Legion Security

Agentic security operations platform that learns analyst workflows and turns them into agentic playbooks

ToolTier 1 SOC AutomationCloudFeaturedVendor-verifiedTier 1 automation in the browser

Reviewed by the Cyber Vendor Guide editorial team against the public sources cited below and information provided directly by the vendor · Last reviewed September 2026 · How we review listings

What is Legion Security?

Legion Security helps enterprise security teams scale detection, investigation and response using agentic AI. The platform learns from the real workflows security teams already run, across the SOC and beyond, and turns that institutional knowledge into agentic playbooks the team can trust and audit. This lets organisations adopt frontier AI models gradually while preserving operational trust, cutting manual effort and building toward autonomous security capabilities. Rather than depending on API integrations, Legion combines vision models with other methods to observe how practitioners actually work, so teams can codify those processes as they are or optimise them into transparent, inspectable agentic workflows, extending the same approach beyond the SOC to security operations across the enterprise. Legion Security has offices in New York and Tel Aviv and is backed by Coatue, Accel and Picture, with investors from Island, CrowdStrike, Wiz and Google DeepMind. The company was founded in 2024 by former Microsoft Sentinel team members and emerged from stealth in July 2025.

Best for: SOC teams that want to automate their existing analyst workflows without building or maintaining API integrations.
Pros
  • Raised $38M total: an $8M seed led by Picture Capital and Accel, and a $30M Series A led by Coatue (Calcalist, Fortune)
  • Founding team includes former members of Microsoft's Sentinel product, per Calcalist
  • Browser-based deployment is designed to avoid custom API integration work, per the company
  • Customers cited on the vendor site report outcomes such as an 81% reduction in MTTI/R (WELL Health Technologies, vendor-cited)

Key Features

Learning mode that extracts operational knowledge from analyst investigations, playbooks, runbooks and past cases
Companion mode that executes workflows through the analyst's browser with human oversight
Autonomous mode for running trusted workflows with reduced human intervention
Browser-native, zero-integration deployment that works across existing security tools
Alert triage and investigation, including email and phishing analysis
DLP alert processing
SOC 2, HIPAA, ISO 27001 and ISO 42001 certifications listed by the company
Legion Security logo

The agentic security operations platform for the enterprise

Case studies

Virgin Money: 30,000 backlogged alerts processed in under two months

60 percent reduction in alert backlog

Legion's agentic SOC automation processed 30,000 backlogged alerts for Virgin Money in under two months, learning the bank's existing analyst workflows along the way. Result as reported by Legion Security; the testimonial is given by Neil Robinson, CISO at Virgin Money.

Read the case study →

Sources & references

Where the information on this listing comes from. Always verify pricing and capabilities against the vendor before a purchasing decision.

Spot an error, or do you represent Legion Security? Request a correction.