Back to vendors
P

Prophet Security

Also known as: ProphetSecurity

Visit site
Entry priceContact sales; enterprise contracts, no public ratesFull pricing detail

AI SOC platform whose agents investigate every alert with documented reasoning, respond through scoped actions with optional sign-off, and test guidance changes against the customer's own history.

Prophet Security builds Prophet AI, an agentic platform for the security operations center. Three agents do separate jobs: the AI SOC Analyst investigates every alert the moment it arrives, at every severity; the AI Threat Hunter runs natural language, scheduled and recurring hunts; and the AI Detection Engineer maps ATT&CK coverage and ships tuned and new detections that are backtested first. A human service, Watchtower, has Prophet's own experts review malicious determinations around the clock and is sold beside the software.

Two traits stand out on the product pages. The first is auditability: every question the agent asks, every query it runs and every reasoning step is documented, so an analyst can check exactly how a determination was reached.

The second is how the agent is taught: teams write guidance in plain language, organization wide, for a full investigation or for a single step, nothing is learned silently, every entry's source is visible and correctable, and changes are previewed and backtested against the customer's own alert history before they apply.

Responses run through scoped, permissioned Agent Actions, from notifications to quarantining a machine, either autonomously or with the customer's sign-off, over more than 200 integrations, with results delivered in the product, Slack, Teams or a webhook.

Prophet deploys as a dedicated single tenant with a bring your own key option, and names SOC 2 Type II, ISO 27001 and ISO 42001. It publishes no pricing, no API documentation and no model providers. For a SOC that wants to check every AI conclusion and control what the agent learns before it changes behavior, Prophet documents that loop in detail. It works with what the connected tools surface.

Vendor details

Canonical URL

https://www.prophetsecurity.ai

Category

Security / SOC agent

Subcategory

AI SOC analyst

Funding status

Independent and venture backed.

Company status

independent

Use cases & customers

Primary use cases

autonomous alert triage and investigationcontinuously learning SOC automationaudit ready AI investigationsthreat hunting

Target customers

enterprise SOC teamsregulated industriessecurity teams with data residency requirements

Deployment options

SaaSsingle tenant

Integrations

More than 200 out of the box integrations; investigations gather evidence across the connected tools, responses run through scoped, permissioned Agent Actions with optional sign-off, and results go to the product, Slack, Teams or the customer's own webhook. Deployed as a dedicated single tenant with a bring your own key option.

In practice

Your last AI security tool changed its behavior without telling you. Prophet learns nothing silently: every guidance entry shows its source, can be corrected, and is backtested against your own alert history before it applies.

Auditors want to see how every AI conclusion was reached. Prophet documents every question, query and reasoning step behind each determination.

You want automated response without handing over the keys. Prophet's Agent Actions are scoped and permissioned, previewed before they run, and can require your sign-off.

Sources & related URLs

Agentic Index coverage score

8.5 / 14 capabilities · 61%

Integrations & Tool Calling Full

Prophet lists more than 200 out of the box integrations, and the AI SOC Analyst responds through scoped, permissioned Agent Actions in the customer's systems, from notifications to quarantining a machine. Results are delivered to Slack, Teams or the customer's own webhook. Investigations query SIEM, EDR, identity, cloud and email tools, and delivery can be set separately for each channel.

SourceProphet Security, prophetsecurity.ai/ai-soc-analystread 2026-10-05

Workflow Orchestration Partial

Each alert runs through a fixed investigation, determination and response sequence, and customers can add guidance to a single step. Prophet documents no branching, conditions, handoff between agents or workflow that customers build. Related investigations are grouped into incidents automatically.

SourceProphet Security, prophetsecurity.ai/ai-soc-analystread 2026-10-05

Knowledge Grounding & RAG Partial

Investigations gather evidence live across the customer's connected tools and apply the guidance the customer writes. Prophet describes no index, graph or embeddings layer over the customer's own knowledge. The AI Detection Engineer maps the customer's MITRE ATT&CK coverage from its own investigations.

SourceProphet Security, prophetsecurity.ai/ai-soc-analyst and prophetsecurity.airead 2026-10-05

Human Oversight & Guardrails Full

Agent Actions run autonomously or only with the customer's sign-off, each remediation is previewed before it runs, and actions are scoped and permissioned. Autonomy covers only the actions a customer has approved, and the customer widens that scope when the agent's track record justifies it. Watchtower experts also review every malicious determination around the clock.

SourceProphet Security, prophetsecurity.ai/ai-soc-analyst and prophetsecurity.airead 2026-10-05

Security, Identity & Governance Partial

Prophet states SOC 2 Type II, ISO/IEC 27001:2022 and ISO/IEC 42001:2023 in its trust center's page description, and the homepage carries a SOC 2 Type 2 badge. Prophet's product pages document no SSO, SCIM or user roles; scoped Agent Actions limit what the agent can do, not what users can reach. The trust center sits at trust.prophetsecurity.ai, and Prophet does not train AI models on personal data.

SourceProphet Security, trust.prophetsecurity.ai and prophetsecurity.airead 2026-10-05

Observability & Auditability Full

Every question asked, every query run and every reasoning step in an investigation is documented, so the team can verify exactly how a determination was reached. Watchtower sends validated escalations in under 30 minutes, and results can go to Slack, Teams or a webhook for each channel.

SourceProphet Security, prophetsecurity.ai/ai-soc-analyst and prophetsecurity.airead 2026-10-05

Memory & State Persistence Partial

Customers teach the agent playbooks, policies and preferences in plain language, organization wide, per investigation or per step. Nothing is learned silently, and every entry's source is visible and correctable. What the agent learns carries into every later investigation and stays when an analyst leaves. Most entries are guidance the product applies, and Prophet does not say how long they are kept.

SourceProphet Security, prophetsecurity.ai/ai-soc-analystread 2026-10-05

Deployment & Data Residency Partial

Each customer gets a dedicated single tenant with a bring your own key option. Where that tenant is hosted is not published, and no region choice or customer environment option (VPC, on premises) is named.

Sourceprophetsecurity.airead 2026-09-28

Prebuilt Agents, Templates & Packs Full

Prophet ships three agents that each do their own job. The AI SOC Analyst investigates alerts, the AI Threat Hunter runs natural language and ready to run hunts, and the AI Detection Engineer maps ATT&CK coverage and ships backtested detections. Watchtower is a human review service rather than an agent. Use cases span endpoint, email, identity, cloud, DLP and network alerts, and named customers include Redis, Udemy, Instacart, Penske and Moveworks.

SourceProphet Security, prophetsecurity.airead 2026-10-05

Triggers & Channel Coverage Full

Alerts are investigated the moment they arrive, 100 percent of them at every severity, with no analyst starting the work. Each investigation begins by summarizing the alert, pulling out its artifacts and planning the questions an expert analyst would ask.

SourceProphet Security, prophetsecurity.ai/ai-soc-analystread 2026-10-05

Model Flexibility & Routing Not documented

No published page names the models or providers behind Prophet AI or offers a model choice.

Sourceprophetsecurity.airead 2026-09-28

APIs, SDKs & MCP Extensibility Not documented

For developers there is no documented way in: no API, SDK or MCP server for the Prophet platform is published, and there are no developer or docs pages. Outbound delivery to the customer's own webhook is the platform calling out, not an interface for calling it.

Sourceprophetsecurity.ai/sitemap.xmlread 2026-09-28

Testing, Debugging & Optimization Full

Changes to the agent's guidance are previewed and backtested against the customer's own alert history before they apply, so a change has to hold up on past alerts first. Remediations and new detections are backtested the same way. One customer reports 95% less manual review, and Prophet cites a 10 times faster MTTR.

SourceProphet Security, prophetsecurity.ai/ai-soc-analystread 2026-10-05

Browser & Computer Use Not documented

No page documents the agents driving a browser, desktop or remote computer. They act through integrations.

Sourceprophetsecurity.airead 2026-09-28

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Recent platform changes

2026-07-23·Agent capabilityVerified

Prophet Security announced the general availability of Prophet AI Threat Researcher and Emerging Threats within the Prophet AI Threat Hunter. This new AI agent autonomously scours open-source intelligence for emerging vulnerabilities and attacker activity, synthesizes its findings, and collaborates with reactive hunting agents to automatically build and execute hunting plans.

Bears on: Agent capability

View source
View all 1 change for Prophet Security →Tracked since Jul 2026 · Verified from public vendor sources

Pricing

Contact sales; enterprise contracts, no public rates

enterprise contract

Trial available

Included quota

Not published; the platform spans alert investigation, threat hunting and detection engineering.

What is public

Nothing numeric; the three agents, the Watchtower service and the single tenant deployment are public.

Billing mechanics

Contracts through sales covering the agent platform, deployed as a dedicated single tenant. The metering basis is not published.

Cost watchouts

Confirm whether Watchtower's human review is in the base contract, and what the contract meters. As an inference, dedicated single tenant hosting may be priced above a shared deployment.

Variable cost rationale

Platform contracts with hunting and tuning included suggest flat enterprise licensing rather than usage metering; no usage based billing is documented.

Additional watchouts

No public anchor to negotiate against; ask what the contract meters (alerts, investigations or a flat platform fee) and whether Watchtower is included.

Overage / add-ons

No public metering or overage terms documented.

Sales call required

Yes, required for paid access

Free / trial

Proof of value evaluations through sales; no self serve trial

Lowest paid plan

None public; enterprise contract only

Commercial notes

Independent, venture backed.

Key ambiguities

Nothing numeric is public, and the metering basis (per alert, per investigation, or flat) is not documented.

Agentic Index verified 2026-09-28

Alternatives to Prophet Security

The closest documented capability profiles to Prophet Security among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.