Insights

Exaforce Review: Agentic SOC Platform vs MDR

Read this Exaforce review to separate its Agentic SOC platform from its MDR service, then evaluate data architecture, response rights and operating evidence.

By Alexej Pikovsky  ·  Updated

Is Exaforce software, a managed service, or both? The answer changes depending on who operates the same Exabots.

My Exaforce review finds a deliberately hybrid Security Operations Center (SOC) operating system, financed by a $125 million Series B at a $725 million valuation (TechCrunch). Exabots are Exaforce's task-specific agents for detection, triage, investigation, and response. An internal team can run them to increase its own capacity, or Exaforce can combine them with human analysts and own the 24/7 Managed Detection and Response (MDR) workflow, the model where the vendor supplies the monitoring and the people rather than only the software (Exaforce, Exaforce MDR).

That flexibility is the attraction and the main diligence risk. Buyers have to separate product architecture from service accountability, and company-reported efficiency from independently proven security outcomes. Platform customers keep the queue, the response approvals, the staffing model, and much of the implementation burden, while MDR customers hand more of the monitoring and investigation to Exaforce. One architecture can support both, but an MDR case study does not underwrite software deployment, and a platform benchmark does not underwrite managed-service quality. Platform and managed service are two of the positions on the five-model map of AI IT and security services, and Exaforce occupies both.

Key takeaways

  • Exaforce sells one Exabot stack through two accountability models: a self-operated platform where the customer keeps the queue, and Exaforce MDR where Exaforce supplies analysts and 24/7 monitoring.
  • Exaforce's four Exabots split detection, triage, investigation, and response across the SOC lifecycle, sharing one real-time security data layer rather than acting as a single general agent.
  • Exaforce's tenfold SOC efficiency figure is a first-party design-partner claim with no shared baseline or independent audit, so treat it as marketing until your own cases reproduce it.
  • Exaforce raised a $125 million Series B in May 2026 at a $725 million valuation, reaching $200 million total, which buys runway rather than proving detection quality (TechCrunch).
  • Exaforce publishes no normalized pricing, so fix the price unit (data volume, alerts, users, connected sources, or outcomes) before comparing platform mode against MDR.
Same stack, two accountability models · Exaforce product and MDR pages
Identical in bothone real-time data layer
four exabots
detection to response
Platform modecustomer keeps the queue
customer approves response
customer staffs the shift
customer carries onboarding
MDR modeexaforce owns the queue
exaforce monitors 24/7
exaforce investigates
customer keeps response rights

The Real-Time Data Layer

The agent is only as useful as the context beneath it. Exaforce starts with a unified, real-time security data layer rather than treating every alert as a standalone prompt (Exaforce).

Sources, normalization, and enrichment

Exaforce says its platform connects telemetry across identity, endpoint, email, cloud infrastructure, software as a service (SaaS), Kubernetes, and code environments (Exaforce). The aim is to normalize and enrich those sources so an investigation can follow an attack chain instead of reading one alert at a time.

That architecture can improve context, but it expands the implementation surface. A buyer must establish which sources are read-only, which support action, how historical data is handled, and whether the platform requires an optional Exaforce data lake or can work against existing stores such as a Security Information and Event Management (SIEM) platform. Product breadth is useful only where the data is complete enough to support the conclusion.

Multiple reasoning layers

Exaforce describes a multi-model approach combining semantic, behavioral, knowledge, and language models (Exaforce Series A announcement). In plain language, the platform is trying to join meaning, observed behavior, known relationships, and natural-language reasoning.

The design is most attractive in broad cloud and identity environments where important evidence sits across several systems. It is less convincing if the pilot uses only a narrow alert feed. Demand a data map before evaluating the agent: connected sources, missing fields, retention, tenancy, regional storage, model access, and deletion terms.

A vendor that controls normalization, enrichment, case history, and agent orchestration also becomes more deeply embedded than a point investigation tool. That may improve results as context accumulates, but it raises switching cost. Export one complete investigation during the pilot, including raw evidence, reasoning history, approvals, and actions. If those records cannot move cleanly into the buyer's evidence store, the data layer is also a lock-in layer.

Four Exabots Across the SOC Lifecycle

The quickest way to understand Exaforce is to stop calling it an artificial intelligence (AI) analyst. The platform assigns four Exabots to distinct jobs across detection, triage, investigation, and response (Exaforce).

Different jobs, shared context

Detection looks for suspicious activity. Triage determines whether an alert deserves attention. Investigation gathers and connects evidence. Response turns a conclusion into a proposed or permitted action. Splitting the lifecycle this way is more credible than asking one general agent to improvise every step.

The common data layer is supposed to keep handoffs coherent: detection passes its entities and reasoning into triage, triage passes a prioritized case into investigation, and response works from the same evidence instead of rebuilding context. Exaforce presents this as a full-lifecycle system rather than a point alert-enrichment product (Exaforce).

Human judgment still defines the boundary

The four-agent design does not settle which actions happen automatically. A buyer still needs a response matrix covering enrichment, ticket creation, account suspension, endpoint isolation, network blocking, rollback, and executive approval. Low-risk gathering can run unattended. High-impact containment may require a human even when the agent is technically capable.

Exaforce says early design partners achieved tenfold SOC efficiency, but this is a first-party performance claim without a shared baseline or independent audit (Exaforce Series A announcement). Scott Ponte, who leads security operations at Robinhood, wrote after Black Hat that he sees little real differentiation between AI SOC vendors beyond interface polish (LinkedIn post). That is one practitioner's read rather than a survey, but it is a good argument for testing each Exabot separately on your own cases. A fast triage result cannot compensate for weak evidence or an unsafe response path.

Score the handoffs too. Check whether detection preserves the evidence triage needs, whether investigation exposes uncertainty, and whether response cites the findings behind an action. Then introduce a conflicting signal: a credible lifecycle revises its conclusion and preserves the audit trail rather than quietly overwriting the first answer. Track correction rates by Exabot so one strong stage does not hide a weak handoff.

Self-Operated Platform Mode

A mature SOC may want more capacity without outsourcing control. In self-operated mode, Exaforce supplies the operating layer while the customer keeps the queue, analysts, response authority, and outcome.

What changes for the analyst

The platform can gather context, build an investigation narrative, prioritize cases, and propose response. The analyst moves from manual retrieval toward review, correction, and higher-judgment decisions. Exaforce describes the platform as spanning the complete SOC lifecycle on one data foundation (Exaforce).

The customer still has to define detections, connect sources, manage permissions, resolve ambiguous business context, and own incident communications. Someone must also evaluate misses. An agent can make handled alerts faster while leaving unknown false negatives invisible.

The implementation burden remains with the buyer

Self-operation needs an accountable internal owner, security engineering support, response playbooks, and a measurement baseline taken from a bounded queue before the platform arrives.

Public normalized pricing is not disclosed on the reviewed product pages. Ask whether price follows data volume, alerts, users, connected sources, agents, or outcomes, and include onboarding, data storage, model usage, premium support, and response connectors in the commercial comparison. Pricing opacity is a category condition rather than an Exaforce quirk: an independent researcher who interviewed early AI SOC adopters found vendors unsure what to charge and buyers unable to attach a monetary value to what they were buying (r/cybersecurity comment). Fix the unit before you compare bids, and read how AI pricing models are shifting across managed services before you agree to one.

Platform mode fits a SOC with credible analysts and a desire to retain control. Skip it if the real problem is an unstaffed night shift, undefined escalation, or no internal owner. Software can compress a functioning operation. It does not create one from nothing.

Build the unit-economic case with loaded analyst cost: license expense, data ingestion, engineering, training, quality review, and work moved to senior responders. Then calculate cost per correctly closed case and per escalated true positive. Anton Chuvakin, a security advisor at Google, warns that the agentic SOC risks repeating the Security Orchestration, Automation and Response (SOAR) era, when a playbook promised to replace one analyst's workload and ended up needing two engineers to keep it running (post on X). That is the shape of the risk here too: a reduction in junior triage time can remain uneconomic if senior review or platform administration rises. Keep the old workflow available long enough to establish a credible control group.

Exaforce MDR Mode

The same Exabots become a different purchase when Exaforce supplies the people and owns continuous operation.

Provider-owned monitoring and investigation

Exaforce MDR combines the platform with human analysts and 24/7 monitoring (Exaforce MDR). That moves daily queue ownership, investigation, and escalation toward Exaforce. A lean team buys an operated outcome instead of another dashboard to staff.

The human component matters. Analysts can inspect uncertain cases, supervise automation, tune the operation, and communicate significant incidents. The software may carry routine volume, but the service promise rests on the combined system.

Customer visibility and response boundaries

Managed does not mean unlimited authority. The customer still controls business decisions, privileged access, regulated notifications, and actions that could interrupt production. The contract should state which actions Exaforce may execute, which require approval, and what happens when the authorized contact is unavailable.

Ask for the monitoring service level agreement (SLA), escalation clock, evidence retention, incident communication path, named responsibilities, excluded sources, and exit process. Require a manual fallback for connector failure, agent outage, and incident surges, with the same escalation owner documented in the SLA. Also establish whether Exaforce tunes customer controls or only investigates what reaches the platform.

MDR mode transfers more accountability than self-operated software, but not all organizational risk. The buyer remains responsible for the wider security program, so the right comparison is Exaforce MDR against other operated outcomes, not against an agent license on price alone. Run the platform versus managed service contract test before the price comparison.

Service reporting deserves equal scrutiny. Ask for volumes by disposition, investigations reopened, customer overrides, response actions, SLA misses, and material detection changes, and require a named process for challenging an Exabot conclusion. If the customer can see only a polished narrative, it cannot distinguish an efficient investigation from a confident summary built on incomplete telemetry.

Integrations, Coverage, and Deployment

Architecture breadth can increase value and onboarding work at the same time. Exaforce's scope extends across identity, endpoint, email, SaaS, infrastructure as a service, Kubernetes, and code context (Exaforce).

Coverage should follow attack chains

A useful integration does more than ingest a headline alert. It should expose the identities, assets, events, relationships, and response actions needed to prove or disprove a case. During evaluation, map one real attack chain across the required systems and mark every point where context disappears.

Read access and write access must be separated. A connector may support evidence gathering without supporting containment. Record permissions at the action level, then test expired credentials, rate limits, partial outages, and stale data.

Treat onboarding speed as a first-party claim

Exaforce markets rapid deployment and early context through its data layer (Exaforce). Treat any time-to-value statement as company-reported until your environment reproduces it. A cloud-native company with standard tools may connect quickly. A regulated enterprise with bespoke logs, regional restrictions, and approval gates will not share that path.

Run the pilot on live historical cases plus controlled new alerts. Score source coverage, evidence accuracy, reproducibility, time saved, analyst corrections, and safe response. Include at least one case that crosses identity, endpoint, and cloud. A clean single-source phishing alert is too easy to validate a full-lifecycle platform.

A useful deployment has three gates. First, confirm data completeness against a known incident. Second, run Exaforce in shadow mode and compare conclusions with the current team. Third, permit low-risk actions only after the evidence and rollback path are repeatable, then expand response authority one action at a time. Deployment succeeds when analysts trust the evidence and the permissions are bounded, not when all connectors show green.

Funding, Customer Evidence, and Strategic Risk

Exaforce has raised enough capital to build aggressively. That fact says more about investor appetite than security efficacy.

Funding is independently corroborated

Exaforce raised $75 million in a Series A round, then announced a $125 million Series B in May 2026, bringing company-stated total funding to $200 million (Exaforce). TechCrunch independently reported the round, a $725 million valuation, and the $200 million total (TechCrunch).

Verified financing against the one performance number · TechCrunch and Exaforce
$75Mseries a round $125Mseries b, may 2026, taking the total to $200m $725Mvaluation, reported independently by techcrunch 10xsoc efficiency, company-reported by design partners, no shared baseline

Exaforce says the money will support product development, the real-time knowledge graph, MDR oversight, customer success, and international expansion (Exaforce). That is the company's intended use of proceeds. The independently reported round gives Exaforce runway; it does not validate detection coverage or customer retention.

Customer proof remains mostly first-party

Exaforce's tenfold efficiency statement comes from its own design-partner announcement (Exaforce Series A announcement). Customer stories and testimonials can show plausible workflows, but they do not provide a common cohort, false-negative measurement, or audited margin result.

Buyers should request reference cohorts that resemble their data volume, stack, and operating model. A design partner using platform mode does not prove MDR service quality, and an MDR testimonial does not prove internal teams can deploy the platform economically. That gap is common among the vendors compared in the AI SOC field guide.

Strategic risks to price into diligence

Four risks stand out: private pricing, dependence on broad data access, difficulty comparing productivity claims, and hybrid channel overlap. A Managed Security Service Provider (MSSP) evaluating platform mode should ask whether Exaforce MDR can pursue the same customers. An enterprise should test data portability and exit before allowing the platform to become the investigation record.

The evidence hierarchy is simple: official architecture supports product scope, independent reporting supports financing, and your own controlled cases must support performance.

Investors should ask how much revenue comes from platform versus MDR, whether delivery headcount grows with managed customers, and how retention differs between modes. Hybrid revenue can be resilient, but it can also hide services cost inside a software story. No public segment economics were available in the reviewed evidence, so margin conclusions would be speculation.

The Bottom Line

Exaforce is not one thing. It is a shared security data and Exabot foundation sold through two accountability models.

A mature SOC should evaluate platform mode if it wants full-lifecycle investigation capacity while retaining its analysts, queue, and response control. A lean team should evaluate Exaforce MDR if 24/7 monitoring and operated investigation matter more than internal control. An MSSP should examine channel ownership carefully, because Exaforce's managed offer can overlap with the service layer the MSSP sells (Exaforce MDR).

My recommendation is to run a bounded proof of value before making the platform central: your own alerts, cross-source attack chains, and every response permission documented. Put the operating boundary in writing: who monitors, who approves, who acts, and who explains a wrong decision. Settle exit and data-export terms in the same decision, not after production rollout.

Exaforce's architecture and financing make it a serious entrant. Its company-reported outcomes are not yet a substitute for independent, comparable security evidence. Buy the mode whose accountability matches your team, then verify the performance in your environment. Select 50 to 100 representative cases, agree the expected evidence and response boundaries before the test, and run both operating modes through the same vendor scorecard. The winner should be the model that produces reliable outcomes with a responsibility split your team can sustain.

For related analysis, see AI SOC economics and the cybersecurity market map.

FAQ

Does Exaforce replace a SIEM?

Exaforce's public materials do not establish a SIEM replacement claim, although the platform presents a unified real-time data layer across the full SOC lifecycle. Map which storage, detection, compliance, and search functions stay in your current stack before removing anything (Exaforce).

What are Exaforce Exabots?

Exabots are Exaforce's task-specific agents for detection, triage, investigation, and response. They share context through Exaforce's security data layer rather than acting as one general chatbot (Exaforce).

Can you use the Exaforce platform without buying Exaforce MDR?

Yes. Exaforce offers a self-operated platform and, separately, a managed MDR service combining Exabots, human analysts, and 24/7 monitoring (Exaforce MDR).

How much does Exaforce cost?

Exaforce publishes no normalized list pricing on its official product pages. Ask for the complete price unit and every extra attached to it before comparing bids against another vendor.

Does Exaforce replace human SOC analysts?

No. In platform mode, customer analysts govern conclusions and response; in MDR mode, Exaforce combines Exabots with its own analysts for continuous operation (Exaforce MDR). The labor mix shifts toward supervision, exceptions, response judgment, and customer communication, so test the supervision burden in both modes and include that human work in the total operating cost.

Should an MSSP resell Exaforce or treat it as a competitor?

An MSSP should resolve channel overlap first, because Exaforce sells both the platform an MSSP would operate and an MDR service that can pursue the same end customers (Exaforce MDR). Get the account-conflict and renewal terms in writing before building a service on top.