Prophet Security is an AI security company building an agentic platform for the security operations center: alert triage, investigation, threat hunting, and detection engineering.
Prophet positions its agents as a way to absorb repetitive investigation work so analysts spend their hours on decisions that carry consequences.
This overview summarizes Prophet’s public product pages.
The company is led by Kamal Shah (CEO) and Vibhav Sreekanti (CTO). Prophet announced a $30 million Series A led by Accel on July 29, 2025, with Bain Capital Ventures participating.
Prophet announced additional strategic investments from Amex Ventures and Citi Ventures in February 2026. The amount was not disclosed.
What is Prophet AI?
On its current product pages, Prophet presents three AI capabilities for alert investigation, threat hunting, and detection engineering, plus an optional human service.

On its AI SOC Analyst page , Prophet says every question, query, and reasoning step is documented so customers can audit how a determination was reached.
Prophet’s Why Prophet page reports 10M investigations completed, 2.5M+ hours of human toil prevented, and a 98.5% accuracy rate.
A separate Prophet investment post describes 98.5% as fewer false positives. Prophet does not publish enough methodology to reconcile the two statements.
What are Prophet AI’s key features?
The table below summarizes Prophet’s product pages for SOC Analyst , Threat Hunter , Detection Engineer , and Watchtower .
| Feature | Details |
|---|---|
| AI SOC Analyst | Investigates alerts at every severity on arrival, in parallel |
| AI Threat Hunter | Plain-language hunts plus a library of pre-codified, schedulable hunt templates |
| AI Detection Engineer | Maps coverage to MITRE ATT&CK, drafts and back-tests new detections |
| Watchtower | Optional 24x7x365 human service; expert engages within 30 minutes |
| Evidence trail | Prophet says every question, query, and reasoning step is documented |
| Response actions | Scoped remediation, previewed and back-tested, executed under rules you set |
| Incident grouping | Related investigations merged into one incident rather than separate tickets |
| Integrations | 200+ out of the box across SIEM, EDR, identity, cloud, email, network |
| SIEM coverage | Named support for Splunk, Sumo Logic, and Microsoft Sentinel |
| Deployment | Dedicated single-tenant, bring-your-own-key option |
| Data handling | Vendor states no model training on customer personal data |
| Delivery surfaces | In-product plus Slack, Teams, or a custom webhook with per-channel scope |
AI SOC Analyst
Prophet describes the AI SOC Analyst as investigating every alert rather than sampling.
Per its product page, it summarizes an alert, extracts the artifacts, plans the questions an experienced analyst would ask, then runs them across connected SIEM, EDR, identity, cloud, and email tools.
Prophet says investigations run in parallel on arrival, and that investigation time stays flat whether a day brings 50 alerts or 2,000.
Response is separated from investigation. Prophet states the platform investigates autonomously from day one but only takes actions you have approved, with scope widening as its track record justifies it.
AI Threat Hunter
Prophet presents the Threat Hunter as supporting analyst-initiated, scheduled, and recurring hunts.
Analysts ask questions of the environment in plain language, and Prophet says the agent plans the hunt, executes it, and returns an answer with the evidence behind it.
A curated library of pre-codified hunt templates covers patterns compatible with your data sources, and hunts can recur on a schedule.
AI Detection Engineer
Detection Engineer works on the layer that produces alerts rather than on the alerts themselves.
Prophet says it maps a customer’s own investigation data against MITRE ATT&CK to show what is genuinely covered, what has gone quiet, and what is dark.
From there it drafts and back-tests net-new detections, tunes noisy existing SIEM rules, and runs hunts against the thinnest parts of coverage.
Autonomy is per-area. Teams can start in a suggest-and-inform mode where every change is reviewed, then raise it selectively.
Watchtower
Prophet describes Watchtower as an optional 24x7x365 team of human analysts working inside the platform, using the same investigative engine and evidence as its AI agents.
When Prophet AI reaches a malicious or inconclusive determination, Prophet states an expert engages within 30 minutes to scope blast radius, assess impact, and guide or execute the response.
Escalations arrive in Slack, Teams, or email as a narrative from the person who did the work. Prophet says guidance is the default and execution happens only when a customer asks for it.

What does the Prophet AI platform include?
| Component | What it does | Who runs it | Autonomy model |
|---|---|---|---|
| AI SOC Analyst | Investigates alerts end to end | AI agents | Investigates autonomously; actions gated |
| AI Threat Hunter | Plain-language, scheduled, recurring hunts | AI agents | Runs on demand or on a schedule |
| AI Detection Engineer | Coverage mapping, detection authoring, tuning | AI agents | Per-area, from suggest-only upward |
| Watchtower | Reviews, scopes, escalates, can remediate | Human analysts | Guidance by default; execution on request |
Prophet’s published architecture diagram names 11 sub-agents across the three AI capabilities.

Prophet calls Watchtower a “natural attach” to the platform. Its public Watchtower page does not provide packaging or pricing details.
What does Prophet AI integrate with?
Prophet lists 200+ out-of-the-box integrations . Its directory groups them by the role each tool plays in an investigation.

| Category | Examples named on Prophet’s site |
|---|---|
| SIEM | Splunk, Sumo Logic, Microsoft Sentinel, QRadar |
| Network | Cisco Umbrella, Infoblox |
| Cloud security | Netskope |
| Identity | Ping Identity |
| SaaS | Obsidian |
| Data lake | Starburst |
| Case management | TheHive |
| Collaboration | Slack, Teams, custom webhook |
On its Detection Engineer page , Prophet names Splunk, Sumo Logic, and Microsoft Sentinel and says detections remain portable and customer-owned.
How does Prophet handle deployment and data?
| Aspect | What Prophet states |
|---|---|
| Deployment model | Dedicated single-tenant |
| Key management | Bring-your-own-key option |
| Model training | No training of AI models with personal data |
| Compliance | SOC 2 Type 2 badge displayed in the site footer |
| Rollout | Integrates with existing tooling, described as no rip-and-replace |
| Notification scope | Per-channel control over scope and frequency |

Prophet’s public pages do not describe these controls in implementation-level detail.
How does Prophet AI compare to other AI SOC platforms?
7AI publishes investigation, detection, response, and threat-hunting capabilities, plus the fully managed PLAID ELITE service. Dropzone AI lists an AI SOC Analyst, AI Threat Hunter, and AI Threat Intel Analyst.
Torq describes an AI SOC platform that acts across triage, investigation, and response on top of its hyperautomation platform.
What does Prophet AI cost?
Prophet does not list prices on its website and directs prospective buyers to request a demo .
What should buyers verify about Prophet AI?
Prophet’s SOC Analyst page says every question, query, and reasoning step is documented so customers can review how a determination was reached.
Prophet says Watchtower analysts review malicious or inconclusive determinations and can scope impact, guide response, or execute containment when requested.
Prophet’s Why page calls 98.5% an accuracy rate, while its February 2026 investment post calls it a reduction in false positives. Neither page explains the methodology or how the figures relate.
Without a public list price, a cost comparison requires a vendor quote.
Prophet’s published use cases cover endpoint, identity, cloud, email, DLP, and network operations. Application and AI model security testing are outside the scope described on the site.
What are alternatives to Prophet AI?
The vendors below publish overlapping security-operations capabilities:
- 7AI — Agentic SOC platform from the Cybereason founders , covering detection, investigation, response, and hunting across endpoint, identity, cloud, email, and network sources.
- Dropzone AI — Agentic SOC platform whose site lists an AI SOC Analyst, AI Threat Hunter, and AI Threat Intel Analyst .
- Torq — AI SOC platform built on a hyperautomation workflow engine, with HyperAgents acting across triage, investigation, and response.
- Tines — Workflow platform spanning AI agents, apps, and automation, with alert intake, triage, and remediation as a security use case.
For the wider landscape, see the AI security tools guide.
