Dropzone AI
Also known as: Dropzone
AI SOC analyst that investigates every alert over the existing security stack, with a threat hunting agent beside it and plans priced by investigation volume through sales.
Dropzone AI builds autonomous LLM powered agents for the security operations center. Its AI SOC Analyst investigates every alert the customer's tools raise, around the clock, closing benign ones and escalating real threats without playbooks, and an AI Threat Hunter runs hypothesis driven hunts across SIEM, EDR and cloud data on a schedule or when a new CVE or campaign appears; an AI Threat Intel Analyst is marked for Fall 2026. Founded by Edward Wu, who previously built the detection engine at ExtraHop, Dropzone raised a $37 million Series B in July 2025 led by Theory Ventures, for more than $50 million in total.
The design philosophy is overlay, not replacement. Dropzone connects to more than 90 tools a SOC already runs, SIEM, EDR, identity, email and cloud, with read only access by default, and produces an evidence backed investigation report that shows its reasoning.
Analysts steer it through versioned custom strategies (priority rules, investigation questions, analysis guidance) and through Context Memory, a store of institutional facts the agent adds to when an analyst corrects a conclusion. Analysts approve or reopen investigations in the product or from Slack, and Response Actions let the buyer run its own Python on more than 50 triggers to notify, remediate or enrich other systems. A documented REST API with an OpenAPI spec covers investigations, feedback, memory, strategies and response actions.
Each customer runs in a dedicated AWS tenant, normally in us-west-2, with in-region EU deployment on request, SSO through SAML providers, documented roles, and SOC 2 Type 2. Plans are priced by investigation volume: the Standard plan covers up to 4,000 investigations a year per AI analyst with unlimited users, and Enterprise and MSSP plans add single tenant or multi tenant environments; no price is published. For a team that wants tier one triage on the stack it already owns, Dropzone works over existing tools rather than replacing them; the flip side is that coverage is bounded by what those tools surface.
Vendor details
Canonical URL
https://www.dropzone.ai
Category
Security / SOC agent
Subcategory
AI SOC analyst
Funding status
Independent, founded by Edward Wu, who previously built the detection engine at ExtraHop. Raised a $37 million Series B in July 2025 led by Theory Ventures, bringing total funding above $50 million.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Drops in over the existing security stack with read only access to SIEM, EDR, identity, email, and cloud tools, investigating alerts those tools surface rather than requiring data migration. Each investigation produces a full evidence backed report, and one AI SOC analyst handles alert volume around the clock with typical analysis under ten minutes per alert.
In practice
Your two analysts face four thousand alerts a week and the backlog keeps growing. Dropzone investigates every alert around the clock, closing benign ones with evidence and escalating real threats for an analyst to approve or reopen.
You cannot rip out the SIEM to adopt AI. Dropzone connects read only by default to the tools you already run and investigates the alerts they raise, with no data migration.
The board asks what the AI spend buys. Dropzone sizes plans by investigation volume, with up to 4,000 investigations a year per AI analyst on the Standard plan, so the bill tracks work performed; the rate is quoted by sales.
Sources & related URLs
Research sources
Agentic Index coverage score
11.0 / 14 capabilities · 79%
| Integrations & Tool Calling | Full |
|---|---|
|
More than 90 integrations across SIEM, EDR, cloud, identity and email, read only by default, plus Response Actions: buyer written Python run in an isolated container with stored secrets injected, used to notify external systems, trigger remediation and apply policy actions. Sourcedocs.dropzone.ai/platform/settings/response-actionsread 2026-09-28 |
|
| Workflow Orchestration | Full |
|
Beyond the agent's own multi step investigation, the buyer configures what follows it: Response Automations fire on more than 50 triggers, among them an investigation completing with a given status, and run the buyer's own code, and versioned custom strategies set priority rules and investigation questions. Sourcedocs.dropzone.ai/platform/settings/response-actionsread 2026-09-28 |
|
| Knowledge Grounding & RAG | Partial |
|
Investigations query the customer's own tools live through the integrations, and analysts set custom strategies and define normal behavior; Context Memory serves as the persistent store. No separate maintained index over the customer's documents is described. Sourcedocs.dropzone.ai/platform/settings/custom-strategiesread 2026-09-28 |
|
| Human Oversight & Guardrails | Full |
|
Analysts approve or reopen each investigation in the product and from Slack (/dzapprove, /dzreopen), access to the customer's tools is read only by default, and response actions run only where the buyer has configured them. Sourcedocs.dropzone.ai/integrations/tools/slack-chatopsread 2026-09-28 |
|
| Security, Identity & Governance | Full |
|
Roles and permissions are documented, and SAML SSO works through Okta, Google Workspace or Microsoft Entra. Compliance rests on SOC 2 Type 2 (Type 1 audited by Sensiba, November 2023), with a trust center at trustcenter.dropzone.ai. Sourcedropzone.ai/security-privacy-trustread 2026-09-28 |
|
| Observability & Auditability | Full |
|
Each investigation produces an evidence backed report that shows the agent's reasoning, and every response action's output, errors and execution status are logged for auditing. Sourcedocs.dropzone.ai/platform/settings/response-actionsread 2026-09-28 |
|
| Memory & State Persistence | Partial |
|
Context Memory holds institutional facts across investigations: the agent writes to it when analysts change a conclusion, users add notes directly, and it is reachable through the API. The docs state neither its scope nor a lifetime and only advise periodic cleanup. Sourcedocs.dropzone.ai/platform/context-memoryread 2026-09-28 |
|
| Deployment & Data Residency | Full |
|
Each customer gets a dedicated tenant in its own AWS subnet, normally in us-west-2, with optional regional deployments and in-region EU deployment on request for GDPR; the Enterprise plan names a dedicated single tenant environment. Sourcedropzone.ai/security-privacy-trustread 2026-09-28 |
|
| Prebuilt Agents, Templates & Packs | Full |
|
Two shipped agents that each do their own job, the AI SOC Analyst for alert investigation and the AI Threat Hunter for hypothesis driven hunts, with prebuilt hunt packs (APT29 among them); the AI Threat Intel Analyst is marked for Fall 2026. Sourcedropzone.airead 2026-09-28 |
|
| Triggers & Channel Coverage | Full |
|
Every alert the connected tools raise starts an investigation, hunts run on a schedule and on new CVEs and campaigns, and response automations fire on more than 50 system triggers. Sourcedropzone.airead 2026-09-28 |
|
| Model Flexibility & Routing | Partial |
|
Dropzone runs on several named LLM services, Anthropic, Azure OpenAI, Perplexity and others, chosen by the vendor; no page offers the customer a model choice, so this is vendor routing across disclosed providers. Sourcedropzone.ai/security-privacy-trustread 2026-09-28 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
A documented REST API under /app/api/v1 with Api-Key authorization covers investigations, bulk feedback, user notes, context memory, custom strategies, response actions and system events, with an OpenAPI 3.0.3 spec and a Swagger UI in the product. Sourcedocs.dropzone.ai/apiread 2026-09-28 |
|
| Testing, Debugging & Optimization | Partial |
|
Analysts record feedback on investigations singly or in bulk and can reopen a conclusion, which is review of the agent's output after the fact; no evaluation harness, scored test set or gate before a strategy change goes live is documented. Sourcedocs.dropzone.ai/apiread 2026-09-28 |
|
| Browser & Computer Use | Not documented |
|
No page documents the agent driving a browser, desktop or remote computer; it queries the customer's tools through their APIs. Sourcedropzone.airead 2026-09-28 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
Dropzone AI announced the general availability of AI Threat Hunter, a proactive threat hunting agent. The tool runs structured hunt packs across environments to uncover threats, emerging risks, and security coverage gaps missed by traditional alerts, leveraging more than 270 prebuilt hunt packs mapped to MITRE ATT&CK.
Bears on: Agent capability
View sourcePricing
Not public; plans priced by investigation volume through sales
investigations per year, per AI analyst
Included quota
Standard plan: up to 4,000 investigations a year per AI analyst, unlimited users.
What is public
The plan structure is public and the price is not: Standard covers up to 4,000 investigations a year per AI analyst with unlimited users, all alert categories, prebuilt integrations and an 8 hour support SLA; Enterprise and MSSP are contact us. The pricing page's ROI calculator shows savings figures, not a price.
Billing mechanics
Annual subscription sized by investigation volume per AI analyst. When a customer approaches its investigation limit Dropzone sends an email notice with a grace window, and additional capacity can be purchased; volume discounts are offered.
Cost watchouts
The unit is investigations, so alert volume drives the bill: a noisy environment or a detection expansion that doubles alerts doubles consumption of the quota. Confirm how the platform counts an investigation and what extra capacity past the plan limit costs.
Variable cost rationale
Investigation volume pricing means cost scales with alert load: predictable for a tuned environment, but detection changes or noisy quarters consume quota faster than budgeted.
Additional watchouts
Pricing couples the bill to alert volume; tune noisy detections before sizing the contract, and confirm how an investigation is counted and what extra capacity costs.
Overage / add-ons
Email notice and a grace window near the limit; additional investigation capacity is purchased, at a price not published.
Sales call required
Yes, required for paid access
Free / trial
Structured proof of concept through sales; no free tier
Commercial notes
Independent, founded by Edward Wu (ex ExtraHop detection engine). $37 million Series B July 2025 led by Theory Ventures, $50 million plus total.
Key ambiguities
No price is published for any plan; the investigation limit and overage path are public, the rates are not.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to Dropzone AI
The closest documented capability profiles to Dropzone AI among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Tines11.5 / 14Fuller documented coverage on Model Flexibility & RoutingDropzone AI vs Tines →
- CrowdStrike12.0 / 14Fuller documented coverage on Knowledge Grounding & RAG and Model Flexibility & RoutingDropzone AI vs CrowdStrike →
- Arctic Wolf9.5 / 14A lighter documented profile than Dropzone AI
- BlinkOps10.5 / 14Fuller documented coverage on Knowledge Grounding & RAG
- D3 Security (Morpheus)10.5 / 14Fuller documented coverage on Model Flexibility & Routing
- Drata10.5 / 14Fuller documented coverage on Knowledge Grounding & RAG
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded