into its environment. The federated read only model connects to its existing data sources with no ingestion or migration, so investigations run on day one.
You want the platform inside your own pipelines rather than another console. The API endpoints and MCP server let SOAR playbooks, custom hunting frameworks and agents like Claude query the same governed, auditable data that produces every verdict.
Sources & related URLs
Research sources
Agentic Index coverage score
10.5 / 14 capabilities · 75%
| Integrations & Tool Calling | Full |
|---|---|
|
Command Zero makes federated read-only connections to 33 named data sources (among them AWS EC2 and IAM, S3, GuardDuty and EKS, CrowdStrike Falcon, Microsoft Defender for Endpoint, GitHub Enterprise, Microsoft 365, Entra ID, Splunk, Flashpoint and FortiDLP), SOAR playbooks start investigations, and remediation actions such as isolate, disable and block run from templates. Sourcecommandzero.ai/questionsread 2026-09-28 |
|
| Workflow Orchestration | Full |
|
Agent Zero investigates alerts end to end while an Agent Validator supervises its verdicts and flags edge cases, two vendor agents working together, and investigations are assembled from questions the customer can extend with Custom Questions. Sourcecommandzero.ai/agent-zeroread 2026-09-28 |
|
| Knowledge Grounding & RAG | Full |
|
Command Zero keeps a knowledge base that grows with every investigation, as enrichment data, watchlists, analyst annotations and prior investigation context accumulate across cases. Business Context APIs upload, list and retrieve customer context, and Throughline draws on prior investigations, analyst notes, company policies and asset inventories. Sourcecommandzero.ai/platformread 2026-09-28 |
|
| Human Oversight & Guardrails | Full |
|
Customers control "which verdict types require human sign-off", along with which questions the agent may ask and which data sources it may touch; Agent Zero documents findings and does not execute response actions on its own, and remediation runs from a template with an analyst's justification. Sourcecommandzero.ai/ai-soc-platformread 2026-09-28 |
|
| Security, Identity & Governance | Partial |
|
Command Zero holds SOC 2 Type 2 (announced 31 July 2025) and shows a SOC 2 footer mark. No SSO, role model or user permissions for the console are documented. The customer controlled agent policy governs the agent rather than console users. Sourcecommandzero.ai/press/command-zero-raises-10m-to-scale-ai-driven-cybersecurity-earns-top-security-certificationread 2026-09-28 |
|
| Observability & Auditability | Full |
|
Every investigation carries audit-grade documentation of all questions asked, data sources queried and artifacts considered, in order, and every action the agent takes is logged with inputs and outputs; the audit trail belongs to the customer. Sourcecommandzero.ai/agent-zeroread 2026-09-28 |
|
| Memory & State Persistence | Full |
|
Throughline merges related alerts into one living investigation with its evidence trail intact: when a new alert arrives the case reopens if closed, its time window extends, every question re-executes and the verdict is re-examined. That state persists and is scoped to the investigation, separate from the knowledge base. Sourceprnewswire.com/news-releases/command-zero-introduces-throughline-living-investigations-debut-at-black-hat-usa-2026-302831167.htmlread 2026-09-28 |
|
| Deployment & Data Residency | Partial |
|
A federated data model queries customer sources in place with no ingestion pipeline or parallel storage, so raw data stays where the customer holds it. The platform itself is vendor hosted, with no region list or customer-environment option documented. Sourcecommandzero.ai/platformread 2026-09-28 |
|
| Prebuilt Agents, Templates & Packs | Full |
|
Command Zero publishes a public, browsable Question Library of 943 named investigative questions across 33 data sources, each described, plus remediation templates; customers adopt them and extend with Custom Questions. Sourcecommandzero.ai/questionsread 2026-09-28 |
|
| Triggers & Channel Coverage | Full |
|
Alerts automatically start investigations around the clock, related alerts reopen a Throughline investigation, and SOAR playbooks can start investigations through the API when alerts fire. Sourcecommandzero.ai/agent-zeroread 2026-09-28 |
|
| Model Flexibility & Routing | Not documented |
|
No model provider, model choice or routing is named: Agent Zero is "a large language model orchestrating structured tool use under customer-controlled policy". Claude can reach the platform through the MCP server, but that does not offer a choice of model. Sourcecommandzero.ai/agent-zeroread 2026-09-28 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
A public API covers investigations (list, start, extend, update, retrieve), business context (list, upload, retrieve), catalog and schema, and remediation (list templates, execute actions), plus an MCP server with 25 tools and slash commands that start investigations and run remediation, published with scripts in a public GitHub recipes repository. How API and MCP access is authenticated is not published. Sourcecommandzero.ai/blog/the-command-zero-api-and-mcp-server-are-liveread 2026-09-28 |
|
| Testing, Debugging & Optimization | Partial |
|
An Agent Validator supervises Agent Zero's verdicts in production, flags edge cases and feeds mistakes back into retraining, a runtime check on the agent's output. No customer-facing harness or scored tests are documented, and the Throughline 41 percent figure comes from the vendor's own testing. Sourcecommandzero.ai/agent-zeroread 2026-09-28 |
|
| Browser & Computer Use | Not documented |
|
No browser or computer use is documented; the agent queries data sources through federated read-only connectors. Sourcecommandzero.ai/platformread 2026-09-28 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Pricing
Not published; quote only
not disclosed
What is public
Nothing on price is public. The Question Library, API and MCP release, and SOC 2 Type 2 status are public.
Billing mechanics
Command Zero sells a quote based enterprise subscription with no published rate card, tiers or billing unit.
Variable cost rationale
With no disclosed unit the exposure cannot be modeled, though the absence of data ingestion removes the storage cost escalation that usually accompanies scaling investigation coverage.
Additional watchouts
No billing unit is published, so whether cost tracks alerts, investigations, seats or data sources, and whether API and MCP access are included, has to be established with sales.
Sales call required
Yes, required for paid access
Free / trial
No published free tier or self serve trial; evaluation runs through a sales process
Commercial notes
Command Zero's federated read only architecture ingests and migrates nothing. Inference, not stated by the vendor: that removes storage and data pipeline spend from adoption, and an acquired environment can be brought into scope without an integration project.
Key ambiguities
No rate, tier or billing unit is published. Whether pricing tracks alert volume, investigations, analyst seats or connected data sources is unknown, and that distinction matters in a category where per alert pricing is a documented trap.
Missing data
Missing are the rate, tiers, billing unit, minimum commitment and whether the API and MCP access are included or separately licensed.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to Command Zero
The closest documented capability profiles to Command Zero among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- ReliaQuest10.0 / 14A lighter documented profile than Command Zero
- Cyware10.0 / 14Fuller documented coverage on Deployment & Data Residency
- 7AI8.5 / 14A lighter documented profile than Command Zero
- BlinkOps10.5 / 14Fuller documented coverage on Security, Identity & Governance and Deployment & Data Residency
- Conifers.ai9.5 / 14Fuller documented coverage on Deployment & Data Residency
- Drata10.5 / 14Fuller documented coverage on Security, Identity & Governance and Deployment & Data Residency
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded