Why do a software vendor, a managed detection and response (MDR) provider, a compliance platform, an information technology (IT) service desk, and a managed service provider (MSP) acquirer all appear in the same AI IT security services landscape?
Because the market is being mapped by technology instead of ownership. Artificial intelligence (AI) changes who performs the work, but ownership of the customer relationship decides who captures the value. I see five distinct models: security applications, AI-native security operators, AI-native IT service management (ITSM), agentic governance, risk and compliance (GRC), and MSP acquisition platforms. Durable value goes to whoever controls the customer contract, the operational outcome, the workflow data, and the automation margin.
That distinction matters more than whose agent sounds most autonomous. It tells an MSP owner whether to buy, partner, compete, or sell, and it tells an investor what the capital is actually funding. Throughout this map I treat company-published productivity figures as first-party claims unless independent evidence says otherwise.
Key takeaways
- The AI IT security services landscape contains five business models: security applications, AI-native security operators, AI-native ITSM, agentic GRC, and MSP acquisition platforms.
- Dropzone sells software and leaves services revenue with the managed security service provider (MSSP), while TENEX and Exaforce also sell managed outcomes where the vendor owns the queue.
- TENEX raised $250 million and Exaforce $125 million, but operator capital buys analysts and coverage while software capital buys product, so the paybacks are not comparable (Bloomberg, TechCrunch).
- Shield Technology Partners and Titan capture MSP automation margin by buying majority stakes in MSPs, which moves the customer contract inside the acquirer's portfolio.
- Vendor productivity claims across AI security and IT automation platforms are first-party figures without audited cohorts, so buyers should reproduce them on their own alerts and tickets.
The categories are useful only if they predict economics. A product can automate investigations without owning the incident. A managed provider can run the same agents while carrying a service level agreement (SLA) and human escalation. An acquisition platform can deploy both inside businesses whose customer relationships it owns. Those differences drive capital intensity, gross-margin potential, channel conflict, and diligence, so the companies here are grouped by the contract being sold, not the language used in a product demo.
The Four Questions That Separate the Five Models
You can classify almost every AI services company with four questions, and they add up to the ownership test that separates an application from an operator. Start there before comparing features or funding.
An AI security operations center (SOC) platform is software that triages and investigates security alerts with AI agents inside a SOC the buyer still runs. Feature comparison is a weak way to separate those platforms, and buyers say so. Scott Ponte, head of security operations at Robinhood, wrote from Black Hat that he sees little real differentiation between AI SOC vendors beyond interface polish, and that the category is quietly reintroducing pay-per-alert, pay-as-you-ingest security information and event management (SIEM) pricing (LinkedIn post). That is one practitioner's read rather than survey data, but it lands on the same point this map makes: commercial terms separate these companies more reliably than demos do.
Who signs the customer contract?
The contract tells you who owns distribution. Dropzone describes itself as 100% software and says an MSSP partner keeps the services revenue, so the MSSP retains the end-customer relationship (Dropzone). TENEX offers Agentic Overwatch, where the customer owns the queue, and Agentic MDR, where TENEX owns the managed operation (TENEX). Shield takes majority stakes in MSPs, which puts customer contracts inside its portfolio rather than outside it (CRN).
Who is accountable when the agent is wrong?
Software can investigate without accepting the service obligation. The buyer still has to approve containment, handle exceptions, and explain the incident to the client. A managed operator takes on more of the queue, staffing, and SLA, although the customer still owns business decisions that cannot be delegated. In GRC, Vanta explicitly tells users to verify AI output, which is a useful reminder that generated evidence is not an audit opinion (Vanta).
Who keeps the productivity gain and operating data?
If an MSSP licenses an application and keeps pricing unchanged, the MSSP captures the labor saving. If an AI-native operator sells the outcome directly, the operator captures it. If an acquisition platform owns the MSP, the saving may increase portfolio earnings before interest, taxes, depreciation and amortization (EBITDA) and equity value. Workflow data follows the same path: the party that sees repeated alerts, tickets, exceptions, and approvals has the best raw material for improving automation. Structural access differs by model. Acquisition platforms own the operating companies, managed operators see the cases they deliver, and applications see only what integrations permit, although the actual rights depend on tenancy, retention, and model-training terms rather than on technical visibility.
Who can change the workflow, and what survives a switch?
A buyer that can encode its own playbooks has a better chance of preserving differentiated operating knowledge than one consuming a fixed service. The matching question is what happens at exit. Data export, investigation history, response logs, and customer records determine whether the productivity gain survives a vendor change, and a platform that holds all four has taken a position in the business regardless of what the invoice says.
The five models side by side
| Model | Typical buyer | Delivery | Outcome owner | Human role |
|---|---|---|---|---|
| Security application | SOC or MSSP | Software | Buyer or partner | Governs, approves, responds |
| AI-native security operator | Security team | Managed or co-managed service | Vendor or shared | Supervises, escalates, owns judgment |
| AI-native ITSM | Internal IT | Software system of record | Customer | Sets policy and handles exceptions |
| Agentic GRC | Compliance and trust teams | Software plus partners | Management and auditor | Verifies evidence and signs representations |
| MSP acquisition platform | MSP owner | Majority investment and operations | Portfolio company and parent | Local delivery plus central engineering |
The table is deliberately about ownership, not intelligence. One company can occupy two rows if the contract genuinely changes, as the vendors compared in the AI SOC field guide do.
Ownership also makes financial comparison possible. Software revenue should be tested against product gross margin and retention. Managed revenue needs delivery headcount, escalation, and SLA cost. Acquisition economics require purchase price, acquired EBITDA, central overhead, organic growth, and cash conversion. A single “AI revenue” line combines incompatible paybacks.
Model 1: Security Applications Arm the Existing Operator
Software only creates margin for the buyer if the buyer still owns the service. That is the attraction and the burden of the application model.
Dropzone is the clean channel case
Dropzone autonomously investigates alerts through the security tools and data sources a customer already runs (Dropzone documentation). Its partner proposition is unusually explicit: Dropzone is software, the MSSP remains the service provider, and the services revenue stays with the MSSP (Dropzone partners).
For an established MSSP, that alignment is valuable, and it explains how Dropzone's channel economics work. The software can absorb repetitive evidence gathering while the provider keeps the account, incident communication, response judgment, and renewal. Dropzone reports more than 90 integrations and over 300 enterprise and MSSP deployments, but those are company-reported scale figures rather than independently audited measures (Dropzone partners).
Exaforce and 7AI can also be applications
Exaforce sells a full-lifecycle platform built around four Exabots for detection, triage, investigation, and response on top of a unified security data layer (Exaforce). In self-operated mode, the customer provides the analysts and owns the outcome. The platform is capacity, not outsourced accountability, and that split defines Exaforce's dual platform and MDR posture.
7AI takes an even broader foundation approach. Its platform covers cases, investigations, detection, response, hunting, and enterprise insights, while humans set intent and govern high-consequence actions (7AI). Buyers can operate the platform themselves or use it as the base for a partner-built service (7AI foundation), which stacks 7AI's service as software layers.
The margin comes with operating obligations
An application buyer must connect data, tune the workflow, define permissions, measure misses, and staff exceptions. A wide integration list does not prove that the product sees the context your analysts use in a real incident, and an autonomous investigation does not remove the need for customer-specific judgment.
Anton Chuvakin, a security advisor at Google and one of the more consistently skeptical named voices on this category, warns that AI SOC tooling risks repeating the security orchestration, automation and response (SOAR) era, when a playbook sold as a replacement for one analyst's workload ended up needing two engineers to keep it running (post on X). That is the honest downside case for the application model. The software arrives, and the operating work moves rather than disappears.
This model fits an operator that already has distribution, credible analysts, escalation procedures, and enough alert volume to spread the software cost. It fits badly when the real constraint is 24/7 staffing or incident accountability. Buying capacity does not transfer either one.
How to run the proof of value
Begin with a baseline from the existing operation. Sample a routine false positive, a true positive, a multi-source investigation, and a case where business context changes the correct response. Measure evidence completeness, analyst handling time, corrections, reopened cases, and response safety. A product that is fast on routine noise but weak on cross-system evidence may improve the cheapest part of the queue while leaving expensive work untouched. Where a vendor quotes a productivity number, ask for the baseline period, the sample size, the definition of automated, and the human-review time it excludes, then rerun the calculation on your own data.
For an MSSP, test tenancy and customer separation. Confirm that analysts can apply client-specific playbooks, permissions, reporting, and escalation without leaking context across accounts. Model total cost, including engineering, data, supervision, and vendor support. Services margin exists only after those costs.
Contract for portability before the platform becomes the investigation record. Export cases, evidence, playbooks, corrections, and response history during the pilot. The operator should be able to change tools without losing the institutional memory used to serve the customer.
Model 2: AI-Native Security Operators Own the Result
MDR is a service in which a provider monitors a customer's environment around the clock, investigates the alerts, and carries contractual responsibility for the outcome. The same agent can sit inside that contract or inside a software license, and the decisive question is who owns the queue after the demo ends.
AirMDR and TENEX sell operated outcomes
AirMDR documents a workflow that ingests an alert, runs quick checks, selects or generates an investigation playbook, gathers evidence, and produces a documented decision (AirMDR documentation). Its service positions human analysts as supervisors and exception handlers while the virtual analyst handles first response, so the product is the combined machine and human operation (AirMDR).
TENEX exposes the contract boundary through three paths. Optimize improves the customer's SIEM operation. Agentic Overwatch leaves the queue with the customer. Agentic MDR gives TENEX the 24/7 managed outcome. The platform runs natively on Google SecOps and Microsoft Sentinel and, according to TENEX, supports more than 300 connectors (TENEX). The difference sharpens with AirMDR and TENEX side by side.
Exaforce and 7AI cross the boundary
Exaforce MDR combines its Exabots with human analysts and 24/7 monitoring (Exaforce MDR). That is materially different from licensing the same technology to an internal SOC. Exaforce now owns daily monitoring and investigation, subject to the response rights in the contract.
7AI makes a similar move with PLAID ELITE, its 24/7 managed service, while also allowing customers and partners to operate the foundation themselves (7AI foundation). Calling either company only software or only MDR hides the most important commercial choice, and it blurs where AI SOC software ends and MDR begins.
Humans remain part of the service
None of these models makes accountability disappear. Humans supervise agents, handle ambiguous cases, approve high-impact actions, and communicate with the customer. The provider can own investigation and escalation, but a client may still retain authority over disabling an executive account, isolating a production server, or notifying a regulator.
The managed model fits a buyer that lacks 24/7 coverage, specialist depth, or confidence operating another platform. It may also fit an MSSP filling a capability gap, provided the customer, data, renewal, and escalation terms are clear. The price should reflect transferred responsibility, not the number of alerts processed.
What to require from a managed operator
Ask for staffing coverage, analyst location, escalation roles, response authorization, excluded sources, service credits, and the procedure for challenging a conclusion. Monthly reporting should separate alerts closed automatically, cases reviewed by humans, customer overrides, confirmed incidents, and SLA misses. A polished narrative does not prove the service found what it should have found.
For an MSSP, a managed operator can fill a night shift and still become a competitor later. No universal account-protection terms were public across the reviewed providers, so the contract must establish brand, renewal, data rights, and direct-sales boundaries.
Test continuity when the agent or a connector fails, and test it at peak volume. A 24/7 outcome needs a documented manual fallback, capacity limits, and a service-credit regime, plus a clear answer on what happens when several customers face incidents at once, how human review is prioritized, and which SLA moves under surge. An operator that depends on automation without resilient human coverage has transferred the interface, not the risk.
Model 3: Serval Moves AI Into the IT System of Record
The largest labor pool in this map may sit in the help desk, not the SOC. Serval attacks that pool by owning the workflow system around the ticket, and that ownership drives Serval's effect on help desk economics.
AI-native ITSM means the system of record for IT requests, assets, and access is built around agents rather than having a chatbot attached to a legacy service desk. Serval combines ITSM, access management, asset management, workflow automation, and built-in AI agents in one system (Serval). It can receive a request, identify an approved procedure, execute steps through connected systems, record the result, and keep the ticket history.
Builder Agent versus Helper Agent
The architecture separates the agent that creates deterministic tools and workflows from the agent that uses those approved tools to handle help-desk requests. TechCrunch described this split as a control mechanism that limits the risk of a general-purpose agent acting with broad permissions (TechCrunch).
That distinction is commercially important. The Builder Agent turns a repeated procedure into a controlled workflow, and the Helper Agent resolves requests within the permissions IT has approved. A human still decides which tools exist, which users may invoke them, and which exceptions require review.
Determinism matters more than chat
IT operations touches identity, software access, devices, payroll, and business systems, so a fluent answer is not enough. The workflow needs explicit permissions, logs, rollback, and a known owner. Serval captures value by sitting at that control point, where requests, policies, assets, and execution meet.
The company says customers automate more than half of their tickets and reported 500% revenue growth in the three months before its Series B. Both are first-party claims without a disclosed audited cohort in the announcement (Serval). Reuters independently reported the $75 million Series B, $1 billion valuation, and $127 million total funding, but not the operating metrics (Reuters via Investing.com).
The MSP pricing problem
If a platform resolves more tickets without proportional labor, per-seat and per-ticket pricing stop describing cost. An MSP can keep the automation margin for a while, but clients will eventually ask why a simple access request carries the same price after the work disappears. The stronger response is to price the managed outcome: availability, response, access governance, device health, and business continuity. Serval does not remove the MSP's customer context or exception handling, but it does pressure any offer whose value proposition is a pile of technician hours. That pricing question is the subject of AI pricing models for MSPs.
The implementation test is more operational than a chatbot pilot. Map the ten highest-volume request types, the systems each touches, approvals required, the cost of a wrong action, and the rollback path. Automate low-risk, specified work first. Measure completion without reopening, human intervention, time saved, and access-policy exceptions. A ticket-automation percentage can hide easy software requests while costly cases remain human.
Staffing changes too. Technicians handle fewer repetitive tickets and more exception design, workflow maintenance, identity governance, and client advisory. An MSP that trains for those roles can keep the customer and repackage the service. One that sells technician activity will feel automation as price pressure.
Model 4: Drata and Vanta Turn Trust Work Into Software
Agentic GRC is compliance software in which agents collect evidence, monitor controls, and draft questionnaire answers while management and auditors keep the assertions. A faster questionnaire is still not an audit opinion, which holds across Drata and Vanta compared as agentic trust platforms.
Drata is building an agentic trust layer
Drata positions AI across control monitoring, evidence work, questionnaires, risk, and trust workflows (Drata). Its channel guide describes routes for service providers and MSSPs, so a partner can package managed compliance around the software instead of sending the customer directly to a generic application (Drata channel guide).
That creates an opening for MSPs and virtual chief information security officer (vCISO) providers. The software can gather evidence and draft answers. The service provider can map business context, resolve exceptions, prepare management, coordinate the auditor, and stand behind the operating process.
Vanta spans GRC, trust, and vendor risk
Vanta applies AI across its GRC and trust platform and offers an AI agent for third-party risk management (TPRM) work (Vanta AI, Vanta TPRM). The useful caveat comes from Vanta itself: users should verify generated output, and feature availability depends on product and plan (Vanta help).
That is the right boundary. An agent can retrieve evidence, summarize a vendor, draft a policy, or propose an answer. It cannot take management's responsibility for whether a control operates, nor can it issue an independent audit opinion.
The service layer does not vanish
Automation makes low-judgment evidence collection cheaper, which makes the remaining work more obviously about interpretation, remediation, stakeholder coordination, and assurance. An MSP that forwards automated reports will face price pressure. One that owns the control program, remediation cadence, and executive communication keeps a defensible service. The partner opportunity is strongest where automation exposes remediation, because a failed control still needs identity, device, cloud, or process work. MSPs that can fix the underlying system, not merely produce the evidence, turn faster GRC into a recurring operating service.
How to measure an agentic GRC program
The economic unit has to change with the tooling. Counting evidence items rewards volume rather than assurance. Better measures include controls operating without exception, remediation cycle time, verified questionnaire turnaround, audit preparation hours, and expansion revenue influenced by trust work. Keep management approvals and auditor independence visible so faster software does not produce weaker representations.
Sample generated questionnaire answers against source evidence and prior approved language, track corrections by question type, and route low-confidence topics to named owners. Faster output is valuable only when review effort falls without raising misrepresentation risk.
Policies, mappings, evidence, risks, answers, and remediation history become the operating memory of a compliance service, so confirm who owns that record and how it exports. Otherwise the software can quietly own the service even when the MSP owns the customer. The choice between Drata and Vanta should then follow evidence integrations, trust workflow, auditor ecosystem, third-party risk needs, and partner fit. Neither publishes normalized pricing, so a feature comparison without commercial terms is incomplete.
Model 5: Shield and Titan Buy the Customer Contract
An MSP acquisition platform buys majority ownership of managed service providers and applies capital, engineering, and AI tooling inside businesses whose customer contracts it now holds. The most direct way to capture an MSP's automation margin is to buy the MSP, so Shield and Titan are acquirers rather than software products sold to independent operators.
Shield uses a federated majority-stake model
Shield says it partners with MSPs while retaining local brands and leadership, and its public portfolio lists 19 companies (Shield, Shield portfolio). CRN reported that Shield typically buys majority stakes of 60% to 90%, leaving owners with continuing equity and operating roles (CRN).
The central platform supplies capital, recruiting, mergers and acquisitions (M&A), and engineering. Omdia describes a model in which forward-deployed engineers, platform staff embedded inside the acquired businesses, work alongside operating teams that retain meaningful autonomy (Omdia). The trade-off is clear: local trust can survive, but a heterogeneous portfolio is harder to standardize, the first split between the two roll-up models Shield and Titan represent.
Titan began with a tighter platform thesis
Titan launched with $74 million of financing and the acquisition of RFA as its anchor MSP, according to Channel Futures (Channel Futures). Its pitch is an augmented-AI holding company where agents take repetitive work and technicians remain client-facing for strategic and exceptional tasks (Titan).
General Catalyst's investment thesis emphasizes building a proprietary operating layer across acquired companies (General Catalyst). That could produce a more consistent platform, but General Catalyst is an investor in Titan, so its article is primary evidence for the investment rationale rather than independent evidence of realized productivity. Public evidence is also earlier than Shield's broader disclosed portfolio, so the thesis should not be mistaken for proven cross-portfolio economics.
Roll-ups need different proof
Omdia's useful roll-up lens is ownership and brand, capital, technology, and execution (Omdia). I would add one more: audited value creation.
Ticket automation is evidence of activity, not evidence of higher retention, better service quality, or durable margin. A roll-up has to show that tools deploy across different stacks, local teams adopt them, customers remain, and savings survive after central costs. That is a much harder test than shipping a feature. Portfolio reporting should therefore separate acquired growth from organic growth, and central cost from local margin, or acquisition activity will make the platform look stronger while the underlying MSPs stagnate.
What a seller should compare
The two models produce different personal outcomes. A federated platform may preserve local brand and leadership while centralizing selected capabilities. A tighter platform may demand faster standardization in return for a stronger shared-product thesis. Compare cash at close, rollover equity, governance, earnout measurement, employment terms, brand control, data rights, acquisition debt, and the conditions attached to a second exit, alongside what an MSP is worth in the AI era.
Ask for cohort evidence before valuing rollover equity: same-company revenue, gross margin, employee retention, client retention, and service levels from entry through the latest period, not selected automation anecdotes. Customers deserve diligence too. Ask how tooling changes are approved, whether service staff remain, how ticket and incident data will be used across the portfolio, and what quality guardrails apply during integration. Automation value that arrives through churn is not value creation.
The Capital Is Funding Three Different Paybacks
A $100 million round can fund code, analysts, or acquisitions. Treating those uses of capital as comparable produces bad conclusions.
security operator $250m
application plus managed $130m
application plus managed $125m
MSP acquisition $100m
AI-native ITSM $75m
MSP acquisition $74m
security application $37m
Software payback comes from recurring product economics
Exaforce raised a $125 million Series B at a reported $725 million valuation, bringing total funding to $200 million (TechCrunch). 7AI raised a $130 million Series A, independently reported by SecurityWeek (SecurityWeek). Dropzone raised a $37 million Series B, bringing reported total funding above $57 million (SecurityWeek).
Those rounds finance product, data infrastructure, go-to-market, and customer deployment. The expected payoff is recurring software revenue with gross profit that grows faster than delivery headcount. Funding corroborates investor demand and provides runway. It does not validate false-negative rates, retention, or software margins.
Operator payback depends on labor compression
TENEX raised $250 million at a valuation above $1 billion, according to Bloomberg (Bloomberg). Its announcement said the money would also expand human defender and engineering teams (TENEX). That is consistent with an operator model: software may compress work, but customers still buy coverage, judgment, and accountability.
For an operator, the crucial numbers are revenue per delivery employee, gross margin after analyst and infrastructure cost, escalation rate, retention, and incident quality. A headline automation percentage has little meaning without its denominator and the cost of the human backstop.
Roll-up payback starts with acquired EBITDA
Shield raised another $100 million to acquire and grow more MSPs, independently covered by SiliconANGLE (SiliconANGLE). Titan's $74 million financed both its platform build and RFA acquisition (Channel Futures).
Here, capital buys existing customers, revenue, staff, and EBITDA, the same arithmetic behind the wider AI services holding company model. Automation is supposed to increase the value of an asset already owned. The proof is therefore portfolio retention, organic growth, margin after central costs, integration speed, and cash conversion. Funding size alone tells you none of those things.
Why a funding number is not a product score
Valuation comparisons across the landscape are therefore dangerous. A product company may be valued on future recurring revenue and software margin. A managed operator blends technology and delivery economics. A roll-up may carry acquisition debt and own current EBITDA. The same funding amount can represent years of product runway, a larger analyst operation, or a handful of acquisitions.
Normalize the models to cash required for one dollar of durable gross profit growth, then inspect retention, concentration, implementation cost, and payback. Public sources establish the rounds here, but they do not disclose enough standardized unit economics to calculate that answer. That missing disclosure is itself useful: funding and valuation belong in a capital map, not a product score, and a better-funded vendor does not automatically investigate better.
Capital efficiency can also reverse as a model matures, since software may need expensive data infrastructure, operators may need more experts, and roll-ups may face higher acquisition prices. Underwrite the next dollar of growth, not the historical round.
What MSP Owners and Investors Should Do With the Map
The map becomes useful when you translate ownership into a decision.
Buy software if you own analysts and distribution
An MSSP with a trusted customer base, a functioning SOC, clear response procedures, and enough volume should buy automation before outsourcing its differentiator. Dropzone's partner model is explicit about keeping services revenue with the MSSP (Dropzone). 7AI also lets partners build services on its foundation (7AI partners).
Run the proof of value on your own alerts, and do not buy on a vendor's aggregate productivity claim.
Partner if you lack 24/7 capability
If your constraint is staffing rather than tooling, a managed operator is the more honest purchase, one branch of the buy, partner, build or compete decision for MSPs. TENEX separates co-managed and fully managed paths, which makes the responsibility transfer visible (TENEX). Require written terms for customer ownership, data reuse, white-label presentation, escalation, incident authority, renewal, and exit.
Compete on trust and vertical workflow
Generic alert enrichment, evidence gathering, and ticket routing will get cheaper. Customer-specific judgment will not disappear as quickly. Build your moat around the response decisions, vertical playbooks, executive communication, and adjacent compliance work that require context and trust.
If an acquirer approaches, compare more than price. Shield publicly emphasizes local leadership and majority partnership (CRN). Titan emphasizes a shared AI platform across owned service businesses (General Catalyst). Your choice changes control, rollover risk, role, and the source of the second bite.
Investor diligence should follow four assets
Ask for evidence on:
- Customer control: who signs, renews, upsells, and owns the brand relationship?
- Workflow and data: what proprietary operating history improves the product?
- Outcome and risk: who carries the SLA and handles a wrong decision?
- Margin: is the productivity gain visible after infrastructure, humans, support, and central costs?
That scorecard works across all five models, and the fuller vendor scorecard template turns it into gate items you can actually score. Either way it stops a large funding round or a polished agent demo from substituting for business-model proof.
Test reversibility too. Start with a bounded workflow and preserve the old process while performance is measured. Require data export and termination support, put data-retention, training, and customer-contact terms in the same diligence schedule, and limit response permissions until rollback works. A system that can prove its value only after it becomes difficult to remove is asking the buyer to finance its evidence.
The decision, and when to revisit it
The strategic answer is rarely to wait. Repetitive investigation, ticket work, and evidence collection will get cheaper, and the only real question is where that saving accrues. Keep it inside your operation when you own the capability, pay an operator when accountability is the scarce asset, and sell equity only when capital, governance, and the second-bite trade fit your goals. Review that position every six months, because the right model follows the asset and the responsibility rather than a permanent preference.
For related analysis, see AI-powered MSP roll-ups, AI SOC economics, the MSP tool stack, AI pricing models for MSPs, and the cybersecurity market map.
FAQ
No. Exaforce, AirMDR, 7AI, TENEX, and Dropzone overlap in security operations. Serval sells IT service management (Serval). Drata and Vanta sell GRC and trust software (Drata, Vanta). Shield and Titan acquire MSPs (Shield, Titan). Compare companies only after matching delivery model, buyer, outcome owner, and contract.
AI SOC software supplies investigation and response capacity while the buyer keeps the queue and the outcome, and MDR supplies an operated service with monitoring, analysts, and contractual responsibility. Exaforce and 7AI sell both modes, which is why the contract matters more than the interface (Exaforce MDR, 7AI).
No. Drata and Vanta automate GRC, evidence, risk, and trust workflows, but management still owns its representations and an independent auditor still owns the audit opinion. Vanta explicitly instructs users to verify AI-generated content (Vanta help).
Buy the investigation layer first if you already operate the queue and own response. Dropzone is the clearest channel-aligned example because it says the MSSP retains services revenue (Dropzone). If you cannot staff 24/7 coverage, evaluate a managed or co-managed operator before adding another tool.
Normalized public list pricing was not found across the ten companies in the reviewed evidence, and most route buyers to a demo. Pricing is unsettled on the sell side as well: an independent researcher who interviewed early AI SOC adopters reported that vendors are unsure what to charge and buyers struggle to attach a monetary value to the product (r/cybersecurity comment). Run a structured request for proposal with identical alert, ticket, data-volume, coverage, and response assumptions so quotes describe the same service.
Ask how much equity is sold, who controls the board, whether the brand and leadership remain, who owns customer and operating data, how automation savings affect earnouts, and what happens if the central platform changes. Shield's disclosed model shows why ownership and operating terms deserve separate diligence (Omdia).