Qevlar AI
European autonomous AI SOC platform using graph based orchestration for hallucination free tier 2 and 3 investigation in about three minutes, live across 1,500 plus organizations.
Qevlar is a European autonomous AI SOC platform built on graph based orchestration, with a design goal that shapes everything: reproducible, grounded investigations at Tier 2 and Tier 3 depth. Founded in 2023 in Paris by CEO Ahmed Achchak and Hamza Sayah, the company raised roughly $44 million in total, most recently a $30 million round in March 2026 co led by Partech and Forgepoint with EQT Ventures, and says it runs in production at more than 1,500 organizations, among them Mercedes-Benz, Sodexo, Orange Cyberdefense and Atos, with a large base of managed security providers.
The platform investigates every alert that arrives from the connected stack, more than 50 integrations across SIEMs, EDRs, identity, cloud, email and ticketing, and can take response actions such as blocking a suspicious IP.
The core reasoning runs in a graph orchestrator rather than an LLM, which the company positions as the reason investigations stay grounded and reproducible; LLMs handle narrow tasks such as enrichment and summaries. Analysts see every step and every observable queried behind a verdict, can override it and add context, and Qevlar applies that context to later cases.
Beyond triage it covers threat hunting, detection tuning and vulnerability prioritization. A documented REST API takes alerts in and returns investigation results.
Qevlar hosts on Google Cloud in Belgium with LLM inference on Azure in Sweden, keeps customer data in the EU, offers a Bring Your Own Cloud deployment for another region, supports SSO and holds a SOC 2 Type II attestation. It publishes no pricing; contracts run through sales, with packaging for managed providers. For SOCs and MSSPs that want deep, reproducible autonomous investigation hosted in Europe, Qevlar is built for that job.
Vendor details
Canonical URL
https://www.qevlar.com
Category
Security / SOC agent
Subcategory
AI SOC platform
Funding status
Independent, founded 2023 in Paris by CEO Ahmed Achchak and Hamza Sayah. Raised about $44 million total, including a $30 million round in March 2026 co led by Partech and Forgepoint Capital International with EQT Ventures, following a $14 million round in 2025. Live in production across more than 1,500 organizations including Mercedes-Benz, Sodexo, Orange Cyberdefense, and Atos.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Automatically investigates alerts by correlating detection signals and telemetry across the entire security stack, including SIEMs, EDRs, identity systems, and threat intelligence sources, using graph based orchestration and LLMs. New agents unify SOC and vulnerability operations, correlating CVEs with live incident data, identifying asset owners, and hunting active CVE exploitation, generally available Fall 2026.
In practice
Your MSSP analysts spend 30 plus minutes per alert across thousands daily. Qevlar investigates every alert at tier 2 and 3 depth in about three minutes with graph based orchestration.
You will not trust an autonomous tool that hallucinates in an investigation. Qevlar's graph based orchestration is built for reproducible, grounded conclusions rather than free form generation.
Your SOC and vulnerability teams work in silos. Qevlar's new vulnerability agents, now in preview, correlate CVEs with live incident data, identify asset owners, and hunt active exploitation across both.
Sources & related URLs
Agentic Index coverage score
8.5 / 14 capabilities · 61%
| Integrations & Tool Calling | Full |
|---|---|
|
More than 50 API based integrations across Microsoft Defender, Sentinel and Entra ID, CrowdStrike, Splunk, Elastic, AWS, Okta, Palo Alto, ServiceNow, Jira, Tines and others, with response actions such as blocking a suspicious IP or contacting the user. They span SIEM, SOAR and ticketing, EDR and XDR, email, identity, threat intel, malware sandboxes, cloud and network tools, including Cortex XSIAM and XSOAR, Google SecOps, SentinelOne, Proofpoint, Mimecast, Zscaler and VirusTotal. After an investigation, Qevlar moves to the next action: containment for malicious activity, tuning for false positives, or a policy or compliance follow up. SourceQevlar AI, qevlar.com/integrations and qevlar.comread 2026-10-05 |
|
| Workflow Orchestration | Partial |
|
A graph based orchestrator, not an LLM, runs each investigation along structured, reproducible paths across the stack and follows the customer's procedures. It connects related activity into a single incident story, maps the full blast radius and moves containment forward. Qevlar does not describe branching, conditions, multiple agents or a flow customers build; each investigation follows the product's own pipeline. SourceQevlar AI, qevlar.comread 2026-10-05 |
|
| Knowledge Grounding & RAG | Partial |
|
Investigations correlate telemetry and threat intelligence from the connected stack and draw on an organizational context of past investigations. For each MSSP client, the provider sets the enrichment and context sources Qevlar uses in every investigation, along with that client's business context. Qevlar does not describe an index or graph it maintains over the customer's own knowledge. SourceQevlar AI, qevlar.com and qevlar.com/solutions/msspsread 2026-10-05 |
|
| Human Oversight & Guardrails | Partial |
|
Investigations follow the customer's procedures with analyst control, and analysts can override any verdict and add context. Analysts review alerts judged malicious, confirm the outcome and take the next steps Qevlar suggests. Qevlar does not describe an approval step before a response action runs. SourceQevlar AI, qevlar.com and qevlar.com/productread 2026-10-05 |
|
| Security, Identity & Governance | Full |
|
The platform supports SSO integration, with role based access and mandatory MFA on internal and production access, and holds a SOC 2 Type II attestation for the Security criteria. Data is encrypted with AES-256 at rest and TLS 1.2 or higher in transit, with keys held in GCP KMS, and an outside firm runs a penetration test every year. Qevlar does not train its AI models on customer data, and it notifies customers within 72 hours of confirming a personal data breach. SourceQevlar AI, help.qevlar.com Data Privacy and Protection FAQsread 2026-10-05 |
|
| Observability & Auditability | Full |
|
Every verdict is transparent: analysts see every step and every observable queried in the investigation, and audit logs are kept for up to 12 months. Full investigation reports can go straight to a SOAR or ticketing system or be read inside Qevlar, and actions can be traced for compliance. SourceQevlar AI, qevlar.com, qevlar.com/solutions/mssps and help.qevlar.com Data Privacy and Protection FAQsread 2026-10-05 |
|
| Memory & State Persistence | Partial |
|
When analysts override a verdict and add context, Qevlar applies it to future cases, and an organizational context keeps past investigations, so state carries across cases. That knowledge stays in the platform as shared intelligence when analysts move on, and each investigation sharpens the next. Qevlar does not say how widely that store applies or how long it is kept. SourceQevlar AI, qevlar.comread 2026-10-05 |
|
| Deployment & Data Residency | Full |
|
Primary hosting is Google Cloud in Belgium with LLM inference on Azure in Sweden, customer data retained in the EU, and a Bring Your Own Cloud deployment through which customers can choose another region. Bring Your Own Cloud runs on GCP or Azure, and Qevlar can run as SaaS or in a private cloud. Setup goes through APIs and usually takes a few hours; the fastest so far took 10 minutes. Alert data is deleted 60 days after a contract ends unless agreed otherwise. SourceQevlar AI, help.qevlar.com Data Privacy and Protection FAQs, qevlar.com/product and qevlar.com/solutions/msspsread 2026-10-05 |
|
| Prebuilt Agents, Templates & Packs | Partial |
|
One platform covers investigation, threat hunting, detection engineering and vulnerability prioritization, and Qevlar sells these as parts of one product rather than as separate ready made agents or templates. The vulnerability agents, still in preview, blend CVE intelligence with live SOC signal into a contextual severity score, find each asset's owner from ITSM, identity provider and EDR records, and write and run threat hunts across the SIEM and EDR. Qevlar packages the product for phishing, network, identity and cloud alerts, and MSSPs get a separate tenant for each client with its own investigations and settings. SourceQevlar AI, qevlar.com, qevlar.com/soc-and-vulnerability and qevlar.com/solutions/msspsread 2026-10-05 |
|
| Triggers & Channel Coverage | Full |
|
New alerts from across the security stack start investigations with no analyst initiating them, alerts can be pushed in through POST /alert, and hunts run continuously. A pushed alert is accepted at once with a PENDING status. Hunt queries are written and run across the SIEM and EDR automatically, and the platform works around the clock. SourceQevlar AI, help.qevlar.com SOC Workflow Integration API and qevlar.com/soc-and-vulnerabilityread 2026-10-05 |
|
| Model Flexibility & Routing | Not documented |
|
Core reasoning runs in Qevlar's graph orchestrator, and LLMs handle narrow tasks such as enrichment and summaries on Azure inference in Sweden. Qevlar chose that single provider, and customers cannot choose a model. Inference stays under EU and EEA processing, and customer data is not used for training. SourceQevlar AI, help.qevlar.com Data Privacy and Protection FAQs and qevlar.comread 2026-10-05 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
A documented REST API at api.qevlar.com with Bearer token auth submits alerts (POST /alert), returns investigation status and results (GET /alert/{id}), and publishes its reference at api.qevlar.com/redoc. A new alert returns an alert ID with a PENDING status, a status check returns IN_PROGRESS, FAILURE or the full results, and rate limits follow the subscription plan. SourceQevlar AI, help.qevlar.com SOC Workflow Integration APIread 2026-10-05 |
|
| Testing, Debugging & Optimization | Not documented |
|
Analyst overrides feed later cases. Qevlar publishes no evaluation harness, scored test cases, quality gate or optimization loop that customers run. It reports a 3 minute average alert investigation and up to 80% of tickets closed automatically, and says MSSPs using it report an average 300% return on investment. SourceQevlar AI, qevlar.com/product and qevlar.com/solutions/mssps; qevlar.comread 2026-10-05 |
|
| Browser & Computer Use | Not documented |
|
Qevlar does not describe an agent driving a browser, desktop or remote computer. Investigations and actions run through API integrations, and results can go straight into the team's SOAR or ticketing tool. SourceQevlar AI, qevlar.com and qevlar.com/solutions/msspsread 2026-10-05 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
Qevlar AI released Identity Hunt, an identity analysis engine that runs autonomously whenever a user observable appears in an investigation. The agent automatically builds a 30-day behavioral baseline for the specific user and evaluates authentication logs in under 10 seconds to return an actionable verdict, even if the primary alert is not identity-related.
Bears on: Security / enterprise
View sourcePricing
Contact sales; enterprise and MSSP contracts, no public rates
enterprise contract (MSSP packaging)
Included quota
Platform contract covering autonomous investigation across the full stack at Tier 2 and 3 depth; Fall 2026 vulnerability operations agents extend scope. No public tiers.
What is public
Nothing numeric; the 1,500 organization base and MSSP focus are public.
Billing mechanics
Enterprise contracts through sales with distinct MSSP packaging for managed providers serving many clients, plus direct enterprise deployment. Pricing not disclosed.
Cost watchouts
MSSP versus direct enterprise packaging differ; a managed provider reselling Qevlar across clients prices differently than a single enterprise deployment. Confirm which model the quote reflects.
Variable cost rationale
Enterprise platform licensing; while investigation volume likely factors in, no usage metering is published, so documented exposure is low.
Additional watchouts
Hosting is in the EU (Google Cloud, Belgium) by default, with Bring Your Own Cloud for another region; buyers outside Europe should confirm which deployment the quote covers.
Overage / add-ons
No public metering documented; likely scales with alert or investigation volume but terms are not published.
Sales call required
Yes, required for paid access
Free / trial
Enterprise evaluations through sales; no self serve trial
Lowest paid plan
None public; enterprise contract only
Commercial notes
Independent, Paris founded 2023, about $44 million raised. Says it is live across 1,500 plus organizations including Mercedes-Benz, Sodexo, Orange Cyberdefense and Atos, with a large managed service provider base.
Key ambiguities
Nothing numeric is public, and MSSP multi tenant pricing versus direct enterprise pricing is not documented.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to Qevlar AI
The closest documented capability profiles to Qevlar AI among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Horizon3.ai8.5 / 14Matches Qevlar AI across all 14 documented capabilities
- Idira8.0 / 14A lighter documented profile than Qevlar AI
- Okta8.5 / 14Fuller documented coverage on Human Oversight & Guardrails
- Operant AI7.5 / 14A lighter documented profile than Qevlar AI
- HiddenLayer9.0 / 14Adds documented Testing, Debugging & Optimization
- XBOW9.0 / 14Adds documented Browser & Computer Use
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded