Radiant Security
AI SOC platform triaging every alert type that reaches the SOC, with analyst confirmed response actions and integrated log management; its technology was acquired by Cribl in August 2026.
Radiant Security builds an AI SOC platform that triages and investigates the alerts a security team's tools raise, across endpoint, identity, email, network and cloud, and pairs it with integrated log management offered as a counterweight to SIEM cost. On 19 August 2026 Cribl announced it had acquired the technology assets and intellectual property of Radiant's AI SOC product, which it plans to adapt as an application on its telemetry data platform; Radiant's own site and help center still present and sell the product, and neither mentions the deal.
Alerts arrive through data connectors or a custom alerts webhook and are triaged and investigated automatically, and each case carries an incident specific response plan.
Response actions run from the case view across CrowdStrike, Microsoft 365 Defender, SentinelOne, Microsoft 365, Okta, Google Workspace, Mimecast, Proofpoint, Netskope and KnowBe4: isolating devices, disabling users, resetting passwords, ending sessions, deleting messages and blocking IPs, URLs and domains. An analyst selects the targets and confirms each action, and many can be reversed with one click.
Audit logs record response actions, verdicts and status changes. Log management stores the customer's logs with search and retention settings, and SSO runs through Okta, Google or Microsoft Entra ID.
Radiant publishes no pricing, no model providers and no hosting regions on the pages that could be read, and its trust center could not be reached. For a team that wants AI triage across all its alerts plus a lever on SIEM spend, Radiant covers both; buyers should now also weigh where Cribl takes the technology.
Vendor details
Canonical URL
https://radiantsecurity.ai
Category
Security / SOC agent
Subcategory
AI SOC analyst
Funding status
Venture backed, raised a $15 million Series A. On 19 August 2026 Cribl announced it had acquired the technology assets and intellectual property of Radiant's AI SOC product.
Company status
acquired
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Ingests alerts from existing detection tools and triages every alert type that reaches the SOC, with integrated log management offered as a lower cost alternative to a standalone SIEM. Real time threat detection and automated response with detailed analytics, built to drop in over the existing stack.
In practice
Your alert stream spans endpoint, identity, and cloud and you want one triage layer for all of it. Radiant is built to triage every alert type that reaches the SOC, not a single class.
Your SIEM bill is the biggest line in the security budget. Radiant's integrated log management offers a lower cost alternative while still triaging your alerts.
You want automated response, not just prioritized alerts. Radiant investigates and drives automated response with detailed analytics on each case.
Sources & related URLs
Research sources
Agentic Index coverage score
6.0 / 14 capabilities · 43%
| Integrations & Tool Calling | Full |
|---|---|
|
Data connectors ingest alerts from the customer's tools, and response actions run from the case view in CrowdStrike, Microsoft 365 Defender, SentinelOne, Microsoft 365, Okta, Google Workspace, Mimecast, Proofpoint, Netskope and KnowBe4: isolating devices, disabling users, resetting passwords, ending sessions, deleting messages and blocking IPs, URLs and domains. Sourcehelp.radiantsecurity.ai/radiant-cases/radiant-cases/response-actionsread 2026-09-28 |
|
| Workflow Orchestration | Partial |
|
Each alert runs through the product's own triage, investigation and case sequence, with response actions launched from the case; no branching, multi agent handoff or automation the buyer configures is documented. Sourcehelp.radiantsecurity.ai/radiant-cases/radiant-cases/response-actions-in-casesread 2026-09-28 |
|
| Knowledge Grounding & RAG | Partial |
|
Integrated log management stores the customer's logs with search, query and retention settings, and the homepage says the platform learns the environment to put alerts in context, but investigations are not shown grounding in a maintained index over the customer's knowledge. Sourcehelp.radiantsecurity.ai/log-management/log-search-and-queryread 2026-09-28 |
|
| Human Oversight & Guardrails | Full |
|
Response actions run only when an analyst selects the targets in a case, clicks the action and confirms it in a confirmation step, and many can be reversed with one click from the action history; the platform produces incident specific response plans for that analyst to execute. Sourcehelp.radiantsecurity.ai/radiant-cases/radiant-cases/response-actions-in-casesread 2026-09-28 |
|
| Security, Identity & Governance | Partial |
|
SAML SSO works with Okta, Google and Microsoft Entra ID and is enforced for all users once set, though every user is assigned the Admin role. No compliance attestation is published, and a trust center sits at trust.radiantsecurity.ai. Sourcehelp.radiantsecurity.ai/manage-radiant/organization-settings/security/set-up-single-sign-on-ssoread 2026-09-28 |
|
| Observability & Auditability | Partial |
|
Audit logs record response actions, alert verdicts and status changes, including those made by the platform, with who, what, when and before and after values, but the AI's investigation steps and reasoning are not documented. Sourcehelp.radiantsecurity.ai/log-management/audit-logs/introduction-to-audit-logsread 2026-09-28 |
|
| Memory & State Persistence | Not documented |
|
The homepage says the platform continuously learns the environment, tooling and normal activity, but the help center documents no memory store, what it keeps, its scope or its lifetime. Sourceradiantsecurity.airead 2026-09-28 |
|
| Deployment & Data Residency | Not documented |
|
Hosting is not described: the homepage and help center name no hosting region or customer environment option. Sourcetrust.radiantsecurity.ai/resourcesread 2026-09-28 |
|
| Prebuilt Agents, Templates & Packs | Partial |
|
One AI SOC analyst with incident response and log management around it, covering many alert types out of the box; these are parts of one product rather than separately adoptable prebuilt agents or templates. Sourceradiantsecurity.airead 2026-09-28 |
|
| Triggers & Channel Coverage | Full |
|
Alerts arriving through data connectors or a custom alerts webhook are triaged and investigated automatically, with no analyst starting the work. Sourcehelp.radiantsecurity.ai/radiant-connectors/ingestion-methods/custom-alerts-webhookread 2026-09-28 |
|
| Model Flexibility & Routing | Not documented |
|
The models and providers behind Radiant's AI are not disclosed, and no model choice is offered. Sourceradiantsecurity.airead 2026-09-28 |
|
| APIs, SDKs & MCP Extensibility | Partial |
|
The help center documents a custom alerts webhook for sending alerts into Radiant, and Radiant's blog carries a post announcing an API for automating operational work; no API reference, endpoints or auth scheme are published in the help center. Sourcehelp.radiantsecurity.ai/radiant-connectors/ingestion-methods/custom-alerts-webhookread 2026-09-28 |
|
| Testing, Debugging & Optimization | Not documented |
|
Neither the homepage nor the help center documents an evaluation harness, scored test cases, a quality gate or an optimization loop the buyer runs. Sourceradiantsecurity.airead 2026-09-28 |
|
| Browser & Computer Use | Not documented |
|
No page documents the AI driving a browser, desktop or remote computer; it works through data connectors and response action integrations. Sourceradiantsecurity.airead 2026-09-28 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
Cribl has acquired the technology assets and intellectual property behind Radiant Security's AI-native SOC product. The acquisition covers Radiant's software for autonomous alert triage, investigation, and resolution, which Cribl plans to adapt as an application on its telemetry data platform.
Bears on: Funding / partnership
View sourcePricing
Contact sales; enterprise contracts with optional integrated log management
enterprise contract
Included quota
Platform contract covering adaptive triage across all alert types, with integrated log management as an option; no public tiers.
What is public
Nothing numeric; the adaptive triage and integrated log management positioning are public.
Billing mechanics
Enterprise platform contracts through sales for adaptive triage, with integrated log management offered as a SIEM cost alternative.
Cost watchouts
Integrated log management changes the cost equation: it can offset a separate SIEM but adds storage scope to the Radiant contract. Compare against keeping the existing SIEM plus a pure overlay analyst.
Variable cost rationale
Enterprise platform licensing; integrated log management may scale with data retained, but no usage metering is documented, so exposure sits at low.
Additional watchouts
Cribl announced in August 2026 that it acquired the technology and IP of Radiant's AI SOC product; confirm contract continuity, support and the product roadmap before committing.
Overage / add-ons
No public metering documented; log management scope would likely affect cost.
Sales call required
Yes, required for paid access
Free / trial
Enterprise evaluations through sales; no self serve trial
Lowest paid plan
None public; enterprise contract only
Commercial notes
Venture backed on a $15 million Series A. Cribl announced the acquisition of the AI SOC product's technology assets and IP on 19 August 2026.
Key ambiguities
Nothing numeric is public, and whether log management is bundled or priced separately is not documented.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to Radiant Security
The closest documented capability profiles to Radiant Security among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- AirMDR6.0 / 14Fuller documented coverage on Security, Identity & Governance
- Intezer7.0 / 14Adds documented Memory & State Persistence
- Darktrace7.5 / 14Adds documented Deployment & Data Residency
- Knostic5.5 / 14Adds documented Testing, Debugging & Optimization
- Linx Security6.5 / 14Fuller documented coverage on Knowledge Grounding & RAG and Observability & Auditability
- Token Security6.5 / 14Fuller documented coverage on Workflow Orchestration and Knowledge Grounding & RAG
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded