D3 Security
Vancouver-based SOAR pioneer whose Smart SOAR and newer Morpheus platform automate SOC alert triage and incident response for enterprise, public-sector, and MSSP customers.
Visit Website ↗ + Add to CompareOverview
D3 Security builds SOAR (security orchestration, automation, and response) technology, most recently under the Morpheus and Smart SOAR product names, designed to automate the triage, investigation, and response work that otherwise consumes SOC analyst time. The platform connects to a large library of third-party security tools (D3 cites more than 800 integrations), correlates and enriches alerts, and applies automated playbooks so that a large share of incoming alerts can be triaged without a human touching each one individually — the company’s own figures put this at up to 95% of alerts triaged and investigated in under two minutes.
D3 traces its incident-response-automation roots back to 2015, before Gartner formally coined the term SOAR, and the company is headquartered in Vancouver, British Columbia, with roughly 175 employees and reported 2024 revenue of about $11.9 million. In 2021, D3 raised $10 million in growth equity from Vistara Growth alongside a $5 million credit facility, funding that supported international expansion. The company has explicitly positioned itself as a vendor-agnostic, independent SOAR platform, distinguishing it from SOAR features bundled into a specific SIEM vendor’s ecosystem, and Microsoft’s own security blog has featured D3’s integration for automating response across Microsoft’s security product suite — a notable third-party validation point given Microsoft’s own competing security tooling.
For CISOs running or evaluating a SOC, D3 is relevant as a platform bet aimed at analyst efficiency and alert fatigue, particularly for MSSPs and larger security teams managing high alert volumes across many disparate tools; its independent, cross-vendor integration approach is the clearest differentiator versus SOAR capabilities built into a single SIEM or XDR vendor’s stack.
Innovation Matrix Assessment
D3 has evolved its platform from legacy SOAR into the newer Morpheus agentic AI SOC product line, indicating continued platform reinvention rather than a static offering.
Roughly 175 employees and approximately $11.9M in 2024 revenue, serving enterprise, public sector, and MSSP customers across multiple global regions, indicate a reasonably mature mid-market security vendor.
Continued platform development (Morpheus) and expanding MSSP multi-tenant capabilities suggest active investment, though the company's last disclosed major funding round was in 2021.
D3's vendor-agnostic, independent SOAR positioning (as opposed to SOAR features bundled into a single SIEM vendor's stack) combined with claims of automating up to 95% of alert triage is a meaningful differentiator, though SOAR itself is now an established category D3 helped pioneer rather than a brand-new concept.
D3's integration being featured on Microsoft's own security blog for automating response across Microsoft's security suite is a notable independent validation point; the 95%-in-under-two-minutes triage figure, however, is a vendor-reported statistic without an independent benchmark found to confirm it.
SOC alert fatigue and analyst shortages remain persistent, well-documented problems, keeping SOAR-style automation a consistently relevant investment area for security operations teams.
Why CISOs Should Care
D3 targets a concrete, costly SOC problem, analyst time spent on repetitive alert triage, with a vendor-agnostic automation platform that connects across a large existing tool stack rather than requiring lock-in to one SIEM ecosystem.
What Makes It Different
D3 markets itself explicitly as an independent, cross-vendor SOAR platform rather than a SOAR feature bundled with a specific SIEM or XDR product, which matters most to MSSPs and larger teams running heterogeneous tool stacks.
The Matrix Verdict
60/100 — INCREMENTAL INNOVATOR
An established SOAR pioneer with a credible, continuously evolving platform and at least one notable independent validation point (Microsoft's own security blog), though its headline automation statistics remain vendor-reported rather than independently benchmarked.
Editorial Note: Claims vs. Verified Findings
The Vistara Growth investment, employee count, and revenue figures are corroborated by Business Wire/BetaKit reporting and third-party data aggregators respectively. The claim that Morpheus triages and investigates up to 95% of alerts in under two minutes is a vendor-stated performance figure with no independent benchmark identified and should be treated as a marketing claim pending third-party verification. D3's own founding-year claims vary across sources (2002 vs. 2012 appear in different databases); 2012 is used here as the more consistently cited figure.
Sources
Alternatives to D3 Security
Abnormal AI
AI-native behavioral security platform that analyzes sender identity and communication patterns, rather than message content alone, to stop…
Palo Alto Networks Cortex XSIAM
Palo Alto Networks' AI-driven 'autonomous SOC' platform that unifies SIEM, EDR, SOAR, and attack-surface data into a single…
Fenix24
Chattanooga-based ransomware recovery specialist that has restored operations after 500+ real-world incidents, including 30 Fortune 500 companies.
Torq
AI-native hyperautomation platform positioning itself as an 'agentic SOC,' using a multi-agent system to autonomously execute large volumes…
Edge Delta
A telemetry pipeline and AI-agent observability platform that processes logs, metrics, and security data at the edge to…
Lumu Technologies
Network detection and response vendor using Continuous Compromise Assessment to show where compromise has actually happened, integrating with…