Back to vendors
T

Torq

Also known as: Torq Hyperautomation

Visit site
Entry priceContact sales; no public ratesFull pricing detail

Security hyperautomation platform with agentic HyperSOC on top, pairing free agent reasoning with a mature governed workflow action layer, valued at $1.2 billion.

Torq is a security automation platform that grew into agentic SOC operations. Independent, it raised a $140 million Series D in January 2026 at a $1.2 billion valuation. Where the pure AI SOC analysts started with autonomous investigation and extended toward action, Torq started as security hyperautomation, a modern successor to SOAR, and extended toward autonomy, meeting the same problem from the orchestration side.

The foundation is a workflow fabric: no code and low code workflows started by integration events, webhooks, schedules, system events or email, with approval steps, more than 100 templates and self hosted step runners that execute inside the customer's network. On top sit the agents: Auto Triage on every incoming alert, the Socrates AI analyst for case investigation, HyperAgents, and AI Agent and AI Task steps the buyer places inside workflows, each running on a model the buyer picks from its own OpenAI, Azure OpenAI, Vertex AI, Anthropic or Bedrock subscription.

A Context Graph resolves identities, assets, networks and policies from the customer's sources into one time stamped, source tagged representation, and a memory layer keeps past cases, confirmed verdicts and corrections so the agents reason from precedent. Workflows are test run in draft before publishing, Case Reviewer adds a human sign off on case conclusions, and audit logs and Socrates auditing record what the AI did.

Torq documents role based access with SSO, names SOC 2, ISO and FedRAMP, and runs workspaces in the US, the EU or Japan. It publishes no pricing; contracts run through sales. Buyers wanting a drop in autonomous L1 analyst may find Torq's automation first surface heavier than a purpose built triage tool, while teams that already think in workflows get agent reasoning and deterministic, governed execution in one platform.

Vendor details

Canonical URL

https://torq.io

Category

Security / SOC agent

Subcategory

Security automation

Funding status

Independent, raised a $140 million Series D in January 2026 at a $1.2 billion valuation. Founded by veterans of the security automation category.

Company status

independent

Use cases & customers

Primary use cases

security hyperautomationautonomous case management (HyperSOC)phishing and incident response workflowsgoverned agentic response

Target customers

enterprise SOC teamsMSSPssecurity automation teams

Deployment options

SaaS

Integrations

AI powered security hyperautomation with a large library of prebuilt integrations and workflow steps across security and IT tools, orchestrating phishing response, incident response, and employee onboarding. Torq HyperSOC layers agentic AI on the automation fabric for autonomous case management, combining no code and low code workflow building with AI agents.

In practice

You want autonomy but cannot let an agent make ad hoc changes in production. Torq pairs agent reasoning with deterministic, auditable workflows, so decisions execute as controlled steps.

Your SOAR playbooks are brittle and hard to maintain. Torq's no code and low code hyperautomation fabric modernizes them, with HyperSOC adding agentic triage on top.

Phishing and incident response eat your team's day. Torq orchestrates the full response across security and IT tools, with agents driving cases autonomously through governed workflows.

Sources & related URLs

Research sources

Agentic Index coverage score

12.5 / 14 capabilities · 89%

Integrations & Tool Calling Full

The Torq Store holds a catalog of vendor integrations and steps, and integration triggers ingest data. AI Tools let agents act through those integrations, and Socrates Tools take action on cases. Self hosted step runners reach systems inside the customer's network.

Sourcekb.torq.io/en/articles/12065486-ai-tools-enhance-ai-agent-capabilitiesread 2026-09-28

Workflow Orchestration Full

Buyers build no code and low code workflows with triggers, conditions and approval steps, embed AI Agents and AI Task steps in them, and run HyperAgents and the Socrates analyst across triage, investigation and response. Socrates Builder can build and modify workflows from chat.

Sourcekb.torq.io/en/articles/12065413-ai-agents-bring-adaptive-intelligence-into-your-workflowsread 2026-09-28

Knowledge Grounding & RAG Full

The Context Graph resolves identities, assets, networks and policies from IdP, EDR, SIEM, CNAPP, HR, ITSM and threat intel into one normalized, time stamped, source tagged representation enriched with business context. It is kept per tenant, and agents ground triage, investigation and response in it.

Sourcetorq.io/context-graph-and-memoryread 2026-09-28

Human Oversight & Guardrails Full

Workflows carry approval steps, and response runs autonomously or human on the loop. Roles can require a workflow to be reviewed before it is published, Case Reviewer lets a reviewer approve or reject a case conclusion before resolution, and analysts can override.

Sourcekb.torq.io/en/articles/10428912-case-reviewer-ensure-investigation-quality-in-torq-s-hypersocread 2026-09-28

Security, Identity & Governance Full

Torq documents RBAC with roles and scopes and organization managed roles, SSO through Okta, OneLogin, Entra ID, Auth0 and JumpCloud, and two factor authentication. On compliance, the site footer carries SOC 2, ISO and FedRAMP badges.

Sourcekb.torq.io/en/articles/9145815-explore-torq-s-rbac-architecture-an-in-depth-guideread 2026-09-28

Observability & Auditability Full

Workflow executions keep step outputs in the workflow context, and audit logs export automatically to Amazon S3. Socrates Auditing lets teams monitor the AI analyst's actions, and verdicts record their rationale.

Sourcekb.torq.io/en/articles/9743934-socrates-auditing-monitor-your-ai-analystread 2026-09-28

Memory & State Persistence Partial

A memory layer keeps historical cases with their notes, actions and resolution rationale (Recall), the team's confirmed verdicts and corrections (Reflex) and imported case history (Retrospect), scoped to the tenant. No lifetime, retention period or way to view, edit or delete entries is documented.

Sourcetorq.io/context-graph-and-memoryread 2026-09-28

Deployment & Data Residency Full

Workspaces run in one of three regions, the United States, the European Union or Japan, provisioned in the region the customer needs. Self hosted step runners run workflow steps inside the customer's own environment, including on EKS and AKS.

Sourcekb.torq.io/en/articles/15516103-regional-availability-deployment-and-data-residency-optionsread 2026-09-28

Prebuilt Agents, Templates & Packs Full

A template library of more than 100 workflow templates covers automations, integrations, case management and security operations. Prebuilt agents include Auto Triage, the Socrates analyst and HyperAgents.

Sourcetorq.ioread 2026-09-28

Triggers & Channel Coverage Full

Workflows start on integration events, webhooks, schedules, Torq system events and inbound email, and Auto Triage runs on every incoming alert.

Sourcekb.torq.io/en/articles/9121101-workflow-triggers-in-torq-initiating-workflow-executionsread 2026-09-28

Model Flexibility & Routing Full

Under Bring Your Own Subscription, customers connect their own subscriptions to OpenAI, Azure OpenAI, Google Vertex AI, Anthropic Claude or Amazon Bedrock and pick the model per AI Agent and per AI Task from a dropdown.

Sourcekb.torq.io/en/articles/13052484-ai-models-bring-your-own-subscription-byosread 2026-09-28

APIs, SDKs & MCP Extensibility Full

The Torq API is reached with workspace API keys (client ID and secret) exchanged for bearer tokens, with key rotation documented. Webhooks give external systems endpoints that start workflows.

Sourcekb.torq.io/en/articles/9145827-create-a-torq-api-key-enable-programmatic-accessread 2026-09-28

Testing, Debugging & Optimization Full

Torq documents a way to evaluate a change before it runs. A workflow, including its AI Agent and AI Task steps, stays in draft where it can be test run with mock outputs and test pads while the published version keeps running, and only a publish puts it live. Torq advises several test runs first, roles can require review before publishing, and Socrates Builder tests and validates workflows before publishing. No scored evaluation set is documented.

Sourcekb.torq.io/en/articles/9115762-workflow-states-testing-and-publishing-workflows-in-torqread 2026-09-28

Browser & Computer Use Not documented

No page documents an agent driving a browser, desktop or remote computer. Agents act through integrations, steps and step runners.

Sourcetorq.ioread 2026-09-28

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Recent platform changes

2026-09-03·IntegrationsVerified

Torq highlighted its integration and partnership with CrowdStrike at Fal.Con 2026, connecting Falcon telemetry directly to the Torq Context Graph. This integration enables near-real-time case management and automated remediation of CrowdStrike detections.

Bears on: Integrations

View source
2026-08-02·Workflow orchestrationVerified

Torq has introduced a new Builder capability for its Socrates AI agent, allowing it to build, modify, and troubleshoot workflows directly from chat. The feature includes a Plan mode for reviewing requests and suggesting solutions, as well as the ability to test and validate workflows before publishing.

Bears on: Workflow orchestration

View source
2026-07-28·Memory / stateVerified

Torq introduced Torq SOC Brain, a new self-learning layer for its AI SOC Platform that trains on an organization's specific investigation history and analyst decisions. The release includes three core capabilities (Recall, Reflex, and Retrospect) that allow the system to reason from past precedent and continuously refine its judgment with every completed security investigation.

Bears on: Memory / state

View source
View all 3 changes for Torq →Tracked since Jul 2026 · Verified from public vendor sources

Pricing

Contact sales; no public rates

not published

Included quota

Contract covering the hyperautomation platform (workflows, integrations) with HyperSOC agentic case management as an added capability layer; no public tiers.

What is public

Nothing numeric; the platform plus HyperSOC layering is public.

Billing mechanics

Contracts through sales. The billing unit is not published; as an inference, scope may track workflow volume, connected integrations and whether HyperSOC agents are included.

Cost watchouts

Two layers to price: the core hyperautomation platform and HyperSOC agentic capabilities on top. Workflow volume and connected integrations drive cost, so a broad deployment scales beyond a narrow triage tool.

Variable cost rationale

Hyperautomation pricing typically scales with workflow execution volume and connected integrations, so a growing automation footprint raises cost more than a flat seat license.

Additional watchouts

Automation first surface can be heavier than a drop in analyst for teams that only want L1 triage; the depth pays off for teams that think in workflows and want governed agentic action.

Overage / add-ons

No public metering documented; cost scales with workflow volume and connected tools.

Sales call required

Yes, required for paid access

Free / trial

Evaluations through sales; no public free tier or trial

Lowest paid plan

None public; enterprise contract only

Commercial notes

Independent, $140 million Series D January 2026 at a $1.2 billion valuation. Security hyperautomation heritage extended into agentic SOC.

Key ambiguities

Nothing numeric is public, and the split between the automation platform and HyperSOC agentic add on is not documented.

Agentic Index verified 2026-09-28

Alternatives to Torq

The closest documented capability profiles to Torq among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • CrowdStrike12.0 / 14A lighter documented profile than Torq
  • Tines11.5 / 14A lighter documented profile than Torq
  • ContraForce11.0 / 14A lighter documented profile than Torq
  • Dropzone AI11.0 / 14A lighter documented profile than Torq
  • Snyk11.0 / 14A lighter documented profile than Torq
  • BlinkOps10.5 / 14A lighter documented profile than Torq

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.