Tuskira
Agentic SecOps platform whose five named agents reason over a federated Security Data Fabric spanning more than 150 security tools, for exposure management, alert triage and containment that waits for an analyst's approval.
Tuskira is an agentic security operations company based in the San Francisco Bay Area, founded by the team behind Accurics, the cloud security firm Tenable acquired. Chief executive Piyush Sharma, chief information security officer and chief product officer Om Moolchandani, and chief technology officer Vipul Parmar launched the company from stealth in December 2024 with twenty eight and a half million dollars led by Intel Capital and SYN Ventures, with Sorenson Capital, Rain Capital and Wipro Ventures participating. Its thesis is that defense needs an agent layer that makes the tools a company already owns work together, not more tools.
Five named agents reason over a Security Data Fabric that normalizes signals from more than 150 security tools into a live digital twin and queries them in place, so logs stay where they live.
Vector, launched in September 2026, probes the approved external scope the way an attacker would; Kairo maps how exposures, identities, workloads and controls chain into breach paths; Lattice reduces findings to the exploitable and reachable; Quell checks whether a new zero day creates a reachable path and recommends a compensating control; and Iris triages alerts and tells L1 and L2 analysts what to do next.
Triage and investigation run end to end on their own, and containment runs through EDR, identity providers, firewalls, WAF and SIEM, with fixes routed through ServiceNow and Jira. The Agentic Control Plane, launched in August 2026, governs AI discovered vulnerabilities from scan to verified closure, including which customer authorized frontier models scan which repositories.
Oversight is built into the action path: the agent prepares a disable, isolate, block or revoke action and an analyst approves it, and customers set the autonomy boundaries. Every agent run is logged with its reasoning chain, prompts, tool calls and token and cost telemetry per case, and engineers can author tenant specific playbooks through the product API. Tuskira has SOC 2 Type 2 and role based access.
It runs as SaaS with federated queries, names no hosting region or customer environment option, and publishes no API reference. It fits security organizations running a crowded stack that want agent driven exposure management and SOC triage layered onto existing tools with approvals and traces built in; a small team looking for a single lightweight scanner will find it more enterprise shaped than it needs.
Vendor details
Canonical URL
https://www.tuskira.ai
Category
Security / SOC agent
Subcategory
Preemptive threat exposure and defense
Funding status
Independent and headquartered in the San Francisco Bay Area. Founded by Piyush Sharma (CEO), Om Moolchandani (CISO and CPO), and Vipul Parmar (CTO), the team behind Accurics, which Tenable acquired. Tuskira launched from stealth in December 2024 with twenty eight and a half million dollars led by Intel Capital and SYN Ventures, alongside Sorenson Capital, Rain Capital, and Wipro Ventures. The Wipro Ventures relationship also opens a global distribution channel. The company positions itself as an agentic SecOps platform and has expanded across North American and international enterprise markets.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Tuskira's Security Data Fabric queries more than 150 security tools in place, across vulnerability scanners, EDR and XDR, CSPM and CNAPP, application security, identity platforms such as Active Directory, Entra and Okta, AWS, Azure and GCP, and network controls such as NGFW and WAF. Agents contain threats through EDR, identity providers, firewalls, WAF and SIEM and route fixes through ServiceNow and Jira; engineers connect through MCP and author tenant specific playbooks through the product API.
In practice
A security team owns dozens of tools but still misses reachable exposures between them. Tuskira's Kairo and Lattice agents map breach paths across the stack and reduce findings to the ones that are exploitable and reachable.
Analysts burn hours triaging alerts that lead nowhere. Tuskira's Iris agent triages and investigates end to end, logs every step, and prepares containment actions that an analyst approves before they run.
A zero day drops and no patch exists yet. Tuskira's Quell agent checks whether the flaw is reachable in the environment and recommends a compensating control through WAF, EDR, IAM or network policy.
Sources & related URLs
Agentic Index coverage score
10.0 / 14 capabilities · 71%
| Integrations & Tool Calling | Full |
|---|---|
|
Agents execute containment across EDR, identity providers, firewalls, WAF and SIEM, including session revocation, IP blocking and IAM policy changes, and route fixes through ServiceNow and Jira, across more than 150 integrations. Sourcetuskira.airead 2026-09-28 |
|
| Workflow Orchestration | Full |
|
Five specialist agents (Vector, Kairo, Lattice, Quell, Iris) reason over one Security Data Fabric, and triage and investigation run end to end. Engineers author tenant-specific playbooks through the product API, so the customer configures the flow. Sourcetuskira.ai/for-engineersread 2026-09-28 |
|
| Knowledge Grounding & RAG | Full |
|
The Security Data Fabric normalizes every signal into the customer's live digital twin and answers each question by federated search across 150+ tools queried in place. That is a maintained retrieval structure over the customer's own security estate, and the agents reason over it. Sourcetuskira.ai/platformread 2026-09-28 |
|
| Human Oversight & Guardrails | Full |
|
For disable, isolate, block or revoke actions, the agent prepares the action and an analyst always approves it. Customers set the autonomy boundaries, high impact actions wait for a person, and the control plane enforces approval workflows and permitted control changes, so approval comes before the agent action commits. Sourcetuskira.ai/platformread 2026-09-28 |
|
| Security, Identity & Governance | Full |
|
SOC 2 Type 1 (2024) and SOC 2 Type 2 (2025) reports are listed in a trust center hosted by Akitra. RBAC respects the customer's existing roles, and each tenant has isolated credentials, a case store and an audit log. Sourcetrustcenter.akitra.net/tuskiraai/index.htmlread 2026-09-28 |
|
| Observability & Auditability | Full |
|
Every agent run is logged with a full reasoning chain, plus end-to-end token and cost telemetry broken out per investigation, model and run. The exact prompt, every tool call, evidence artifact and model response are captured per case and open for inspection, so the agent's own run trace is kept. Sourcetuskira.ai/for-engineersread 2026-09-28 |
|
| Memory & State Persistence | Partial |
|
An isolated case store per tenant lets the Analyst Copilot resume a case with the full transcript. Each investigation writes entities, outcomes and prior probabilities back into the customer's twin, which Tuskira describes as built on memory, not prompts. No lifetime or customer control over the case store is stated, and the write-back lands in the twin, the knowledge layer, not in agent memory. Sourcetuskira.ai/platformread 2026-09-28 |
|
| Deployment & Data Residency | Partial |
|
Tuskira is SaaS with federated queries. The customer's data never leaves, only context and verdicts move, residency stays with the customer, and each tenant is isolated. No hosting region, customer VPC or on premises option for the platform itself is named. Sourcetuskira.ai/for-engineersread 2026-09-28 |
|
| Prebuilt Agents, Templates & Packs | Full |
|
Five named prebuilt agents have stated jobs. They are Vector (external red team, launched 16 Sep 2026), Kairo (breach paths), Lattice (vulnerability prioritization), Quell (zero day reachability and compensating controls) and Iris (alert triage). Earlier agent names (Zero Day Analyst, Post Breach Analyst) are retired. Sourcetuskira.airead 2026-09-28 |
|
| Triggers & Channel Coverage | Full |
|
Work starts without a person. Iris takes incoming tool alerts and Quell takes newly disclosed CVEs, and triage and investigation run end to end with zero human intervention. Sourcetuskira.ai/platformread 2026-09-28 |
|
| Model Flexibility & Routing | Partial |
|
The Agentic Control Plane routes customer-authorized frontier models to repositories and risk tiers and enforces model selection for AI vulnerability scanning, and run telemetry is broken out per model. That customer choice covers one workflow, no provider is named, and the model behind the five agents cannot be selected. Sourcetuskira.ai/blog/agentic-control-plane-for-exposure-managementread 2026-09-28 |
|
| APIs, SDKs & MCP Extensibility | Partial |
|
Engineers author tenant-specific playbooks through the product API and connect through MCP. There is no published API reference, auth scheme or MCP tool list, and the MCP connection reaches the customer's 150+ tools and does not expose Tuskira itself. Sourcetuskira.ai/for-engineersread 2026-09-28 |
|
| Testing, Debugging & Optimization | Not documented |
|
There is no harness, scored test cases or release gate for Tuskira's agents. Re-testing attack paths, zero day simulation and SIEM tuning test and tune the customer's estate, and schema-validated reports check the shape of the output. Sourcetuskira.ai/platformread 2026-09-28 |
|
| Browser & Computer Use | Not documented |
|
Tuskira works through federated queries and tool integrations. Vector probes the approved external scope as an attacker would, but no agent operates a browser or desktop. Sourcetuskira.airead 2026-09-28 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
An open source AI Agent Gateway from Tuskira, released under Apache 2.0 as an early alpha, sits between agents such as Claude Code, Cursor and Codex and the MCP servers and models they call. It checks per profile tool allow lists on every call, injects stored credentials per request, and logs each call with tokens and estimated cost.
Bears on: Security / enterprise
View sourceTuskira launched Vector, an autonomous red teaming agent that simulates external attacks and validates an organization's exploitable attack surface against its internal security data.
Bears on: Agent capability
View sourceTuskira launched the Agentic Control Plane for Exposure Management to govern AI-discovered vulnerabilities from initial scan to verified closure. The capability connects vulnerability findings with production context across 150 integrations to determine reachability, apply compensating controls, and route durable code fixes.
Bears on: Workflow orchestration
View sourcePricing
Not public; quoted through enterprise sales after a demo
enterprise subscription; basis not disclosed
What is public
No list pricing, tiers, or entry point are published. Only the product description is public.
Billing mechanics
Rates and billing basis are not disclosed. Inference, not stated by the vendor: an enterprise subscription keyed to environment size and the number of integrated tools.
Cost watchouts
Integrating a large existing security stack can add onboarding and professional services effort beyond license cost.
Variable cost rationale
Inference, not stated by the vendor: scope likely grows with the number of integrated tools and the size of the monitored environment; the control plane's own spending limits govern frontier model scanning cost.
Additional watchouts
Confirm how pricing scales as you connect more tools and as the estate grows, and whether onboarding across a large stack carries professional services cost.
Sales call required
Yes, required for paid access
Free / trial
No public free tier
Key ambiguities
No public anchor for entry price or how tiers are structured.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to Tuskira
The closest documented capability profiles to Tuskira among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- 7AI8.5 / 14A lighter documented profile than Tuskira
- Anvilogic8.5 / 14A lighter documented profile than Tuskira
- BlinkOps10.5 / 14Fuller documented coverage on Deployment & Data Residency and APIs, SDKs & MCP ExtensibilityTuskira vs BlinkOps →
- SentinelOne10.5 / 14Fuller documented coverage on Deployment & Data Residency and APIs, SDKs & MCP Extensibility
- Abnormal AI9.0 / 14Adds documented Testing, Debugging & Optimization
- Astelia8.0 / 14A lighter documented profile than Tuskira
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded