PRE Security
Also known as: CyberLLM, SOCGPT
AI native predictive SecOps platform with parserless ingestion, a SignalGate data fabric and an Autonomous Security Operator (SOARGPT, SOCGPT, ReportGPT, BreachGPT) that triages and acts across the security stack, deployable on premises, in a private cloud or as SaaS.
PRE Security is a San Jose company, led by co founders and co CEOs Paul Jespersen and JP Peterson, that sells an AI native predictive security operations platform meant to replace or augment a legacy SIEM.
Parserless ingestion uses generative AI to identify, interpret and classify any data source, SignalGate, its AI security data fabric added in Version 3.3 (March 2026), processes, classifies, prioritizes and routes signals across the asset landscape, and CyberLLM correlates signals across the environment; a patented process converts logs and alerts into natural language.
A Predict and Prevent layer adds a statistical model of attacker behavior and Monte Carlo scenario modeling to flag attack patterns before impact.
Version 3.3 introduced the Autonomous Security Operator, whose SOARGPT reasons across alerts, asset relationships and threat intelligence and executes coordinated actions across the security stack with minimal analyst intervention, directed in natural language, alongside SOCGPT for plain language investigation, ReportGPT for reports and BreachGPT for breach attack simulation, in a multi tenant interface for enterprise SOCs and MSSPs.
PRE deploys on premises, in a private cloud or as SaaS, down to a Mac mini based miniSOC for small teams. Its pages document no approval step or autonomy control for SOARGPT's actions, no log of what the agents did, no attestation or access controls for the platform, no named models and no API. It fits SOC teams and MSSPs that want an AI native SIEM replacement they can run on their own hardware; buyers who need documented oversight controls and attestations should ask for them.
Vendor details
Canonical URL
https://presecurity.ai
Category
Security / SOC agent
Subcategory
AI native predictive SecOps / AI SIEM
Funding status
Seed; headquartered in San Jose / Silicon Valley; leadership from NetScreen, Fortinet, Cisco, Splunk, Zscaler backgrounds
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Parserless ingestion accepts any data source or format, streamed or through API connectors, with SignalGate classifying and routing signals; PRE can sit in front of an existing SIEM or XDR or replace it, includes a lightweight Windows EDR agent, and SOARGPT acts across the security stack (systems not named publicly).
In practice
A SOC replaces its legacy SIEM, ingesting any log source without parsers as SignalGate suppresses noise and generative XDR surfaces behavioral threats
The Predict and Prevent layer models attack patterns in formation with Monte Carlo scenarios, giving the team time to act before impact
An analyst uses SOCGPT to investigate an incident in plain language and runs a breach attack simulation through BREACHGPT without query languages
Sources & related URLs
Agentic Index coverage score
6.0 / 14 capabilities · 43%
| Integrations & Tool Calling | Full |
|---|---|
|
SOARGPT reasons across alerts, asset relationships and threat intelligence and executes "coordinated actions across the security stack with minimal analyst intervention", though PRE does not name the systems it acts in. Data comes in from any source through log receivers or data connectors without parsers, and SignalGate can sit in front of an existing SIEM, sending low value logs to cheap storage while forwarding high value signal for analysis. MSSPs can white label the platform or brand it jointly, and PRE says flexible integrations fit it into an existing stack. SourcePRE Security, presecurity.ai/product, /partners and /pre-security-unveils-breakthrough-version-3-3-and-earns-top-industry-awards-ahead-of-rsa-conference-2026; presecurity.ai/pre-security-unveils-breakthrough-version-3-3-and-earns-top-industry-awards-ahead-of-rsa-conference-2026read 2026-10-06 |
|
| Workflow Orchestration | Full |
|
SOARGPT is built as an agentic system that reasons and acts rather than following scripts, moving beyond static playbooks, and teams direct it with prompts in natural language. It works beside SOCGPT for investigation, ReportGPT for reports and BreachGPT for breach attack simulation inside the Autonomous Security Operator, which carries investigation, triage, reporting and response through natural language. SourcePRE Security, presecurity.ai/product and /pre-security-unveils-breakthrough-version-3-3-and-earns-top-industry-awards-ahead-of-rsa-conference-2026; presecurity.ai/pre-security-unveils-breakthrough-version-3-3-and-earns-top-industry-awards-ahead-of-rsa-conference-2026read 2026-10-06 |
|
| Knowledge Grounding & RAG | Full |
|
SignalGate, an AI security data fabric, processes, classifies, prioritizes and routes security signals across the entire asset landscape, and CyberLLM "correlates signals across your entire environment with full context", reading narrative, intent and threat context. Log2NLP turns raw logs into natural language and PRE retains the data at full fidelity, so the agents reason over the customer's own telemetry. SourcePRE Security, presecurity.ai, /product, /wp-content/uploads/2026/03/PRESecurity_SolutionBrief.pdf and /pre-security-unveils-breakthrough-version-3-3-and-earns-top-industry-awards-ahead-of-rsa-conference-2026read 2026-10-06 |
|
| Human Oversight & Guardrails | Not documented |
|
SOARGPT executes actions across the security stack "with minimal analyst intervention", and PRE says its agentic AI takes the repetitive work so analysts can focus on decisions rather than alert queues. No approval step, autonomy setting or customer controlled constraint on agent actions is documented. SourcePRE Security, presecurity.ai/product and /partnersread 2026-10-06 |
|
| Security, Identity & Governance | Not documented |
|
No attestation, SSO, role model or trust page for the platform is published. The multi tenant design gives each client an isolated tenant environment under central management, but no controls over who inside a customer's team can do what are documented. SourcePRE Security, presecurity.ai, /partners and /wp-content/uploads/2026/03/PRESecurity_SolutionBrief.pdfread 2026-10-06 |
|
| Observability & Auditability | Not documented |
|
No log or trace of what SOARGPT or the other assistants did is documented. Alerts, threat hunting, SearchGPT investigation and the daily posture report, modeled on a weather forecast with prioritized recommended actions, describe the customer's estate rather than the agents' own steps. SourcePRE Security, presecurity.ai/product and /pre-security-unveils-breakthrough-version-3-3-and-earns-top-industry-awards-ahead-of-rsa-conference-2026read 2026-10-06 |
|
| Memory & State Persistence | Not documented |
|
The statistical memory PRE added to its data pipeline captures the natural flow of attacker behavior patterns so predictions become more stable earlier in the pipeline. It models attacks rather than holding what the agents did or learned, and no agent memory with a stated scope and lifetime is documented. SourcePRE Security, prnewswire.com/news-releases/pre-security-enhances-ai-data-fabric-use-case-and-expands-predictive-capabilities-302564442.htmlread 2026-10-06 |
|
| Deployment & Data Residency | Full |
|
PRE deploys on premises, in a private cloud or as SaaS, from "a Mac mini based miniSOC to enterprise class servers to cloud scale SaaS". The solution brief describes a fully managed cloud with automatic updates, the customer's own data center or hardware with full data sovereignty, a hybrid of cloud and on premises with flexible data residency, and isolated tenant environments under central management. The platform can also run in parallel to an existing workflow during a transition. SourcePRE Security, presecurity.ai, /product and /wp-content/uploads/2026/03/PRESecurity_SolutionBrief.pdfread 2026-10-06 |
|
| Prebuilt Agents, Templates & Packs | Full |
|
The Autonomous Security Operator ships four named assistants with stated jobs, SOCGPT for investigation in plain language, SOARGPT for agentic response, ReportGPT for reports built from prompts and BreachGPT for breach attack simulation. PRE also sells a miniSOC package for small teams and an offer for MSSPs, who can white label the platform with native multi tenancy and pricing per asset, and three ways in: a full SIEM replacement, SignalGate and parserless ingestion in front of an existing SIEM, or a parallel addition. SourcePRE Security, presecurity.ai, /product, /partners and /pre-security-unveils-breakthrough-version-3-3-and-earns-top-industry-awards-ahead-of-rsa-conference-2026read 2026-10-06 |
|
| Triggers & Channel Coverage | Full |
|
SOARGPT reasons across alerts, asset relationships and threat intelligence in real time and executes coordinated actions as signals arrive, and the homepage promises no manual triage, with agentic AI handling the repetitive work. Work starts when alerts come in rather than when someone asks. SourcePRE Security, presecurity.ai and /pre-security-unveils-breakthrough-version-3-3-and-earns-top-industry-awards-ahead-of-rsa-conference-2026read 2026-10-06 |
|
| Model Flexibility & Routing | Not documented |
|
PRE's own CyberLLM is described as a proprietary security LLM trained for detection and prediction, combined with generative AI and statistical methods, and the solution brief adds consensus predictions that aggregate several models for threat forecasting. No outside model provider is named and no customer choice of model is documented. SourcePRE Security, presecurity.ai/product and /wp-content/uploads/2026/03/PRESecurity_SolutionBrief.pdfread 2026-10-06 |
|
| APIs, SDKs & MCP Extensibility | Not documented |
|
No API reference, SDK or MCP server is published. Log receivers and data connectors bring data into the platform from any source, and nothing documents a way for outside software to call PRE. SourcePRE Security, presecurity.ai/productread 2026-10-06 |
|
| Testing, Debugging & Optimization | Not documented |
|
No harness, scored tests or quality gate for the agents' own work is documented. BreachGPT runs breach attack simulation for vulnerability testing and red team work, and Monte Carlo scenario modeling simulates thousands of attack vectors, both aimed at the customer's estate. PRE's own figures call the platform 10X more effective and claim SIEM ingestion costs fall by 50 to 80%. SourcePRE Security, presecurity.ai, /wp-content/uploads/2026/03/PRESecurity_SolutionBrief.pdf and /pre-security-unveils-breakthrough-version-3-3-and-earns-top-industry-awards-ahead-of-rsa-conference-2026read 2026-10-06 |
|
| Browser & Computer Use | Not documented |
|
PRE works on ingested telemetry and a Windows EDR agent, and its agents act through the security stack rather than through a screen. No agent operating a browser or desktop is documented. SourcePRE Security, presecurity.ai and /resourcesread 2026-10-06 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Pricing
Contact sales; no public pricing
per asset (no rates published)
What is public
No prices. The pricing basis is public: the partners page describes asset based pricing with no ingestion based charges. Deployment choices (on premises, private cloud, SaaS, miniSOC) are public.
Billing mechanics
Asset based pricing with no ingestion based charges, per the partners page, which says it keeps costs predictable as data volumes grow; no per asset rates or tiers are published.
Cost watchouts
Cost scales with the number of assets protected rather than data volume, since pricing is asset based. Inference, not stated: the EDR agent and miniSOC packaging may price separately.
Variable cost rationale
Asset based pricing, stated on the partners page, keeps cost predictable within a defined estate, with asset growth the main lever.
Additional watchouts
Confirm what counts as an asset and whether EDR endpoints, MiniSOC, and predictive modules are bundled or add ons.
Sales call required
Yes, required for paid access
Free / trial
No free tier documented; can run in parallel to an existing SIEM for low disruption evaluation
Key ambiguities
The pricing basis (asset based, no ingestion charges) is public but no dollar figures, per asset rates or tier boundaries are.
Missing data
Per asset rates, tier boundaries, EDR and MiniSOC pricing.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to PRE Security
The closest documented capability profiles to PRE Security among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- StrikeReady7.0 / 14Adds documented Human Oversight & Guardrails and Security, Identity & Governance, among others
- Mycroft6.5 / 14Adds documented Human Oversight & Guardrails and Security, Identity & Governance
- Seemplicity8.5 / 14Adds documented Human Oversight & Guardrails and Security, Identity & Governance, among others
- Crogl9.0 / 14Adds documented Human Oversight & Guardrails and Security, Identity & Governance, among others
- Quantro Security7.0 / 14Adds documented Human Oversight & Guardrails and Security, Identity & Governance, among others
- Simbian9.0 / 14Adds documented Human Oversight & Guardrails and Observability & Auditability, among others
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded