Simbian
Family of SOC, pentest, threat hunting and network security agents sharing one Context Lake, with analyst approved responses and self scoring against the customer's own objectives.
Simbian fields a family of security agents that share a common memory and close a loop between offensive validation and defensive work. The AI SOC Agent investigates every alert to a verdict and proposes a response, the AI Pentest Agent tests and validates exploit paths, the AI Threat Hunt Agent tests hypotheses against months of historical data, and the AI NetSecOps Agent runs firewall and network operations. Simbian says it is in production in more than 300 enterprise environments and that the customer's analysts approve 95 percent of the responses it proposes.
Two design choices define it. The first is Context Lake, an organization wide, persistent map of the customer's assets, identities and past verdicts, built from more than 100 sources including SIEM, EDR, identity, CVE feeds, pentest reports, firewall rules and ITSM runbooks, and kept in the customer's tenant; every closed alert is written back to it.
The second is the cascade between agents: when alerts cluster on an application, Simbian launches a pentest, and the proven exploit becomes a detection rule, a WAF rule, a network firewall rule and a patch ticket. Simbian also scores itself against objectives the customer writes, shows which cases fell short and why, and asks for approval before changing its own skills.
The AI SOC Agent is offered as SaaS or as an on premises agent. Simbian publishes no pricing, no API documentation, no model providers, and no security attestation or access controls; its /security page returns 404. For security teams that want triage grounded in their own environment and a validated feedback loop between pentesting and defense, the shared context architecture is the reason to look; teams that only need tier one triage on an existing stack may need less.
Vendor details
Canonical URL
https://simbian.ai
Category
Security / SOC agent
Subcategory
AI SOC platform
Funding status
Independent, venture backed.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
A family of agents (AI SOC Agent, Threat Hunt Agent, AI Pentest Agent) reasoning over Context Lake, the customer's own SOPs, entity data, and analyst feedback, so triage stays specific to the environment rather than the vendor's training set. The Pentest Agent writes validated findings back to the same Context Lake the defensive agents read, closing an offensive to defensive loop.
In practice
Generic AI triage keeps misjudging your environment. Simbian's agents reason over Context Lake, your own SOPs and entity data, so decisions fit your organization not the vendor's training set.
Your pentest findings sit in a report nobody reads. Simbian's Pentest Agent writes validated findings back into the Context Lake your defensive agents read, so they act on real risk.
You run separate tools for hunting, triage, and testing. Simbian's agent family shares one context layer, so each agent builds on what the others learned.
Sources & related URLs
Research sources
Agentic Index coverage score
9.0 / 14 capabilities · 64%
| Integrations & Tool Calling | Full |
|---|---|
|
Reads more than 100 integrated sources (SIEM, EDR, XDR, identity, CVE feeds, firewall rules, ITSM) and writes back into the customer's tools: response actions in EDR, cloud and Active Directory, detection rules in the SIEM's own query language, WAF and firewall rules, and ITSM tickets. Sourcesimbian.ai/self-improving-defenseread 2026-09-28 |
|
| Workflow Orchestration | Full |
|
Several agents hand work to each other: when alerts cluster on an application the SOC Agent launches a pentest, and the proven exploit becomes a detection rule, a WAF rule, a network firewall rule and a patch ticket, with SOC, Pentest, Threat Hunt and NetSecOps agents sharing one Context Lake. Sourcesimbian.ai/self-improving-defenseread 2026-09-28 |
|
| Knowledge Grounding & RAG | Full |
|
Context Lake is an organization wide, persistent map of the customer's assets and identities built from more than 100 sources, including SIEM, EDR, identity, CVE feeds, pentest reports, firewall rules and ITSM runbooks, which every agent queries; it stays in the customer's tenant. Sourcesimbian.airead 2026-09-28 |
|
| Human Oversight & Guardrails | Full |
|
The customer's analysts approve the responses Simbian proposes (95 percent approved, the vendor reports), and before the agents change their own skills Simbian shows the change and its evidence and the customer approves before anything is applied. Sourcesimbian.ai/self-improving-defenseread 2026-09-28 |
|
| Security, Identity & Governance | Not documented |
|
Simbian publishes no attestation and no SSO, SCIM or role model; the DPA lists Auth0 as the authentication sub-processor, simbian.ai/security returns 404 and trust.simbian.ai does not resolve. Sourcesimbian.ai/legal/dparead 2026-09-28 |
|
| Observability & Auditability | Partial |
|
Each investigation returns a verdict with its reasoning, which analysts can watch and correct, and self scoring shows which cases fell short and why. No page documents a per run trace of the steps and tool calls or an audit log. Sourcesimbian.ai/products/ai-soc-agentread 2026-09-28 |
|
| Memory & State Persistence | Partial |
|
Every alert the SOC Agent closes is written back to the shared Context Lake, an organization wide persistent memory the other agents read. No retention period, lifetime or delete path is documented. Sourcesimbian.ai/products/ai-soc-agentread 2026-09-28 |
|
| Deployment & Data Residency | Full |
|
The AI SOC Agent is offered as SaaS or as an on premises agent, and the Context Lake stays in the customer's tenant. No hosting regions are named, and the DPA lists US based sub-processors. Sourcesimbian.ai/products/ai-soc-agentread 2026-09-28 |
|
| Prebuilt Agents, Templates & Packs | Full |
|
The lineup is four named agents, each with its own job: the AI SOC Agent investigates alerts, the AI Pentest Agent tests and validates exploit paths, the AI Threat Hunt Agent tests hypotheses against historical data, and the AI NetSecOps Agent runs firewall and network operations. Sourcesimbian.airead 2026-09-28 |
|
| Triggers & Channel Coverage | Full |
|
Work starts without a person asking: every alert is investigated on arrival, clustered alerts launch a pentest, and vulnerability feeds and peer breach reports start agent work. Sourcesimbian.ai/self-improving-defenseread 2026-09-28 |
|
| Model Flexibility & Routing | Not documented |
|
No page names the models behind Simbian's agents or offers the customer a model choice; the 27 models on the homepage are the entrants in Simbian's Cyber Defense Benchmark research, not a menu the product offers. Sourcesimbian.airead 2026-09-28 |
|
| APIs, SDKs & MCP Extensibility | Not documented |
|
No developer docs are linked, and no API, SDK or MCP server for the Simbian platform is documented. Sourcesimbian.airead 2026-09-28 |
|
| Testing, Debugging & Optimization | Full |
|
Simbian builds a test for a customer authored objective, scores itself on the customer's own data and shows which cases fell short and why, and proposed changes to its skills are shown with evidence for approval before they apply. Sourcesimbian.ai/self-improving-defenseread 2026-09-28 |
|
| Browser & Computer Use | Not documented |
|
No page documents an agent driving a browser, desktop or remote computer; the agents read and write through integrations, and the pentest agent's method of reaching applications is not described as browser control. Sourcesimbian.airead 2026-09-28 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
Simbian released its autonomous AI Threat Hunt Agent, designed to independently generate and validate investigative hypotheses to uncover threats. The agent integrates with SIEM, EDR, cloud infrastructure, data lakes, and MCP servers to analyze historical data spanning months or years.
Bears on: Agent capability
View sourcePricing
Contact sales; demo led, no public rates
not published
Included quota
Contract scoped to the agents deployed, all reasoning over the shared Context Lake; no public tiers.
What is public
Nothing numeric; the agent family and Context Lake architecture are public.
Billing mechanics
Contracts through sales after a demo. How the four agents are packaged or priced is not published. Inference, not stated by the vendor: scope may follow the agents deployed.
Cost watchouts
The offensive to defensive loop is strongest with multiple agents deployed (SOC plus Pentest plus Threat Hunt); a single agent contract underuses the shared context architecture that is the differentiator.
Variable cost rationale
Enterprise platform licensing scoped by agent count; no usage metering documented, so exposure is low aside from adding agents.
Additional watchouts
Inference, not stated by the vendor: value concentrates when the offensive and defensive agents run together, so price and scope the loop, not just a single triage agent.
Overage / add-ons
No public metering or overage terms documented.
Sales call required
Yes, required for paid access
Free / trial
Enterprise evaluations through sales; no self serve trial
Lowest paid plan
None public; enterprise contract only
Commercial notes
Independent, venture backed. Says it is in production in more than 300 enterprise environments.
Key ambiguities
Nothing numeric is public, and how the four agents are packaged is not documented.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to Simbian
The closest documented capability profiles to Simbian among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Conifers.ai9.5 / 14Adds documented Security, Identity & Governance
- 7AI8.5 / 14Adds documented Security, Identity & GovernanceSimbian vs 7AI →
- Prophet Security8.5 / 14Adds documented Security, Identity & GovernanceSimbian vs Prophet Security →
- Abnormal AI9.0 / 14Adds documented Security, Identity & Governance and APIs, SDKs & MCP Extensibility
- Cyware10.0 / 14Adds documented Security, Identity & Governance and APIs, SDKs & MCP Extensibility
- Exaforce8.0 / 14Adds documented Security, Identity & GovernanceSimbian vs Exaforce →
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded