Prophet AI logo
Privacy Security · Security Fraud

Prophet AI

Prophet AI is an agentic AI SOC platform that triages, investigates and responds to every security alert across an existing stack, giving enterprise SecOps teams senior-analyst depth, full reasoning traceability and optional round-the-clock human backup.

Active GDPR compliant Free trial Contact Sales No public API 13+ Verified by Guidaio
Overview

What is Prophet AI?

Prophet AI is the agentic AI SOC platform built by Prophet Security, Inc., a Delaware company whose principal place of business is in Atherton, California. It targets a familiar operational problem: too many alerts, tooling spread across too many consoles, and hours burned on repetitive manual investigation, what the company calls operational drag.

The platform is a constellation of agents rather than a single assistant. The AI SOC Analyst summarises each alert, extracts its artefacts, plans the questions a senior analyst would ask and runs them across the stack, documenting every query and every reasoning step along the way. Investigations run in parallel, so investigation time stays constant whether the day brings 50 alerts or 2,000. The AI Threat Hunter adds a conversational layer: hypotheses are stated in plain language, such as Are we impacted? or Where else is this happening?, drawn from a library of pre-codified hunt templates and scheduled to repeat. The AI Detection Engineer builds a MITRE ATT&CK coverage map from real investigations, drafts and backtests new detections, and tunes existing rules on Splunk, Sumo Logic and Microsoft Sentinel. AI Watchtower is the optional human tier, a 24x7x365 service in which any malicious or inconclusive determination is picked up by a senior analyst within 30 minutes.

Autonomy is graduated. Prophet investigates on its own from day one but only acts inside the perimeter the customer has approved. It learns from plain-language instructions, meaning playbooks, policies and preferences, shows the source behind every element so it can be corrected, and previews and backtests changes before applying them. The vendor claims more than 200 ready-made integrations and lets teams work in the product, in Slack, in Microsoft Teams or through a webhook, with scope controlled channel by channel.

The headline figures published by the vendor are 10 million investigations run, more than 2.5 million hours of manual work avoided, a 98.5% accuracy rate and zero minutes of alert wait time. The positioning is firmly enterprise, with dedicated single-tenant deployment, a bring-your-own-key option and no training of AI models on personal data, and documented use cases spanning endpoint, email, identity, cloud, DLP and network.

What it does

  • Investigate 100% of incoming alerts, at every severity, from the moment they arrive
  • Plan investigation questions dynamically and run them across SIEM, EDR, identity, cloud and email tools
  • Group related investigations into a single incident
  • Execute scoped remediation actions, such as notifying a user or quarantining a host, previewed and backtested before they run
  • Launch threat hunts written in natural language and schedule them to repeat
  • Map detection coverage to MITRE ATT&CK, draft new detections and tune noisy SIEM rules
  • Escalate to Watchtower human analysts, on duty 24x7x365, in under 30 minutes
Audience

When to use Prophet AI / When not to

A quick filter to help you decide if Prophet AI is the right fit.

When to use Prophet AI

  • Enterprise SOC teams drowning in alert volume: one customer CISO reports the queue dropping from thousands of alerts to dozens.
  • Security operations teams that want every alert investigated at every severity, not only the criticals their analysts have time for.
  • Organisations with an established SIEM, EDR, identity and cloud stack, since Prophet connects to what is already in place instead of replacing it and claims value from day one.
  • Teams reconsidering a traditional MDR contract, thanks to per-investigation pricing with no data-ingest fees and an optional 24x7x365 human service for round-the-clock coverage.
  • Detection engineering teams that must evidence their coverage, using a MITRE ATT&CK map generated from their own investigations.

When not to use Prophet AI

  • Individuals or small teams looking for a self-service sign-up: there is no public price list, no permanent free plan and no mobile app, and access runs through a demo or a commercial proof of value.
  • Buyers who need published pricing to build a budget before speaking to a sales representative.
  • Developers expecting a documented public API to build their own automation: none is published on the site or listed in its sitemap.
  • Teams without a connectable security stack, since Prophet has nothing to investigate without SIEM, EDR, identity, cloud or email data sources.
  • Anyone under 13, excluded by the Master Services Agreement, and users in countries under United States embargo or named on US sanctions lists.
Get started

How to use Prophet AI

A typical end-to-end flow, from setup to results.

  1. Request a demo or ask for a free proof of value: there is no self-service sign-up.
  2. Create your Prophet account once the commercial conversation is under way.
  3. Connect your data sources, from SIEM and EDR to identity, cloud and email, using the out-of-the-box integrations; setup is announced at 30 minutes or less.
  4. Choose your level of autonomy, from human review of every step to direct shipping of versioned, backtested and reversible changes.
  5. Let the AI SOC Analyst investigate incoming alerts, and read the documented question, query and reasoning trail behind each verdict.
  6. Teach Prophet your context in plain language through playbooks, policies and preferences, applied organisation-wide, to a single investigation or to one step.
  7. Turn on the AI Detection Engineer from the workspace: it works on the investigation data you already hold and returns a MITRE ATT&CK coverage map plus a ranked list of the highest-impact actions.
  8. Run threat hunts in natural language and schedule the ones worth repeating.
  9. Route notifications and escalations to Slack, Microsoft Teams, email or a webhook, tuning scope and frequency per channel.
  10. Push investigations into the case management tools you already use, such as Jira, ServiceNow, TheHive, Linear, Datadog Case Management or GitHub, and reach support through your dedicated Slack channel or at support@prophetsecurity.ai.
Quick read

Pros & Cons

Pros

  • Full coverage: every alert is investigated at every severity, and investigation time stays constant whether the day brings 50 alerts or 2,000.
  • Auditability: every question, query and reasoning step is kept and can be reviewed, which few agentic tools expose.
  • Graduated autonomy: Prophet investigates on its own from day one but acts only inside the perimeter the customer has approved.
  • A contractual rather than merely marketing commitment on training, since the Master Services Agreement states that Customer Data is not used to train Third Party Generative AI Services.
  • Enterprise isolation: dedicated single-tenant deployment with a bring-your-own-key option.
  • Verifiable openness on suppliers and connectors: a named public sub-processor list covering AWS, Microsoft Azure, Google Cloud Platform, Slack, Google Workspace, SerpApi and IPInfo, plus 73 integrations named publicly out of the 200+ claimed.
  • An optional 24x7x365 human tier with escalation in under 30 minutes, without staffing a night shift, backed by a reinforced liability cap of the greater of USD 500,000 or three times the fees paid and USD 5 million of Tech E&O and cyber insurance.

Cons

  • No public pricing at all: no pricing page, no rate card and no entry-level amount, only a statement that autonomous investigation is billed per investigation.
  • No self-service sign-up: a sales demo or a commercial proof of value is the only way in.
  • No documented public API, so automation is limited to the integrations Prophet ships.
  • Data is hosted in the United States only, with no European data residency option mentioned anywhere.
  • No Article 27 EU representative is designated, although the DPA explicitly addresses European customers.
  • No security certification such as SOC 2 or ISO 27001 is displayed on the public site, which is unexpected from a security vendor.
  • Signs of a site still under construction: the published FAQ page contains placeholder content, and Annex II of the DPA, covering technical and organisational measures, is blank on the web page.
Pricing

Pricing & Plans

Prophet Security publishes no price list: there is no pricing page on the site or in its sitemap, and no entry-level amount or currency is disclosed. Licences are purchased through a negotiated Order Form governed by the Master Services Agreement, with billable units expressed as Investigations or other quantity. The vendor's MDR comparison page states that autonomous investigation is priced per investigation, with no data-ingest fees. No permanent free plan is advertised. A free proof of value is offered, with setup announced at 30 minutes or less, and the Master Services Agreement provides for a contractual Trial Period, subject to any fees stated on the Order Form and terminable in writing before it ends. Fees are payable within 30 days of the Order Form date and are non-cancellable and non-refundable, with late-payment interest capped at 1.5% per month or the maximum rate permitted by law. Purchases may also be made through authorised partners and cloud marketplaces, in which case commercial terms are negotiated with the partner.

No named or priced plan is published
  • every purchase is defined by a negotiated Order Form.
Plan 3
  • AI Threat Hunter
  • sold as a separate module
  • price on request.
Plan 4
  • AI Detection Engineer
  • sold as a separate module
  • price on request.
Plan 5
  • AI Watchtower
  • presented as an optional 24x7x365 human-in-the-loop service
  • price on request.
Plan 6
  • Billing is expressed contractually in Units
  • for example Investigations or other quantity
  • with the volume fixed on the Order Form.
Plan 7
  • Beta Features are provided at no additional cost
  • without support and without any commitment to general availability.
Special offers — A free proof of value is offered on several product pages, with setup announced at 30 minutes or less. · An open partner programme covering resellers and VARs, consulting and services firms, technology alliances and cloud marketplace partners, with deal registration available. · An MDR savings calculator for teams comparing Prophet with a traditional managed detection and response contract. · A downloadable media kit for press use. · No discount, promotional code or dated offer is published, and no student, non-profit or jobseeker pricing is mentioned.
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Prophet AI handles your data.

GDPR overview

GDPR is addressed contractually rather than by a compliance badge. The published Data Processing Addendum, updated 6 May 2026 for its Annex III, states that Prophet will process personal data in accordance with the GDPR, defined as Regulation (EU) 2016/679, with separate GDPR, UK GDPR and CCPA schedules. Transfers outside the EU rely on the Standard Contractual Clauses of implementing decision (EU) 2021/914; the Privacy Policy of 15 May 2026 confirms that EU, UK and Swiss data reaches the United States under contractual, technical and organisational measures. No Article 27 EU representative is designated by Prophet and no DPO is named: the single privacy contact is legal@prophetsecurity.ai. Prophet states it mostly processes personal data on behalf of its customers and redirects data-subject requests to them. Global Privacy Control is honoured, Do Not Track is not, and CCPA and Nevada opt-out rights are covered.

Who owns the data?

Ownership is split by the Master Services Agreement of 21 April 2026. The customer keeps all right, title and interest in its Customer Data and in the AI Output generated from it (section 9b). Prophet Security retains the Prophet Assets, the Prompt, Usage Data and Security Threat Data (section 9a); Security Threat Data is de-identified, non-personal information extracted from incidents, and Usage Data is aggregated, anonymised interaction data expressly carved out of Customer Data. The customer grants Prophet only a limited licence, for the subscription period, to run the service and produce the AI Output. Under the DPA, Prophet acts as processor or sub-processor and the customer as controller or processor.

Reuse rights

The customer may reuse its own Customer Data and the AI Output without asking Prophet Security for permission, since it owns both. Prophet's own use is bounded by the Master Services Agreement of 21 April 2026: Customer Data is used to deliver the service and, combined with the Prompt, to query a Third Party Generative AI Service so that the AI Output can be produced (section 5a). The same clause states plainly that Customer Data is not used to train Third Party Generative AI Services. The generative services named in the agreement are Anthropic Claude, OpenAI GPT and Google Gemini; the Privacy Policy of 15 May 2026 additionally names Microsoft Azure OpenAI Service and Google Gemini as possible recipients of Customer Data. Usage Data, aggregated and anonymised, is used by Prophet to improve and develop the service (section 5b). On its product pages the vendor states that Prophet AI deploys as a dedicated single tenant, with a bring-your-own-key option and no training of AI models with personal data. Data collected through the website itself, namely name, email, phone number, employment details, device and IP data and web analytics, is processed for service delivery and improvement, marketing and correspondence, on the basis of contractual necessity, legitimate interest or consent.

Data retention & training

Retention summary
Retention is tied to the contract rather than to fixed durations. Annex I of the DPA states that personal data is kept for the term of the Agreement. On termination or expiry, and on written request, Prophet deletes all Customer Data processed on the customer's behalf within 30 days. Before deletion, the DPA requires Customer Data to be made available for export or download, and a certification of deletion can be requested, in line with clauses 8.5 and 16(d) of the Standard Contractual Clauses. For website data, the Privacy Policy keeps information as long as needed to deliver the service or fulfil the purpose, profile information for instance for as long as the account exists, with longer retention possible for legal obligations, disputes or debt recovery, and possible retention in anonymised or aggregated form. No figure other than the 30-day deletion window is published.
Trains on customer data
No
Subprocessors disclosed
Yes
DPA available
Yes

Hosting summary

Prophet Security is a United States company and states in its Privacy Policy of 15 May 2026 that information may be stored on servers in the United States, and may also be stored or processed in other countries by its service providers where the law allows. Hosting is delegated to Amazon Web Services, named in the public sub-processor list of 6 May 2026 as the provider that securely hosts the infrastructure and ensures reliable data storage, processing and availability. Microsoft Azure and Google Cloud Platform appear on the same list for access to hosted AI models, alongside Slack, Google Workspace, SerpApi and IPInfo. The product itself is delivered as a dedicated single-tenant deployment with a bring-your-own-key option. No European hosting region is mentioned anywhere: EU, UK and Swiss transfers are covered by the Standard Contractual Clauses rather than by local residency. The marketing site is a separate matter, built on Webflow and served behind Cloudflare, whose anycast address resolves to 198.202.211.1, which says nothing about where the application servers actually sit.

Hosting countries
🇺🇸 United States
Availability

Where Prophet AI works

Country-level availability.

Not available in

Countries subject to United States embargoes: the Master Services Agreement forbids accessing or using the service from any such territory.Individuals and entities named on United States restricted Party lists, including the Specially Designated Nationals list, the Entity List and the Denied Persons List, are barred from using the service.
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Prophet AI.

  • AI output is delivered as is: the Master Services Agreement disclaims any warranty of accuracy, completeness or reliability, so a wrong or missed verdict remains the customer's risk.
  • Automation bias: analysts who stop reading the reasoning trail can lose the investigative reflexes the platform is meant to amplify, and junior staff may never build them at all.
  • No security certification such as SOC 2 or ISO 27001 is displayed on the public site, which should be raised during due diligence with a vendor that sells security.
  • Data is hosted and processed in the United States; EU, UK and Swiss transfers rely on the Standard Contractual Clauses, with no European data residency and no Article 27 representative.
  • Annex II of the DPA, covering technical and organisational measures, is empty on the web page: the content exists only in the downloadable document and has to be requested.
  • Liability is capped, at the fees paid over the previous 12 months in general, and even Excluded Claims are limited to the greater of USD 500,000 or three times the fees.
  • Customer data may feed external search-engine queries through the SerpApi sub-processor, and the contract is governed by California law with exclusive jurisdiction in San Francisco County.
Setup

Setup & Integrations

Technical difficulty

Moderate, and deliberately light on paper. Prophet advertises setup in 30 minutes or less across three steps: create an account, connect your data sources, then choose your autonomy level. The no rip and replace positioning relies on out-of-the-box integrations with the existing stack, and the AI Detection Engineer runs on investigation data you already hold. The real prerequisites are organisational: a connectable SIEM, EDR, identity, cloud and email estate, plus the matching access rights. Remediation actions must be scoped explicitly, since nothing runs outside the approved perimeter. One customer describes the product as intuitive and fast to deploy.

Deployment

Web app

Integrations

Cisco Umbrella QRadar Infoblox Netskope Ping Identity Starburst Vega Obsidian TheHive Upwind Shodan Censys AWS Microsoft Azure Google Cloud Platform Wiz AWS GuardDuty CrowdStrike CNAPP Zscaler Microsoft Defender PAN Cortex XDR SentinelOne CrowdStrike Falcon Okta Microsoft Entra ID CrowdStrike Falcon Identity Protection Microsoft Defender for Identity Microsoft Sentinel Elastic Anvilogic Sumo Logic Splunk Hunters Panther Datadog Crowdstrike Falcon Next Gen SIEM Rapid7 IDR Scanner RunReveal Google Security Operations (Chronicle) Abnormal Security Mimecast Sublime Security Proofpoint Gmail Exchange Online Snowflake Databricks Slack Microsoft Teams PagerDuty Datadog Case Management Jira Linear Github ServiceNow Office 365 Google Workspace Microsoft Defender for Office 365 BambooHR ExtraHop VirusTotal IPinfo Spur Recorded Future URLScan Have I Been Pwned VMRay DNSlytics Reversing Labs AbuseIPDB Greynoise
Company

Behind Prophet AI

Company name
Prophet Security, Inc.
Founded
17/07/2024
Country of origin
🇺🇸 United States
Headquarters
349 Selby Lane, Atherton, CA 94027
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇺🇸 United States
Legal contact
Support contact

Fundraising

Seed round: USD 11 million announced on 23 April 2024, led by Bain Capital Ventures alongside security executives and angel investors (reported by third-party press, not by the vendor's own site).
Series A: USD 30 million announced on 29 July 2025, led by Accel with participation from Bain Capital Ventures and other strategic investors, confirmed by Prophet Security's own announcement.
Total disclosed funding to date: USD 41 million.
The company was co-founded by Kamal Shah (CEO) and Vibhav Sreekanti (CTO); Eric Wolford, Partner at Accel, is quoted in the Series A announcement.

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

What is Prophet AI?
Prophet AI is an agentic AI SOC analyst platform that autonomously triages and investigates security alerts. It gathers evidence across your stack, reasons about context and explains each decision, so analysts resolve alerts faster and with less manual work.
Which agents make up the platform?
Four: the AI SOC Analyst for alert triage and investigation, the AI Threat Hunter for natural-language and scheduled hunts, the AI Detection Engineer for coverage mapping and rule tuning, and AI Watchtower, an optional 24x7x365 human-in-the-loop service.
How much does Prophet AI cost?
No price is published. Licences are bought through a negotiated Order Form after a demo, and the vendor's MDR comparison page states that autonomous investigation is priced per investigation, with no data-ingest fees.
Is there a free trial?
There is a free proof of value rather than a self-service trial: you contact the vendor first, and setup is announced at 30 minutes or less. The Master Services Agreement also provides for a contractual Trial Period defined on the Order Form.
Is my data used to train AI models?
No. Section 5a of the Master Services Agreement states that Customer Data is not used to train Third Party Generative AI Services, and the product pages add that no AI models are trained with personal data.
Which third-party AI models does Prophet use?
The Master Services Agreement names Anthropic Claude, OpenAI GPT and Google Gemini as Third Party Generative AI Services. The Privacy Policy additionally cites Microsoft Azure OpenAI Service and Google Gemini as possible recipients of Customer Data.
Where is the data hosted, and is a DPA available?
Data is hosted in the United States, with Amazon Web Services named as the hosting sub-processor. A Data Processing Addendum is published, together with a named sub-processor list covering AWS, Microsoft Azure, Google Cloud Platform, Slack, Google Workspace, SerpApi and IPInfo.
How many integrations are available?
Prophet claims more than 200 out-of-the-box integrations. The public integrations page names 73 products across SIEM, EDR, identity, cloud, email, network, threat intelligence, data lakes, collaboration and case management.
Is there a public API?
No API documentation is published on the site or listed in its sitemap, so automation relies on the supplied integrations.
Is there a minimum age?
Yes, 13. Both the Privacy Policy and the Master Services Agreement state that the service is not intended for anyone under 13 years of age.
Conclusion

Should you pick Prophet AI?

Prophet AI is not a triage assistant bolted onto a SIEM, but a set of agents covering the SecOps cycle end to end: investigation, hunting, detection engineering and an optional human layer on top. What the vendor puts forward as its edge is investigation depth at senior-analyst level combined with complete traceability of the reasoning, which matters more than raw automation when an auditor or an incident review asks how a verdict was reached.

The contractual side is unusually solid for a young vendor. The Master Services Agreement states in plain terms that Customer Data is not used to train third-party generative AI services, deployment is dedicated single-tenant with a bring-your-own-key option, the sub-processor list is public and named, and liability cover on security and data protection claims rises to the greater of USD 500,000 or three times the fees paid, backed by USD 5 million of Tech E&O and cyber insurance.

The reservations are real. Pricing is entirely opaque: no page, no rate card, no entry point, only per-investigation billing mentioned in passing. And a security vendor that displays no SOC 2 or ISO 27001 certification on its public site invites the question. Secondary reservations: hosting is United States only, with no European residency option, and no Article 27 EU representative is designated even though the DPA explicitly addresses European customers.

Maturity is the last variable. The company came out of stealth in April 2024 and its site was first archived in July 2024, yet it has raised USD 41 million and names customers such as Cabinetworks, ZIP, Clari, Upwind and JBPCO. Recommended for enterprise SOCs with an established stack and a genuine alert-volume problem, provided the buying team is ready to negotiate pricing and to press for the security attestations the site does not publish.