SCALR AI
by Security Risk Advisors
A licence-free multi-agent SOC workbench that runs in your own Azure tenant
SCALR AI is a multi-agent security operations workbench from Security Risk Advisors that automates incident triage, enrichment, threat hunting, vulnerability management and phishing analysis. It carries no licence fee — customers deploy it into their own Azure tenant and pay only Microsoft's standard compute rates, which makes it aimed squarely at SOC leaders priced out of the 70-plus commercial SOC AI platforms now on the market.
SCALR AI, announced on 24 August 2026 by Philadelphia-based Security Risk Advisors, is a multi-agentic workflow engine for security operations, distributed through the Azure Marketplace with a $0 licence fee and no usage limits. Rather than a chatbot bolted onto a SIEM, it is positioned as an agentive workbench where agents run as digital workers triggered by incidents, events or schedules; CTO Mike Pinch frames the distinction as agents that respond to events "not prompts," producing results that persist beyond an individual operator. It ships with functioning incident triage, enrichment, escalation and closure workflows plus an AI-driven quality review pass, and teams compose additional multi-agent workflows from agents, tools and Model Context Protocol servers instead of hand-building each automation. The platform is model-agnostic and selects a model per task rather than routing everything through one expensive frontier model, and it exposes cost visibility per workflow, per agent and per model. Critically, it deploys into the customer's own private Azure tenant, so security telemetry and workflows never enter shared SaaS infrastructure — the same custody argument SRA made with VECTR, its free purple-team benchmarking platform now nine years old. CEO Tim Wainwright pitched the licence-free model explicitly against procurement fatigue, arguing there have never been 70 credible choices for anything in cyber and that marketing budgets should not decide the winner. SRA, founded in 2010 with roughly 287 staff and operations across the USA, Ireland and Australia, also sells SCALR XDR, a security data lake and 24x7 monitoring service, and SCALR Sight for vulnerability and cloud policy monitoring.
A CISO or SOC manager already standardised on Microsoft Azure and Sentinel who wants to test agentic triage without a six-figure platform licence or a procurement cycle across 70-plus competing SOC AI vendors.
Working multi-agent incident triage and enrichment running inside your own Azure tenant for the cost of the compute alone — no licence fee, no usage cap, no data leaving your custody.
At a Glance
- Category
- Governance & Security
- Pricing
- Free, Usage-based
- Target Market
- CISOs, SOC Managers, Detection Engineers, Security Architects, CIOs
- Deployment
- Cloud-only, Self-hosted
- Founded
- 2010
- Headquarters
- Philadelphia, United States
- Team Size
- 201-500
Key Features
- ✓Multi-agent workflow engine
Teams compose agents, tools and MCP servers into workflows rather than hand-building each security automation from scratch.
- ✓Built-in incident triage and enrichment
Ships functioning triage, enrichment, escalation and closure workflows out of the box, so the platform is useful before any customisation.
- ✓AI-driven quality review
A built-in review pass checks agent output, addressing the consistency problem that undermines trust in automated triage decisions.
- ✓Per-task model selection
Selects an appropriate model for each task instead of routing every query through one high-cost frontier model, which is what keeps the compute bill down.
- ✓Private Azure tenant deployment
Runs entirely inside the customer's own Azure subscription so security data and workflows never enter shared SaaS infrastructure.
- ✓Per-workflow cost visibility
Reports spend per workflow, per agent and per model, so a SOC can see which automations are economic before scaling them.
Capabilities
Use Cases
- •Tier 0 alert triage
Agents perform first-pass triage, enrichment and intelligent routing so human analysts receive contextualised incidents rather than raw alert queues.
- •Phishing report analysis
Reported messages are automatically analysed, enriched with threat intelligence and dispositioned, removing one of the highest-volume manual SOC tasks.
- •Threat hunting campaigns
Scheduled multi-agent workflows execute hunt hypotheses across telemetry on a recurring basis instead of depending on analyst availability.
- •Vulnerability management triage
Agents correlate scanner findings with asset and exposure context to prioritise remediation, cutting the queue a vulnerability team works manually.
- •Evaluating agentic SOC tooling
Because there is no licence cost, teams can run the platform on real production alerts before committing budget to a commercial competitor.
Ideal For
Best For
- ✓Azure- and Sentinel-centric SOCs that want Tier 0 alert triage and enrichment without adding a platform licence
- ✓Security teams that must keep detection telemetry inside their own tenant for regulatory or contractual custody reasons
- ✓Building repeatable multi-agent workflows for phishing analysis, threat hunting and vulnerability triage
- ✓Teams evaluating agentic SOC tooling on a real workload before committing budget to a commercial platform
- ✓SRA's existing 24x7 XDR and SCALR XDR customers extending their existing detection stack
Not Ideal For
- ✗AWS- or GCP-centric security teams — SCALR AI deploys into an Azure tenant and there is no documented path on other clouds
- ✗Organisations with no cloud platform engineering capacity: 'free' covers the licence only, and you own the deployment, operation and the entire Azure compute bill
- ✗Buyers who need a production track record or third-party benchmarks before deploying — the platform launched in August 2026 with no independent evaluation of its triage quality yet published
Deployment
Market Analysis
Pros
- ✓Removes the cost barrier entirely — a SOC can evaluate agentic triage on production alerts with no licence spend or procurement cycle
- ✓Data custody is architecturally enforced by running in the customer's own Azure tenant rather than promised in a contract
- ✓Backed by an established firm: SRA has been operating since 2010 with ~287 staff and has maintained the free VECTR platform for nine years
- ✓Per-workflow and per-model cost reporting makes the economics of each automation visible before it is scaled
Cons
- ✗Azure-only — there is no documented AWS or GCP deployment path, which excludes a large share of enterprise SOCs outright
- ✗Free means the licence, not the bill: customers carry all Azure compute cost plus the deployment and ongoing operations burden themselves
- ✗No independent evaluation exists — a Hacker News Algolia search returns zero results for SCALR, VECTR or Security Risk Advisors, and coverage to date is the press release syndicated across trade outlets
- ✗Launched 24 August 2026, so there is no published production track record, no triage-accuracy benchmark and no public roadmap commitment
- ✗The free platform sits inside a commercial portfolio (SCALR XDR, SCALR Sight, 24x7 XDR services) and functions as a funnel into paid SRA engagements
Pricing
SCALR AI (licence-free)
$0
- ✓No licence fee and no usage limits
- ✓Deployed in the customer's own Azure tenant
- ✓Prebuilt incident triage, enrichment and quality-review workflows
- ✓Multi-agent, multi-LLM workflow builder
- ✓Customer pays Azure compute directly to Microsoft
The software licence genuinely costs nothing and carries no stated usage limits, but that is not the same as free to run: customers pay Microsoft directly for the Azure compute their workflows consume, at standard rates, and absorb the deployment and operations effort themselves. SRA argues the total lands below rival platforms' combined licence plus consumption fees because SCALR AI picks a cheaper model per task; that comparison is the vendor's own and no independent cost benchmark has been published.
Security & Compliance
Sources
This page was written from 7 sources, 4 on domains other than sra.io.
- 1.sra.io — press release security risk advisors launches scalr ai as a vendor
- 2.sra.io — scalr aivendor
- 3.securityboulevard.com — security risk advisors launches scalr ai as a free soc ai pl
- 4.lastwatchdog.com — news alert sra makes soc ai license free customers pay only
- 5.cioinfluence.com — security risk advisors launches scalr ai as a free soc ai pl
- 6.mychesco.com — philadelphia cybersecurity firm offers ai platform free
- 7.sra.io — sra.iovendor
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
Kosmoy
A self-hosted AI control plane: inventory, gateway, observability and agent sandboxing
RadarFirst
Compliance agents that prepare the work — people still make every regulatory decision
Lema
Agentic third-party risk management — treat vendor risk as a security problem, not a checklist
AIR Security
A context firewall that vets every skill, plugin and MCP server an AI agent touches