SentinelOne
Also known as: S1, Purple AI, Purple AI Athena, Purple AI Agentic Investigation, Singularity Platform, Singularity Hyperautomation, Singularity Credits, Purple AI MCP Server, Prompt Security
Endpoint security leader turned agentic: Purple AI runs zero click autonomous investigations that deliver a verdict with a full evidence chain, while Hyperautomation executes response inside pre approved policies.
SentinelOne built its business on endpoint protection and has moved its centre of gravity to Purple AI, an agentic AI security analyst embedded in the Singularity Platform. The Athena release, announced at RSA 2025, moved Purple AI from an assistant answering analyst questions to a system that reasons and acts, on three stated pillars: deep security reasoning at machine speed, full loop workflows with automation and response, and data source agnostic integration across any SIEM or data lake.
In June 2026 it opened Purple AI Agentic Investigation to all customers. These are zero click, autonomously initiated investigations that detect, investigate, verify and respond without human dependencies, running on telemetry already in the platform with nothing to deploy, integrate or tune and no data leaving the platform. The framing SentinelOne uses is precise and worth borrowing: analysts start at the verdict instead of the alert.
The division of labour is explicit. Purple AI delivers the investigation verdict; Singularity Hyperautomation executes the response automatically, but only within pre approved policies. Every verdict carries a full evidence chain. The underlying models are tuned across trillions of security relevant data points and refined through a closed feedback loop with SentinelOne's own managed detection team and global partners.
Alongside this it introduced Singularity Credits, described as a unified currency for running AI powered work across the platform, and a Purple AI MCP Server that pushes platform intelligence outward into customer built agents.
SentinelOne is unusually candid about limits, acknowledging directly that hallucinations and biased responses still occur and framing humans as supervisors of these systems rather than as bystanders.
Vendor details
Canonical URL
https://www.sentinelone.com
Category
Security / SOC agent
Subcategory
Agentic security operations and endpoint platform
Funding status
Public company, NYSE: S. Co-founder and CEO Tomer Weingarten. Named a Leader in the 2026 Gartner Magic Quadrant for Endpoint Protection, its sixth consecutive year. Acquired Prompt Security, previously logged in this index's AI security consolidation cohort at a reported 250 million USD.
Company status
public
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Deliberately data source agnostic, operating across any SIEM or data lake without requiring migrations or additional pipelines, and drawing on endpoint, identity, cloud and third party telemetry already in the platform. Singularity Hyperautomation provides no code workflow connection. The Purple AI MCP Server extends the platform's security data and workflows outward into the customer's own AI agents.
In practice
An analyst opens the console to find investigations already completed, each with a verdict and a full evidence chain, rather than a queue of alerts to triage from scratch.
A team keeps its existing SIEM and data lake and adds agentic investigation on top, since the platform is deliberately data source agnostic and requires no migration.
A security engineering team uses the Purple AI MCP Server to pull live platform intelligence into an agent it built itself, rather than working only inside the vendor's console.
Sources & related URLs
Research sources
Agentic Index coverage score
11.0 / 14 capabilities · 79%
| Integrations & Tool CallingExplicitly DATA SOURCE AGNOSTIC, operating across any SIEM or data lake without costly migrations or additional pipelines, drawing on endpoint, identity, cloud and third party telemetry already present, with no code Hyperautomation connecting workflows and a Purple AI MCP Server extending data outward. SentinelOne Athena release and Agentic Investigation announcement 2026-08-07 | Full |
|---|---|
| Workflow OrchestrationPurple AI executes full investigations across multiple sources and ORCHESTRATES MULTI STEP RESPONSE ACTIONS, with Singularity Hyperautomation providing full loop workflows from detection through remediation and the ability to turn auto investigation insights into autonomous end to end workflows. SentinelOne Purple AI Athena release and platform pages 2026-08-07 | Full |
| Knowledge Grounding & RAGSecurity models fine tuned by advanced neural networks working across TRILLIONS OF SECURITY RELEVANT DATA POINTS, refined through a closed feedback loop with SentinelOne's in house managed detection team and a global network of elite security professionals, over a dataset built from fine grained endpoint and cloud telemetry. SentinelOne Athena release materials 2026-08-07 | Full |
| Human Oversight & GuardrailsA clean separation of reasoning from action: PURPLE AI DELIVERS THE VERDICT and Singularity Hyperautomation EXECUTES THE RESPONSE ONLY WITHIN PRE APPROVED POLICIES, so the human control point sits on the policy envelope rather than each action. Every verdict carries a full evidence chain, the system is framed as amplifying rather than replacing defenders, and the CEO describes humans as SUPERVISORS OF THESE SYSTEMS. SentinelOne Purple AI platform page and launch commentary 2026-08-07 | Full |
| Security, Identity & GovernanceSecurity is the product, with a Leader placement in the 2026 Gartner Magic Quadrant for Endpoint Protection for a sixth consecutive year, and an explicit commitment that NO DATA LEAVES THE PLATFORM during agentic investigation. SentinelOne also owns Prompt Security, extending its remit to securing AI usage itself. VERIFICATION FLAG: SentinelOne's own corporate attestations were not retrieved in this pass; confirm before citing. SentinelOne platform and Agentic Investigation materials 2026-08-07 | Full |
| Observability & AuditabilityA FULL EVIDENCE CHAIN SITS BEHIND EVERY VERDICT, with the agent collecting evidence, correlating telemetry and building the attack timeline so the reasoning is inspectable rather than asserted, plus automated response and reporting across the platform. SentinelOne Agentic Investigation announcement 2026-08-07 | Full |
| Memory & State PersistencePlatform telemetry and investigation history persist and the evidence chain accumulates per verdict, but no agent memory or learned context layer distinct from the security data platform is documented. Same shape as the airtable, pega and gong rulings. SentinelOne platform materials 2026-08-07 | Partial |
| Deployment & Data ResidencyDelivered through the Singularity Platform cloud with the notable property that no data leaves the platform during agentic investigation, but no self hosted option, government cloud detail or published regional residency matrix was retrieved in this pass. SentinelOne platform materials 2026-08-07 | Partial |
| Prebuilt Agents, Templates & PacksShips packaged agentic capabilities rather than components to assemble: auto triage, auto investigation, automated threat hunting and detection, novel detection rule creation, automated response and reporting, and AI powered support, all available with single click activation and zero configuration. SentinelOne Athena release and Agentic Investigation announcement 2026-08-07 | Full |
| Triggers & Channel CoverageZERO CLICK, AUTONOMOUSLY INITIATED investigations run without human dependencies on telemetry already in the platform, alongside auto triage applying similarity analysis to incoming alerts. The agent initiates rather than waiting to be invoked, which is the strongest form of this axis. SentinelOne Agentic Investigation announcement June 2026 2026-08-07 | Full |
| Model Flexibility & RoutingRuns proprietary security models on its own agentic framework tuned across trillions of security relevant data points, and the Purple AI MCP Server lets customers bring platform intelligence into agents built on models of their choosing, but no model selection or routing for Purple AI itself was documented. SentinelOne platform materials 2026-08-07 | Partial |
| APIs, SDKs & MCP ExtensibilityThe PURPLE AI MCP SERVER extends trusted security data and workflows INTO THE CUSTOMER'S OWN AI AGENTS so they can build custom defence experiences grounded in live platform intelligence, alongside no code Hyperautomation and data source agnostic integration across any SIEM. SentinelOne Purple AI platform page 2026-08-07 | Full |
| Testing, Debugging & OptimizationA closed feedback loop between the in house managed detection team, global partners and the models continuously refines output quality, and auto triage applies similarity analysis to prioritise likely true positives, but no customer facing evaluation harness, simulation mode or regression testing capability was documented. SentinelOne Athena release materials 2026-08-07 | Partial |
| Browser & Computer UseAgents operate on security telemetry through platform integrations and automated workflows; no browser control, page navigation or computer use capability is documented. SentinelOne platform materials 2026-08-07 | Unable to verify |
The Agentic Index coverage score grades every vendor Full, Partial or Unable to verify against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Pricing
Contact sales; AI work metered in Singularity Credits
Singularity Credits, a platform wide currency for AI powered work
Included quota
Not published. Singularity Credits allocations by tier were not retrieved.
What is public
The existence and framing of Singularity Credits, and that Agentic Investigation launched with a complimentary trial. No rates.
Billing mechanics
Not publicly disclosed. Platform subscription sold through direct enterprise sales and channel, with AI powered work metered in Singularity Credits across the Singularity Platform.
Cost watchouts
**The credit model is the thing to model, not the licence. Because Singularity Credits are a platform wide currency rather than a per product meter, AI consumption in one area draws down the same balance as another, so an increase in autonomous investigation volume can quietly consume budget allocated elsewhere.** No credit rate, allocation or consumption rate per investigation was published, so the included allowance cannot be translated into a number of investigations. The agentic capabilities also sit on top of an existing Singularity Platform commitment rather than standing alone.
Variable cost rationale
Consumption is metered in credits whose rate is unpublished, and the work consuming them is autonomously initiated by the system in response to threat activity rather than scheduled by the customer. That combination - an unpublished unit driven by an uncontrollable trigger - is the least forecastable shape encountered in this sweep, and the credits being a platform wide currency means spend in one area depletes the same pool as another.
Additional watchouts
Autonomous investigations are initiated by the system, not the customer, so credit consumption tracks threat volume. Establish the allocation and the per investigation cost before enabling it broadly.
Overage / add-ons
Not published.
Sales call required
Yes, required for paid access
Free / trial
Complimentary trial of Purple AI Agentic Investigation at launch, single click activation
Commercial notes
Public company (NYSE: S), so aggregate financials are visible in filings. **SEVENTH NAMED AGENT CONSUMPTION UNIT IN THIS INDEX AND THE MOST AMBITIOUS FRAMING: every other unit meters one product - airtable AI credits, retool agent hours, superblocks Governed Agent Units, cognition Agent Compute Units, appian AI actions and token limits. Singularity Credits are positioned as a CROSS PRODUCT CURRENCY, which is a different commercial idea: an internal economy rather than a meter. Watch whether competitors follow.**
Key ambiguities
The credit economics entirely: what a credit buys, how many an autonomous investigation consumes, and what allocation each platform tier includes. Given investigations are zero click and autonomously initiated, consumption is driven by threat volume rather than by anything the customer schedules, which is the least controllable kind of driver.
Missing data
All pricing, credit rates, credit allocations by tier, and consumption per investigation.
Related vendors
- 7AI — Swarming agentic SOC from the Cybereason founders: sixty plus domain…
- Abnormal AI — Behavioural AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR built around a Virtual Analyst that triages 95% of…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Bionic SOC: a human-AI collaboration platform that automates triage,…
- Anvilogic — Agentic security operations platform that decouples detection from…
Alternatives to SentinelOne
The closest documented capability profiles to SentinelOne among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Palo Alto Networks11.0 / 14Matches SentinelOne across all 14 documented capabilities
- Zeron11.5 / 14Fuller documented coverage on Deployment & Data Residency
- Command Zero11.0 / 14Fuller documented coverage on Memory & State Persistence
- Cyware12.0 / 14Adds documented Browser & Computer Use
- Seemplicity10.0 / 14A lighter documented profile than SentinelOne
- ThreatModeler12.0 / 14Fuller documented coverage on Memory & State Persistence and Model Flexibility & Routing
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded