Back to vendors
Q

Qevlar AI

Visit site
Entry priceContact sales; enterprise and MSSP contracts, no public ratesFull pricing detail

European autonomous AI SOC platform using graph based orchestration for hallucination free tier 2 and 3 investigation in about three minutes, live across 1,500 plus organizations.

Qevlar is a European autonomous AI SOC platform built on graph based orchestration, with a design goal that shapes everything: reproducible, grounded investigations at Tier 2 and Tier 3 depth. Founded in 2023 in Paris by CEO Ahmed Achchak and Hamza Sayah, the company raised roughly $44 million in total, most recently a $30 million round in March 2026 co led by Partech and Forgepoint with EQT Ventures, and says it runs in production at more than 1,500 organizations, among them Mercedes-Benz, Sodexo, Orange Cyberdefense and Atos, with a large base of managed security providers.

The platform investigates every alert that arrives from the connected stack, more than 50 integrations across SIEMs, EDRs, identity, cloud, email and ticketing, and can take response actions such as blocking a suspicious IP.

The core reasoning runs in a graph orchestrator rather than an LLM, which the company positions as the reason investigations stay grounded and reproducible; LLMs handle narrow tasks such as enrichment and summaries. Analysts see every step and every observable queried behind a verdict, can override it and add context, and Qevlar applies that context to later cases.

Beyond triage it covers threat hunting, detection tuning and vulnerability prioritization. A documented REST API takes alerts in and returns investigation results.

Qevlar hosts on Google Cloud in Belgium with LLM inference on Azure in Sweden, keeps customer data in the EU, offers a Bring Your Own Cloud deployment for another region, supports SSO and holds a SOC 2 Type II attestation. It publishes no pricing; contracts run through sales, with packaging for managed providers. For SOCs and MSSPs that want deep, reproducible autonomous investigation hosted in Europe, Qevlar is built for that job.

Vendor details

Canonical URL

https://www.qevlar.com

Category

Security / SOC agent

Subcategory

AI SOC platform

Funding status

Independent, founded 2023 in Paris by CEO Ahmed Achchak and Hamza Sayah. Raised about $44 million total, including a $30 million round in March 2026 co led by Partech and Forgepoint Capital International with EQT Ventures, following a $14 million round in 2025. Live in production across more than 1,500 organizations including Mercedes-Benz, Sodexo, Orange Cyberdefense, and Atos.

Company status

independent

Use cases & customers

Primary use cases

autonomous tier 2 and 3 investigationhallucination free graph orchestrationMSSP alert overloadSOC and vulnerability operations unification

Target customers

MSSPsFortune 500 enterprisesEuropean SOC teams

Deployment options

SaaS

Integrations

Automatically investigates alerts by correlating detection signals and telemetry across the entire security stack, including SIEMs, EDRs, identity systems, and threat intelligence sources, using graph based orchestration and LLMs. New agents unify SOC and vulnerability operations, correlating CVEs with live incident data, identifying asset owners, and hunting active CVE exploitation, generally available Fall 2026.

In practice

Your MSSP analysts spend 30 plus minutes per alert across thousands daily. Qevlar investigates every alert at tier 2 and 3 depth in about three minutes with graph based orchestration.

You will not trust an autonomous tool that hallucinates in an investigation. Qevlar's graph based orchestration is built for reproducible, grounded conclusions rather than free form generation.

Your SOC and vulnerability teams work in silos. Qevlar's new vulnerability agents, now in preview, correlate CVEs with live incident data, identify asset owners, and hunt active exploitation across both.

Agentic Index coverage score

8.5 / 14 capabilities · 61%

Integrations & Tool Calling Full

More than 50 API based integrations across Microsoft Defender, Sentinel and Entra ID, CrowdStrike, Splunk, Elastic, AWS, Okta, Palo Alto, ServiceNow, Jira, Tines and others, with response actions such as blocking a suspicious IP or contacting the user.

They span SIEM, SOAR and ticketing, EDR and XDR, email, identity, threat intel, malware sandboxes, cloud and network tools, including Cortex XSIAM and XSOAR, Google SecOps, SentinelOne, Proofpoint, Mimecast, Zscaler and VirusTotal.

After an investigation, Qevlar moves to the next action: containment for malicious activity, tuning for false positives, or a policy or compliance follow up.

SourceQevlar AI, qevlar.com/integrations and qevlar.comread 2026-10-05

Workflow Orchestration Partial

A graph based orchestrator, not an LLM, runs each investigation along structured, reproducible paths across the stack and follows the customer's procedures. It connects related activity into a single incident story, maps the full blast radius and moves containment forward. Qevlar does not describe branching, conditions, multiple agents or a flow customers build; each investigation follows the product's own pipeline.

SourceQevlar AI, qevlar.comread 2026-10-05

Knowledge Grounding & RAG Partial

Investigations correlate telemetry and threat intelligence from the connected stack and draw on an organizational context of past investigations. For each MSSP client, the provider sets the enrichment and context sources Qevlar uses in every investigation, along with that client's business context. Qevlar does not describe an index or graph it maintains over the customer's own knowledge.

SourceQevlar AI, qevlar.com and qevlar.com/solutions/msspsread 2026-10-05

Human Oversight & Guardrails Partial

Investigations follow the customer's procedures with analyst control, and analysts can override any verdict and add context. Analysts review alerts judged malicious, confirm the outcome and take the next steps Qevlar suggests. Qevlar does not describe an approval step before a response action runs.

SourceQevlar AI, qevlar.com and qevlar.com/productread 2026-10-05

Security, Identity & Governance Full

The platform supports SSO integration, with role based access and mandatory MFA on internal and production access, and holds a SOC 2 Type II attestation for the Security criteria. Data is encrypted with AES-256 at rest and TLS 1.2 or higher in transit, with keys held in GCP KMS, and an outside firm runs a penetration test every year. Qevlar does not train its AI models on customer data, and it notifies customers within 72 hours of confirming a personal data breach.

SourceQevlar AI, help.qevlar.com Data Privacy and Protection FAQsread 2026-10-05

Observability & Auditability Full

Every verdict is transparent: analysts see every step and every observable queried in the investigation, and audit logs are kept for up to 12 months. Full investigation reports can go straight to a SOAR or ticketing system or be read inside Qevlar, and actions can be traced for compliance.

SourceQevlar AI, qevlar.com, qevlar.com/solutions/mssps and help.qevlar.com Data Privacy and Protection FAQsread 2026-10-05

Memory & State Persistence Partial

When analysts override a verdict and add context, Qevlar applies it to future cases, and an organizational context keeps past investigations, so state carries across cases. That knowledge stays in the platform as shared intelligence when analysts move on, and each investigation sharpens the next. Qevlar does not say how widely that store applies or how long it is kept.

SourceQevlar AI, qevlar.comread 2026-10-05

Deployment & Data Residency Full

Primary hosting is Google Cloud in Belgium with LLM inference on Azure in Sweden, customer data retained in the EU, and a Bring Your Own Cloud deployment through which customers can choose another region. Bring Your Own Cloud runs on GCP or Azure, and Qevlar can run as SaaS or in a private cloud. Setup goes through APIs and usually takes a few hours; the fastest so far took 10 minutes. Alert data is deleted 60 days after a contract ends unless agreed otherwise.

SourceQevlar AI, help.qevlar.com Data Privacy and Protection FAQs, qevlar.com/product and qevlar.com/solutions/msspsread 2026-10-05

Prebuilt Agents, Templates & Packs Partial

One platform covers investigation, threat hunting, detection engineering and vulnerability prioritization, and Qevlar sells these as parts of one product rather than as separate ready made agents or templates.

The vulnerability agents, still in preview, blend CVE intelligence with live SOC signal into a contextual severity score, find each asset's owner from ITSM, identity provider and EDR records, and write and run threat hunts across the SIEM and EDR.

Qevlar packages the product for phishing, network, identity and cloud alerts, and MSSPs get a separate tenant for each client with its own investigations and settings.

SourceQevlar AI, qevlar.com, qevlar.com/soc-and-vulnerability and qevlar.com/solutions/msspsread 2026-10-05

Triggers & Channel Coverage Full

New alerts from across the security stack start investigations with no analyst initiating them, alerts can be pushed in through POST /alert, and hunts run continuously. A pushed alert is accepted at once with a PENDING status. Hunt queries are written and run across the SIEM and EDR automatically, and the platform works around the clock.

SourceQevlar AI, help.qevlar.com SOC Workflow Integration API and qevlar.com/soc-and-vulnerabilityread 2026-10-05

Model Flexibility & Routing Not documented

Core reasoning runs in Qevlar's graph orchestrator, and LLMs handle narrow tasks such as enrichment and summaries on Azure inference in Sweden. Qevlar chose that single provider, and customers cannot choose a model. Inference stays under EU and EEA processing, and customer data is not used for training.

SourceQevlar AI, help.qevlar.com Data Privacy and Protection FAQs and qevlar.comread 2026-10-05

APIs, SDKs & MCP Extensibility Full

A documented REST API at api.qevlar.com with Bearer token auth submits alerts (POST /alert), returns investigation status and results (GET /alert/{id}), and publishes its reference at api.qevlar.com/redoc. A new alert returns an alert ID with a PENDING status, a status check returns IN_PROGRESS, FAILURE or the full results, and rate limits follow the subscription plan.

SourceQevlar AI, help.qevlar.com SOC Workflow Integration APIread 2026-10-05

Testing, Debugging & Optimization Not documented

Analyst overrides feed later cases. Qevlar publishes no evaluation harness, scored test cases, quality gate or optimization loop that customers run. It reports a 3 minute average alert investigation and up to 80% of tickets closed automatically, and says MSSPs using it report an average 300% return on investment.

SourceQevlar AI, qevlar.com/product and qevlar.com/solutions/mssps; qevlar.comread 2026-10-05

Browser & Computer Use Not documented

Qevlar does not describe an agent driving a browser, desktop or remote computer. Investigations and actions run through API integrations, and results can go straight into the team's SOAR or ticketing tool.

SourceQevlar AI, qevlar.com and qevlar.com/solutions/msspsread 2026-10-05

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Recent platform changes

2026-08-13·Agent capabilityVerified

Qevlar AI released Identity Hunt, an identity analysis engine that runs autonomously whenever a user observable appears in an investigation. The agent automatically builds a 30-day behavioral baseline for the specific user and evaluates authentication logs in under 10 seconds to return an actionable verdict, even if the primary alert is not identity-related.

Bears on: Security / enterprise

View source
View all 1 change for Qevlar AI →Tracked since Aug 2026 · Verified from public vendor sources

Pricing

Contact sales; enterprise and MSSP contracts, no public rates

enterprise contract (MSSP packaging)

Trial available

Included quota

Platform contract covering autonomous investigation across the full stack at Tier 2 and 3 depth; Fall 2026 vulnerability operations agents extend scope. No public tiers.

What is public

Nothing numeric; the 1,500 organization base and MSSP focus are public.

Billing mechanics

Enterprise contracts through sales with distinct MSSP packaging for managed providers serving many clients, plus direct enterprise deployment. Pricing not disclosed.

Cost watchouts

MSSP versus direct enterprise packaging differ; a managed provider reselling Qevlar across clients prices differently than a single enterprise deployment. Confirm which model the quote reflects.

Variable cost rationale

Enterprise platform licensing; while investigation volume likely factors in, no usage metering is published, so documented exposure is low.

Additional watchouts

Hosting is in the EU (Google Cloud, Belgium) by default, with Bring Your Own Cloud for another region; buyers outside Europe should confirm which deployment the quote covers.

Overage / add-ons

No public metering documented; likely scales with alert or investigation volume but terms are not published.

Sales call required

Yes, required for paid access

Free / trial

Enterprise evaluations through sales; no self serve trial

Lowest paid plan

None public; enterprise contract only

Commercial notes

Independent, Paris founded 2023, about $44 million raised. Says it is live across 1,500 plus organizations including Mercedes-Benz, Sodexo, Orange Cyberdefense and Atos, with a large managed service provider base.

Key ambiguities

Nothing numeric is public, and MSSP multi tenant pricing versus direct enterprise pricing is not documented.

Agentic Index verified 2026-09-28

Alternatives to Qevlar AI

The closest documented capability profiles to Qevlar AI among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • Horizon3.ai8.5 / 14Matches Qevlar AI across all 14 documented capabilities
  • Idira8.0 / 14A lighter documented profile than Qevlar AI
  • Okta8.5 / 14Fuller documented coverage on Human Oversight & Guardrails
  • Operant AI7.5 / 14A lighter documented profile than Qevlar AI
  • HiddenLayer9.0 / 14Adds documented Testing, Debugging & Optimization
  • XBOW9.0 / 14Adds documented Browser & Computer Use

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.