Back to vendors
C

Crogl

Visit site
Entry priceFree plan: $0 forever for one analyst per workspace, all connectors, unlimited skills and audit trail, with a 30-day full-feature trial. Enterprise: custom annual team contract.Full pricing detail

Autonomous alert and advisory investigation that runs inside the customer's environment (on-premises, private cloud or air-gapped) with a knowledge graph, playbook-free orchestration, a skills library, a full audit trail in the ticketing system and the customer's choice of LLM; free single-user edition, Enterprise by quote.

Crogl runs autonomous investigations of security alerts and threat intelligence advisories inside the customer's own environment. Alerts arriving from a SIEM, SOAR, ticketing system or any integrated source, and advisories such as CRISP reports, ISAC advisories and vendor bulletins, start investigations with no playbook, schema normalization or human trigger. A semantic knowledge graph maintains live context on the environment's entities, relationships and behaviors; an orchestration layer plans and executes each investigation, querying every data source in place in its own language; and a library of skills (threat hunting, alert investigation, report creation) covers the core SOC workflow, with a skill builder for new ones.

Every query, finding and decision is documented in the customer's ticketing system, and analysts review the evidence, override any step and make the call. Crogl deploys on-premises, in a private cloud or air-gapped, keeps data inside the customer's environment, and is model-agnostic, running the frontier, open weight or enterprise LLM service the customer chooses. A free single-user edition is available by request with a 30-day full-feature trial; Enterprise adds teams, OIDC SSO, role-based access, autonomous execution and audit log exports.

Vendor details

Canonical URL

https://www.crogl.com

Category

Security / SOC agent

Funding status

Independent; founded in 2023 by CEO Monzy Merza; $30M raised from Menlo Ventures, Tola Capital and S3 Ventures, with board members from Menlo Ventures and Tola Capital (company page).

Company status

independent

Use cases & customers

Target customers

enterprise SOC teamsMSSPsgovernment

Deployment options

on-premisesprivate cloudair-gappedsingle workstation (free edition)

Integrations

Connectors for Splunk, Microsoft Sentinel, CrowdStrike, ServiceNow, Jira, Databricks, Snowflake, Amazon S3 and Cribl, and all connectors for SIEMs, EDRs, identity providers, ticketing and threat intelligence feeds in every tier. Investigations are documented back into the customer's ticketing or case management system, and LLMs never see the secrets behind connectors.

In practice

Your team receives thousands of alerts a day and investigates a fraction of them. Crogl investigates every alert autonomously without a playbook and hands back a documented, decision ready case rather than a priority score.

Your data cannot leave your environment for regulatory reasons, which rules out most AI SOC overlays. Crogl runs against your own tools and workflows with data staying in place.

A new ISAC advisory lands. Crogl treats threat intelligence advisories as first class inputs alongside alerts and hunts against them rather than waiting for a matching detection to fire.

Agentic Index coverage score

9.0 / 14 capabilities · 64%

Integrations & Tool Calling Full

Named connectors for Splunk, Microsoft Sentinel, CrowdStrike, ServiceNow, Jira, Databricks, Snowflake, Amazon S3 and Cribl, with all connectors for SIEMs, EDRs, identity providers, ticketing and threat intelligence included in every tier; the agent queries each source in place in its own language, and LLMs never see connector secrets.

Sourcecrogl.comread 2026-09-28

Workflow Orchestration Full

An orchestration layer plans and executes the investigation workflow with no playbook, agents do the work across investigation, hunting and reporting, and a skill builder lets the team create new skills the orchestration uses.

Sourcecrogl.com/productread 2026-09-28

Knowledge Grounding & RAG Full

A semantic knowledge graph maintains live environmental context (entities, relationships and behaviors) that investigations draw on: a maintained retrieval structure over the customer's estate.

Sourcecrogl.com/productread 2026-09-28

Human Oversight & Guardrails Partial

"Your analyst reviews the evidence, overrides any step, and makes the call" and every action is visible and modifiable, so analysts keep the decision and can steer. No approve or confirm step before a generated response plan executes is described, and autonomous execution is listed as an Enterprise capability.

Sourcecrogl.comread 2026-09-28

Security, Identity & Governance Partial

Enterprise adds OIDC SSO and role-based access controls, with audit log exports, but they appear as two lines on a pricing page, and no attestation of Crogl's own is published. The SOC 2, ISO 27001 and NIST mentions describe frameworks its investigation records map to, and trust.crogl.com does not resolve.

Sourcecrogl.com/pricingread 2026-09-28

Observability & Auditability Full

Every investigation is documented in the customer's ticketing system with a complete audit trail of every query, finding and decision, logged in real time with full provenance, and every action is visible.

Sourcecrogl.com/productread 2026-09-28

Memory & State Persistence Not documented

The knowledge graph holds environmental context rather than agent memory, and the product says it learns from analyst feedback; no agent memory with a scope and lifetime is documented.

Sourcecrogl.com/productread 2026-09-28

Deployment & Data Residency Full

"On-premises. Private cloud. Air-gapped. Your choice." Crogl runs entirely within the customer's environment and data never leaves it, with deployments in air-gapped federal environments; the free edition installs on a single workstation.

Sourcecrogl.com/productread 2026-09-28

Prebuilt Agents, Templates & Packs Full

Ships a library of named skills covering the core SOC workflow (Threat Hunting, Alert Investigation, Report Creation), each doing its own job if another is removed, with a skill builder for more and unlimited reusable investigation playbooks in every tier.

Sourcecrogl.com/productread 2026-09-28

Triggers & Channel Coverage Full

Alerts arriving from the SIEM, SOAR, ticketing system or any integrated source start investigations, and threat intelligence advisories (CRISP reports, ISAC advisories, vendor bulletins) enter the same way as first-class inputs.

Sourcecrogl.com/productread 2026-09-28

Model Flexibility & Routing Full

"Crogl is model-agnostic. Choose the LLM that fits your security requirements" across frontier models, open weight models and enterprise LLM services, and Enterprise can use its own frontier model or open weight LLM service: customer model choice and bring your own model.

Sourcecrogl.com/productread 2026-09-28

APIs, SDKs & MCP Extensibility Not documented

Crogl documents no API, SDK, CLI or MCP server for calling it; the skill builder is in-product authoring, and connectors reach out to other systems rather than letting them call in.

Sourcecrogl.com/productread 2026-09-28

Testing, Debugging & Optimization Not documented

No harness, scored tests or evaluation of skills or investigations is documented; learning from analyst feedback is a claim, and the audit trail is a record of work rather than a test.

Sourcecrogl.com/productread 2026-09-28

Browser & Computer Use Not documented

The agent queries each data source in place through connectors; no browser or computer use is documented.

Sourcecrogl.com/productread 2026-09-28

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Pricing

Free plan: $0 forever for one analyst per workspace, all connectors, unlimited skills and audit trail, with a 30-day full-feature trial. Enterprise: custom annual team contract.

Annual team-based contract (Enterprise); no per-alert, per-investigation or per-user fees stated.

Free tierTrial available

What is public

The pricing page publishes the Free plan ($0, one analyst per workspace, all connectors, unlimited skills and audit trail, 30-day full-feature trial) and the Enterprise inclusions (teams, OIDC SSO, role-based access, customer's own LLM service, autonomous execution, audit log exports, 24/7 SLA). No Enterprise price is published.

Billing mechanics

Free plan with no expiration. Enterprise is an annual, team-based contract with unlimited investigations; the vendor states no per-alert, per-investigation or per-user fees.

Cost watchouts

Inference, not stated by the vendor: Crogl runs on the customer's infrastructure with the customer's chosen LLM service, so compute and model costs sit outside the Crogl contract.

Variable cost rationale

The vendor states no per-alert, per-investigation or per-user fees and unlimited investigations on Enterprise; the customer runs it on its own infrastructure and chosen LLM service, which carry their own costs.

Additional watchouts

Free downloads require an approved request, and autonomous execution, SSO and role-based access are Enterprise only.

Sales call required

Mixed (some tiers require a call)

Free / trial

Free plan at $0 forever (one analyst, username and password sign-in, community Slack support) with a 30-day full-feature trial; download requests are reviewed

Key ambiguities

The Enterprise price and what sets it (team size or environment) are not published, and free downloads are granted after a manual review of each request.

Missing data

Enterprise price, contract minimum and the unit behind the team-based model.

Agentic Index verified 2026-09-28

Alternatives to Crogl

The closest documented capability profiles to Crogl among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • UnderDefense8.5 / 14A lighter documented profile than Crogl
  • ThreatModeler10.0 / 14Adds documented APIs, SDKs & MCP Extensibility and Testing, Debugging & Optimization
  • Andesite9.0 / 14Fuller documented coverage on Human Oversight & Guardrails and Security, Identity & Governance
  • Ghost Security10.0 / 14Adds documented APIs, SDKs & MCP Extensibility
  • StrikeReady7.0 / 14A lighter documented profile than Crogl
  • Trent AI8.0 / 14Adds documented APIs, SDKs & MCP Extensibility

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.