Vigil vs. AI SOC

Evaluating Dropzone, Crogl or Torq? Start with the questions a closed AI SOC cannot answer.

Many AI SOC products ask you to trust agents you cannot read, reasoning over alerts from detections you still maintain yourself. Vigil 1.0 is different by design. It is open source under Apache 2.0. With it, your team runs the detection rules you already trust, including federated detections in Splunk and Elastic, and adds LogLM for the attacks rules miss.

Read the code

Apache 2.0. Your analysts read, extend and fork each agent and skill.

Keep your detections

Vigil manages the rules you already run, including federated detections in Splunk and Elastic.

Ground it in a real model

Pair Vigil with LogLM, a foundation model pretrained on security telemetry: 99% zero-shot, 1% or fewer false positives.

Side by side

A proprietary AI SOC and Vigil differ in what you can inspect, keep and prove.

Dimension
Typical proprietary AI SOC
Vigil 1.0
Code
Proprietary AI SOC:Closed, including products offered as free downloads
Vigil:Apache 2.0: read, extend and fork
Detection grounding
Proprietary AI SOC:LLM reasoning over alerts from existing tools
Vigil:LogLM foundation model, plus the rules you already run
Existing detections
Proprietary AI SOC:Consumed as alerts
Vigil:Managed in Vigil, including federated detections in Splunk and Elastic, with coverage assessed through the closed loop
Playbooks
Proprietary AI SOC:Vendor playbooks or no-code workflows
Vigil:Skills written in Markdown, under change control
Model
Proprietary AI SOC:Vendor-selected
Vigil:Bring your own LLM, local or hosted
Autonomy
Proprietary AI SOC:Configured per workflow
Vigil:Earned per skill, with declared permissions, cost ceilings, confidence thresholds and human gates
Evidence
Proprietary AI SOC:Vendor-reported metrics
Vigil:SOCBench open benchmark; Vigil Assured release evidence
Where it runs
Proprietary AI SOC:Often vendor SaaS; some run in the customer environment
Vigil:Your infrastructure: on premises, air-gapped or your own cloud

The left column describes common AI SOC architectures as vendors publicly present them. Individual products vary; confirm current capabilities with each vendor.

Vigil and LogLM

The perfect complement to LogLM, and the autonomic system the industry needs.

With Vigil, we are building the perfect complement to LogLM and the autonomic cyber security system the industry needs. LogLM supplies the intelligence: zero-shot detection of concerning sequences across logs and telemetry. Vigil supplies the execution: triage, investigation, response, reporting and detection rule management, covering substantially all of a SOC's day-to-day work. Together they close the loop, as teams red team their own environment, create detections from that experience and measure coverage with SOCBench.

Autonomy is earned

Each skill earns its license to act through measured evidence, bounded by declared permissions, cost ceilings, confidence thresholds and human gates.

Skills as desired state

Declared intent lives in Markdown under change control, so review moves from each action to the declaration behind it.

Vigil Assured

Signed builds, SBOM and provenance, validated deployment profiles and patch SLAs, available as part of the Intelligent Defense Platform.

Evaluating a vendor

Questions to ask any AI SOC vendor.

The answers expose the architecture you will live with long after the evaluation ends: whether your team can read the code, what grounds each verdict, and who maintains the detections underneath.

Crogl

Crogl describes an autonomous AI SOC agent that runs in the customer's environment, now offered as a free download. Ask whether your team can read and change the code, and what grounds its detections.

Dropzone AI and Prophet Security

Both describe pre-trained AI analysts for alert triage and investigation. Ask who writes and maintains the detections that produce those alerts.

Torq, Swimlane and Tines

Each describes hyperautomation and no-code workflows, increasingly operated by AI agents. Ask who maintains the workflows when your environment changes.

Radiant Security

Cribl acquired the technology assets behind Radiant Security's AI SOC product in August 2026, and Radiant customers are re-evaluating. Ask what your migration path is, and what it costs.

Cortex XSOAR and Splunk SOAR

Teams replacing brittle playbooks can move to Vigil skills, which declare intent instead of scripting each step.

How teams start

From a clone of the repository to a supported platform.

1

Get Vigil

Clone the repository and run it with your own LLM, local or hosted.

2

Bring your detections

Connect Splunk or Elastic, and manage the rules and federated detections you already run in Vigil.

3

Add LogLM

Move to the Intelligent Defense Platform for LogLM, signed builds, validated deployment profiles and patch SLAs.

Run your SOC on code you can read.

Start with Vigil today, or talk to us about the Intelligent Defense Platform with LogLM and Vigil Assured.