STOCK TITAN

SentinelOne Opens Purple AI Agentic Investigation to All Customers, Bringing Frontier AI Directly Into the SOC

(Neutral)
(Negative)
Tags
AI

Key Terms

soc technical
Standard of care (often abbreviated SOC) is the treatment or management approach that is widely accepted and used by medical professionals for a particular disease or condition. For investors, SOC provides the benchmark against which new therapies, devices, or clinical results are judged—like comparing a new car to the current most popular model; a product that meaningfully outperforms the SOC can win market share and drive revenue, while failure to beat or match it limits commercial potential.
telemetry technical
Telemetry is the automatic collection and transmission of measurements from remote devices, systems, or patients to a central system for monitoring and analysis—like a car sending engine, speed and location data back to a dashboard. For investors it matters because telemetry provides real-time evidence of product performance, safety and user behavior, helping assess revenue potential, operational risk, regulatory compliance and whether a product is meeting market demand.
human-in-the-loop technical
Human-in-the-loop describes systems where people supervise, check, or make final decisions on work performed by automated tools or algorithms. Like a pilot overseeing an autopilot, humans step in to catch errors, interpret nuance, and apply judgment that machines may miss. For investors, this matters because human oversight can reduce operational and regulatory risk, improve decision quality, and increase trust in results produced by automated systems.
frontier-ai models technical
Frontier-AI models are the most advanced, high-performance artificial intelligence systems available, built to solve complex tasks like understanding language, generating images or making predictions at human or superhuman levels. For investors they matter because these models can create big commercial opportunities (new products, cost savings, platform dominance) but also concentrate risk through high development costs, heavy computing needs, regulatory scrutiny and safety concerns—similar to backing the fastest, most expensive engine in a car race.
policy-driven responses technical
Policy-driven responses are actions or communications by companies, regulators, or policymakers that are prompted mainly by laws, rules, or official guidance rather than by market demand or internal strategy. Think of them like a driver changing route because of a new traffic sign: these responses can alter costs, operations, or market access, so investors watch them as signals of regulatory risk, potential fines, or shifts in future revenue and expenses.
role-based technical
Role-based describes policies, systems or decisions that grant access, responsibilities or privileges according to a person’s formal position or function inside an organization. Like giving different keys to different rooms in a building, it controls who can see data, approve transactions or perform tasks. Investors care because role-based approaches affect operational efficiency, security, regulatory compliance and the risk of mistakes or fraud, all of which can influence a company’s costs and reputation.
automated workflows technical
Automated workflows are software-driven sequences that move tasks, data, or approvals from one step to the next without manual intervention, like an assembly-line conveyor that routes parts to the right station. For investors, they matter because they can lower costs, reduce human errors, speed up service or product delivery, and make operations easier to scale — all of which can improve a company’s efficiency, margins, and risk controls.
See more from StockTitan in Google Search and AI answers. Adds StockTitan as a preferred source · opens Google
Add on Google

Zero-configuration, autonomously initiated investigations run inside customers’ existing Singularity™ Platform workflows, detecting, investigating, and responding to threats at machine speed, and giving every analyst a force multiplier, with a full evidence chain behind every verdict

MOUNTAIN VIEW, Calif.--(BUSINESS WIRE)-- SentinelOne® (NYSE: S), the AI security leader, today opened Purple AI Agentic Investigation to its customers and introduced Singularity Credits, a unified currency for running AI-powered work across the Singularity Platform. Starting this week, customers can opt into a complimentary trial of the newest capability from Purple AI, SentinelOne’s autonomous security reasoning for the agentic SOC. That capability — ‘zero-click,’ autonomously initiated investigations — detects, investigates, verifies, and responds to threats without human dependencies. When a threat crosses a defined threshold, Purple AI investigates, renders a verdict, and stops it at machine speed, while analysts keep full visibility and control.

The capability arrives as security teams confront a hard limit, not detection, but investigation capacity. Detections climb with every new tool and every expansion of the attack surface, alerts queue for attention, and verdicts wait on analyst availability, with coverage thinning on nights, weekends, and during surges. Frontier-AI-powered threats are poised to widen that gap further.

“Today’s security teams face more critical alerts than any staffing plan could investigate, and AI-powered threats are only going to make that worse,” said Chris Corde, Chief Product Officer of SentinelOne. “Investigation capacity has become the binding constraint of the modern SOC: detections climb, alerts queue, and verdicts wait on analyst availability. Purple AI’s Agentic Investigation capability is designed to remove that constraint by making investigations automatic, continuous, and immediate.”

Why SOC Teams Are Adopting Purple AI Agentic Investigation

  • Seamlessly integrated — zero configuration, working from day one
    Purple AI is built into the Singularity Platform, not bolted onto it. The new Agentic Investigation capability runs on telemetry already in the platform across endpoint, identity, cloud, and third-party security data, as well as inside the automated workflows customers already use. There is nothing to deploy, integrate, or tune, and no data leaves the platform. Activation is a single click.
  • A force multiplier for every analyst
    Purple AI does the investigation work, collecting evidence, correlating telemetry, and building the attack timeline, so analysts start at the verdict instead of the alert. It scales a team’s investigation capacity without scaling headcount, and frees analysts for the judgment, threat hunting, and response decisions that need a human. It is designed as an extension of the analyst: amplifying human defenders, not replacing them.
  • Fully audited — governed autonomy, no black box
    Every verdict carries a complete, auditable evidence chain, so analysts can review each AI step and outcome with confidence. Customers set the degree of autonomy through an adjustable human-in-the-loop approach that scales to their confidence and SOC maturity. Verdicts can trigger automated, policy-driven responses, or prompt an analyst with recommended actions. Activation is admin-controlled, role-based, and reversible at any time, and consumption guardrails keep usage and downstream cost in the hands of those with the right authority.
  • Built on the most advanced reasoning in cybersecurity
    Purple AI is the reasoning brain and interface for the entire Singularity Platform. It brings human-level reasoning from advanced frontier-AI models to bear through a multi-model approach, combining Anthropic’s Claude, OpenAI’s GPT, and SentinelOne’s proprietary “Ultraviolet” models to compress investigations that once took hours or days into minutes and seconds. For critical threats, investigations trigger automatically and deliver verdicts that can be acted on autonomously or by an analyst.

The introduction of Singularity Credits

Singularity Credits are a flexible, unified currency customers draw down across AI-powered work in the Singularity Platform, including Purple AI Agentic Investigation. To start, SentinelOne is granting customers a complimentary allotment of Credits to trial the capability.

Delivering on the agentic SOC by amplifying defenders, not replacing them

Agentic Investigation advances SentinelOne’s vision of the agentic SOC: one where frontier-AI reasoning amplifies and scales human defenders rather than sidelining them. Purple AI acts as the brain and interface for the entire platform from simplifying querying, to recommending actions, to autonomously detecting, triaging, and stopping threats. Because it operates natively on AI, endpoint, identity, cloud, and third-party telemetry already in the Singularity Platform, it drives Singularity to be an agentic realization of the integrated security operations center (ISOC) category defined by Gartner.

Availability & access

The Purple AI Agentic Investigation trial is now available in Singularity Platform consoles. New and existing Singularity customers can opt in and begin running agentic investigations immediately. Investigations utilize Singularity Credits during the trial, but customers are not charged and no payment method is required. After the trial, customers can purchase Singularity Credits through partners, direct billing, and eCommerce.

About SentinelOne

SentinelOne (NYSE: S) is the leader in AI security, setting the standard for using AI and automation to give defenders a decisive operating advantage. Built for those who secure our world, its platform delivers unified coverage across endpoints, identity, cloud, and AI. Powered by Autonomous Security Intelligence, SentinelOne stops attacks at machine speed, reducing risk and delivering clarity and control to stay one step ahead. Headquartered in Mountain View, California, with teams worldwide, SentinelOne protects nearly one-fifth of the Fortune 500 and hundreds of Global 2000 enterprises. From Main Street to Wall Street, the world’s most critical organizations trust SentinelOne with their security.

All third-party product names, logos, and brands mentioned in this publication are the property of their respective owners and are for identification purposes only. Use of these names, logos, and brands does not imply affiliation, endorsement, sponsorship, or association with the third party.

Media Contact
Regan DePinto
press@sentinelone.com

Source: SentinelOne