SentinelOne
Also known as: Purple AI, Purple AI Athena, Purple AI Agentic Investigation, Singularity Platform, Singularity Hyperautomation, Purple AI MCP Server, Prompt Security
Purple AI runs zero-click investigations to a verdict with an auditable evidence chain, then either triggers policy-driven response or prompts an analyst; Hyperautomation adds 130+ templates and approval gates. From $179.99 per endpoint per year; the agentic analyst is in Enterprise.
SentinelOne is an endpoint and security operations platform whose agentic analyst is Purple AI, embedded in the Singularity Platform. Since June 2026 Purple AI Agentic Investigation runs zero-click, autonomously initiated investigations from alert to verdict, each verdict backed by a complete, auditable evidence chain, combining Anthropic's Claude, OpenAI's GPT and SentinelOne's own Ultraviolet models.
Purple AI also auto-triages alerts, supports hunting through investigation notebooks, and answers security questions across the customer's OCSF-normalized native and third-party data. Depending on governance settings, a verdict either triggers an automated, policy-driven response or prompts an analyst with recommended actions.
Singularity Hyperautomation, the no-code workflow layer, brings 160+ integrations, 130+ workflow templates, triggers on high-severity alerts, exposures and console activity, human approval gates through messaging apps or email, and a log of every action. The Purple AI MCP Server extends platform data into customers' own agents, and REST and GraphQL APIs cover most console functions. AI work is paid for in Singularity Credits, a unified currency across the platform.
The platform runs as SaaS on AWS or as an on-premises virtual appliance, with on-premises, air-gapped and sovereign offerings added in March 2026, and holds SOC 2 Type 2, ISO 27001 and FedRAMP High.
Vendor details
Canonical URL
https://www.sentinelone.com
Category
Security / SOC agent
Subcategory
Agentic security operations and endpoint platform
Funding status
SentinelOne is a public company (NYSE: S). Its co-founder and CEO is Tomer Weingarten, and it owns Prompt Security.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Singularity Hyperautomation provides 160+ prebuilt integrations across security and IT tools with thousands of actions, and Purple AI works over OCSF-normalized native and third-party data. The Purple AI MCP Server extends platform data into customer-built agents, and REST (OpenAPI) and GraphQL APIs cover most console functions.
In practice
An analyst opens the console to find investigations already completed, each with a verdict and a full evidence chain, rather than a queue of alerts to triage from scratch.
A team keeps its existing SIEM and data lake and adds agentic investigation on top, since the platform is deliberately data source agnostic and requires no migration.
A security engineering team uses the Purple AI MCP Server to pull live platform intelligence into an agent it built itself, rather than working only inside the vendor's console.
Sources & related URLs
Research sources
Agentic Index coverage score
10.5 / 14 capabilities · 75%
| Integrations & Tool Calling | Full |
|---|---|
|
Singularity Hyperautomation offers 160+ prebuilt integrations across security and IT tools with thousands of actions. Purple AI works over OCSF-normalized native and third-party data, and the Purple AI MCP Server extends platform data into customers' own agents. Sourcesentinelone.com/platform/singularity-hyperautomationread 2026-09-28 |
|
| Workflow Orchestration | Full |
|
Purple AI runs investigations from alert to verdict. Customers build their own no-code Hyperautomation workflows, with governed LLM actions, human-in-the-loop steps and reusable snippets, that act on those verdicts. Sourcesentinelone.com/platform/singularity-hyperautomationread 2026-09-28 |
|
| Knowledge Grounding & RAG | Full |
|
Purple AI answers security questions across the customer's OCSF-normalized native and third-party data in the Singularity Platform, without the analyst writing queries. That is retrieval over a maintained store of the customer's own security data. Sourcesentinelone.com/platform/purpleread 2026-09-28 |
|
| Human Oversight & Guardrails | Full |
|
Since the Agentic Investigation release of 17 June 2026, verdicts either trigger automated, policy-driven responses or "prompt an analyst with recommended actions" under configurable governance. Hyperautomation adds human approval gates for high-impact actions, with approvals through messaging apps or email. Sourcesentinelone.com/platform/singularity-hyperautomationread 2026-09-28 |
|
| Security, Identity & Governance | Full |
|
SentinelOne's Trust Center at trust.sentinelone.com lists SOC 2 Type 2, ISO/IEC 27001:2022, 27017, 27018 and FedRAMP High, which covers attestation. SSO and SAML, MFA and role-based access control are listed too, which covers access. Sourcetrust.sentinelone.comread 2026-09-28 |
|
| Observability & Auditability | Full |
|
Every verdict carries a complete, auditable evidence chain, and investigation notebooks document the work. Automated actions are "logged for compliance", and every Hyperautomation action is "logged and reviewable". Sourcesentinelone.com/platform/purpleread 2026-09-28 |
|
| Memory & State Persistence | Not documented |
|
Investigation notebooks document an analyst's work, and the platform's data store holds the customer's security data, but neither is agent memory. No agent memory with a scope and lifetime is documented. Sourcesentinelone.com/platform/purpleread 2026-09-28 |
|
| Deployment & Data Residency | Full |
|
SentinelOne runs as SaaS on AWS or as an on premises virtual appliance. On premises, self hosted, air gapped and sovereign offerings for endpoint, Prompt Security and the AI data pipeline were announced on 23 March 2026, and FedRAMP High is supported, so customers have options to run it in their own environment. Whether Purple AI itself runs on premises is not stated. Sourcesentinelone.com/press/sentinelone-brings-ai-security-to-on-premise-regulated-sovereign-self-hosted-and-airgapped-environmentsread 2026-09-28 |
|
| Prebuilt Agents, Templates & Packs | Full |
|
Hyperautomation offers 130+ workflow templates for common SOC use cases that customers adopt, alongside Purple AI's built-in auto triage, agentic investigation and hunting. Sourcesentinelone.com/platform/singularity-hyperautomationread 2026-09-28 |
|
| Triggers & Channel Coverage | Full |
|
Purple AI starts zero-click investigations on its own, and Hyperautomation workflows are triggered by high-severity alerts, detected exposures and console activity. Work starts without a person initiating it. Sourcesentinelone.com/platform/singularity-hyperautomationread 2026-09-28 |
|
| Model Flexibility & Routing | Partial |
|
Agentic Investigation combines Anthropic's Claude, OpenAI's GPT and SentinelOne's own Ultraviolet models. SentinelOne picks among those providers itself, and no customer choice of model is documented. Sourceinvestors.sentinelone.com/press-releases/news-details/2026/sentinelone-opens-purple-ai-agentic-investigation-to-all-customers-bringing-frontier-ai-directly-into-the-soc/default.aspxread 2026-09-28 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
SentinelOne documents RESTful APIs in OpenAPI (Swagger) alongside GraphQL APIs, and most UI functions are exposed through a customer-facing API. The API reference sits in the console's API Hub, behind a customer login. The Purple AI MCP Server extends platform data into customers' own agents. Sourcesentinelone.com/faqread 2026-09-28 |
|
| Testing, Debugging & Optimization | Not documented |
|
Purple AI's Community Verdict is trained on Wayfinder managed-service investigations and refined by the analyst community, which is SentinelOne's own practice rather than a tool customers use. No harness for customers to evaluate Purple AI or their workflows is documented. Sourcesentinelone.com/platform/purpleread 2026-09-28 |
|
| Browser & Computer Use | Not documented |
|
Purple AI and Hyperautomation act through platform data and integrations. No browser or computer use is documented. Sourcesentinelone.com/platform/purpleread 2026-09-28 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Pricing
Singularity Complete at $179.99 per endpoint per year (about $15 a month); Commercial $229.99; Enterprise, which includes the agentic AI SOC analyst, quoted.
Per endpoint per year, plus Singularity Credits for AI work
What is public
Per-endpoint annual list prices for Singularity Complete ($179.99) and Commercial ($229.99), the Enterprise inclusions (agentic AI SOC analyst), Singularity Credits as the AI currency, and a complimentary credit allotment to trial Agentic Investigation.
Billing mechanics
Per endpoint per year for platform packages, bought through authorized partners; AI-powered work draws on Singularity Credits.
Cost watchouts
Inference, not stated by the vendor: the agentic analyst sits in the quoted Enterprise package and AI work draws credits, so the listed per-endpoint prices do not cover agentic investigation volume.
Variable cost rationale
Autonomously initiated investigations draw Singularity Credits whose rate is not published, so AI spend tracks alert volume rather than endpoint count.
Additional watchouts
Establish the credit allocation and per-investigation consumption before enabling zero-click investigations broadly.
Sales call required
Mixed (some tiers require a call)
Free / trial
Complimentary Singularity Credits allotment to trial Agentic Investigation, no payment method required
Lowest paid plan
Singularity Complete, $179.99 per endpoint per year.
Commercial notes
Public company (NYSE: S).
Key ambiguities
The price of a credit, credits per investigation and the Enterprise package price are not published.
Missing data
Credit rate and allocation, credits per investigation, and Enterprise package price.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to SentinelOne
The closest documented capability profiles to SentinelOne among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- BlinkOps10.5 / 14Adds documented Memory & State Persistence
- Drata10.5 / 14Adds documented Testing, Debugging & Optimization
- Palo Alto Networks10.5 / 14Fuller documented coverage on Model Flexibility & Routing
- Swimlane10.5 / 14Fuller documented coverage on Model Flexibility & Routing
- Vanta9.5 / 14A lighter documented profile than SentinelOne
- Zeron10.5 / 14Adds documented Testing, Debugging & Optimization
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded