Back to vendors
S

SentinelOne

Also known as: S1, Purple AI, Purple AI Athena, Purple AI Agentic Investigation, Singularity Platform, Singularity Hyperautomation, Singularity Credits, Purple AI MCP Server, Prompt Security

Visit site
Entry priceContact sales; AI work metered in Singularity CreditsFull pricing detail

Endpoint security leader turned agentic: Purple AI runs zero click autonomous investigations that deliver a verdict with a full evidence chain, while Hyperautomation executes response inside pre approved policies.

SentinelOne built its business on endpoint protection and has moved its centre of gravity to Purple AI, an agentic AI security analyst embedded in the Singularity Platform. The Athena release, announced at RSA 2025, moved Purple AI from an assistant answering analyst questions to a system that reasons and acts, on three stated pillars: deep security reasoning at machine speed, full loop workflows with automation and response, and data source agnostic integration across any SIEM or data lake.

In June 2026 it opened Purple AI Agentic Investigation to all customers. These are zero click, autonomously initiated investigations that detect, investigate, verify and respond without human dependencies, running on telemetry already in the platform with nothing to deploy, integrate or tune and no data leaving the platform. The framing SentinelOne uses is precise and worth borrowing: analysts start at the verdict instead of the alert.

The division of labour is explicit. Purple AI delivers the investigation verdict; Singularity Hyperautomation executes the response automatically, but only within pre approved policies. Every verdict carries a full evidence chain. The underlying models are tuned across trillions of security relevant data points and refined through a closed feedback loop with SentinelOne's own managed detection team and global partners.

Alongside this it introduced Singularity Credits, described as a unified currency for running AI powered work across the platform, and a Purple AI MCP Server that pushes platform intelligence outward into customer built agents.

SentinelOne is unusually candid about limits, acknowledging directly that hallucinations and biased responses still occur and framing humans as supervisors of these systems rather than as bystanders.

Vendor details

Canonical URL

https://www.sentinelone.com

Category

Security / SOC agent

Subcategory

Agentic security operations and endpoint platform

Funding status

Public company, NYSE: S. Co-founder and CEO Tomer Weingarten. Named a Leader in the 2026 Gartner Magic Quadrant for Endpoint Protection, its sixth consecutive year. Acquired Prompt Security, previously logged in this index's AI security consolidation cohort at a reported 250 million USD.

Company status

public

Use cases & customers

Primary use cases

autonomous security investigation and responseendpoint detection and responseAI powered SIEM and threat huntingauto triage of alert volumeextending security data into customer built agents via MCP

Target customers

large enterprisesecurity operations centresmid-marketmanaged security service providers

Deployment options

Singularity Platform cloud

Integrations

Deliberately data source agnostic, operating across any SIEM or data lake without requiring migrations or additional pipelines, and drawing on endpoint, identity, cloud and third party telemetry already in the platform. Singularity Hyperautomation provides no code workflow connection. The Purple AI MCP Server extends the platform's security data and workflows outward into the customer's own AI agents.

In practice

An analyst opens the console to find investigations already completed, each with a verdict and a full evidence chain, rather than a queue of alerts to triage from scratch.

A team keeps its existing SIEM and data lake and adds agentic investigation on top, since the platform is deliberately data source agnostic and requires no migration.

A security engineering team uses the Purple AI MCP Server to pull live platform intelligence into an agent it built itself, rather than working only inside the vendor's console.

Agentic Index coverage score

11.0 / 14 capabilities · 79%

Integrations & Tool CallingExplicitly DATA SOURCE AGNOSTIC, operating across any SIEM or data lake without costly migrations or additional pipelines, drawing on endpoint, identity, cloud and third party telemetry already present, with no code Hyperautomation connecting workflows and a Purple AI MCP Server extending data outward. SentinelOne Athena release and Agentic Investigation announcement 2026-08-07 Full
Workflow OrchestrationPurple AI executes full investigations across multiple sources and ORCHESTRATES MULTI STEP RESPONSE ACTIONS, with Singularity Hyperautomation providing full loop workflows from detection through remediation and the ability to turn auto investigation insights into autonomous end to end workflows. SentinelOne Purple AI Athena release and platform pages 2026-08-07 Full
Knowledge Grounding & RAGSecurity models fine tuned by advanced neural networks working across TRILLIONS OF SECURITY RELEVANT DATA POINTS, refined through a closed feedback loop with SentinelOne's in house managed detection team and a global network of elite security professionals, over a dataset built from fine grained endpoint and cloud telemetry. SentinelOne Athena release materials 2026-08-07 Full
Human Oversight & GuardrailsA clean separation of reasoning from action: PURPLE AI DELIVERS THE VERDICT and Singularity Hyperautomation EXECUTES THE RESPONSE ONLY WITHIN PRE APPROVED POLICIES, so the human control point sits on the policy envelope rather than each action. Every verdict carries a full evidence chain, the system is framed as amplifying rather than replacing defenders, and the CEO describes humans as SUPERVISORS OF THESE SYSTEMS. SentinelOne Purple AI platform page and launch commentary 2026-08-07 Full
Security, Identity & GovernanceSecurity is the product, with a Leader placement in the 2026 Gartner Magic Quadrant for Endpoint Protection for a sixth consecutive year, and an explicit commitment that NO DATA LEAVES THE PLATFORM during agentic investigation. SentinelOne also owns Prompt Security, extending its remit to securing AI usage itself. VERIFICATION FLAG: SentinelOne's own corporate attestations were not retrieved in this pass; confirm before citing. SentinelOne platform and Agentic Investigation materials 2026-08-07 Full
Observability & AuditabilityA FULL EVIDENCE CHAIN SITS BEHIND EVERY VERDICT, with the agent collecting evidence, correlating telemetry and building the attack timeline so the reasoning is inspectable rather than asserted, plus automated response and reporting across the platform. SentinelOne Agentic Investigation announcement 2026-08-07 Full
Memory & State PersistencePlatform telemetry and investigation history persist and the evidence chain accumulates per verdict, but no agent memory or learned context layer distinct from the security data platform is documented. Same shape as the airtable, pega and gong rulings. SentinelOne platform materials 2026-08-07 Partial
Deployment & Data ResidencyDelivered through the Singularity Platform cloud with the notable property that no data leaves the platform during agentic investigation, but no self hosted option, government cloud detail or published regional residency matrix was retrieved in this pass. SentinelOne platform materials 2026-08-07 Partial
Prebuilt Agents, Templates & PacksShips packaged agentic capabilities rather than components to assemble: auto triage, auto investigation, automated threat hunting and detection, novel detection rule creation, automated response and reporting, and AI powered support, all available with single click activation and zero configuration. SentinelOne Athena release and Agentic Investigation announcement 2026-08-07 Full
Triggers & Channel CoverageZERO CLICK, AUTONOMOUSLY INITIATED investigations run without human dependencies on telemetry already in the platform, alongside auto triage applying similarity analysis to incoming alerts. The agent initiates rather than waiting to be invoked, which is the strongest form of this axis. SentinelOne Agentic Investigation announcement June 2026 2026-08-07 Full
Model Flexibility & RoutingRuns proprietary security models on its own agentic framework tuned across trillions of security relevant data points, and the Purple AI MCP Server lets customers bring platform intelligence into agents built on models of their choosing, but no model selection or routing for Purple AI itself was documented. SentinelOne platform materials 2026-08-07 Partial
APIs, SDKs & MCP ExtensibilityThe PURPLE AI MCP SERVER extends trusted security data and workflows INTO THE CUSTOMER'S OWN AI AGENTS so they can build custom defence experiences grounded in live platform intelligence, alongside no code Hyperautomation and data source agnostic integration across any SIEM. SentinelOne Purple AI platform page 2026-08-07 Full
Testing, Debugging & OptimizationA closed feedback loop between the in house managed detection team, global partners and the models continuously refines output quality, and auto triage applies similarity analysis to prioritise likely true positives, but no customer facing evaluation harness, simulation mode or regression testing capability was documented. SentinelOne Athena release materials 2026-08-07 Partial
Browser & Computer UseAgents operate on security telemetry through platform integrations and automated workflows; no browser control, page navigation or computer use capability is documented. SentinelOne platform materials 2026-08-07 Unable to verify

The Agentic Index coverage score grades every vendor Full, Partial or Unable to verify against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Pricing

Contact sales; AI work metered in Singularity Credits

Singularity Credits, a platform wide currency for AI powered work

Trial available

Included quota

Not published. Singularity Credits allocations by tier were not retrieved.

What is public

The existence and framing of Singularity Credits, and that Agentic Investigation launched with a complimentary trial. No rates.

Billing mechanics

Not publicly disclosed. Platform subscription sold through direct enterprise sales and channel, with AI powered work metered in Singularity Credits across the Singularity Platform.

Cost watchouts

**The credit model is the thing to model, not the licence. Because Singularity Credits are a platform wide currency rather than a per product meter, AI consumption in one area draws down the same balance as another, so an increase in autonomous investigation volume can quietly consume budget allocated elsewhere.** No credit rate, allocation or consumption rate per investigation was published, so the included allowance cannot be translated into a number of investigations. The agentic capabilities also sit on top of an existing Singularity Platform commitment rather than standing alone.

Variable cost rationale

Consumption is metered in credits whose rate is unpublished, and the work consuming them is autonomously initiated by the system in response to threat activity rather than scheduled by the customer. That combination - an unpublished unit driven by an uncontrollable trigger - is the least forecastable shape encountered in this sweep, and the credits being a platform wide currency means spend in one area depletes the same pool as another.

Additional watchouts

Autonomous investigations are initiated by the system, not the customer, so credit consumption tracks threat volume. Establish the allocation and the per investigation cost before enabling it broadly.

Overage / add-ons

Not published.

Sales call required

Yes, required for paid access

Free / trial

Complimentary trial of Purple AI Agentic Investigation at launch, single click activation

Commercial notes

Public company (NYSE: S), so aggregate financials are visible in filings. **SEVENTH NAMED AGENT CONSUMPTION UNIT IN THIS INDEX AND THE MOST AMBITIOUS FRAMING: every other unit meters one product - airtable AI credits, retool agent hours, superblocks Governed Agent Units, cognition Agent Compute Units, appian AI actions and token limits. Singularity Credits are positioned as a CROSS PRODUCT CURRENCY, which is a different commercial idea: an internal economy rather than a meter. Watch whether competitors follow.**

Key ambiguities

The credit economics entirely: what a credit buys, how many an autonomous investigation consumes, and what allocation each platform tier includes. Given investigations are zero click and autonomously initiated, consumption is driven by threat volume rather than by anything the customer schedules, which is the least controllable kind of driver.

Missing data

All pricing, credit rates, credit allocations by tier, and consumption per investigation.

Agentic Index verified 2026-08-07

Alternatives to SentinelOne

The closest documented capability profiles to SentinelOne among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • Palo Alto Networks11.0 / 14Matches SentinelOne across all 14 documented capabilities
  • Zeron11.5 / 14Fuller documented coverage on Deployment & Data Residency
  • Command Zero11.0 / 14Fuller documented coverage on Memory & State Persistence
  • Cyware12.0 / 14Adds documented Browser & Computer Use
  • Seemplicity10.0 / 14A lighter documented profile than SentinelOne
  • ThreatModeler12.0 / 14Fuller documented coverage on Memory & State Persistence and Model Flexibility & Routing

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.