Cyware
Also known as: Cyware Quarterback, Cyware Intel Exchange
Threat intelligence and security operations platform whose Quarterback AI agents research threats, triage alerts and vulnerabilities, write detections and map attack flows under customer defined approvals, with Orchestrate playbooks, an open source MCP server and cloud, on premises or air gapped deployment.
Cyware sells an AI powered threat intelligence and security operations platform for enterprises, MSSPs and threat sharing networks. Its products, packaged as the Cyware Intelligence Suite for enterprise SOCs and the Cyware Collaboration Suite for ISACs, ISAOs, CERTs and sharing networks, include Intel Exchange (threat intelligence management), Collaborate (sharing), Orchestrate (automation and orchestration) and Respond (incident response), with more than 400 integrations. Cyware states more than 30,000 organizations use the platform.
Cyware Quarterback AI delivers agents through the Agent Hub, available inside Intel Exchange and as a Chrome and Edge extension. Named agents include Threat Intel Research, Vulnerability Exposure Analysis, DRP Triage, Threat Briefing, Priority Intelligence Requirement, Vulnerability Triage, Security Advisory, Detection Engineering (editable detection rules from alerts, IOCs, TTPs and malware) and Attack Flow Intelligence, alongside a Playbook Builder, a Custom Code Generator and a run log debugger for Orchestrate playbooks.
Customers define approval workflows, autonomy levels and governance policies so agents perform only authorized actions, every action is logged, and playbook run logs show each node's inputs, outputs, timing and errors. An open source Cyware MCP Server lets assistants such as Claude Desktop and Cursor search intelligence, create intel and tags, and run Orchestrate playbooks and app actions.
Cyware lists a SOC 2 Type 2 report and ISO 27001:2022 certification, and its Cyber Fusion Center appears on the FedRAMP Marketplace as Legacy FedRAMP Ready at Moderate. It supports cloud, on premises and air gapped deployments. Founded by CEO Anuj Goel, it raised a thirty million dollar Series C in 2023 led by Ten Eleven Ventures with Advent International and Zscaler participating. It fits SOC and threat intelligence teams, MSSPs and sharing communities that want intelligence driven automation with customer set approvals and on premises options; the models behind its agents are not named.
Vendor details
Canonical URL
https://www.cyware.com
Category
Security / SOC agent
Subcategory
Cyber fusion and agentic threat intelligence
Funding status
Series C of thirty million dollars led by Ten Eleven Ventures with Advent International, Zscaler, and others (2023); FedRAMP Ready; serves Fortune 1000, MSSPs, and 20+ ISACs
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
More than 400 integrations across the security stack, with agents acting through existing tools over MCP connections and Orchestrate app actions; enrichment sources such as VirusTotal and Mandiant; STIX 2.1 normalization and MITRE ATT&CK mapping; a Microsoft Sentinel partnership; an App Marketplace and Playbook Store; the Agent Hub browser extension for Chrome and Edge; and the open source Cyware MCP Server for Claude Desktop, Cursor and other assistants.
In practice
The SOC Analysis Agent enriches IOCs, correlates alerts, and delivers step by step mitigation from the analyst's browser, cutting triage time two to three times
The Detection Engineering Agent converts a threat report into validated YARA and Sigma rules and Splunk queries with no manual coding
An ISAC uses Cyware to automatically ingest, normalize to STIX, and share threat intelligence across tens of thousands of member organizations
Sources & related URLs
Research sources
Agentic Index coverage score
10.0 / 14 capabilities · 71%
| Integrations & Tool Calling | Full |
|---|---|
|
More than 400 integrations, with agents taking "direct action through existing security tools" over MCP server connections, and Cyware Orchestrate executing app actions across the connected stack (10M+ mitigation actions stated). Sourcecyware.comread 2026-09-28 |
|
| Workflow Orchestration | Full |
|
Cyware Orchestrate runs node based playbooks the customer builds, with an LLM assisted Playbook Builder Agent and a Custom Code Generator, and the homepage sells orchestration playbooks "with bounded autonomy and guardrails you define", a flow the buyer configures. Sourcetechdocs.cyware.com/conextgen/en/playbooks.htmlread 2026-09-28 |
|
| Knowledge Grounding & RAG | Full |
|
Cyware Intel Exchange ingests, enriches, scores and relates threat intelligence into a maintained repository the agents query (CQL search, threat data objects, enrichment metadata), a persistent retrieval structure over the customer's own intelligence. Sourcecyware.com/blog/talk-to-your-threat-intelligence-platform-introducing-the-cyware-mcp-serverread 2026-09-28 |
|
| Human Oversight & Guardrails | Full |
|
"You define approval workflows, autonomy levels, and governance policies, ensuring agents only perform authorized actions", with every action authorized and logged, an approval step the customer places before agent actions. The workflow mechanics themselves are not published in the docs. Sourcecyware.com/quarterback-airead 2026-09-28 |
|
| Security, Identity & Governance | Partial |
|
The compliance page lists a SOC 2 Type 2 report and ISO 27001:2022 certification by Coalfire, and the FedRAMP Marketplace lists Cyware Cyber Fusion Center as Legacy FedRAMP Ready at Moderate. Agents act only on authorized actions, but no console SSO, role model or permission reference is published. Sourcecyware.com/complianceread 2026-09-28 |
|
| Observability & Auditability | Full |
|
Playbook run logs show every node's inputs and outputs, execution status, run time and errors with debug information, and agent actions are fully audit logged with tenant isolation, a step level record of the automation's own execution. MTTD and MTTR are reported across the estate. Sourcetechdocs.cyware.com/conextgen/en/run-logs.htmlread 2026-09-28 |
|
| Memory & State Persistence | Not documented |
|
Agents connect to the deployment with "no local data storage", and outside the threat intelligence repository no agent memory with a stated scope and lifetime is documented. Sourcecyware.com/blog/cyware-ai-agent-ecosystem-deep-dive-operational-impactread 2026-09-28 |
|
| Deployment & Data Residency | Full |
|
"Cyware supports cloud, on-premise, and air-gapped deployments, along with staging environments", named customer environment options, and the deployment model is an input to the quote. Sourcecyware.com/pricingread 2026-09-28 |
|
| Prebuilt Agents, Templates & Packs | Full |
|
Named prebuilt agents with stated jobs in the Agent Hub, including Threat Intel Research, Vulnerability Exposure Analysis, DRP Triage, Threat Briefing, Priority Intelligence Requirement, Vulnerability Triage, Security Advisory, Detection Engineering and Attack Flow Intelligence, plus a Playbook Store. Sourcecyware.com/airead 2026-09-28 |
|
| Triggers & Channel Coverage | Full |
|
Intelligence is ingested, enriched, scored and actioned automatically as it arrives, and Orchestrate playbooks fire on incoming alerts and intelligence, an autonomous wake on inbound events; the DRP Triage Agent prioritizes incoming alerts. Sourcecyware.comread 2026-09-28 |
|
| Model Flexibility & Routing | Not documented |
|
The models behind Cyware's agents are not named, and no choice of provider is offered. LLMs run in playbooks and MCP support lets outside assistants reach Cyware, but neither gives the buyer a choice of model. Sourcecyware.com/airead 2026-09-28 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
The open source Cyware MCP Server (github.com/cyware-labs/cyware-mcpserver) publishes its install and transport (stdio or SSE), authentication with Cyware application credentials and an enumerated tool list for Intel Exchange and Orchestrate, including creating intel, tags and bulk actions and executing playbooks and app actions; a playbook API sits at orchestrateapi.cyware.com. Sourcegithub.com/cyware-labs/cyware-mcpserverread 2026-09-28 |
|
| Testing, Debugging & Optimization | Partial |
|
Run logs give node level debug information with error summaries and remediation steps, and an AI Playbook Runlog Debugger analyzes failed runs, a debugging surface; no harness, scored test cases or quality gate for the agents is documented. Sourcetechdocs.cyware.com/conextgen/en/run-logs.htmlread 2026-09-28 |
|
| Browser & Computer Use | Not documented |
|
The Agent Hub is also delivered as a Chrome and Edge extension, which is where the product runs, not an agent operating a browser; the agents connect back to the Cyware deployment by API. Sourcecyware.com/blog/cyware-ai-agent-ecosystem-deep-dive-operational-impactread 2026-09-28 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
Cyware launched a new integration with Armis Centrix to deliver asset-centric threat contextualization. The partnership connects Armis asset visibility with the agentic AI capabilities of the Cyware Intelligence Suite to map global threat data directly onto an organization's device landscape.
Bears on: Integrations
View sourcePricing
Contact sales; custom quote per engagement
custom quote by suite, deployment model, analyst seats, feeds, automation volume and add ons
What is public
A pricing page with no prices: it names the two suites and the pricing inputs (deployment model, analyst seats, intelligence feeds, automation volume, sandbox capacity, digital risk protection, add ons) and offers a custom quote.
Billing mechanics
Custom quoted per engagement across two suites (Intelligence Suite for enterprise SOCs, Collaboration Suite for ISACs and sharing networks); cloud, on premises, air gapped and staging deployments are available and the deployment model is a pricing input.
Cost watchouts
Automation volume, sandbox capacity and add ons are named pricing inputs, so heavier automation and extra modules raise the quote.
Variable cost rationale
Cyware names automation volume, analyst seats and feeds among its pricing inputs, so cost scales with operational scale and the suites adopted; no metering rates are published.
Additional watchouts
Component mix drives cost; MSSP and ISAC deployments scale by members; confirm whether agentic AI is bundled or an add on.
Sales call required
Yes, required for paid access
Free / trial
No public free tier; custom quote or demo request
Key ambiguities
Pricing axis and figures are unpublished; modular structure means quotes depend heavily on component mix and member scale.
Missing data
All pricing figures, per component rates, AI feature pricing.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to Cyware
The closest documented capability profiles to Cyware among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Drata10.5 / 14Fuller documented coverage on Security, Identity & Governance
- Zeron10.5 / 14Fuller documented coverage on Security, Identity & Governance
- BlinkOps10.5 / 14Adds documented Memory & State Persistence
- Command Zero10.5 / 14Adds documented Memory & State Persistence
- Conifers.ai9.5 / 14Adds documented Memory & State Persistence
- Seemplicity8.5 / 14A lighter documented profile than Cyware
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded