Legion Security
Legion Security is a browser-native, agentic AI platform that observes human SOC analysts' investigations and automates their workflows, launched publicly in mid-2025 with $38M in seed and Series A funding.
Visit Website ↗ + Add to CompareOverview
Legion Security, founded in 2024 by security veterans including Ely Abramovitch (CEO) and Michael Gladishev (VP of R&D, both credited with prior work building Microsoft Sentinel), emerged from stealth in July 2025 with $38 million raised from Coatue, Accel, and Picture Capital, plus angel backing from individuals connected to Google, CrowdStrike, and Wiz.
Its Agentic Security Operations Platform runs as a browser extension across three modes — Learning (observing analyst workflows), Companion (executing with human oversight), and Autonomous (independent scaling of trusted workflows) — with the explicit design goal of learning an organization’s specific tools and processes without requiring API integrations. The company holds SOC 2, HIPAA, ISO 27001, and ISO 42001 certifications and reports enterprise customers including Virgin Money, IQ-EQ, and the University of Tulsa.
Innovation Matrix Assessment
Legion shipped a working three-mode agentic platform and landed named enterprise customers within roughly a year of founding, indicating rapid execution for a company still this early.
If its reported up-to-90% reduction in investigation and response time holds even partially, integration-free analyst workflow automation would meaningfully ease Tier 1 SOC staffing pressure — though this figure is company-reported.
Winner of three 2026 Global InfoSec Awards (Best Solution — Security Automation; Market Disruptor — AI Powered Cybersecurity Solutions; Most Innovative — AI SOC); also raised $38M from Coatue, Accel, and Picture Capital with named enterprise customers including Virgin Money and IQ-EQ.
The browser-native, no-integration model for learning and automating analyst workflows is a genuinely different architecture from the API-integration-heavy SOAR/XDR automation model most competitors use.
SOC 2, HIPAA, ISO 27001, and ISO 42001 certifications and named enterprise customers provide some independent grounding, but the company is under two years old and its headline efficacy statistics remain vendor-reported.
SOC analyst shortages and rising alert volumes make AI-driven investigation automation a durable, growing need rather than a passing trend.
Why CISOs Should Care
For CISOs struggling to retain and scale Tier 1 SOC analyst capacity, Legion offers a way to encode institutional investigation knowledge into AI agents without a lengthy, integration-heavy SOAR deployment.
What Makes It Different
Legion's browser-native, integration-free approach — learning by observing analysts directly rather than requiring API connections to every tool in the stack — is a meaningfully different architecture from typical SOAR/XDR automation platforms.
The Matrix Verdict
65/100 — INCREMENTAL INNOVATOR
A well-funded, credibly staffed early-stage SOC automation platform with genuine architectural differentiation and real 2026 award recognition, though still young enough that long-term efficacy at scale is not yet independently proven.
Editorial Note: Claims vs. Verified Findings
Founding team background, funding amount and investors, and certifications are corroborated via independent press coverage (SiliconANGLE, Newswire); the reported 90% investigation-time reduction and specific customer outcomes are company-reported and not independently audited.
Sources
- https://cyberdefenseawards.com/global-infosec-awards-for-2026-winners-by-company/
- https://www.legionsecurity.ai/
- https://siliconangle.com/2025/07/30/legion-raises-38m-automate-soc-workflows-browser-native-ai/
- https://www.newswire.com/news/legion-emerges-from-stealth-with-38m-to-redefine-ai-driven-security-22614382
Alternatives to Legion Security
Abnormal AI
AI-native behavioral security platform that analyzes sender identity and communication patterns, rather than message content alone, to stop…
Palo Alto Networks Cortex XSIAM
Palo Alto Networks' AI-driven 'autonomous SOC' platform that unifies SIEM, EDR, SOAR, and attack-surface data into a single…
Fenix24
Chattanooga-based ransomware recovery specialist that has restored operations after 500+ real-world incidents, including 30 Fortune 500 companies.
Torq
AI-native hyperautomation platform positioning itself as an 'agentic SOC,' using a multi-agent system to autonomously execute large volumes…
Anvilogic
Palo Alto-based AI security operations platform that automates SOC detection engineering across existing SIEMs and data lakes without…
Tines
No-code security automation platform letting SOC teams build and share automated workflows ('Stories') without proprietary scripting or vendor…