Skip to content
Prophet AI

Prophet AI

NEW
Category: AI Security
License: Commercial
Suphi Cankurt
Suphi Cankurt
+8 Years in AppSec
Updated August 6, 2026
8 min read
Key Takeaways
  • Three AI capabilities — SOC Analyst, Threat Hunter, Detection Engineer — plus Watchtower, which Prophet describes as a human-in-the-loop service rather than an agent.
  • Prophet states that every question, query, and reasoning step in an investigation is recorded, which is what makes a determination reviewable rather than a score to trust.
  • Watchtower engages within 30 minutes on malicious or inconclusive determinations, per Prophet, and can scope impact, guide response, or execute containment on request.
  • Prophet reports 10M investigations and 2.5M+ hours prevented. One Prophet page calls 98.5% an accuracy rate, while another calls it a reduction in false positives.
  • Deploys dedicated single-tenant with a bring-your-own-key option, and Prophet states it does not train models on customer personal data.

Prophet Security is an AI security company building an agentic platform for the security operations center: alert triage, investigation, threat hunting, and detection engineering.

Prophet positions its agents as a way to absorb repetitive investigation work so analysts spend their hours on decisions that carry consequences.

Founded by Kamal Shah (CEO) and Vibhav Sreekanti (CTO), the company announced a $30 million Series A led by Accel on July 29, 2025, with Bain Capital Ventures participating.

Prophet announced additional strategic investments from Amex Ventures and Citi Ventures in February 2026. The amount was not disclosed.

What is Prophet AI?

Prophet AI is the platform itself. Three AI capabilities investigate alerts, hunt for threats, and maintain the detection rules feeding both, with an optional human service behind them.

That split matters, because each piece addresses a different workflow. Triage backlog, hunting that only happens when someone has time, and unmapped detection coverage are separate problems with separate owners.

Prophet AI platform map: AI SOC Analyst, AI Threat Hunter, and AI Detection Engineer as AI agents, plus Watchtower as an optional human tier
Three AI capabilities plus one human service, as described on Prophet's product pages.

The company leans on a reviewable evidence trail. Prophet states that every question asked, every query run, and every reasoning step is documented, so a determination can be inspected rather than accepted.

Prophet’s Why Prophet page reports 10M investigations completed, 2.5M+ hours of human toil prevented, and a 98.5% accuracy rate.

A separate Prophet investment post describes 98.5% as fewer false positives. Prophet does not publish enough methodology to reconcile the two statements.

What are Prophet AI’s key features?

The table below summarizes capabilities described on Prophet’s own product pages: SOC Analyst , Threat Hunter , Detection Engineer , and Watchtower . These are vendor-published claims, not hands-on results.

FeatureDetails
AI SOC AnalystInvestigates alerts at every severity on arrival, in parallel
AI Threat HunterPlain-language hunts plus a library of pre-codified, schedulable hunt templates
AI Detection EngineerMaps coverage to MITRE ATT&CK, drafts and back-tests new detections
WatchtowerOptional 24x7x365 human service; expert engages within 30 minutes
Evidence trailEvery question, query, and reasoning step recorded and reviewable
Response actionsScoped remediation, previewed and back-tested, executed under rules you set
Incident groupingRelated investigations merged into one incident rather than separate tickets
Integrations200+ out of the box across SIEM, EDR, identity, cloud, email, network
SIEM coverageNamed support for Splunk, Sumo Logic, and Microsoft Sentinel
DeploymentDedicated single-tenant, bring-your-own-key option
Data handlingVendor states no model training on customer personal data
Delivery surfacesIn-product plus Slack, Teams, or a custom webhook with per-channel scope

AI SOC Analyst

The SOC Analyst is the core of the platform, and Prophet’s stated design is investigating everything rather than sampling.

Per its product page, it summarizes an alert, extracts the artifacts, plans the questions an experienced analyst would ask, then runs them across connected SIEM, EDR, identity, cloud, and email tools.

Prophet says investigations run in parallel on arrival, and that investigation time stays flat whether a day brings 50 alerts or 2,000.

Response is separated from investigation. Prophet states the platform investigates autonomously from day one but only takes actions you have approved, with scope widening as its track record justifies it.

AI Threat Hunter

The Threat Hunter is aimed at turning hunting from an occasional project into something scheduled.

Analysts ask questions of the environment in plain language, and Prophet says the agent plans the hunt, executes it, and returns an answer with the evidence behind it.

A curated library of pre-codified hunt templates covers patterns compatible with your data sources, and hunts can recur on a schedule.

AI Detection Engineer

Detection Engineer works on the layer that produces alerts rather than on the alerts themselves.

Prophet says it maps a customer’s own investigation data against MITRE ATT&CK to show what is genuinely covered, what has gone quiet, and what is dark.

From there it drafts and back-tests net-new detections, tunes noisy existing SIEM rules, and runs hunts against the thinnest parts of coverage.

Autonomy is per-area. Teams can start in a suggest-and-inform mode where every change is reviewed, then raise it selectively.

Watchtower

Watchtower is the part of the offering that is deliberately not AI.

Prophet describes it as an optional 24x7x365 team of human analysts working inside the platform, using the same investigative engine and evidence the agents use.

When Prophet AI reaches a malicious or inconclusive determination, Prophet states an expert engages within 30 minutes to scope blast radius, assess impact, and guide or execute the response.

Escalations arrive in Slack, Teams, or email as a narrative from the person who did the work. Prophet says guidance is the default and execution happens only when a customer asks for it.

Prophet determination flow: alert arrives, agent investigates, determination is recorded as evidence, malicious or inconclusive verdicts escalate to a Watchtower analyst
Where a determination lands, and the point at which a human enters the loop.

The better an AI gets at clearing noise, the more each remaining determination matters. Watchtower is Prophet’s answer for that consequential tail.

What does the Prophet AI platform include?

ComponentWhat it doesWho runs itAutonomy model
AI SOC AnalystInvestigates alerts end to endAI agentsInvestigates autonomously; actions gated
AI Threat HunterPlain-language, scheduled, recurring huntsAI agentsRuns on demand or on a schedule
AI Detection EngineerCoverage mapping, detection authoring, tuningAI agentsPer-area, from suggest-only upward
WatchtowerReviews, scopes, escalates, can remediateHuman analystsGuidance by default; execution on request

Prophet’s architecture diagram names 11 sub-agents across the three AI capabilities.

Prophet AI architecture diagram: AI Threat Hunter with Threat Researcher, Reactive, Proactive and Custom Hunter agents; AI SOC Analyst with Investigator, Case Manager and Remediator; AI Detection Engineer with Resilience Analyzer, Gap Analyzer, Author and Tuner, under AI Watchtower and a Guidance layer
Prophet's published agent architecture: 11 named sub-agents across the three capabilities, with Watchtower above and organizational Guidance below.

Prophet sells Watchtower as an attach to the platform rather than a standalone product. It does not publish Watchtower packaging or pricing.

What does Prophet AI integrate with?

Prophet lists 200+ out-of-the-box integrations. Its integrations directory groups them by the role each tool plays in an investigation.

Prophet AI integration categories: SIEM (Splunk, Sumo Logic, Microsoft Sentinel, QRadar), Network (Cisco Umbrella, Infoblox), Cloud security (Netskope), Identity (Ping Identity), SaaS (Obsidian), Data lake (Starburst), Case management (TheHive), and Collaboration (Slack, Teams, custom webhook)
Eight of the 12 roles in Prophet's integrations directory, with examples named on its site.
CategoryExamples named on Prophet’s site
SIEMSplunk, Sumo Logic, Microsoft Sentinel, QRadar
NetworkCisco Umbrella, Infoblox
Cloud securityNetskope
IdentityPing Identity
SaaSObsidian
Data lakeStarburst
Case managementTheHive
CollaborationSlack, Teams, custom webhook

Detection Engineer works against the SIEM you already run. Prophet names Splunk, Sumo Logic, and Microsoft Sentinel, and states that detections stay portable and yours.

How does Prophet handle deployment and data?

AspectWhat Prophet states
Deployment modelDedicated single-tenant
Key managementBring-your-own-key option
Model trainingNo training of AI models with personal data
ComplianceSOC 2 Type 2 badge displayed in the site footer
RolloutIntegrates with existing tooling, described as no rip-and-replace
Notification scopePer-channel control over scope and frequency
Six deployment and data controls Prophet states on its site: dedicated single-tenant isolation, optional bring-your-own-key, no model training on personal data, a SOC 2 Type 2 badge, no rip-and-replace rollout, and per-channel notification scope
Six vendor-stated controls. Each is what Prophet publishes, not something verified here.

Dedicated single-tenant deployment and bring-your-own-key give buyers explicit isolation and key-management controls. Whether that is stronger than a multi-tenant deployment depends on the implementation and contract.

The exact boundary of the no-training statement is also a contract question, not a website question.

How does Prophet AI compare to other AI SOC platforms?

I compare investigation-first platforms with workflow platforms that add agents. This is an editorial grouping, not a vendor-defined market taxonomy.

DimensionProphet AI7AIDropzone AITorq
Core modelAgentic AI SOC platformEnd-to-end agentic SOCAgentic investigationHyperautomation + agents
Named AI components3 (Analyst, Hunter, Detection Engineer)Platform capabilities: Detect, Investigate, Respond, Hunt2 available; Threat Intel Analyst due Summer 2026HyperAgents on a workflow engine
Detection engineeringYes, with ATT&CK mappingATT&CK coverage mapping and rule-tuning recommendationsNot a named moduleVia workflow automation
Human service tierYes, WatchtowerYes, PLAID ELITENo first-party managed serviceNo first-party managed service
Public pricingNo list priceNo list pricePricing page and unit published, no list priceNo list price

Prophet packages detection engineering and human coverage as named offerings, but those capability categories are not unique to Prophet.

7AI publishes both detection optimization and the 24x7 PLAID ELITE service. Torq publishes agentic response and remediation .

If you already run a mature SOAR, the comparison is not Prophet against the category. It is Prophet against your existing platform’s own agentic roadmap.

What does Prophet AI cost?

Prophet Security does not publish pricing. Engagement starts with a demo request or a proof of value, and packaging goes through their sales team.

Watchtower is described as a natural attach to the platform. Prophet publishes neither its packaging nor its price.

What are Prophet AI’s strengths and limitations?

I see the recorded evidence trail as the strongest part of the proposition. Each determination includes the questions, queries, and reasoning steps Prophet says it records.

Watchtower adds human review for malicious or inconclusive determinations. Its analysts can scope impact, guide response, or execute containment when a customer requests it.

The limitations are about verification. Prophet’s public materials do not explain how the company calculates or reconciles its two uses of the 98.5% figure.

Unpublished pricing is the second gap. Comparing budget across this category means a sales conversation with each vendor, which is slow when you are shortlisting four of them.

The last thing I would settle before a demo is scope. Prophet’s published use cases cover endpoint, identity, cloud, email, DLP, and network operations, not the security of AI models or applications.

What are alternatives to Prophet AI?

For comparison, I separate investigation-first platforms from workflow platforms that add agents. The boundary is not absolute, and several products now span investigation, detection, and response:

  • 7AI — Agentic SOC platform from the Cybereason founders , covering detection, investigation, response, and hunting across endpoint, identity, cloud, email, and network sources.
  • Dropzone AI — Agentic SOC platform with an AI SOC Analyst and Threat Hunter. Its AI Threat Intel Analyst is listed as launching in Summer 2026, with early access on request.
  • Torq — AI SOC platform built on a hyperautomation workflow engine, with HyperAgents acting across triage, investigation, and response.
  • Tines — Workflow platform spanning AI agents, apps, and automation, with alert intake, triage, and remediation as a security use case.

For the wider landscape, see the AI security tools guide. For AI-focused threat detection in models and code rather than SOC operations, consider Protect AI Guardian or CalypsoAI .

Frequently Asked Questions

What is Prophet AI?
Prophet AI is the agentic AI SOC platform built by Prophet Security, and it investigates security alerts autonomously. It combines an AI SOC Analyst, an AI Threat Hunter, an AI Detection Engineer, and Watchtower, an optional human-in-the-loop service. The company was founded by Kamal Shah and Vibhav Sreekanti and raised a $30 million Series A led by Accel in July 2025.
How much does Prophet AI cost?
Prophet Security does not publish pricing. Engagement starts with a demo request or a proof of value, and packaging goes through their sales team.
What is Prophet AI Watchtower?
Watchtower is an optional 24x7x365 service staffed by human analysts who work inside the Prophet platform. Prophet states that an expert engages within 30 minutes on a malicious or inconclusive determination, scoping impact and either guiding or executing response. Those analysts also tune the customer’s instance with what they learn.
Does Prophet AI replace SOAR?
Prophet says it plans each investigation dynamically rather than relying only on predefined playbooks. Several SOAR vendors now ship agentic features of their own, so the comparison is worth running against your specific SOAR rather than the category.
What does Prophet AI integrate with?
Prophet lists 200+ out-of-the-box integrations across SIEM, EDR, identity, cloud, email, network, threat intelligence, data lake, and case management. Its Detection Engineer page names Splunk, Sumo Logic, and Microsoft Sentinel as supported SIEMs.
Does Prophet AI train AI models on customer data?
Prophet states that its platform deploys dedicated single-tenant, offers a bring-your-own-key option, and does not train AI models with personal data. The exact scope of that statement across all telemetry is worth confirming in writing during an evaluation.
Is Prophet AI an application security tool?
No. Prophet’s published use cases cover endpoint, email, identity, cloud, DLP, and network security operations. I found no application or model security testing capability in its documentation.