Agentic AI SOC platform built to replace legacy SOAR

Torq is a Tel Aviv-based AI SOC platform that combines agentic AI with what it calls Hyperautomation — the ability to build, deploy, and run security workflows via no-code, low-code, or full-code approaches — to automate alert triage, investigation, containment, and remediation at machine speed. Founded in 2020 and having raised $332M total (including a $140M Series D in early 2026 at a $1.2B valuation), Torq’s core argument is that legacy SOAR platforms are brittle and people-intensive, while its multi-agent system handles the full SOC lifecycle without pre-written playbooks for every scenario. Its customers span hundreds of multinationals and it is actively expanding into the U.S. federal and government market through a partnership with Merlin Ventures. Named customers include Marriott, PepsiCo, Procter & Gamble, Siemens, Uber, and Virgin Atlantic.

Compliance

GDPR ISO 27001 SOC 2

Visit Torq

Key Features

  • Torq HyperSOC and multi-agent system: Specialized AI agents — Case Management, Enrichment, Investigation, and Response — work autonomously in parallel, covering the full SOC lifecycle from triage to containment without requiring human handoffs between steps.
  • Hyperautomation workflow engine: Supports no-code, low-code, and full-code workflow construction; analysts describe a use case in natural language and the platform generates production-ready workflows validated against the organization’s security stack.
  • 100% triage coverage: Designed to achieve full coverage of low-fidelity alerts autonomously, routing only verified, high-impact threats to human analysts — Torq claims up to 90% reduction in analyst investigation time.
  • Natural language MITRE ATT&CK cross-referencing: During investigations, the platform references industry frameworks and proprietary playbooks in natural language, presenting analysts with context and next-step recommendations when human review is needed.
  • Elastic cloud-native scale: Architecture designed to handle volume spikes and multinational environments without the performance limits of on-premises SOAR deployments.
  • SOC performance dashboards: Tracks MTTD, MTTR, alert volumes, false positive rates, and closure times, with customizable views for SOC analysts and executive stakeholders.

Use Cases

  • For enterprises replacing legacy SOAR: A Fortune 500 security team migrates from a legacy SOAR platform and uses Torq to automate phishing triage, alert handling, and response across its global SOC without maintaining fragile rule libraries.
  • For MSSPs scaling across client environments: A managed security service provider deploys Torq to automate tier-1 and tier-2 SOC tasks across multiple client environments, growing case volume without proportional analyst headcount growth.
  • For SOCs with alert fatigue: A security team processing thousands of daily alerts uses Torq’s multi-agent triage to achieve 100% alert investigation coverage, reserving analyst time for genuine, high-severity incidents.

Pricing MODELS

Enterprise

Pricing Summary

Enterprise-only, custom-quoted pricing. No self-serve or published list pricing.

Company Size Fit

Enterprise Mid-market

Technical Snapshot

API Available

Yes

LLM Provider

Multi-model

Open Source

No

Deployment Options

Cloud Saas