Qevlar AI is a Paris/New York-based autonomous SOC platform founded in 2023 by AI engineers Ahmed Achchak and Hamza Sayah. Its central architectural distinction is that LLMs are deliberately not used to drive investigation reasoning — instead, a deterministic graph orchestrator makes structured, reproducible decisions, with LLMs handling only bounded tasks like enrichment and report generation. This design choice is positioned as addressing a core production security concern: an investigation must produce the same verdict for the same evidence every time, whereas LLMs can produce different conclusions on different runs. Qevlar raised $30M in March 2026 ($44M total), and its customer base spans Fortune 500 enterprises including Mercedes-Benz, Sodexo, and MediaMarkt, as well as major MSSPs including Atos, Orange Cyberdefense, and ECI. Documented outcomes include a 10x reduction in investigation time (to under 3 minutes) and 100% alert investigation coverage around the clock.
Qevlar AI
Autonomous security investigations that turn alerts into posture intelligence
Compliance
SOC 2
Key Features
- Deterministic graph orchestrator: Investigation reasoning is structured and reproducible — the same alert always follows the same logic path, eliminating the inconsistency that occurs when LLMs drive verdict decisions directly.
- End-to-end autonomous investigation: From alert receipt through enrichment, correlation, verdict, and remediation suggestion — the platform closes the full investigation loop rather than stopping at triage or summary generation.
- Alert correlation into incident narratives: Connects related alerts into single incident stories with a mapped blast radius, rather than processing each alert in isolation as most AI triage tools do.
- Adaptive threat hunting: Proactively searches for attacker TTPs, behavioral anomalies, and patterns hidden across past investigations — not just processing the queue, but looking for threats not yet generating alerts.
- Compounding posture intelligence: Every closed investigation updates the platform’s shared intelligence layer, improving detection rules, expanding coverage, and making future investigations sharper — institutional knowledge that survives analyst turnover.
- Per-investigation pricing: Charged per completed investigation rather than per token or compute time, giving CISOs predictable cost forecasting.
Use Cases
- For MSSPs serving multiple enterprise clients: An MSSP deploys Qevlar to autonomously investigate alerts across client environments, each with its own context and tool sources, delivering consistent investigation quality at scale.
- For SOC teams aiming to eliminate the alert backlog: An enterprise security team with thousands of daily alerts achieves 100% investigation coverage by routing the full queue to Qevlar, reserving analyst time for the malicious findings the platform escalates.
- For SOCs that want posture improvement, not just alert processing: A security team uses Qevlar’s compounding intelligence layer to turn investigation work into detection improvements and pattern insights — closing the loop between reactive response and proactive hardening.
Pricing MODELS
Enterprise
Pricing Summary
Enterprise-only, per-completed-investigation pricing model (not per seat or per token). Custom quotes; contact sales. Qevlar offers proof-of-value deployments where customers benchmark the platform before committing.
Company Size Fit
Enterprise Mid-market
Technical Snapshot
API Available
Yes
LLM Provider
Multi-model
Open Source
No
Deployment Options
Cloud Saas
Notable Customers
Undisclosed