Back to vendors
D

Dropzone AI

Also known as: Dropzone

Visit site
Entry priceNot public; plans priced by investigation volume through salesFull pricing detail

AI SOC analyst that investigates every alert over the existing security stack, with a threat hunting agent beside it and plans priced by investigation volume through sales.

Dropzone AI builds autonomous LLM powered agents for the security operations center. Its AI SOC Analyst investigates every alert the customer's tools raise, around the clock, closing benign ones and escalating real threats without playbooks, and an AI Threat Hunter runs hypothesis driven hunts across SIEM, EDR and cloud data on a schedule or when a new CVE or campaign appears; an AI Threat Intel Analyst is marked for Fall 2026. Founded by Edward Wu, who previously built the detection engine at ExtraHop, Dropzone raised a $37 million Series B in July 2025 led by Theory Ventures, for more than $50 million in total.

The design philosophy is overlay, not replacement. Dropzone connects to more than 90 tools a SOC already runs, SIEM, EDR, identity, email and cloud, with read only access by default, and produces an evidence backed investigation report that shows its reasoning.

Analysts steer it through versioned custom strategies (priority rules, investigation questions, analysis guidance) and through Context Memory, a store of institutional facts the agent adds to when an analyst corrects a conclusion. Analysts approve or reopen investigations in the product or from Slack, and Response Actions let the buyer run its own Python on more than 50 triggers to notify, remediate or enrich other systems. A documented REST API with an OpenAPI spec covers investigations, feedback, memory, strategies and response actions.

Each customer runs in a dedicated AWS tenant, normally in us-west-2, with in-region EU deployment on request, SSO through SAML providers, documented roles, and SOC 2 Type 2. Plans are priced by investigation volume: the Standard plan covers up to 4,000 investigations a year per AI analyst with unlimited users, and Enterprise and MSSP plans add single tenant or multi tenant environments; no price is published. For a team that wants tier one triage on the stack it already owns, Dropzone works over existing tools rather than replacing them; the flip side is that coverage is bounded by what those tools surface.

Vendor details

Canonical URL

https://www.dropzone.ai

Category

Security / SOC agent

Subcategory

AI SOC analyst

Funding status

Independent, founded by Edward Wu, who previously built the detection engine at ExtraHop. Raised a $37 million Series B in July 2025 led by Theory Ventures, bringing total funding above $50 million.

Company status

independent

Use cases & customers

Primary use cases

autonomous L1 alert triage24/7 alert investigationinvestigation backlog eliminationevidence backed investigation reports

Target customers

enterprise SOC teamsmid market security teamsMSSPs

Deployment options

SaaS

Integrations

Drops in over the existing security stack with read only access to SIEM, EDR, identity, email, and cloud tools, investigating alerts those tools surface rather than requiring data migration. Each investigation produces a full evidence backed report, and one AI SOC analyst handles alert volume around the clock with typical analysis under ten minutes per alert.

In practice

Your two analysts face four thousand alerts a week and the backlog keeps growing. Dropzone investigates every alert around the clock, closing benign ones with evidence and escalating real threats for an analyst to approve or reopen.

You cannot rip out the SIEM to adopt AI. Dropzone connects read only by default to the tools you already run and investigates the alerts they raise, with no data migration.

The board asks what the AI spend buys. Dropzone sizes plans by investigation volume, with up to 4,000 investigations a year per AI analyst on the Standard plan, so the bill tracks work performed; the rate is quoted by sales.

Sources & related URLs

Research sources

Agentic Index coverage score

11.0 / 14 capabilities · 79%

Integrations & Tool Calling Full

More than 90 integrations across SIEM, EDR, cloud, identity and email, read only by default, plus Response Actions: buyer written Python run in an isolated container with stored secrets injected, used to notify external systems, trigger remediation and apply policy actions.

Sourcedocs.dropzone.ai/platform/settings/response-actionsread 2026-09-28

Workflow Orchestration Full

Beyond the agent's own multi step investigation, the buyer configures what follows it: Response Automations fire on more than 50 triggers, among them an investigation completing with a given status, and run the buyer's own code, and versioned custom strategies set priority rules and investigation questions.

Sourcedocs.dropzone.ai/platform/settings/response-actionsread 2026-09-28

Knowledge Grounding & RAG Partial

Investigations query the customer's own tools live through the integrations, and analysts set custom strategies and define normal behavior; Context Memory serves as the persistent store. No separate maintained index over the customer's documents is described.

Sourcedocs.dropzone.ai/platform/settings/custom-strategiesread 2026-09-28

Human Oversight & Guardrails Full

Analysts approve or reopen each investigation in the product and from Slack (/dzapprove, /dzreopen), access to the customer's tools is read only by default, and response actions run only where the buyer has configured them.

Sourcedocs.dropzone.ai/integrations/tools/slack-chatopsread 2026-09-28

Security, Identity & Governance Full

Roles and permissions are documented, and SAML SSO works through Okta, Google Workspace or Microsoft Entra. Compliance rests on SOC 2 Type 2 (Type 1 audited by Sensiba, November 2023), with a trust center at trustcenter.dropzone.ai.

Sourcedropzone.ai/security-privacy-trustread 2026-09-28

Observability & Auditability Full

Each investigation produces an evidence backed report that shows the agent's reasoning, and every response action's output, errors and execution status are logged for auditing.

Sourcedocs.dropzone.ai/platform/settings/response-actionsread 2026-09-28

Memory & State Persistence Partial

Context Memory holds institutional facts across investigations: the agent writes to it when analysts change a conclusion, users add notes directly, and it is reachable through the API. The docs state neither its scope nor a lifetime and only advise periodic cleanup.

Sourcedocs.dropzone.ai/platform/context-memoryread 2026-09-28

Deployment & Data Residency Full

Each customer gets a dedicated tenant in its own AWS subnet, normally in us-west-2, with optional regional deployments and in-region EU deployment on request for GDPR; the Enterprise plan names a dedicated single tenant environment.

Sourcedropzone.ai/security-privacy-trustread 2026-09-28

Prebuilt Agents, Templates & Packs Full

Two shipped agents that each do their own job, the AI SOC Analyst for alert investigation and the AI Threat Hunter for hypothesis driven hunts, with prebuilt hunt packs (APT29 among them); the AI Threat Intel Analyst is marked for Fall 2026.

Sourcedropzone.airead 2026-09-28

Triggers & Channel Coverage Full

Every alert the connected tools raise starts an investigation, hunts run on a schedule and on new CVEs and campaigns, and response automations fire on more than 50 system triggers.

Sourcedropzone.airead 2026-09-28

Model Flexibility & Routing Partial

Dropzone runs on several named LLM services, Anthropic, Azure OpenAI, Perplexity and others, chosen by the vendor; no page offers the customer a model choice, so this is vendor routing across disclosed providers.

Sourcedropzone.ai/security-privacy-trustread 2026-09-28

APIs, SDKs & MCP Extensibility Full

A documented REST API under /app/api/v1 with Api-Key authorization covers investigations, bulk feedback, user notes, context memory, custom strategies, response actions and system events, with an OpenAPI 3.0.3 spec and a Swagger UI in the product.

Sourcedocs.dropzone.ai/apiread 2026-09-28

Testing, Debugging & Optimization Partial

Analysts record feedback on investigations singly or in bulk and can reopen a conclusion, which is review of the agent's output after the fact; no evaluation harness, scored test set or gate before a strategy change goes live is documented.

Sourcedocs.dropzone.ai/apiread 2026-09-28

Browser & Computer Use Not documented

No page documents the agent driving a browser, desktop or remote computer; it queries the customer's tools through their APIs.

Sourcedropzone.airead 2026-09-28

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Recent platform changes

2026-07-30·Agent capabilityPartially Verified

Dropzone AI announced the general availability of AI Threat Hunter, a proactive threat hunting agent. The tool runs structured hunt packs across environments to uncover threats, emerging risks, and security coverage gaps missed by traditional alerts, leveraging more than 270 prebuilt hunt packs mapped to MITRE ATT&CK.

Bears on: Agent capability

View source
View all 1 change for Dropzone AI →Tracked since Jul 2026 · Verified from public vendor sources

Pricing

Not public; plans priced by investigation volume through sales

investigations per year, per AI analyst

Trial available

Included quota

Standard plan: up to 4,000 investigations a year per AI analyst, unlimited users.

What is public

The plan structure is public and the price is not: Standard covers up to 4,000 investigations a year per AI analyst with unlimited users, all alert categories, prebuilt integrations and an 8 hour support SLA; Enterprise and MSSP are contact us. The pricing page's ROI calculator shows savings figures, not a price.

Billing mechanics

Annual subscription sized by investigation volume per AI analyst. When a customer approaches its investigation limit Dropzone sends an email notice with a grace window, and additional capacity can be purchased; volume discounts are offered.

Cost watchouts

The unit is investigations, so alert volume drives the bill: a noisy environment or a detection expansion that doubles alerts doubles consumption of the quota. Confirm how the platform counts an investigation and what extra capacity past the plan limit costs.

Variable cost rationale

Investigation volume pricing means cost scales with alert load: predictable for a tuned environment, but detection changes or noisy quarters consume quota faster than budgeted.

Additional watchouts

Pricing couples the bill to alert volume; tune noisy detections before sizing the contract, and confirm how an investigation is counted and what extra capacity costs.

Overage / add-ons

Email notice and a grace window near the limit; additional investigation capacity is purchased, at a price not published.

Sales call required

Yes, required for paid access

Free / trial

Structured proof of concept through sales; no free tier

Commercial notes

Independent, founded by Edward Wu (ex ExtraHop detection engine). $37 million Series B July 2025 led by Theory Ventures, $50 million plus total.

Key ambiguities

No price is published for any plan; the investigation limit and overage path are public, the rates are not.

Agentic Index verified 2026-09-28

Alternatives to Dropzone AI

The closest documented capability profiles to Dropzone AI among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.