Dossier · Private startup · 1 independent source
Torq
Last updated: Jul 31, 2026
Agentic AI SOC and security hyperautomation platform that helps enterprise and managed security teams triage, investigate, and remediate security events across their existing tool stacks.
Visit WebsiteCompany Overview
Torq builds an agentic AI security operations platform centered on hyperautomation, case management, and workflow execution. HyperSOC groups alerts into cases, enriches them with context, prioritizes them, and supports investigation through Socrates, while the underlying Hyperautomation layer connects security, identity, IT, and business systems. The product combines deterministic playbooks with AI agents for runbook creation, investigation, remediation, and case management. That architecture matters because it gives customers a controlled path from natural-language intent to repeatable actions rather than asking an LLM to operate without the surrounding workflow, evidence, and approval context.
The market problem is persistent: SOC teams face high alert volumes, fragmented telemetry, staffing constraints, and pressure to reduce mean time to respond. Torq sells into enterprise security teams and MSSPs that already own many detection and response tools but need an orchestration layer across them. Its use cases include phishing response, identity and access actions, threat-intelligence enrichment, alert investigation, fraud workflows, and operational ticket automation. The commercial value proposition is therefore less about replacing every security control than about making the existing stack produce a faster, more consistently governed response.
Commercially, Torq has moved well beyond an early niche tool. The company reported 300% revenue growth and 200% employee growth in 2024, opened a London EMEA headquarters, and lists enterprise and MSSP customer stories involving organizations such as Check Point, RSM, Valvoline, Kenvue, and Deepwatch. In January 2026 it announced a $140 million Series D led by Merlin Ventures at a reported $1.2 billion valuation, bringing total funding to $332 million; those figures are company-reported and should be confirmed in diligence. Torq's own company page now reports 400+ employees, while its customer page reports large automation volumes and response improvements. These signals indicate substantial adoption and financing, but they do not substitute for checking recurring revenue quality, retention, gross margins, deployment concentration, and the proportion of outcomes attributable to customer-specific services.
From a defense and national-security perspective, the overlap is substantive but bounded. Automated triage, evidence collection, case orchestration, and policy-constrained containment can support government SOCs, critical-infrastructure defenders, cyber defense units, and MSSP operations serving those customers. The technology does not itself provide offensive capability, battlefield sensing, or mission hardware; its relevance is in defensive cyber operations and the resilience of security teams. Torq's 2026 announcement explicitly identifies expansion into the U.S. federal market, but public materials reviewed here do not establish government contracts, certifications, or production deployment in defense organizations. Those deployment, compliance, data-residency, auditability, human-approval, and fail-safe questions are central to validating the dual-use thesis.
Dual-Use Assessment
Torq's security automation, case orchestration, and response tooling have clear commercial SOC value and credible applicability to government, critical-infrastructure, and defense cyber operations. The adjacency is defensive and operational: reducing analyst load, accelerating investigation, and executing governed containment, with public-sector deployment and compliance still requiring verification.
Strategic Fit Assessment
Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.
Torq fits the site's dual-use technology thesis because its core product applies agentic AI and workflow orchestration to a mission-critical cybersecurity bottleneck. The Series D, reported customer expansion, and 400+ employee scale are credible maturity signals, while deep workflow and integration adoption could create operational stickiness. The priority signal is offset by a crowded market, high valuation expectations, and the need to verify retention, unit economics, model safety, and public-sector readiness; this field is not an investment recommendation.
Strategic Value to U.S.-Israel Alliance
Torq's strategic value lies in owning the control plane between security detections and operational action. If its agents can reliably correlate alerts, gather evidence, and execute bounded responses across heterogeneous tools, it can improve cyber-defense capacity without proportional analyst growth. That is relevant to enterprises, MSSPs, critical infrastructure, and government SOCs. The value is strongest as defensive cyber infrastructure, but depends on auditability, deployment controls, data handling, and the ability to coexist with incumbent SIEM, XDR, identity, and case-management systems.
Key Technologies
- Multi-agent AI for SOC triage, investigation, and remediation
- Security hyperautomation and SOAR workflow orchestration
- Alert correlation, case creation, prioritization, and evidence assembly
- Natural-language runbook and workflow generation
- Policy-constrained deterministic and agentic response playbooks
- Threat-intelligence enrichment across security and identity systems
- Large connector and integration layer for enterprise security stacks
Use Cases & Applications
- High-volume SOC alert triage and prioritization
- Automated enrichment of suspicious events with threat intelligence
- Incident investigation, case timelines, and evidence gathering
- Containment and remediation across endpoint, identity, email, and cloud tools
- Phishing, identity, fraud, and abuse response workflows
- Security operations automation for MSSPs and multi-tenant customers
- Government, critical-infrastructure, and defense cyber defense center workflows
- Custom workflow generation for repetitive security and IT processes
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.
This record lists 7 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- torq.io Public source used for profile verification.
- torq.io Public source used for profile verification.
- torq.io Public source used for profile verification.
- torq.io Public source used for profile verification.
- torq.io Public source used for profile verification.
- torq.io Public source used for profile verification.
- kb.torq.io Public source used for profile verification.
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.