Back to vendors
D

Darktrace

Also known as: Darktrace ActiveAI Security Platform, ActiveAI, Cyber AI Analyst, Antigena, Darktrace PREVENT, Darktrace DETECT, Darktrace RESPOND, Darktrace HEAL, Enterprise Immune System, Cado Security, Cybersprint

Visit site
Entry priceContact salesFull pricing detail

Self-learning AI that models each customer's normal and flags deviation, with Cyber AI Analyst investigating every alert into a written summary and Autonomous Response acting in Human Confirmation or autonomous mode; cloud regions chosen by the customer.

Darktrace builds self-learning AI that models the patterns of life of each customer's environment and treats deviation from that learned normal as the signal, across network, email, cloud, operational technology, identity, SaaS and endpoint.

Cyber AI Analyst investigates every alert, including custom and third-party alerts, by questioning data, testing hypotheses and reaching conclusions with its own machine-learning models (DEMIST-2 for attacker behavior and DIGEST for escalation risk), deliberately without prompt-based generative AI, and produces a natural-language summary with its decision logic and recommended actions for each incident.

Autonomous Response acts on threats by blocking matching connections, isolating devices or enforcing a device's normal pattern of life, natively or through third-party firewalls, Microsoft Defender for Endpoint and CrowdStrike; it can run in Human Confirmation mode, where the team confirms each action, or autonomously within guiderails set by time window, device group and event type. The platform integrates with 40+ SIEM, SOAR, EDR, firewall, cloud and collaboration tools.

Darktrace runs cloud infrastructure in customer-chosen regions across AWS, Azure and Google Cloud and publishes appliance specifications for on-network deployment. It holds ISO 27001, ISO 42001, ISO 27018, Cyber Essentials and IRAP. OpenAI Daybreak models for incident context and a SECURE AI product for monitoring enterprise AI agents are in development.

Vendor details

Canonical URL

https://www.darktrace.com

Category

Security / SOC agent

Subcategory

Self learning autonomous detection and response

Funding status

Private, owned by Thoma Bravo since a take-private completed in October 2024.

Company status

acquired

Use cases & customers

Primary use cases

autonomous threat detection and response across the digital estateAI led alert investigation and incident prioritizationemail and Microsoft Teams threat detectionoperational technology and network anomaly detectionattack path analysis and breach simulation

Target customers

large enterprisemid-marketoperational technology and industrial environmentsorganizations with unknown threat exposure

Deployment options

cloud infrastructure in customer-chosen regions across AWS, Azure and Google Cloudon-network appliances (published specifications)

Integrations

40+ integrations across SIEMs (Microsoft Sentinel, Elastic, LogRhythm, InsightIDR), SOAR (Cortex XSOAR, FortiSOAR, InsightConnect), EDR (CrowdStrike Falcon, Carbon Black, Cybereason, Microsoft), firewalls (Check Point, Cisco, Fortigate, Juniper), AWS, Azure, Google Cloud, Microsoft 365, Google Workspace, Jira and Teams. Autonomous Response acts through third-party firewalls, Microsoft Defender for Endpoint and CrowdStrike, and Cyber AI Analyst ingests third-party alerts and common log formats.

In practice

A security team faces a threat with no known signature, and the platform acts on it anyway because it deviates from that organization's own learned normal rather than matching a global indicator.

An analyst opens Cyber AI Analyst to find alerts already correlated across network, cloud and email into a written incident narrative with a priority attached.

An industrial operator extends the same anomaly detection into operational technology environments where signature based tooling has poor coverage.

Agentic Index coverage score

7.5 / 14 capabilities · 54%

Integrations & Tool Calling Full

40+ named integrations across SIEMs (Sentinel, Elastic, LogRhythm, InsightIDR), SOAR (Cortex XSOAR, FortiSOAR, InsightConnect), EDR (CrowdStrike Falcon, Carbon Black, Cybereason, Microsoft), firewalls (Check Point, Cisco, Fortigate, Juniper), clouds, Jira and Teams; Autonomous Response acts through third-party firewalls, Microsoft Defender for Endpoint and CrowdStrike, and Cyber AI Analyst ingests third-party alerts.

Sourcedarktrace.com/integrationsread 2026-09-28

Workflow Orchestration Partial

Detection and Cyber AI Analyst investigation lead into Autonomous Response and then recovery, a fixed product pipeline. Cyber AI Analyst is a single investigating agent, and Autonomous Response is configured by time window, device group and event type rather than through a flow the buyer builds.

Sourcedarktrace.com/cyber-ai-analystread 2026-09-28

Knowledge Grounding & RAG Partial

Darktrace's self-learning AI models each customer's patterns of life and flags deviation, and Cyber AI Analyst runs ML models (DEMIST-2, DIGEST) over the customer's telemetry. The knowledge lives in learned models whose runs return predictions, not in a structure the customer can add knowledge to without retraining.

Sourcedarktrace.com/cyber-ai-analystread 2026-09-28

Human Oversight & Guardrails Full

Autonomous Response can run in Human Confirmation mode, where the team confirms actions before they execute, or entirely on its own within guiderails set by time window, device group and event type. Teams typically start in Human Confirmation mode.

Sourcedarktrace.com/darktrace-autonomous-responseread 2026-09-28

Security, Identity & Governance Partial

Darktrace's trust center at trust.darktrace.com lists ISO 27001:2022, ISO 42001:2023 and ISO 27018, along with Cyber Essentials and IRAP. Its only SSO statement covers Darktrace's own employees, and nothing describes SSO, a role model or permissions for the customer console.

Sourcetrust.darktrace.comread 2026-09-28

Observability & Auditability Partial

Each Cyber AI Analyst investigation produces a natural language summary with its decision logic and recommended actions, and re-investigates as new data arrives. That is a write-up and decision record for each investigation; no log of each step or action is described, for the analyst or for Autonomous Response.

Sourcedarktrace.com/cyber-ai-analystread 2026-09-28

Memory & State Persistence Not documented

The learned pattern of life model is a detection model, not agent memory, and no memory with a scope and lifetime is described.

Sourcedarktrace.com/cyber-ai-analystread 2026-09-28

Deployment & Data Residency Full

Cloud infrastructure on AWS (US, Canada, UK, Ireland, Netherlands, Australia, Singapore), Azure (US, UK, Canada, UAE, Netherlands, Ireland, Singapore, Australia, South Africa) and Google Cloud (US, Netherlands), with "location based upon customer's choice": a named region list with selection. Darktrace also publishes appliance specifications for on-network deployment.

Sourcetrust.darktrace.comread 2026-09-28

Prebuilt Agents, Templates & Packs Full

Separate products cover network, email and cloud, as well as OT, identity and endpoint, and each runs the self-learning AI and Cyber AI Analyst on its own domain, so removing one leaves the others whole. Native Autonomous Response actions need no scripting.

Sourcedarktrace.com/cyber-ai-analystread 2026-09-28

Triggers & Channel Coverage Full

Cyber AI Analyst investigates every alert, including custom alerts and third-party triggers and log feeds from SIEM and SOAR, and Autonomous Response acts on detections by event type and time window: alert-arrival wakes.

Sourcedarktrace.com/cyber-ai-analystread 2026-09-28

Model Flexibility & Routing Not documented

Cyber AI Analyst runs Darktrace's own ML models (DEMIST-2, DIGEST) and deliberately avoids prompt based generative AI; OpenAI Daybreak models are being added in development (September 2026). The models are Darktrace's own, and the customer has no choice among them.

Sourcedarktrace.com/cyber-ai-analystread 2026-09-28

APIs, SDKs & MCP Extensibility Partial

SOAR integrations such as Cortex XSOAR, FortiSOAR and InsightConnect imply a programmable interface into Darktrace, but no API reference, SDK or MCP server is published.

Sourcedarktrace.com/integrationsread 2026-09-28

Testing, Debugging & Optimization Not documented

Attack path simulation and readiness exercises test the customer's estate and response plan, not the AI, and Human Confirmation mode is oversight rather than evaluation. Nothing is offered for evaluating Cyber AI Analyst or Autonomous Response themselves.

Sourcedarktrace.com/darktrace-autonomous-responseread 2026-09-28

Browser & Computer Use Not documented

Darktrace works on telemetry and acts through native controls and integrations; no browser or computer use by an agent is documented.

Sourcedarktrace.com/darktrace-autonomous-responseread 2026-09-28

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Pricing

Contact sales

not disclosed

What is public

Nothing on price.

Billing mechanics

Not publicly disclosed; sold through sales and partners.

Cost watchouts

Inference, not stated by the vendor: coverage is sold by domain product, so extending to more of the estate adds cost.

Variable cost rationale

Inference, not stated by the vendor: with no billing unit published, cost depends on which domain products and how much of the estate are covered.

Additional watchouts

Scope the domain products deliberately, since cross-domain correlation is part of the value case.

Sales call required

Yes, required for paid access

Free / trial

Not published

Commercial notes

Private, owned by Thoma Bravo.

Key ambiguities

No rate card or billing unit is published.

Missing data

All pricing and packaging.

Agentic Index verified 2026-09-28

Alternatives to Darktrace

The closest documented capability profiles to Darktrace among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • Radiant Security6.0 / 14A lighter documented profile than Darktrace
  • Sprinto9.0 / 14Fuller documented coverage on Workflow Orchestration and Security, Identity & Governance
  • Anvilogic8.5 / 14Fuller documented coverage on Workflow Orchestration and Knowledge Grounding & RAG
  • DeepKeep8.5 / 14Adds documented Testing, Debugging & Optimization
  • Okta8.5 / 14Fuller documented coverage on Security, Identity & Governance and Observability & Auditability
  • Operant AI7.5 / 14Fuller documented coverage on Security, Identity & Governance and Observability & Auditability

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.