Torq SOC Brain
by Torq
A self-learning layer that trains your SOC's own AI on your analysts' past verdicts
Torq SOC Brain is a learning layer inside the Torq AI SOC Platform that trains dedicated models on a security team's own closed investigations, analyst verdicts and corrections, so triage decisions reflect how that specific SOC judges risk. It targets security operations leaders drowning in alerts who want autonomous triage that improves with use rather than a static playbook.
Torq SOC Brain, announced July 28, 2026, is a new layer of the Torq AI SOC Platform that makes autonomous investigation learn from an organisation's own history instead of a generic model. It has three named parts. Torq Recall retrieves relevant historical cases using deterministic matching on security observables — IPs, file hashes, URLs, hostnames — ranks them by relevance, reads the analyst notes attached to them, identifies conflicting precedent and adjusts its confidence accordingly, with no manual tagging required. Torq Reflex continuously trains dedicated models on confirmed verdicts and analyst corrections, learning how a particular SOC weighs risk; Torq reports it matches analyst-corrected verdicts 85% of the time immediately, auto-closing the confident cases and escalating the rest. Torq Retrospect imports resolved incidents from tools the team already runs, so the system starts with years of institutional knowledge rather than earning it over months. CEO Ofer Smadari frames the distinction bluntly: most vendors claiming self-learning ship retrieval-augmented memory that hands old cases to an LLM at decision time, whereas SOC Brain trains on the customer's operational data to reach new conclusions from it. Each customer gets a private SOC Brain; Torq states it never pools customer data, shares model parameters or trains one customer's models on another's incidents, and describes that isolation as architectural rather than a setting. It sits on the wider Torq platform — Auto Triage, Case Management, HyperAgents, the Socrates agentic assistant and roughly 300 prebuilt integrations with 4,000+ steps. Torq, founded 2020, raised a $140M Series D in January 2026 at a $1.2B valuation, bringing total funding to $332M.
A SOC or security operations director running a high-volume alert queue on a modern EDR/SIEM/identity stack who already has years of closed cases sitting unused in a ticketing system.
Autonomous triage that mirrors your own analysts' judgement on day one, because it was trained on their past verdicts rather than on a generic threat model.
At a Glance
- Category
- Governance & Security
- Pricing
- Contact for pricing, Subscription
- Target Market
- CISOs, SOC Managers, Security Engineers, CIOs, MSSPs
- Deployment
- Cloud-only
- Founded
- 2020
- Team Size
- 201-500
Key Features
- ✓Torq Recall
Deterministic matching on observables such as IPs, hashes, URLs and hostnames surfaces relevant past cases, ranks them and weighs conflicting precedent without manual tagging.
- ✓Torq Reflex
Trains dedicated per-customer models on confirmed verdicts and analyst corrections, reported to match analyst-corrected verdicts 85% of the time immediately.
- ✓Torq Retrospect
Imports resolved incidents from existing security tools before go-live so the system reasons from years of organisational history on day one.
- ✓Per-customer model isolation
Each tenant gets a private SOC Brain; Torq states it never pools data, shares parameters or trains one customer's model on another's incidents.
- ✓Agentic SOC platform underneath
Auto Triage, Case Management, HyperAgents and the Socrates assistant cover triage, investigation, response, threat hunting and reporting end to end.
- ✓Broad integration surface
Around 300 prebuilt integrations and 4,000+ steps across EDR, SIEM, identity, cloud, email and SaaS security tools reduce custom connector work.
- ✓Enterprise compliance posture
SOC 2 Type II, HIPAA with BAAs available, GDPR with a DPA, BSI C5:2020, plus SSO via Okta, Entra ID, Ping, OneLogin, Google and Duo.
Capabilities
Use Cases
- •Recurring false-positive suppression
Alerts matching observables from previously dismissed cases are auto-closed with reference to the earlier analyst decision, removing repetitive tier-1 work.
- •Cold-start triage for a new deployment
Retrospect ingests historical resolved incidents so autonomous triage is useful from week one rather than after months of accumulated verdicts.
- •Encoding analyst judgement before attrition
Reflex captures how senior analysts weigh risk, preserving institutional knowledge that would otherwise leave with departing staff.
- •Phishing and identity alert investigation
Native connectors to Okta, Entra ID, Proofpoint and major EDR tools let agents gather evidence and reach a verdict without analyst pivoting.
- •Reducing analyst hours on high-volume queues
Torq cites a Valvoline deployment saving roughly seven analyst hours daily through automated handling of routine security cases.
Ideal For
Best For
- ✓Tier-1 alert triage where the same false positives recur and analysts keep re-deciding cases the team already resolved
- ✓SOCs with a large archive of resolved incidents in an existing SIEM or case tool that can be imported as training history
- ✓Teams that need automation decisions to reflect organisation-specific risk tolerance rather than vendor defaults
- ✓Enterprises consolidating SOAR playbooks onto an agentic platform with broad prebuilt integration coverage
- ✓Regulated environments needing per-customer model isolation with no cross-tenant training
Not Ideal For
- ✗Small teams with little investigation history — Recall and Reflex both depend on prior verdicts, so a new SOC gets the least benefit exactly when it needs help most
- ✗Organisations whose historical case data is inconsistently labelled or poorly documented, since the models learn whatever bias and error that archive contains
- ✗Buyers wanting self-hosted or air-gapped deployment; Torq runs as SaaS on GCP and AWS with no on-premise option
- ✗Teams needing transparent list pricing, as Torq publishes no public rate card and the platform is quoted by sales
Deployment
Market Analysis
Pros
- ✓Workflow builder is consistently praised by reviewers for a drag-and-drop interface and conveniences that speed automation development
- ✓Integrations to existing security tools are reported as straightforward and low-configuration, which is where SOAR projects usually stall
- ✓Named enterprise references at real scale, including Blackstone, Procter & Gamble, Siemens, Telefónica, Uber, Chipotle, Lego and Wiz
- ✓Per-customer model isolation is stated as an architectural property rather than a configuration toggle, which is a stronger guarantee than a policy promise
Cons
- ✗PeerSpot reviewers report that asking the AI to build or template a workflow from scratch 'does not go well' — the assistant helps inside an existing workflow more than it authors one
- ✗Very large workflows processing heavy data volumes can crash the browser, and reviewers flag scalability friction at that end
- ✗Reporting is constrained: reviewers say the platform does not expose complete datasets for their own reporting needs, and in-platform search needs improvement
- ✗As SaaS, reviewers cite transparency issues about what is happening behind the scenes when something errors — a real problem when the tool is auto-closing security cases
- ✗The 85% verdict-match figure is vendor-reported with no third-party benchmark, and SOC Brain launched July 2026, so independent production evidence for this specific layer is thin
Pricing
Torq AI SOC Platform (Enterprise)
Contact for pricing
- ✓SOC Brain learning layer
- ✓Auto Triage and Case Management
- ✓HyperAgents and Socrates
- ✓~300 prebuilt integrations
- ✓SSO, RBAC, SOC 2 Type II, HIPAA, GDPR, BSI C5
Torq publishes no list pricing — there is no public rate card page, and every deal is quoted by sales. SOC Brain is a layer of the AI SOC Platform rather than a separately priced SKU, so it arrives as part of a platform subscription rather than as an add-on line item. Third-party writeups describe subscription tiers scaled by workflows, integrations and automation actions, which means execution volume is the variable to model: a high-alert-volume SOC should get per-execution assumptions in writing before signing, since that is where cost scales rather than seats.
Security & Compliance
Sources
This page was written from 7 sources, 4 on domains other than torq.io.
- 1.torq.io — soc brainvendor
- 2.torq.io — ai soc platformvendor
- 3.torq.io — security compliancevendor
- 4.siliconangle.com — torq unveils soc brain self learning layer ai soc platform
- 5.helpnetsecurity.com — torq soc brain
- 6.peerspot.com — torq reviews
- 7.siliconangle.com — torq raises 140m 1 2b valuation scale ai driven security hyp
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
Norm Ai
Regulatory AI agents that turn written rules into executable compliance checks
Okta for AI Agents
Identity, least-privilege access and a kill switch for every AI agent in the enterprise
ServiceNow AI Control Tower
Enterprise command center to discover, govern, secure and measure every AI agent and model
Cyabra Coordinated Activity Detection
An AI agent that investigates coordinated online manipulation and returns an evidence-backed verdict in under 30 seconds