Torq SOC Brain adds customer-trained learning to its AI SOC platform
Torq launched SOC Brain, an AI SOC layer trained on each customer’s case history and analyst decisions; pricing was not disclosed.
By Wei-Lin Zhao · AI Correspondent
· 3 min read
Torq launched Torq SOC Brain, a new layer for its AI security operations center platform that the company says learns from each customer’s prior investigations and analyst decisions. The release is meant to move Torq’s AI SOC product beyond case retrieval, a common pattern in which tools fetch similar incidents and hand them to a large language model at decision time.
Torq did not disclose pricing, customer adoption figures or independent benchmark results for SOC Brain. The company is positioning the product around a practical SOC problem: analysts often handle repeat alert patterns, but many automation tools still treat each alert as a standalone investigation unless teams build rules or manually tag cases.
What is Torq SOC Brain?
Torq SOC Brain is a customer-specific learning layer for Torq’s AI SOC platform. According to Torq, it uses an organization’s resolved incidents, analyst notes and confirmed verdicts to influence future alert decisions, while keeping each customer’s data and models separate.
The product has three named components: Recall, Reflex and Retrospect.
Torq Recall searches prior cases using deterministic matches on observables including IP addresses, file hashes, URLs and hostnames. Torq says it then ranks the cases, reads analyst notes, identifies conflicting precedents and adjusts confidence based on the quality of the evidence.
Torq Reflex trains dedicated models on confirmed analyst verdicts and corrections. The company says Reflex matches analyst-corrected decisions 85% of the time immediately, automating alerts when confidence is high and sending other cases to a human analyst.
Torq Retrospect is aimed at the deployment problem. It imports previously resolved incidents from a customer’s existing security tools so the system has historical material before the first new alert arrives.
Torq says analysts do not need to create rules or tag historical incidents for the system to work. That claim is central to the launch, because SOC automation often slows down when it depends on teams maintaining brittle workflows across changing tools and alert types.
How Torq is framing the AI claim
Ofer Smadari, Torq’s co-founder and chief executive, argued that many cybersecurity vendors call their AI systems self-learning even when they are mostly retrieving past cases for an LLM. His position is that a system should draw new conclusions from prior investigations and adapt to how a specific security team weighs evidence.
Torq also says each customer receives a private SOC Brain. The company said it does not combine customer data, share model parameters across customers or train one customer’s models on another customer’s incidents. Torq described that isolation as part of the architecture, rather than a configuration option controlled by an administrator.
The company is also pitching explainability and auditability. Torq says SOC Brain decisions can be reviewed, and that automation is controlled through confidence thresholds and human oversight. Torq tied that positioning to governance pressure on security leaders, including developing rules such as the European Union’s AI Act.
Why the launch fits Torq’s year
SOC Brain follows a busy stretch for Torq. In May, the company acquired application security startup Jit.io to add context graphs to its platform. In January, Torq raised a $140 million Series D led by Merlin Ventures at a $1.2 billion valuation.
Those moves show Torq trying to broaden its security hyperautomation platform at a time when AI SOC products are competing on how much investigative work they can absorb without creating governance risk. Torq plans to demonstrate SOC Brain at Black Hat USA in Las Vegas from Aug. 3 to Aug. 6.
This story draws on original reporting from SiliconANGLE.