Torq
Also known as: Torq Hyperautomation
Security hyperautomation platform with agentic HyperSOC on top, pairing free agent reasoning with a mature governed workflow action layer, valued at $1.2 billion.
Torq is a security automation platform that grew into agentic SOC operations. Independent, it raised a $140 million Series D in January 2026 at a $1.2 billion valuation. Where the pure AI SOC analysts started with autonomous investigation and extended toward action, Torq started as security hyperautomation, a modern successor to SOAR, and extended toward autonomy, meeting the same problem from the orchestration side.
The foundation is a workflow fabric: no code and low code workflows started by integration events, webhooks, schedules, system events or email, with approval steps, more than 100 templates and self hosted step runners that execute inside the customer's network. On top sit the agents: Auto Triage on every incoming alert, the Socrates AI analyst for case investigation, HyperAgents, and AI Agent and AI Task steps the buyer places inside workflows, each running on a model the buyer picks from its own OpenAI, Azure OpenAI, Vertex AI, Anthropic or Bedrock subscription.
A Context Graph resolves identities, assets, networks and policies from the customer's sources into one time stamped, source tagged representation, and a memory layer keeps past cases, confirmed verdicts and corrections so the agents reason from precedent. Workflows are test run in draft before publishing, Case Reviewer adds a human sign off on case conclusions, and audit logs and Socrates auditing record what the AI did.
Torq documents role based access with SSO, names SOC 2, ISO and FedRAMP, and runs workspaces in the US, the EU or Japan. It publishes no pricing; contracts run through sales. Buyers wanting a drop in autonomous L1 analyst may find Torq's automation first surface heavier than a purpose built triage tool, while teams that already think in workflows get agent reasoning and deterministic, governed execution in one platform.
Vendor details
Canonical URL
https://torq.io
Category
Security / SOC agent
Subcategory
Security automation
Funding status
Independent, raised a $140 million Series D in January 2026 at a $1.2 billion valuation. Founded by veterans of the security automation category.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
AI powered security hyperautomation with a large library of prebuilt integrations and workflow steps across security and IT tools, orchestrating phishing response, incident response, and employee onboarding. Torq HyperSOC layers agentic AI on the automation fabric for autonomous case management, combining no code and low code workflow building with AI agents.
In practice
You want autonomy but cannot let an agent make ad hoc changes in production. Torq pairs agent reasoning with deterministic, auditable workflows, so decisions execute as controlled steps.
Your SOAR playbooks are brittle and hard to maintain. Torq's no code and low code hyperautomation fabric modernizes them, with HyperSOC adding agentic triage on top.
Phishing and incident response eat your team's day. Torq orchestrates the full response across security and IT tools, with agents driving cases autonomously through governed workflows.
Sources & related URLs
Research sources
Agentic Index coverage score
12.5 / 14 capabilities · 89%
| Integrations & Tool Calling | Full |
|---|---|
|
The Torq Store holds a catalog of vendor integrations and steps, and integration triggers ingest data. AI Tools let agents act through those integrations, and Socrates Tools take action on cases. Self hosted step runners reach systems inside the customer's network. Sourcekb.torq.io/en/articles/12065486-ai-tools-enhance-ai-agent-capabilitiesread 2026-09-28 |
|
| Workflow Orchestration | Full |
|
Buyers build no code and low code workflows with triggers, conditions and approval steps, embed AI Agents and AI Task steps in them, and run HyperAgents and the Socrates analyst across triage, investigation and response. Socrates Builder can build and modify workflows from chat. Sourcekb.torq.io/en/articles/12065413-ai-agents-bring-adaptive-intelligence-into-your-workflowsread 2026-09-28 |
|
| Knowledge Grounding & RAG | Full |
|
The Context Graph resolves identities, assets, networks and policies from IdP, EDR, SIEM, CNAPP, HR, ITSM and threat intel into one normalized, time stamped, source tagged representation enriched with business context. It is kept per tenant, and agents ground triage, investigation and response in it. Sourcetorq.io/context-graph-and-memoryread 2026-09-28 |
|
| Human Oversight & Guardrails | Full |
|
Workflows carry approval steps, and response runs autonomously or human on the loop. Roles can require a workflow to be reviewed before it is published, Case Reviewer lets a reviewer approve or reject a case conclusion before resolution, and analysts can override. Sourcekb.torq.io/en/articles/10428912-case-reviewer-ensure-investigation-quality-in-torq-s-hypersocread 2026-09-28 |
|
| Security, Identity & Governance | Full |
|
Torq documents RBAC with roles and scopes and organization managed roles, SSO through Okta, OneLogin, Entra ID, Auth0 and JumpCloud, and two factor authentication. On compliance, the site footer carries SOC 2, ISO and FedRAMP badges. Sourcekb.torq.io/en/articles/9145815-explore-torq-s-rbac-architecture-an-in-depth-guideread 2026-09-28 |
|
| Observability & Auditability | Full |
|
Workflow executions keep step outputs in the workflow context, and audit logs export automatically to Amazon S3. Socrates Auditing lets teams monitor the AI analyst's actions, and verdicts record their rationale. Sourcekb.torq.io/en/articles/9743934-socrates-auditing-monitor-your-ai-analystread 2026-09-28 |
|
| Memory & State Persistence | Partial |
|
A memory layer keeps historical cases with their notes, actions and resolution rationale (Recall), the team's confirmed verdicts and corrections (Reflex) and imported case history (Retrospect), scoped to the tenant. No lifetime, retention period or way to view, edit or delete entries is documented. Sourcetorq.io/context-graph-and-memoryread 2026-09-28 |
|
| Deployment & Data Residency | Full |
|
Workspaces run in one of three regions, the United States, the European Union or Japan, provisioned in the region the customer needs. Self hosted step runners run workflow steps inside the customer's own environment, including on EKS and AKS. Sourcekb.torq.io/en/articles/15516103-regional-availability-deployment-and-data-residency-optionsread 2026-09-28 |
|
| Prebuilt Agents, Templates & Packs | Full |
|
A template library of more than 100 workflow templates covers automations, integrations, case management and security operations. Prebuilt agents include Auto Triage, the Socrates analyst and HyperAgents. Sourcetorq.ioread 2026-09-28 |
|
| Triggers & Channel Coverage | Full |
|
Workflows start on integration events, webhooks, schedules, Torq system events and inbound email, and Auto Triage runs on every incoming alert. Sourcekb.torq.io/en/articles/9121101-workflow-triggers-in-torq-initiating-workflow-executionsread 2026-09-28 |
|
| Model Flexibility & Routing | Full |
|
Under Bring Your Own Subscription, customers connect their own subscriptions to OpenAI, Azure OpenAI, Google Vertex AI, Anthropic Claude or Amazon Bedrock and pick the model per AI Agent and per AI Task from a dropdown. Sourcekb.torq.io/en/articles/13052484-ai-models-bring-your-own-subscription-byosread 2026-09-28 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
The Torq API is reached with workspace API keys (client ID and secret) exchanged for bearer tokens, with key rotation documented. Webhooks give external systems endpoints that start workflows. Sourcekb.torq.io/en/articles/9145827-create-a-torq-api-key-enable-programmatic-accessread 2026-09-28 |
|
| Testing, Debugging & Optimization | Full |
|
Torq documents a way to evaluate a change before it runs. A workflow, including its AI Agent and AI Task steps, stays in draft where it can be test run with mock outputs and test pads while the published version keeps running, and only a publish puts it live. Torq advises several test runs first, roles can require review before publishing, and Socrates Builder tests and validates workflows before publishing. No scored evaluation set is documented. Sourcekb.torq.io/en/articles/9115762-workflow-states-testing-and-publishing-workflows-in-torqread 2026-09-28 |
|
| Browser & Computer Use | Not documented |
|
No page documents an agent driving a browser, desktop or remote computer. Agents act through integrations, steps and step runners. Sourcetorq.ioread 2026-09-28 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
Torq highlighted its integration and partnership with CrowdStrike at Fal.Con 2026, connecting Falcon telemetry directly to the Torq Context Graph. This integration enables near-real-time case management and automated remediation of CrowdStrike detections.
Bears on: Integrations
View sourceTorq has introduced a new Builder capability for its Socrates AI agent, allowing it to build, modify, and troubleshoot workflows directly from chat. The feature includes a Plan mode for reviewing requests and suggesting solutions, as well as the ability to test and validate workflows before publishing.
Bears on: Workflow orchestration
View sourceTorq introduced Torq SOC Brain, a new self-learning layer for its AI SOC Platform that trains on an organization's specific investigation history and analyst decisions. The release includes three core capabilities (Recall, Reflex, and Retrospect) that allow the system to reason from past precedent and continuously refine its judgment with every completed security investigation.
Bears on: Memory / state
View sourcePricing
Contact sales; no public rates
not published
Included quota
Contract covering the hyperautomation platform (workflows, integrations) with HyperSOC agentic case management as an added capability layer; no public tiers.
What is public
Nothing numeric; the platform plus HyperSOC layering is public.
Billing mechanics
Contracts through sales. The billing unit is not published; as an inference, scope may track workflow volume, connected integrations and whether HyperSOC agents are included.
Cost watchouts
Two layers to price: the core hyperautomation platform and HyperSOC agentic capabilities on top. Workflow volume and connected integrations drive cost, so a broad deployment scales beyond a narrow triage tool.
Variable cost rationale
Hyperautomation pricing typically scales with workflow execution volume and connected integrations, so a growing automation footprint raises cost more than a flat seat license.
Additional watchouts
Automation first surface can be heavier than a drop in analyst for teams that only want L1 triage; the depth pays off for teams that think in workflows and want governed agentic action.
Overage / add-ons
No public metering documented; cost scales with workflow volume and connected tools.
Sales call required
Yes, required for paid access
Free / trial
Evaluations through sales; no public free tier or trial
Lowest paid plan
None public; enterprise contract only
Commercial notes
Independent, $140 million Series D January 2026 at a $1.2 billion valuation. Security hyperautomation heritage extended into agentic SOC.
Key ambiguities
Nothing numeric is public, and the split between the automation platform and HyperSOC agentic add on is not documented.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to Torq
The closest documented capability profiles to Torq among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- CrowdStrike12.0 / 14A lighter documented profile than Torq
- Tines11.5 / 14A lighter documented profile than Torq
- ContraForce11.0 / 14A lighter documented profile than Torq
- Dropzone AI11.0 / 14A lighter documented profile than Torq
- Snyk11.0 / 14A lighter documented profile than Torq
- BlinkOps10.5 / 14A lighter documented profile than Torq
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded