Crogl
Autonomous alert and advisory investigation that runs inside the customer's environment (on-premises, private cloud or air-gapped) with a knowledge graph, playbook-free orchestration, a skills library, a full audit trail in the ticketing system and the customer's choice of LLM; free single-user edition, Enterprise by quote.
Crogl runs autonomous investigations of security alerts and threat intelligence advisories inside the customer's own environment. Alerts arriving from a SIEM, SOAR, ticketing system or any integrated source, and advisories such as CRISP reports, ISAC advisories and vendor bulletins, start investigations with no playbook, schema normalization or human trigger. A semantic knowledge graph maintains live context on the environment's entities, relationships and behaviors; an orchestration layer plans and executes each investigation, querying every data source in place in its own language; and a library of skills (threat hunting, alert investigation, report creation) covers the core SOC workflow, with a skill builder for new ones.
Every query, finding and decision is documented in the customer's ticketing system, and analysts review the evidence, override any step and make the call. Crogl deploys on-premises, in a private cloud or air-gapped, keeps data inside the customer's environment, and is model-agnostic, running the frontier, open weight or enterprise LLM service the customer chooses. A free single-user edition is available by request with a 30-day full-feature trial; Enterprise adds teams, OIDC SSO, role-based access, autonomous execution and audit log exports.
Vendor details
Canonical URL
https://www.crogl.com
Category
Security / SOC agent
Funding status
Independent; founded in 2023 by CEO Monzy Merza; $30M raised from Menlo Ventures, Tola Capital and S3 Ventures, with board members from Menlo Ventures and Tola Capital (company page).
Company status
independent
Use cases & customers
Target customers
Deployment options
Integrations
Connectors for Splunk, Microsoft Sentinel, CrowdStrike, ServiceNow, Jira, Databricks, Snowflake, Amazon S3 and Cribl, and all connectors for SIEMs, EDRs, identity providers, ticketing and threat intelligence feeds in every tier. Investigations are documented back into the customer's ticketing or case management system, and LLMs never see the secrets behind connectors.
In practice
Your team receives thousands of alerts a day and investigates a fraction of them. Crogl investigates every alert autonomously without a playbook and hands back a documented, decision ready case rather than a priority score.
Your data cannot leave your environment for regulatory reasons, which rules out most AI SOC overlays. Crogl runs against your own tools and workflows with data staying in place.
A new ISAC advisory lands. Crogl treats threat intelligence advisories as first class inputs alongside alerts and hunts against them rather than waiting for a matching detection to fire.
Sources & related URLs
Agentic Index coverage score
9.0 / 14 capabilities · 64%
| Integrations & Tool Calling | Full |
|---|---|
|
Named connectors for Splunk, Microsoft Sentinel, CrowdStrike, ServiceNow, Jira, Databricks, Snowflake, Amazon S3 and Cribl, with all connectors for SIEMs, EDRs, identity providers, ticketing and threat intelligence included in every tier; the agent queries each source in place in its own language, and LLMs never see connector secrets. Sourcecrogl.comread 2026-09-28 |
|
| Workflow Orchestration | Full |
|
An orchestration layer plans and executes the investigation workflow with no playbook, agents do the work across investigation, hunting and reporting, and a skill builder lets the team create new skills the orchestration uses. Sourcecrogl.com/productread 2026-09-28 |
|
| Knowledge Grounding & RAG | Full |
|
A semantic knowledge graph maintains live environmental context (entities, relationships and behaviors) that investigations draw on: a maintained retrieval structure over the customer's estate. Sourcecrogl.com/productread 2026-09-28 |
|
| Human Oversight & Guardrails | Partial |
|
"Your analyst reviews the evidence, overrides any step, and makes the call" and every action is visible and modifiable, so analysts keep the decision and can steer. No approve or confirm step before a generated response plan executes is described, and autonomous execution is listed as an Enterprise capability. Sourcecrogl.comread 2026-09-28 |
|
| Security, Identity & Governance | Partial |
|
Enterprise adds OIDC SSO and role-based access controls, with audit log exports, but they appear as two lines on a pricing page, and no attestation of Crogl's own is published. The SOC 2, ISO 27001 and NIST mentions describe frameworks its investigation records map to, and trust.crogl.com does not resolve. Sourcecrogl.com/pricingread 2026-09-28 |
|
| Observability & Auditability | Full |
|
Every investigation is documented in the customer's ticketing system with a complete audit trail of every query, finding and decision, logged in real time with full provenance, and every action is visible. Sourcecrogl.com/productread 2026-09-28 |
|
| Memory & State Persistence | Not documented |
|
The knowledge graph holds environmental context rather than agent memory, and the product says it learns from analyst feedback; no agent memory with a scope and lifetime is documented. Sourcecrogl.com/productread 2026-09-28 |
|
| Deployment & Data Residency | Full |
|
"On-premises. Private cloud. Air-gapped. Your choice." Crogl runs entirely within the customer's environment and data never leaves it, with deployments in air-gapped federal environments; the free edition installs on a single workstation. Sourcecrogl.com/productread 2026-09-28 |
|
| Prebuilt Agents, Templates & Packs | Full |
|
Ships a library of named skills covering the core SOC workflow (Threat Hunting, Alert Investigation, Report Creation), each doing its own job if another is removed, with a skill builder for more and unlimited reusable investigation playbooks in every tier. Sourcecrogl.com/productread 2026-09-28 |
|
| Triggers & Channel Coverage | Full |
|
Alerts arriving from the SIEM, SOAR, ticketing system or any integrated source start investigations, and threat intelligence advisories (CRISP reports, ISAC advisories, vendor bulletins) enter the same way as first-class inputs. Sourcecrogl.com/productread 2026-09-28 |
|
| Model Flexibility & Routing | Full |
|
"Crogl is model-agnostic. Choose the LLM that fits your security requirements" across frontier models, open weight models and enterprise LLM services, and Enterprise can use its own frontier model or open weight LLM service: customer model choice and bring your own model. Sourcecrogl.com/productread 2026-09-28 |
|
| APIs, SDKs & MCP Extensibility | Not documented |
|
Crogl documents no API, SDK, CLI or MCP server for calling it; the skill builder is in-product authoring, and connectors reach out to other systems rather than letting them call in. Sourcecrogl.com/productread 2026-09-28 |
|
| Testing, Debugging & Optimization | Not documented |
|
No harness, scored tests or evaluation of skills or investigations is documented; learning from analyst feedback is a claim, and the audit trail is a record of work rather than a test. Sourcecrogl.com/productread 2026-09-28 |
|
| Browser & Computer Use | Not documented |
|
The agent queries each data source in place through connectors; no browser or computer use is documented. Sourcecrogl.com/productread 2026-09-28 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Pricing
Free plan: $0 forever for one analyst per workspace, all connectors, unlimited skills and audit trail, with a 30-day full-feature trial. Enterprise: custom annual team contract.
Annual team-based contract (Enterprise); no per-alert, per-investigation or per-user fees stated.
What is public
The pricing page publishes the Free plan ($0, one analyst per workspace, all connectors, unlimited skills and audit trail, 30-day full-feature trial) and the Enterprise inclusions (teams, OIDC SSO, role-based access, customer's own LLM service, autonomous execution, audit log exports, 24/7 SLA). No Enterprise price is published.
Billing mechanics
Free plan with no expiration. Enterprise is an annual, team-based contract with unlimited investigations; the vendor states no per-alert, per-investigation or per-user fees.
Cost watchouts
Inference, not stated by the vendor: Crogl runs on the customer's infrastructure with the customer's chosen LLM service, so compute and model costs sit outside the Crogl contract.
Variable cost rationale
The vendor states no per-alert, per-investigation or per-user fees and unlimited investigations on Enterprise; the customer runs it on its own infrastructure and chosen LLM service, which carry their own costs.
Additional watchouts
Free downloads require an approved request, and autonomous execution, SSO and role-based access are Enterprise only.
Sales call required
Mixed (some tiers require a call)
Free / trial
Free plan at $0 forever (one analyst, username and password sign-in, community Slack support) with a 30-day full-feature trial; download requests are reviewed
Key ambiguities
The Enterprise price and what sets it (team size or environment) are not published, and free downloads are granted after a manual review of each request.
Missing data
Enterprise price, contract minimum and the unit behind the team-based model.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to Crogl
The closest documented capability profiles to Crogl among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- UnderDefense8.5 / 14A lighter documented profile than Crogl
- ThreatModeler10.0 / 14Adds documented APIs, SDKs & MCP Extensibility and Testing, Debugging & Optimization
- Andesite9.0 / 14Fuller documented coverage on Human Oversight & Guardrails and Security, Identity & Governance
- Ghost Security10.0 / 14Adds documented APIs, SDKs & MCP Extensibility
- StrikeReady7.0 / 14A lighter documented profile than Crogl
- Trent AI8.0 / 14Adds documented APIs, SDKs & MCP Extensibility
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded