Prophet Security is an AI security company building an agentic platform for the security operations center: alert triage, investigation, threat hunting, and detection engineering.
Prophet positions its agents as a way to absorb repetitive investigation work so analysts spend their hours on decisions that carry consequences.
Founded by Kamal Shah (CEO) and Vibhav Sreekanti (CTO), the company announced a $30 million Series A led by Accel on July 29, 2025, with Bain Capital Ventures participating.
Prophet announced additional strategic investments from Amex Ventures and Citi Ventures in February 2026. The amount was not disclosed.
What is Prophet AI?
Prophet AI is the platform itself. Three AI capabilities investigate alerts, hunt for threats, and maintain the detection rules feeding both, with an optional human service behind them.
That split matters, because each piece addresses a different workflow. Triage backlog, hunting that only happens when someone has time, and unmapped detection coverage are separate problems with separate owners.

The company leans on a reviewable evidence trail. Prophet states that every question asked, every query run, and every reasoning step is documented, so a determination can be inspected rather than accepted.
Prophet’s Why Prophet page reports 10M investigations completed, 2.5M+ hours of human toil prevented, and a 98.5% accuracy rate.
A separate Prophet investment post describes 98.5% as fewer false positives. Prophet does not publish enough methodology to reconcile the two statements.
What are Prophet AI’s key features?
The table below summarizes capabilities described on Prophet’s own product pages: SOC Analyst , Threat Hunter , Detection Engineer , and Watchtower . These are vendor-published claims, not hands-on results.
| Feature | Details |
|---|---|
| AI SOC Analyst | Investigates alerts at every severity on arrival, in parallel |
| AI Threat Hunter | Plain-language hunts plus a library of pre-codified, schedulable hunt templates |
| AI Detection Engineer | Maps coverage to MITRE ATT&CK, drafts and back-tests new detections |
| Watchtower | Optional 24x7x365 human service; expert engages within 30 minutes |
| Evidence trail | Every question, query, and reasoning step recorded and reviewable |
| Response actions | Scoped remediation, previewed and back-tested, executed under rules you set |
| Incident grouping | Related investigations merged into one incident rather than separate tickets |
| Integrations | 200+ out of the box across SIEM, EDR, identity, cloud, email, network |
| SIEM coverage | Named support for Splunk, Sumo Logic, and Microsoft Sentinel |
| Deployment | Dedicated single-tenant, bring-your-own-key option |
| Data handling | Vendor states no model training on customer personal data |
| Delivery surfaces | In-product plus Slack, Teams, or a custom webhook with per-channel scope |
AI SOC Analyst
The SOC Analyst is the core of the platform, and Prophet’s stated design is investigating everything rather than sampling.
Per its product page, it summarizes an alert, extracts the artifacts, plans the questions an experienced analyst would ask, then runs them across connected SIEM, EDR, identity, cloud, and email tools.
Prophet says investigations run in parallel on arrival, and that investigation time stays flat whether a day brings 50 alerts or 2,000.
Response is separated from investigation. Prophet states the platform investigates autonomously from day one but only takes actions you have approved, with scope widening as its track record justifies it.
AI Threat Hunter
The Threat Hunter is aimed at turning hunting from an occasional project into something scheduled.
Analysts ask questions of the environment in plain language, and Prophet says the agent plans the hunt, executes it, and returns an answer with the evidence behind it.
A curated library of pre-codified hunt templates covers patterns compatible with your data sources, and hunts can recur on a schedule.
AI Detection Engineer
Detection Engineer works on the layer that produces alerts rather than on the alerts themselves.
Prophet says it maps a customer’s own investigation data against MITRE ATT&CK to show what is genuinely covered, what has gone quiet, and what is dark.
From there it drafts and back-tests net-new detections, tunes noisy existing SIEM rules, and runs hunts against the thinnest parts of coverage.
Autonomy is per-area. Teams can start in a suggest-and-inform mode where every change is reviewed, then raise it selectively.
Watchtower
Watchtower is the part of the offering that is deliberately not AI.
Prophet describes it as an optional 24x7x365 team of human analysts working inside the platform, using the same investigative engine and evidence the agents use.
When Prophet AI reaches a malicious or inconclusive determination, Prophet states an expert engages within 30 minutes to scope blast radius, assess impact, and guide or execute the response.
Escalations arrive in Slack, Teams, or email as a narrative from the person who did the work. Prophet says guidance is the default and execution happens only when a customer asks for it.

The better an AI gets at clearing noise, the more each remaining determination matters. Watchtower is Prophet’s answer for that consequential tail.
What does the Prophet AI platform include?
| Component | What it does | Who runs it | Autonomy model |
|---|---|---|---|
| AI SOC Analyst | Investigates alerts end to end | AI agents | Investigates autonomously; actions gated |
| AI Threat Hunter | Plain-language, scheduled, recurring hunts | AI agents | Runs on demand or on a schedule |
| AI Detection Engineer | Coverage mapping, detection authoring, tuning | AI agents | Per-area, from suggest-only upward |
| Watchtower | Reviews, scopes, escalates, can remediate | Human analysts | Guidance by default; execution on request |
Prophet’s architecture diagram names 11 sub-agents across the three AI capabilities.

Prophet sells Watchtower as an attach to the platform rather than a standalone product. It does not publish Watchtower packaging or pricing.
What does Prophet AI integrate with?
Prophet lists 200+ out-of-the-box integrations. Its integrations directory groups them by the role each tool plays in an investigation.

| Category | Examples named on Prophet’s site |
|---|---|
| SIEM | Splunk, Sumo Logic, Microsoft Sentinel, QRadar |
| Network | Cisco Umbrella, Infoblox |
| Cloud security | Netskope |
| Identity | Ping Identity |
| SaaS | Obsidian |
| Data lake | Starburst |
| Case management | TheHive |
| Collaboration | Slack, Teams, custom webhook |
Detection Engineer works against the SIEM you already run. Prophet names Splunk, Sumo Logic, and Microsoft Sentinel, and states that detections stay portable and yours.
How does Prophet handle deployment and data?
| Aspect | What Prophet states |
|---|---|
| Deployment model | Dedicated single-tenant |
| Key management | Bring-your-own-key option |
| Model training | No training of AI models with personal data |
| Compliance | SOC 2 Type 2 badge displayed in the site footer |
| Rollout | Integrates with existing tooling, described as no rip-and-replace |
| Notification scope | Per-channel control over scope and frequency |

Dedicated single-tenant deployment and bring-your-own-key give buyers explicit isolation and key-management controls. Whether that is stronger than a multi-tenant deployment depends on the implementation and contract.
The exact boundary of the no-training statement is also a contract question, not a website question.
How does Prophet AI compare to other AI SOC platforms?
I compare investigation-first platforms with workflow platforms that add agents. This is an editorial grouping, not a vendor-defined market taxonomy.
| Dimension | Prophet AI | 7AI | Dropzone AI | Torq |
|---|---|---|---|---|
| Core model | Agentic AI SOC platform | End-to-end agentic SOC | Agentic investigation | Hyperautomation + agents |
| Named AI components | 3 (Analyst, Hunter, Detection Engineer) | Platform capabilities: Detect, Investigate, Respond, Hunt | 2 available; Threat Intel Analyst due Summer 2026 | HyperAgents on a workflow engine |
| Detection engineering | Yes, with ATT&CK mapping | ATT&CK coverage mapping and rule-tuning recommendations | Not a named module | Via workflow automation |
| Human service tier | Yes, Watchtower | Yes, PLAID ELITE | No first-party managed service | No first-party managed service |
| Public pricing | No list price | No list price | Pricing page and unit published, no list price | No list price |
Prophet packages detection engineering and human coverage as named offerings, but those capability categories are not unique to Prophet.
7AI publishes both detection optimization and the 24x7 PLAID ELITE service. Torq publishes agentic response and remediation .
If you already run a mature SOAR, the comparison is not Prophet against the category. It is Prophet against your existing platform’s own agentic roadmap.
What does Prophet AI cost?
Prophet Security does not publish pricing. Engagement starts with a demo request or a proof of value, and packaging goes through their sales team.
Watchtower is described as a natural attach to the platform. Prophet publishes neither its packaging nor its price.
What are Prophet AI’s strengths and limitations?
I see the recorded evidence trail as the strongest part of the proposition. Each determination includes the questions, queries, and reasoning steps Prophet says it records.
Watchtower adds human review for malicious or inconclusive determinations. Its analysts can scope impact, guide response, or execute containment when a customer requests it.
The limitations are about verification. Prophet’s public materials do not explain how the company calculates or reconciles its two uses of the 98.5% figure.
Unpublished pricing is the second gap. Comparing budget across this category means a sales conversation with each vendor, which is slow when you are shortlisting four of them.
The last thing I would settle before a demo is scope. Prophet’s published use cases cover endpoint, identity, cloud, email, DLP, and network operations, not the security of AI models or applications.
What are alternatives to Prophet AI?
For comparison, I separate investigation-first platforms from workflow platforms that add agents. The boundary is not absolute, and several products now span investigation, detection, and response:
- 7AI — Agentic SOC platform from the Cybereason founders , covering detection, investigation, response, and hunting across endpoint, identity, cloud, email, and network sources.
- Dropzone AI — Agentic SOC platform with an AI SOC Analyst and Threat Hunter. Its AI Threat Intel Analyst is listed as launching in Summer 2026, with early access on request.
- Torq — AI SOC platform built on a hyperautomation workflow engine, with HyperAgents acting across triage, investigation, and response.
- Tines — Workflow platform spanning AI agents, apps, and automation, with alert intake, triage, and remediation as a security use case.
For the wider landscape, see the AI security tools guide. For AI-focused threat detection in models and code rather than SOC operations, consider Protect AI Guardian or CalypsoAI .
