Swimlane
Also known as: Swimlane Turbine, Swimlane Hero AI
Agentic security automation platform (Turbine) whose Hero AI agents work inside customer built playbooks, with explicit approval before state changing actions, a reasoning chain per investigation, per agent model choice including BYOM, and cloud, on premises or air gapped deployment.
Swimlane, founded in 2015 and headquartered in Denver, builds Turbine, an agentic AI automation platform for security operations, vulnerability response, compliance and MSSP work. Turbine Canvas is a playbook and AI agent builder where teams build no code, low code or full code playbooks and drop AI agents in as steps, and incoming alerts are routed to playbooks through the Active Sensing Fabric ingestion layer.
Hero AI supplies deep agents that use MCP and methodical reasoning for hard problems, expert agents for skills based tasks, and named agents for playbook generation from natural language, intelligent visualization and data ingestion from any API, with more agents, playbooks and connectors in the Swimlane Marketplace.
The AI SOC requires explicit human approval before any state changing action the organization has not already trusted to automation, lets analysts pause, reject or roll back a recommendation, escalates uncertain cases to a person, and produces a human readable reasoning chain for every investigation, exportable for audit. Customers select the model for each agent, including AWS Bedrock models and bring your own model support for Anthropic and select Bedrock models.
Swimlane runs in the cloud across eight regions, including Canada and a FedRAMP High government region, or on premises and air gapped, and Swimlane Cloud lists SOC 2 Type II and the ISO 27001 family with SAML SSO and field level role based access. It fits enterprise SOCs and MSSPs that want AI agents inside auditable, approval gated playbooks with a choice of model and deployment.
Vendor details
Canonical URL
https://swimlane.com
Category
Security / SOC agent
Subcategory
Agentic security automation platform
Funding status
Private equity backed; last funding round private equity, June 2025, per Crunchbase batch data
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Marketplace with thousands of prebuilt connectors plus on demand connectors built at no cost; integrates with any REST API. Named integrations include Palo Alto Cortex XDR, SentinelOne, Tenable, Trend Micro, Splunk, Elastic, VMware Carbon Black, Tanium, and Microsoft Entra ID, Azure, 365 Defender, and Graph API.
In practice
A SOC team routes phishing alerts through Turbine playbooks where Hero AI agents enrich indicators, summarize cases, and close low risk alerts autonomously.
A vulnerability management team picks up where scanners stop, using Turbine to prioritize and route remediation with NIST aligned recommended actions.
An MSSP runs multi tenant automation across clients with white labeling and aggregated action based pricing.
Sources & related URLs
Agentic Index coverage score
10.5 / 14 capabilities · 75%
| Integrations & Tool Calling | Full |
|---|---|
|
The Swimlane Marketplace has connectors for Microsoft, AWS, Cisco, CrowdStrike, Palo Alto Networks and others. An Ingestion Agent integrates with any API instantly, and playbooks act across the connected stack after approval. Turbine has connectors for more than 30 vendors, Splunk among them, and every plan includes unlimited integrations. The Threat Intelligence Agent pulls together sources such as VirusTotal and Recorded Future. Hero AI tools reach the connected stack through an MCP server that calls the Turbine engine. SourceSwimlane, swimlane.com/swimlane-turbine, /platform/enterprise-packaging and swimlane.com/news/ai-agents-case-managementread 2026-10-05 |
|
| Workflow Orchestration | Full |
|
Swimlane calls Turbine Canvas the world's first ultra simple playbook and AI agent builder. Customers build playbooks with agents as steps, and they decide how alerts are routed between deterministic playbooks and deep and expert agents. Each alert goes to an existing playbook, an AI assisted investigation or a fully agentic one, depending on how complex it is. Hero AI agents can be dragged into a playbook as steps. In a playbook step, the Hero AI action takes a plain language prompt and decides which of its configured tools to call and when. SourceSwimlane, swimlane.com/swimlane-turbine, /product/ai-soc and docs.swimlane.com Hero AI Native Actionread 2026-10-05 |
|
| Knowledge Grounding & RAG | Partial |
|
Deep agents use MCP and methodical reasoning, and the AI SOC collects data for each investigation. The Investigation Agent uses identified threats, past investigations and knowledge base articles to plan an investigation and write the playbooks that carry it out. The Verdict Agent reads current, linked and historical case context, including knowledge base articles, threat intelligence and analyst notes. Swimlane does not say how a customer adds its own articles or how that knowledge store is kept up to date. SourceSwimlane, swimlane.com/product/ai-soc and swimlane.com/news/ai-agents-case-managementread 2026-10-05 |
|
| Human Oversight & Guardrails | Full |
|
The AI SOC requires explicit human approval before any state changing action the organization has not already trusted to automation. Analysts can review, change or rebuild any plan the AI writes before it runs, and they can pause, reject or roll back a recommendation at any point. When Hero AI is unsure, it hands the case to a person instead of guessing. In the builder, a component Hero AI drafts stays on the canvas for review until someone saves it. SourceSwimlane, swimlane.com/product/ai-soc and docs.swimlane.com Create and Modify Components with Hero AIread 2026-10-05 |
|
| Security, Identity & Governance | Full |
|
Swimlane Cloud holds SOC 2 Type II, ISO/IEC 27001, 27017, 27018 and 27701 and CSA STAR, with a FedRAMP High GOV region, globally enforced two factor authentication, SAML SSO and role based access down to field level, plus SCIM provisioning and audit logging. It also holds SOC 1 Type II and ISO 9001, and Swimlane cites ISO 42001 and FedRAMP High authorization for Hero AI. Role based access covers workspaces, dashboards, reports, applications and records, and sign in also works through LDAP and Active Directory. Data is encrypted at rest and in transit, and credentials are kept in a secure database. Only a few employees can reach production systems, and contractors have no access to customer production data. SourceSwimlane, swimlane.com/solutions/swimlane-cloud and swimlane.com/platform/airead 2026-10-05 |
|
| Observability & Auditability | Full |
|
For every investigation, the AI SOC keeps a plain language record of the agent's reasoning, covering what data it collected, what logic it applied and what conclusion it reached, which can be exported for audit. Turbine also keeps audit logs. The Investigation Agent writes a summary and a timeline for each case. Each Hero AI action returns a request ID, a finish reason and token counts along with its result, and dashboards and reports track how the security team is performing. SourceSwimlane, swimlane.com/product/ai-soc, swimlane.com/news/ai-agents-case-management and docs.swimlane.com Hero AI Native Actionread 2026-10-05 |
|
| Memory & State Persistence | Not documented |
|
Case management is the system of record, where case data sits in a set structure. The Verdict Agent and the Investigation Agent read historical cases and past investigations as they work, but Swimlane does not say what an agent keeps between runs, for how long or for whom. Case records count against a yearly allowance, from 100,000 records on the Starter plan to 1 million on Elite. SourceSwimlane, swimlane.com/product/ai-soc, /platform/ai and /platform/enterprise-packagingread 2026-10-05 |
|
| Deployment & Data Residency | Full |
|
Swimlane runs in the cloud, on premises or air gapped, and Swimlane Cloud is offered in eight regions, the US, UK, EU, Canada, Singapore, Tokyo, Australia and a dedicated FedRAMP High GOV region. The cloud service runs on AWS. In an on premises install, the tools Hero AI calls run inside the customer's own cluster. Setup takes two weeks on the Starter plan and four weeks on the larger plans. SourceSwimlane, swimlane.com/platform/enterprise-packaging, /swimlane-turbine and docs.swimlane.com Hero AI Native Actionread 2026-10-05 |
|
| Prebuilt Agents, Templates & Packs | Full |
|
Hero AI ships named agents (Playbook Generator, Intelligent Visualization, Ingestion) alongside deep and expert agents, and the Swimlane Marketplace carries prebuilt agents, playbooks and connectors that drop into playbooks. Hero AI has seven agents in all, adding Agentic Investigations, Verdict, Threat Intelligence, and MITRE ATT&CK and D3FEND. The Verdict Agent gives a verdict on a case the way an analyst would, and the MITRE agent maps alerts to standard attack techniques. The Playbook Generator asks clarifying questions as it builds. NIST aligned action recommendations sort each response into containment, eradication, recovery and hardening. SourceSwimlane, swimlane.com/platform/ai, /product/ai-soc and swimlane.com/news/ai-agents-case-managementread 2026-10-05 |
|
| Triggers & Channel Coverage | Full |
|
Incoming alerts are routed to playbooks and AI SOC investigations through the Active Sensing Fabric ingestion layer, so work starts on an alert with no person launching it. Routing checks every alert and sends it to a playbook, an AI assisted investigation or a fully agentic one. The 26.4 release added custom dynamic responses to webhooks. Analysts can also start work from Hero AI chat, which finds and runs components marked visible to Hero AI. SourceSwimlane, swimlane.com/swimlane-turbine, /product/ai-soc and docs.swimlane.com Create and Modify Components with Hero AIread 2026-10-05 |
|
| Model Flexibility & Routing | Full |
|
Customers select the AI model for each agent, including their own model, based on performance and availability. Any AWS Bedrock model can run a Hero AI agent, and customers can bring their own model from Anthropic and select Bedrock models. The Hero AI playbook action defaults to Claude Haiku 4.5, can switch to Sonnet or Opus models, and also offers OpenAI and Qwen models. Each plan includes a Hero AI credit allowance, from 37,500 credits on Starter to 262,600 on Elite. SourceSwimlane, swimlane.com/product/ai-soc, /platform/ai, /platform/enterprise-packaging and docs.swimlane.com Hero AI Native Actionread 2026-10-05 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
The Turbine API uses personal access token authentication and has a generic request action for any endpoint, Turbine Canvas supports full code, and SCIM provisioning is supported. The API connector accepts a username and password or a personal access token, and its request action takes any method and path. Hero AI actions can return JSON shaped to a schema the builder defines, and the Plus plan and above add an App Builder and a Git repository. Hero AI calls its tools through an MCP server that talks to the Turbine engine, and the deep agents use MCP as clients, but there is no MCP server for outside agents to connect to. SourceSwimlane, docs.swimlane.com Swimlane Turbine API connector and Hero AI Native Actionread 2026-10-05 |
|
| Testing, Debugging & Optimization | Not documented |
|
There is no way to run agents or playbooks against test cases and score the results. The Playbook Generator writes and changes playbooks from prompts, and it does not test them. Swimlane's accuracy and savings figures come from customer stories, such as 100% recommendation accuracy at one customer and 128 of about 180 daily cases closed at a healthcare customer. SourceSwimlane, swimlane.com/product/ai-soc and swimlane.com/platform/airead 2026-10-05 |
|
| Browser & Computer Use | Not documented |
|
Automation acts through API connectors, and no agent operates a browser or desktop. Hero AI works through playbook actions and tools that call the Turbine engine, and the Ingestion Agent reaches new data sources through their APIs. None of these opens a web page or works a screen. SourceSwimlane, swimlane.com/swimlane-turbine and docs.swimlane.com Hero AI Native Actionread 2026-10-05 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
Swimlane released Turbine 26.4, which adds structured JSON schema outputs from Hero AI actions, custom dynamic webhook responses and replay for package imports.
Bears on: Agent capability
View sourceSwimlane launched Swimlane AI SOC for MSSPs, a platform built on Swimlane Turbine that uses agentic AI to automate alert handling and multi-step security investigations. The offering includes a central command center for multi-tenant management and cross-tenant threat intelligence sharing that aggregates enrichment results across all connected client environments.
Bears on: Agent capability
View sourceSwimlane introduced Turbine Widgets, enabling security teams to build custom web components that extend the Turbine UI on case records and dashboards. Users can now utilize the 'Build with Hero AI' feature to automatically generate widget code from plain-English descriptions.
Bears on: Agent capability
View sourcePricing
Contact sales
average daily actions automated (tiered); Hero AI credits by tier plus daily credit packs
What is public
The pricing structure is public on the packaging page: five action based tiers (Starter to Elite), Hero AI credits by tier and daily credit packs, fair use overage terms, deployment based pricing. Dollar figures are not published.
Billing mechanics
Five tiers keyed to average daily actions automated, Starter at 50,000 a day through Elite at 500,000 or more, priced by deployment model (cloud, on premises, air gapped). Hero AI credits run from about 37,500 to 262,600 a month by tier, with extra packs of 1,000 to 1,000,000 credits a day. Enterprise tiers include unlimited tenants.
Cost watchouts
Hero AI credit packs are additive to the platform tier, and on premises and air gapped deployments price differently from cloud; exceeding the fair use allowance more than four times a month triggers an upgrade discussion.
Variable cost rationale
Tiers key to average daily actions, so automation growth moves customers up tiers; the fair use policy allows overages up to 25 percent of the daily limit up to four times a month before an upgrade, and Hero AI usage is bought in daily credit packs.
Additional watchouts
Deployment model changes the quote; Hero AI prompts are a separate capacity dimension from actions; sustained overages trigger upgrade conversations under the fair use policy.
Overage / add-ons
Fair use policy: playbooks never stopped; overages tracked quarterly and sustained excess triggers an upgrade conversation
Sales call required
Yes, required for paid access
Free / trial
Demo and value evaluation via sales; no self serve free tier documented
Key ambiguities
Whether action tier boundaries and Hero AI pack pricing scale linearly is not public; quotes are customized.
Missing data
No published tier prices, tier boundaries, or Hero AI pack prices; trial availability unclear.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to Swimlane
The closest documented capability profiles to Swimlane among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Palo Alto Networks10.5 / 14Matches Swimlane across all 14 documented capabilities
- Ghost Security10.0 / 14A lighter documented profile than Swimlane
- D3 Security (Morpheus)10.5 / 14Adds documented Memory & State Persistence
- SentinelOne10.5 / 14Fuller documented coverage on Knowledge Grounding & RAG
- Tines11.5 / 14Adds documented Memory & State Persistence and Testing, Debugging & Optimization
- Andesite9.0 / 14A lighter documented profile than Swimlane
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded