Prophet AI
Prophet AI is an agentic AI SOC platform that triages, investigates and responds to every security alert across an existing stack, giving enterprise SecOps teams senior-analyst depth, full reasoning traceability and optional round-the-clock human backup.
What is Prophet AI?
Prophet AI is the agentic AI SOC platform built by Prophet Security, Inc., a Delaware company whose principal place of business is in Atherton, California. It targets a familiar operational problem: too many alerts, tooling spread across too many consoles, and hours burned on repetitive manual investigation, what the company calls operational drag.
The platform is a constellation of agents rather than a single assistant. The AI SOC Analyst summarises each alert, extracts its artefacts, plans the questions a senior analyst would ask and runs them across the stack, documenting every query and every reasoning step along the way. Investigations run in parallel, so investigation time stays constant whether the day brings 50 alerts or 2,000. The AI Threat Hunter adds a conversational layer: hypotheses are stated in plain language, such as Are we impacted? or Where else is this happening?, drawn from a library of pre-codified hunt templates and scheduled to repeat. The AI Detection Engineer builds a MITRE ATT&CK coverage map from real investigations, drafts and backtests new detections, and tunes existing rules on Splunk, Sumo Logic and Microsoft Sentinel. AI Watchtower is the optional human tier, a 24x7x365 service in which any malicious or inconclusive determination is picked up by a senior analyst within 30 minutes.
Autonomy is graduated. Prophet investigates on its own from day one but only acts inside the perimeter the customer has approved. It learns from plain-language instructions, meaning playbooks, policies and preferences, shows the source behind every element so it can be corrected, and previews and backtests changes before applying them. The vendor claims more than 200 ready-made integrations and lets teams work in the product, in Slack, in Microsoft Teams or through a webhook, with scope controlled channel by channel.
The headline figures published by the vendor are 10 million investigations run, more than 2.5 million hours of manual work avoided, a 98.5% accuracy rate and zero minutes of alert wait time. The positioning is firmly enterprise, with dedicated single-tenant deployment, a bring-your-own-key option and no training of AI models on personal data, and documented use cases spanning endpoint, email, identity, cloud, DLP and network.
What it does
- Investigate 100% of incoming alerts, at every severity, from the moment they arrive
- Plan investigation questions dynamically and run them across SIEM, EDR, identity, cloud and email tools
- Group related investigations into a single incident
- Execute scoped remediation actions, such as notifying a user or quarantining a host, previewed and backtested before they run
- Launch threat hunts written in natural language and schedule them to repeat
- Map detection coverage to MITRE ATT&CK, draft new detections and tune noisy SIEM rules
- Escalate to Watchtower human analysts, on duty 24x7x365, in under 30 minutes
When to use Prophet AI / When not to
A quick filter to help you decide if Prophet AI is the right fit.
When to use Prophet AI
- Enterprise SOC teams drowning in alert volume: one customer CISO reports the queue dropping from thousands of alerts to dozens.
- Security operations teams that want every alert investigated at every severity, not only the criticals their analysts have time for.
- Organisations with an established SIEM, EDR, identity and cloud stack, since Prophet connects to what is already in place instead of replacing it and claims value from day one.
- Teams reconsidering a traditional MDR contract, thanks to per-investigation pricing with no data-ingest fees and an optional 24x7x365 human service for round-the-clock coverage.
- Detection engineering teams that must evidence their coverage, using a MITRE ATT&CK map generated from their own investigations.
When not to use Prophet AI
- Individuals or small teams looking for a self-service sign-up: there is no public price list, no permanent free plan and no mobile app, and access runs through a demo or a commercial proof of value.
- Buyers who need published pricing to build a budget before speaking to a sales representative.
- Developers expecting a documented public API to build their own automation: none is published on the site or listed in its sitemap.
- Teams without a connectable security stack, since Prophet has nothing to investigate without SIEM, EDR, identity, cloud or email data sources.
- Anyone under 13, excluded by the Master Services Agreement, and users in countries under United States embargo or named on US sanctions lists.
How to use Prophet AI
A typical end-to-end flow, from setup to results.
- Request a demo or ask for a free proof of value: there is no self-service sign-up.
- Create your Prophet account once the commercial conversation is under way.
- Connect your data sources, from SIEM and EDR to identity, cloud and email, using the out-of-the-box integrations; setup is announced at 30 minutes or less.
- Choose your level of autonomy, from human review of every step to direct shipping of versioned, backtested and reversible changes.
- Let the AI SOC Analyst investigate incoming alerts, and read the documented question, query and reasoning trail behind each verdict.
- Teach Prophet your context in plain language through playbooks, policies and preferences, applied organisation-wide, to a single investigation or to one step.
- Turn on the AI Detection Engineer from the workspace: it works on the investigation data you already hold and returns a MITRE ATT&CK coverage map plus a ranked list of the highest-impact actions.
- Run threat hunts in natural language and schedule the ones worth repeating.
- Route notifications and escalations to Slack, Microsoft Teams, email or a webhook, tuning scope and frequency per channel.
- Push investigations into the case management tools you already use, such as Jira, ServiceNow, TheHive, Linear, Datadog Case Management or GitHub, and reach support through your dedicated Slack channel or at support@prophetsecurity.ai.
Pros & Cons
Pros
- Full coverage: every alert is investigated at every severity, and investigation time stays constant whether the day brings 50 alerts or 2,000.
- Auditability: every question, query and reasoning step is kept and can be reviewed, which few agentic tools expose.
- Graduated autonomy: Prophet investigates on its own from day one but acts only inside the perimeter the customer has approved.
- A contractual rather than merely marketing commitment on training, since the Master Services Agreement states that Customer Data is not used to train Third Party Generative AI Services.
- Enterprise isolation: dedicated single-tenant deployment with a bring-your-own-key option.
- Verifiable openness on suppliers and connectors: a named public sub-processor list covering AWS, Microsoft Azure, Google Cloud Platform, Slack, Google Workspace, SerpApi and IPInfo, plus 73 integrations named publicly out of the 200+ claimed.
- An optional 24x7x365 human tier with escalation in under 30 minutes, without staffing a night shift, backed by a reinforced liability cap of the greater of USD 500,000 or three times the fees paid and USD 5 million of Tech E&O and cyber insurance.
Cons
- No public pricing at all: no pricing page, no rate card and no entry-level amount, only a statement that autonomous investigation is billed per investigation.
- No self-service sign-up: a sales demo or a commercial proof of value is the only way in.
- No documented public API, so automation is limited to the integrations Prophet ships.
- Data is hosted in the United States only, with no European data residency option mentioned anywhere.
- No Article 27 EU representative is designated, although the DPA explicitly addresses European customers.
- No security certification such as SOC 2 or ISO 27001 is displayed on the public site, which is unexpected from a security vendor.
- Signs of a site still under construction: the published FAQ page contains placeholder content, and Annex II of the DPA, covering technical and organisational measures, is blank on the web page.
Pricing & Plans
Prophet Security publishes no price list: there is no pricing page on the site or in its sitemap, and no entry-level amount or currency is disclosed. Licences are purchased through a negotiated Order Form governed by the Master Services Agreement, with billable units expressed as Investigations or other quantity. The vendor's MDR comparison page states that autonomous investigation is priced per investigation, with no data-ingest fees. No permanent free plan is advertised. A free proof of value is offered, with setup announced at 30 minutes or less, and the Master Services Agreement provides for a contractual Trial Period, subject to any fees stated on the Order Form and terminable in writing before it ends. Fees are payable within 30 days of the Order Form date and are non-cancellable and non-refundable, with late-payment interest capped at 1.5% per month or the maximum rate permitted by law. Purchases may also be made through authorised partners and cloud marketplaces, in which case commercial terms are negotiated with the partner.
- every purchase is defined by a negotiated Order Form.
- AI SOC Analyst
- sold as a separate module
- price on request.
- AI Threat Hunter
- sold as a separate module
- price on request.
- AI Detection Engineer
- sold as a separate module
- price on request.
- AI Watchtower
- presented as an optional 24x7x365 human-in-the-loop service
- price on request.
- Billing is expressed contractually in Units
- for example Investigations or other quantity
- with the volume fixed on the Order Form.
- Beta Features are provided at no additional cost
- without support and without any commitment to general availability.
Data, GDPR & hosting
A consolidated view of how Prophet AI handles your data.
GDPR overview
GDPR is addressed contractually rather than by a compliance badge. The published Data Processing Addendum, updated 6 May 2026 for its Annex III, states that Prophet will process personal data in accordance with the GDPR, defined as Regulation (EU) 2016/679, with separate GDPR, UK GDPR and CCPA schedules. Transfers outside the EU rely on the Standard Contractual Clauses of implementing decision (EU) 2021/914; the Privacy Policy of 15 May 2026 confirms that EU, UK and Swiss data reaches the United States under contractual, technical and organisational measures. No Article 27 EU representative is designated by Prophet and no DPO is named: the single privacy contact is legal@prophetsecurity.ai. Prophet states it mostly processes personal data on behalf of its customers and redirects data-subject requests to them. Global Privacy Control is honoured, Do Not Track is not, and CCPA and Nevada opt-out rights are covered.
Who owns the data?
Ownership is split by the Master Services Agreement of 21 April 2026. The customer keeps all right, title and interest in its Customer Data and in the AI Output generated from it (section 9b). Prophet Security retains the Prophet Assets, the Prompt, Usage Data and Security Threat Data (section 9a); Security Threat Data is de-identified, non-personal information extracted from incidents, and Usage Data is aggregated, anonymised interaction data expressly carved out of Customer Data. The customer grants Prophet only a limited licence, for the subscription period, to run the service and produce the AI Output. Under the DPA, Prophet acts as processor or sub-processor and the customer as controller or processor.
Reuse rights
The customer may reuse its own Customer Data and the AI Output without asking Prophet Security for permission, since it owns both. Prophet's own use is bounded by the Master Services Agreement of 21 April 2026: Customer Data is used to deliver the service and, combined with the Prompt, to query a Third Party Generative AI Service so that the AI Output can be produced (section 5a). The same clause states plainly that Customer Data is not used to train Third Party Generative AI Services. The generative services named in the agreement are Anthropic Claude, OpenAI GPT and Google Gemini; the Privacy Policy of 15 May 2026 additionally names Microsoft Azure OpenAI Service and Google Gemini as possible recipients of Customer Data. Usage Data, aggregated and anonymised, is used by Prophet to improve and develop the service (section 5b). On its product pages the vendor states that Prophet AI deploys as a dedicated single tenant, with a bring-your-own-key option and no training of AI models with personal data. Data collected through the website itself, namely name, email, phone number, employment details, device and IP data and web analytics, is processed for service delivery and improvement, marketing and correspondence, on the basis of contractual necessity, legitimate interest or consent.
Data retention & training
Hosting summary
Prophet Security is a United States company and states in its Privacy Policy of 15 May 2026 that information may be stored on servers in the United States, and may also be stored or processed in other countries by its service providers where the law allows. Hosting is delegated to Amazon Web Services, named in the public sub-processor list of 6 May 2026 as the provider that securely hosts the infrastructure and ensures reliable data storage, processing and availability. Microsoft Azure and Google Cloud Platform appear on the same list for access to hosted AI models, alongside Slack, Google Workspace, SerpApi and IPInfo. The product itself is delivered as a dedicated single-tenant deployment with a bring-your-own-key option. No European hosting region is mentioned anywhere: EU, UK and Swiss transfers are covered by the Standard Contractual Clauses rather than by local residency. The marketing site is a separate matter, built on Webflow and served behind Cloudflare, whose anycast address resolves to 198.202.211.1, which says nothing about where the application servers actually sit.
Where Prophet AI works
Country-level availability.
Not available in
Things to keep in mind
Risks and trade-offs to weigh before adopting Prophet AI.
- AI output is delivered as is: the Master Services Agreement disclaims any warranty of accuracy, completeness or reliability, so a wrong or missed verdict remains the customer's risk.
- Automation bias: analysts who stop reading the reasoning trail can lose the investigative reflexes the platform is meant to amplify, and junior staff may never build them at all.
- No security certification such as SOC 2 or ISO 27001 is displayed on the public site, which should be raised during due diligence with a vendor that sells security.
- Data is hosted and processed in the United States; EU, UK and Swiss transfers rely on the Standard Contractual Clauses, with no European data residency and no Article 27 representative.
- Annex II of the DPA, covering technical and organisational measures, is empty on the web page: the content exists only in the downloadable document and has to be requested.
- Liability is capped, at the fees paid over the previous 12 months in general, and even Excluded Claims are limited to the greater of USD 500,000 or three times the fees.
- Customer data may feed external search-engine queries through the SerpApi sub-processor, and the contract is governed by California law with exclusive jurisdiction in San Francisco County.
Setup & Integrations
Technical difficulty
Moderate, and deliberately light on paper. Prophet advertises setup in 30 minutes or less across three steps: create an account, connect your data sources, then choose your autonomy level. The no rip and replace positioning relies on out-of-the-box integrations with the existing stack, and the AI Detection Engineer runs on investigation data you already hold. The real prerequisites are organisational: a connectable SIEM, EDR, identity, cloud and email estate, plus the matching access rights. Remediation actions must be scoped explicitly, since nothing runs outside the approved perimeter. One customer describes the product as intuitive and fast to deploy.
Deployment
Integrations
Behind Prophet AI
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
What is Prophet AI?
Which agents make up the platform?
How much does Prophet AI cost?
Is there a free trial?
Is my data used to train AI models?
Which third-party AI models does Prophet use?
Where is the data hosted, and is a DPA available?
How many integrations are available?
Is there a public API?
Is there a minimum age?
Should you pick Prophet AI?
Prophet AI is not a triage assistant bolted onto a SIEM, but a set of agents covering the SecOps cycle end to end: investigation, hunting, detection engineering and an optional human layer on top. What the vendor puts forward as its edge is investigation depth at senior-analyst level combined with complete traceability of the reasoning, which matters more than raw automation when an auditor or an incident review asks how a verdict was reached.
The contractual side is unusually solid for a young vendor. The Master Services Agreement states in plain terms that Customer Data is not used to train third-party generative AI services, deployment is dedicated single-tenant with a bring-your-own-key option, the sub-processor list is public and named, and liability cover on security and data protection claims rises to the greater of USD 500,000 or three times the fees paid, backed by USD 5 million of Tech E&O and cyber insurance.
The reservations are real. Pricing is entirely opaque: no page, no rate card, no entry point, only per-investigation billing mentioned in passing. And a security vendor that displays no SOC 2 or ISO 27001 certification on its public site invites the question. Secondary reservations: hosting is United States only, with no European residency option, and no Article 27 EU representative is designated even though the DPA explicitly addresses European customers.
Maturity is the last variable. The company came out of stealth in April 2024 and its site was first archived in July 2024, yet it has raised USD 41 million and names customers such as Cabinetworks, ZIP, Clari, Upwind and JBPCO. Recommended for enterprise SOCs with an established stack and a genuine alert-volume problem, provided the buying team is ready to negotiate pricing and to press for the security attestations the site does not publish.
- Choosing a selection results in a full page refresh.
- Opens in a new window.