Back to vendors
P

PRE Security

Also known as: CyberLLM, SOCGPT

Visit site
Entry priceContact sales; no public pricingFull pricing detail

AI native predictive SecOps platform with parserless ingestion, a SignalGate data fabric and an Autonomous Security Operator (SOARGPT, SOCGPT, ReportGPT, BreachGPT) that triages and acts across the security stack, deployable on premises, in a private cloud or as SaaS.

PRE Security is a San Jose company, led by co founders and co CEOs Paul Jespersen and JP Peterson, that sells an AI native predictive security operations platform meant to replace or augment a legacy SIEM.

Parserless ingestion uses generative AI to identify, interpret and classify any data source, SignalGate, its AI security data fabric added in Version 3.3 (March 2026), processes, classifies, prioritizes and routes signals across the asset landscape, and CyberLLM correlates signals across the environment; a patented process converts logs and alerts into natural language.

A Predict and Prevent layer adds a statistical model of attacker behavior and Monte Carlo scenario modeling to flag attack patterns before impact.

Version 3.3 introduced the Autonomous Security Operator, whose SOARGPT reasons across alerts, asset relationships and threat intelligence and executes coordinated actions across the security stack with minimal analyst intervention, directed in natural language, alongside SOCGPT for plain language investigation, ReportGPT for reports and BreachGPT for breach attack simulation, in a multi tenant interface for enterprise SOCs and MSSPs.

PRE deploys on premises, in a private cloud or as SaaS, down to a Mac mini based miniSOC for small teams. Its pages document no approval step or autonomy control for SOARGPT's actions, no log of what the agents did, no attestation or access controls for the platform, no named models and no API. It fits SOC teams and MSSPs that want an AI native SIEM replacement they can run on their own hardware; buyers who need documented oversight controls and attestations should ask for them.

Vendor details

Canonical URL

https://presecurity.ai

Category

Security / SOC agent

Subcategory

AI native predictive SecOps / AI SIEM

Funding status

Seed; headquartered in San Jose / Silicon Valley; leadership from NetScreen, Fortinet, Cisco, Splunk, Zscaler backgrounds

Company status

independent

Use cases & customers

Primary use cases

Legacy SIEM replacement or augmentationParserless log ingestion and noise reductionGenerative XDR threat detectionPredictive attack preventionNatural language SOC investigation and response

Target customers

Enterprise SOC and security operations teamsMSSPs and MiniSOC operatorsSecurity leaders replacing legacy SIEM

Deployment options

SaaSRuns in parallel to existing SIEM/stack

Integrations

Parserless ingestion accepts any data source or format, streamed or through API connectors, with SignalGate classifying and routing signals; PRE can sit in front of an existing SIEM or XDR or replace it, includes a lightweight Windows EDR agent, and SOARGPT acts across the security stack (systems not named publicly).

In practice

A SOC replaces its legacy SIEM, ingesting any log source without parsers as SignalGate suppresses noise and generative XDR surfaces behavioral threats

The Predict and Prevent layer models attack patterns in formation with Monte Carlo scenarios, giving the team time to act before impact

An analyst uses SOCGPT to investigate an incident in plain language and runs a breach attack simulation through BREACHGPT without query languages

Agentic Index coverage score

6.0 / 14 capabilities · 43%

Integrations & Tool Calling Full

SOARGPT reasons across alerts, asset relationships and threat intelligence and executes "coordinated actions across the security stack with minimal analyst intervention", though PRE does not name the systems it acts in. Data comes in from any source through log receivers or data connectors without parsers, and SignalGate can sit in front of an existing SIEM, sending low value logs to cheap storage while forwarding high value signal for analysis. MSSPs can white label the platform or brand it jointly, and PRE says flexible integrations fit it into an existing stack.

SourcePRE Security, presecurity.ai/product, /partners and /pre-security-unveils-breakthrough-version-3-3-and-earns-top-industry-awards-ahead-of-rsa-conference-2026; presecurity.ai/pre-security-unveils-breakthrough-version-3-3-and-earns-top-industry-awards-ahead-of-rsa-conference-2026read 2026-10-06

Workflow Orchestration Full

SOARGPT is built as an agentic system that reasons and acts rather than following scripts, moving beyond static playbooks, and teams direct it with prompts in natural language. It works beside SOCGPT for investigation, ReportGPT for reports and BreachGPT for breach attack simulation inside the Autonomous Security Operator, which carries investigation, triage, reporting and response through natural language.

SourcePRE Security, presecurity.ai/product and /pre-security-unveils-breakthrough-version-3-3-and-earns-top-industry-awards-ahead-of-rsa-conference-2026; presecurity.ai/pre-security-unveils-breakthrough-version-3-3-and-earns-top-industry-awards-ahead-of-rsa-conference-2026read 2026-10-06

Knowledge Grounding & RAG Full

SignalGate, an AI security data fabric, processes, classifies, prioritizes and routes security signals across the entire asset landscape, and CyberLLM "correlates signals across your entire environment with full context", reading narrative, intent and threat context. Log2NLP turns raw logs into natural language and PRE retains the data at full fidelity, so the agents reason over the customer's own telemetry.

SourcePRE Security, presecurity.ai, /product, /wp-content/uploads/2026/03/PRESecurity_SolutionBrief.pdf and /pre-security-unveils-breakthrough-version-3-3-and-earns-top-industry-awards-ahead-of-rsa-conference-2026read 2026-10-06

Human Oversight & Guardrails Not documented

SOARGPT executes actions across the security stack "with minimal analyst intervention", and PRE says its agentic AI takes the repetitive work so analysts can focus on decisions rather than alert queues. No approval step, autonomy setting or customer controlled constraint on agent actions is documented.

SourcePRE Security, presecurity.ai/product and /partnersread 2026-10-06

Security, Identity & Governance Not documented

No attestation, SSO, role model or trust page for the platform is published. The multi tenant design gives each client an isolated tenant environment under central management, but no controls over who inside a customer's team can do what are documented.

SourcePRE Security, presecurity.ai, /partners and /wp-content/uploads/2026/03/PRESecurity_SolutionBrief.pdfread 2026-10-06

Observability & Auditability Not documented

No log or trace of what SOARGPT or the other assistants did is documented. Alerts, threat hunting, SearchGPT investigation and the daily posture report, modeled on a weather forecast with prioritized recommended actions, describe the customer's estate rather than the agents' own steps.

SourcePRE Security, presecurity.ai/product and /pre-security-unveils-breakthrough-version-3-3-and-earns-top-industry-awards-ahead-of-rsa-conference-2026read 2026-10-06

Memory & State Persistence Not documented

The statistical memory PRE added to its data pipeline captures the natural flow of attacker behavior patterns so predictions become more stable earlier in the pipeline. It models attacks rather than holding what the agents did or learned, and no agent memory with a stated scope and lifetime is documented.

SourcePRE Security, prnewswire.com/news-releases/pre-security-enhances-ai-data-fabric-use-case-and-expands-predictive-capabilities-302564442.htmlread 2026-10-06

Deployment & Data Residency Full

PRE deploys on premises, in a private cloud or as SaaS, from "a Mac mini based miniSOC to enterprise class servers to cloud scale SaaS". The solution brief describes a fully managed cloud with automatic updates, the customer's own data center or hardware with full data sovereignty, a hybrid of cloud and on premises with flexible data residency, and isolated tenant environments under central management. The platform can also run in parallel to an existing workflow during a transition.

SourcePRE Security, presecurity.ai, /product and /wp-content/uploads/2026/03/PRESecurity_SolutionBrief.pdfread 2026-10-06

Prebuilt Agents, Templates & Packs Full

The Autonomous Security Operator ships four named assistants with stated jobs, SOCGPT for investigation in plain language, SOARGPT for agentic response, ReportGPT for reports built from prompts and BreachGPT for breach attack simulation. PRE also sells a miniSOC package for small teams and an offer for MSSPs, who can white label the platform with native multi tenancy and pricing per asset, and three ways in: a full SIEM replacement, SignalGate and parserless ingestion in front of an existing SIEM, or a parallel addition.

SourcePRE Security, presecurity.ai, /product, /partners and /pre-security-unveils-breakthrough-version-3-3-and-earns-top-industry-awards-ahead-of-rsa-conference-2026read 2026-10-06

Triggers & Channel Coverage Full

SOARGPT reasons across alerts, asset relationships and threat intelligence in real time and executes coordinated actions as signals arrive, and the homepage promises no manual triage, with agentic AI handling the repetitive work. Work starts when alerts come in rather than when someone asks.

SourcePRE Security, presecurity.ai and /pre-security-unveils-breakthrough-version-3-3-and-earns-top-industry-awards-ahead-of-rsa-conference-2026read 2026-10-06

Model Flexibility & Routing Not documented

PRE's own CyberLLM is described as a proprietary security LLM trained for detection and prediction, combined with generative AI and statistical methods, and the solution brief adds consensus predictions that aggregate several models for threat forecasting. No outside model provider is named and no customer choice of model is documented.

SourcePRE Security, presecurity.ai/product and /wp-content/uploads/2026/03/PRESecurity_SolutionBrief.pdfread 2026-10-06

APIs, SDKs & MCP Extensibility Not documented

No API reference, SDK or MCP server is published. Log receivers and data connectors bring data into the platform from any source, and nothing documents a way for outside software to call PRE.

SourcePRE Security, presecurity.ai/productread 2026-10-06

Testing, Debugging & Optimization Not documented

No harness, scored tests or quality gate for the agents' own work is documented. BreachGPT runs breach attack simulation for vulnerability testing and red team work, and Monte Carlo scenario modeling simulates thousands of attack vectors, both aimed at the customer's estate. PRE's own figures call the platform 10X more effective and claim SIEM ingestion costs fall by 50 to 80%.

SourcePRE Security, presecurity.ai, /wp-content/uploads/2026/03/PRESecurity_SolutionBrief.pdf and /pre-security-unveils-breakthrough-version-3-3-and-earns-top-industry-awards-ahead-of-rsa-conference-2026read 2026-10-06

Browser & Computer Use Not documented

PRE works on ingested telemetry and a Windows EDR agent, and its agents act through the security stack rather than through a screen. No agent operating a browser or desktop is documented.

SourcePRE Security, presecurity.ai and /resourcesread 2026-10-06

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Pricing

Contact sales; no public pricing

per asset (no rates published)

What is public

No prices. The pricing basis is public: the partners page describes asset based pricing with no ingestion based charges. Deployment choices (on premises, private cloud, SaaS, miniSOC) are public.

Billing mechanics

Asset based pricing with no ingestion based charges, per the partners page, which says it keeps costs predictable as data volumes grow; no per asset rates or tiers are published.

Cost watchouts

Cost scales with the number of assets protected rather than data volume, since pricing is asset based. Inference, not stated: the EDR agent and miniSOC packaging may price separately.

Variable cost rationale

Asset based pricing, stated on the partners page, keeps cost predictable within a defined estate, with asset growth the main lever.

Additional watchouts

Confirm what counts as an asset and whether EDR endpoints, MiniSOC, and predictive modules are bundled or add ons.

Sales call required

Yes, required for paid access

Free / trial

No free tier documented; can run in parallel to an existing SIEM for low disruption evaluation

Key ambiguities

The pricing basis (asset based, no ingestion charges) is public but no dollar figures, per asset rates or tier boundaries are.

Missing data

Per asset rates, tier boundaries, EDR and MiniSOC pricing.

Agentic Index verified 2026-10-06

Alternatives to PRE Security

The closest documented capability profiles to PRE Security among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • StrikeReady7.0 / 14Adds documented Human Oversight & Guardrails and Security, Identity & Governance, among others
  • Mycroft6.5 / 14Adds documented Human Oversight & Guardrails and Security, Identity & Governance
  • Seemplicity8.5 / 14Adds documented Human Oversight & Guardrails and Security, Identity & Governance, among others
  • Crogl9.0 / 14Adds documented Human Oversight & Guardrails and Security, Identity & Governance, among others
  • Quantro Security7.0 / 14Adds documented Human Oversight & Guardrails and Security, Identity & Governance, among others
  • Simbian9.0 / 14Adds documented Human Oversight & Guardrails and Observability & Auditability, among others

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.