Overview

Product video
Torq is the AI SOC platform that combines agentic insights and automation so that enterprises can triage, investigate, and respond to actual risks, faster. Torq streamlines every step from alert through resolution, expanding capacity and throughput. First, Torq ingests and normalizes telemetry from across your security stack, preparing the data for agentic reasoning at scale. Auto Triage filters out noise and prioritizes actual threats. Next, cases are automatically opened and assigned to highly specialized AI agents designed for investigation and response. Using tools and actions you specify, they gather evidence, assemble timelines, and transparently record decisions and authorized actions. Your team is in complete control. With Torq, your SOC delivers more results, more efficiently, from triage through remediation.
Highlights
- Eliminates alert fatigue - Torq's AI SOC platform integrates with AWS security tools to provide a unified view of security cases that prioritizes urgent threats to help decrease mean-time-to-response (MTTR).
- Ends tech sprawl - Torq's AI SOC platform addresses tech sprawl with integrations across the entire security stack. Now security teams can overcome the challenges posed by complex multi-cloud environments and evolving security threats.
- Addresses talent shortage- Torq's AI SOC platform capabilities enable security teams to achieve more with fewer resources, reducing the need for manual tasks. Pre-built integrations with AWS services automate complex processes, empowering less experienced analysts, and improving overall productivity.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
Torq Essential | Essential Plan | $450,000.00 |
Torq Enterprise | Enterprise Plan | $450,000.00 |
Torq Elite | Elite Plan | $450,000.00 |
Vendor refund policy
Please contact us at sales@torq.io
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
https://support.torq.io support@torq.io . By purchasing, deploying, accessing, or using this product, you agree to comply with the AWS Marketplace Standard EULA, and the terms of applicable open source software licenses bundled with the product. In addition, if you elect to use any artificial intelligence (AI) features made available by Torq as part of the product, the Torq AI Terms shall govern your use thereof. Pursuant with the Data Processing Addendum, you authorize the engagement of the sub processors listed at: https://torq.io/legal/subprocessors/ , as may be updated by Torq from time to time.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

Standard contract
Customer reviews
Modern automation has transformed alert triage and now unifies incident handling for analysts
What is our primary use case?
As MSSPs, we serve our customers using Torq , and I work as a consultant in an MSSP that uses Torq as our main SOAR platform for our SOC.
Our usual use cases for Torq involve a variable amount of scenarios. We use it for fast automation building, as the automation building capability in Torq is low-code and quick with less scripting involved. This enables faster Tier 1 SOC automation, so all Level 1 analyst work is eliminated with Torq.
Our other use case centers on its cloud-native architecture. Torq makes use of API-first integrations and event-driven workflows with AI-assisted triage and response capabilities. It can be integrated with different multi-cloud vendors as well as other SaaS stacks, other MDR, and MSSP operations. Integration with cloud technologies is very straightforward.
Regarding Torq's automation of triage, investigation, and remediation actions across multiple attack surfaces, the data ingestion pipeline and workflow are excellent. Torq ingests alerts from a SIEM , EDR, CSPM, IAM , email, ASM, and other sources. It then performs normalization and enrichment. The third phase involves correlation across services, correlating data between different platforms when alerts arrive from endpoints, identity, cloud, network, or other sources. After correlation, the AI rule-based triage determines whether an alert is a false positive, a real attack, or its priority level. This is managed by the AI Agentic software within Torq. The automated response playbook then comes into play for remediation. If a playbook has been configured, it may disable a user, isolate a host, revoke a token, or patch a cloud issue based on what the AI detected. The final stage involves ticketing and validation. Torq audits everything, generates a ticket regarding whether the task has been completed, and includes a validation point that ensures all completed work has been confirmed or validated for completeness.
What is most valuable?
The valuable and important aspects I find about Torq include how it was deployed in our environment and integrated with every other technology within our SOC, which was a straightforward task with minimal hassle. The documentation from Torq was thorough, and we were able to integrate other technologies well.
Torq's UI interface is easy to understand and digest. It is visually appealing and information flows consistently, making it easy to grasp whether you are looking at it for the first time or have been working on it for a month or two. The interface is logical in terms of page navigation and how settings are organized by category, all sensibly categorized.
In terms of how Torq has changed the day-to-day experience for my security analysts regarding their workload and job satisfaction, the analysts feel more confident. They believe Torq has all the elements that increase their confidence in how technology should look and integrate with every other piece of technology within our SOC. Under one SOC tool in Torq, analysts get to know everything within the context of an alert or incident they are working on. Torq also provides analysts with a comprehensive viewpoint where they can see all alerts coming from various software, technologies, and alerting systems for a certain customer. This ability to view the whole picture within Torq is one of the major breakthroughs and best offerings of Torq.
What needs improvement?
Torq does extensive marketing saying that SOAR is dead and markets itself as an all-in-one solution, but this is not actually true. Torq is a SOAR platform. Branding that suggests SOAR is dead might not be the best approach. Similarly, marketing Torq as an AI SOC replacing SOAR is part of the overall branding strategy, but Torq should position itself as a SOAR platform because that is what it is. If Torq brands itself as an AI SOC or something else, there might be different outcomes in the long run.
The AI value depends on maturity. Real value depends heavily on telemetry, integration depth, and workflow design, all of which rely on how mature customers are in their SOC department. There is a dependency in this relationship. Enterprise complexity still exists as well. Although Torq is easier than older SOAR tools, large deployments can still become operationally complex, integration-heavy, and governance-sensitive. Many organizations apply extensive governance for security, and Torq does not always comply with all the policies that certain enterprises require.
For how long have I used the solution?
I have been working with Torq for almost four months.
What do I think about the stability of the solution?
Torq is quite stable and reliable with consistent performance. I have not encountered any bugs or errors.
What do I think about the scalability of the solution?
Torq is quite scalable and can scale to accommodate whatever amount of customers you onboard or whatever volume of incidents or alerts are generated daily.
How are customer service and support?
We do not often communicate with Torq's technical support. We had to contact them during initial installation, but we have not needed to since. My impression of their technical support during the initial setup was that they were helpful, responded within a reasonable timeframe, and provided exactly what we needed.
Which solution did I use previously and why did I switch?
Before using Torq, we were using Google Simplify, a SOAR platform by Google, which we used for about four or five years. Before that, we were not using any SOAR solution.
How was the initial setup?
I participated in the initial setup of Torq, which was not complex. Everything was straightforward with minimal hassle. All customization had to be done through APIs, which is always the best approach. There were not many issues during the initial deployment.
What was our ROI?
We are still in the process of realizing value with Torq. Since we transitioned from another SOAR just a few months ago, we have not conducted any system review or performance review. After a six-month or twelve-month period, we will likely conduct a performance review. For now, we are still assessing how much efficiency improvement we have achieved with Torq enablement. Generally speaking, the analysts are very pleased with it, and the integration of how Torq connects is working well.
Which other solutions did I evaluate?
Before choosing Torq, we evaluated other vendors including Tines , Splunk SOAR , Microsoft Sentinel Automation, and Palo Alto Cortex XSOAR . We ultimately decided on Torq.
We dismissed other options in favor of Torq for a variety of reasons. Our solution architect team conducted extensive analysis to determine which platform would move forward, alongside company negotiations and the support we were receiving from Torq. The decision was not based on just one or two factors, but rather on an in-depth analysis.
What other advice do I have?
Comparing Torq's unified platform approach to AI SOC automation and case management with my experience managing multiple point solutions across my security stack, I find that Torq is modern because many other platforms lack this quality. When I say modern, I mean it encompasses everything—the UI interface, integrations, the ability to use AI, and the ability to navigate through cases. Other platforms that are not as modern lack in one or two departments. With Torq, case handling and how a case moves from instantiation through analyst work to resolution or closure—all these stages are managed in a way that is somewhat similar to how other platforms handle them, but it is more modern and represents how technology should look in 2026. The UI interface is quite good, which makes a significant difference in how you view the technology. While it is not a very big leap in terms of case handling compared to other platforms, it still represents an improvement when compared with other multi-integration or multi-connecting platforms.
Regarding the pricing and licensing of Torq, I cannot comment extensively because pricing has been controlled by our product manager. The relativeness between what pricing we received from the previous SOAR and our current Torq pricing is something that should be asked from a product manager, as we as architects and engineers do not handle the sales aspect of the technology. The pricing appears to be user-based rather than database-based, meaning it is based on the number of analysts working on the platform, whether that is fifty, twenty, or thirty, which represents good value.
I would rate this review eight out of ten.
Automation has transformed security operations and now reduces manual soc effort significantly
What is our primary use case?
Torq is primarily used for security operations, mainly for the SOC team. I develop use cases based on requirements from what the SOC team does in everyday operations. Based on those requirements, I implement security use cases and automations.
For example, when a new user is created, there is a simple workflow where you provide a username, start the workflow, and it completes execution, creating the user everywhere without issues. We have a lot of use cases implemented and are actively using them.
Torq automates triage, investigation, and remediation actions across multiple attack surfaces. Currently, we are using it for SOC operations only, but it satisfies everything we need.
How has it helped my organization?
Torq has helped a lot regarding SOC analyst efficiency. We previously had a team of thirty people working in shifts, but now we have reduced the team by half to fifteen members, which allows the remaining members to focus on other areas. Our team is able to handle all activities because everything was previously manual.
Now they just need to get a URL from Torq, hit that URL, and the workflow runs and does the job. Previously, they spent hours on single tasks, but now they can complete them in five minutes, two minutes, or ten minutes, which is very time-saving.
What is most valuable?
Torq is an excellent product. There are no significant drawbacks. However, sometimes we need to write custom scripting. Personally, I love to write scripts, but this is a problem for people who do not know scripting or do not prefer scripting.
Additionally, the documentation for Torq is not very clear. Most of the information is presented in videos, which are not ideal for reading; there are mostly paragraphs and other text-based content.
Torq demonstrates very good scalability. We can create any number of use cases and alerts. There are also default ready-to-use playbooks available that we can use. It is a scalable product.
What needs improvement?
To improve alert handling capability, there are ready-to-use playbooks available, but there are very few. Torq should add more playbooks. For example, everyone needs user creation and deletion, and all companies use firewall data. Torq should offer default templates that can directly scan firewall data and automate actions.
Additionally, the logging and debugging visibility for what Torq does in the backend is not very visible, so this aspect could be improved.
For how long have I used the solution?
I have been using Torq for the last one and a half years. We recently purchased this new product in our environment.
What do I think about the stability of the solution?
Torq is good from a stability perspective. I have never faced any downtime or issues.
How are customer service and support?
We have contacted technical support many times. When we purchased the product, we often called the pre-sales person to discuss use cases. We asked if we could build certain use cases and if not, what the alternatives were. This support was very helpful and is a good aspect of Torq. The support team is always available. I would give them a nine out of ten for support.
Which solution did I use previously and why did I switch?
Previously, we were using Splunk SOAR , and we switched to Torq because Splunk SOAR requires a lot of technical knowledge. In Torq, we found it very easy with its graphical GUI. There is no code required; you just drag and drop everything and do simple configurations on the right-hand side tab panel, and that is all. Workflows are implemented easily, which is excellent.
How was the initial setup?
The initial deployment is easy because we purchased only the cloud version. I do not know if it is also possible on a hybrid model, but we purchased the cloud version. It requires very minimal effort to deploy all workflows easily.
What was our ROI?
We did not see the benefits of Torq immediately. After four or five months, we started to see the benefits because it was in the beginning stage, and no one was familiar with it. Initially, we learned and investigated the product and conducted many POCs. It took about five to six months because I did not find much proper documentation. I did some courses, including a pre-sales course and an admin course, which were good, but it took six months to see the benefits.
What's my experience with pricing, setup cost, and licensing?
I do not have much knowledge about the pricing. Initially, I heard that we are using the cloud version, which is considered cheap compared to Splunk and others.
Which other solutions did I evaluate?
Torq is very comparable to other tools. I know some products in the market, including Tines , Palo Alto XSOAR, and Splunk SOAR. Compared to these three, I find Torq valuable because other products do not do all the things.
However, one disadvantage of Torq is that it works only for security and security-related operations. It will not do any other automation, like alerting through email or getting data from Splunk to alert somewhere in ServiceNow ; that is not possible.
What other advice do I have?
The maintenance side is very good because we are using the product to reduce activities. For instance, sometimes there is an alert or phishing email, and we want to address it immediately. For that purpose, Torq is very helpful and is doing its job greatly. There is no maintenance required on our end. I would rate this product at nine out of ten.
Automation has transformed security operations and streamlines complex incident triage
What is our primary use case?
My use case for Torq encompasses all aspects of security automation. I utilize it for running automation for the security department, not all departments in my organization, but mainly for the security department.
I use it for operations automation, where I automate some of the operations processes. I also use it for a SOC platform, as I get all of my security incidents into Torq and prioritize and escalate to the relevant person to review and take response actions automatically.
How has it helped my organization?
reduced MTTD MTTR MTTE
What is most valuable?
The best features in Torq make it feel versatile and comprehensive. I can do everything with Torq. If something is not possible through out-of-the-box integration between two vendors, I can put Torq in the middle of the process and Torq will help me connect systems together, automate the entire process, and automate data flows, prioritization, and data manipulation.
Any request that comes in, regardless of how complex it is, I can accomplish it with Torq. If there are no direct integrations between two systems, Torq can always come in between them and automate the integration.
It has so many capabilities that I can connect everything by using APIs or HTTP requests or running scripts to automate the connection between systems. Regardless of how complex the things I would like to do with Torq are, I will always be able to do that. There is no such thing as not being able to do something with Torq; I will find a way to do that.
Agentic AI helps with alert handling by simplifying the process of parsing different data where data sources can change the schema of the data. It is really simple for me to do that with Torq and the Agentic AI; I do not need to keep track of everything and manage that manually in the automation, as the Agentic AI can do that for me.
Also, for the enrichment part, the Agentic AI can enrich all of my data straightforwardly with the right guardrails in place.
Regarding Torq's unified platform approach to AI SOC automation, I understand it is not a global feature yet, but they are working on one of the most critical features called Auto Triage. This feature would dramatically change the way AI SOC is provided to customers.
The AI can investigate cases or security incidents, and through their AI agents or engines, they can determine whether a case is a true positive benign, true positive malicious, or false positive. Based on this categorization, I can really reduce the amount of work that escalates for a human being to review and take action upon.
What needs improvement?
The areas that have room for improvement in Torq include the way cases or data can be presented and data manipulation in automation.
For how long have I used the solution?
My experience using Torq is about a year and a half, or even more than that, maybe two years.
What do I think about the stability of the solution?
I would rate Torq's product stability at eight, acknowledging that there are bugs, glitches, and downtimes.
What do I think about the scalability of the solution?
From a scalability perspective, I would rate Torq as a ten for my 30 people working globally.
How are customer service and support?
I would rate the vendor's technical support as an eight.
Which solution did I use previously and why did I switch?
When I decided to go with Torq, I did a POC with three other major players in the SOAR world. What I appreciated most about Torq is the simplicity to connect systems or to do things that are not available outside of the box.
If Torq does not provide a step or an action out of the box to do with a third-party system, I can simply and straightforwardly plug it into Torq by reviewing the third-party system documentation and do it on my own without a lot of complexity. It is easy and impressive.
How was the initial setup?
Torq is very easy to maintain.
What about the implementation team?
Regarding how often maintenance is required, I would say that the maintenance involves automation, not the platform itself. It is maintaining the things that I have built, so I would say maintenance occurs on a weekly basis.
What was our ROI?
In terms of return on investment, I think I have saved about one hundred fifty percent in time, resources, and money.
What's my experience with pricing, setup cost, and licensing?
Regarding the pricing of Torq, I would say it is expensive. All cyber solutions are expensive. When they bring more and more value into the platform, it makes more sense to pay that price, but still, it is expensive.
Which other solutions did I evaluate?
What other advice do I have?
I realized the value of Torq even within days. It was much easier and much simpler. Even on the demo call, I asked very specific questions because I knew the gaps that I had in other platforms.
In the demo call, I saw that they had solutions to all of my pain points, so I knew from the beginning that it was going to be a match. I do recommend this product.
My advice to others looking into implementing it would be to utilize their AI agents to help build things they do not know how to do. Their AI assistants and AI agents helped me accomplish many complex tasks with minimal effort. I would rate this product a nine overall.
Automation has transformed daily alert handling and now frees hours for deeper security work
What is our primary use case?
I use Torq as my case management and alert system. Working as a SOC analyst, the first thing I do every morning is get into Torq , review all the open cases and incidents, understand their severity, investigate them, and close them if they are legitimate. I also investigate whether there is anything malicious. I use Torq daily.
We build workflows inside Torq—automations that can automate every action that we do manually. For example, we send Slack messages to users who we think shared corporate data, or investigate specific machines where we suspect there is some sort of SQL injection. We can automate every type of security-related incident through the workflows in Torq.
What is most valuable?
All the workflows are something really particular. From what I have seen in the past, I have never seen this maturity of automated processes, and the whole idea of drag and drop automation is really simple. This is something I have never seen before. Even with our previous vendor, we did not have this type of maturity. We needed to manually create our own tasks, and it took much longer than what we are doing with Torq.
AI is helping us summarize security alerts. The first thing I do in the morning is get into cases and review all the open cases and incidents. The first thing I see is the AI summary, and it is already telling me all the details that I need to know. Of course, we configured it so that all the relevant details appear in the AI summary, but I almost never need to check the actual details in the logs of the case because I have this summary. On the workflow aspect, I have created multiple tasks that work with AI. For example, I summarize some sort of log and extract only the relevant data from it. I created an agent that can automate processes and make manual API calls to review and collect data that I need for some specific alerts. Recently, they upgraded the Hyperagents and added many automated processes that I am looking forward to using. For example, they created a prompt that can help analyze JSON, which is really good for me because I needed to use it and looked for something like this. They have an option to output from an LLM as JSON, which also really helped me. I am using it on a daily basis.
In the previous system, we were not happy with it. We saw that there were many processes we needed to do manually, while there are options around the market that can help us do those processes automatically. For example, for collecting data, we needed to create the HTTP request ourselves, while in Torq, there are already multiple custom-made tasks that collect the API data themselves, and we do not need to build the whole HTTP request. We looked for a way to save time and automate processes, and Torq really answered those questions.
What needs improvement?
This is exactly what we discussed two days ago with the Torq team. We told them where we want to see improvements. For example, we have MCP that we are working with our cloud security platform, and we wanted to connect this MCP to the case management. When I go inside a case, I want to have a search bar where I can search details about my cloud and everything in my cloud, details about the specific vendors of the alert, not only the alert itself. Currently, we have a search bar for the alert itself, but we do not have a search bar for the connectors. This is one place for improvement.
We already talked about some filtering that they can add. They have a dashboard case dashboard, which is a separate page from the cases itself. We thought about adding a specific widget to the cases page so that we can see statistics inside the cases page. However, there were a few things before that we wanted them to work on, and they have already solved them. For example, we wanted to implement Torq to have access only within our VPN, and as far as I know, they worked on it. A month ago, it succeeded, and we are currently only connecting inside of the VPN.
For how long have I used the solution?
I have been using Torq for the past four to five months.
What do I think about the stability of the solution?
As far as I know for now, I have never seen any message from them that there is maintenance and we need to wait or something like that.
What do I think about the scalability of the solution?
I would rate scalability about nine.
How are customer service and support?
I would rate customer service nine.
Which solution did I use previously and why did I switch?
Our previous solution was Cortex . When we reviewed multiple SOAR solutions, we saw that all the new SOAR companies are doing basically the same thing. We then looked for the specific company that could help us automate and create automated processes with the most mature solution. Torq really answered those questions and really helped us with it. When we started the process and began working with Torq and seeing all the system, we saw that it became really easy to create a workflow. I do not need to think too much. I know I have many drag and drop tasks that can automate a process, which I could have done manually for months.
How was the initial setup?
The setup was easy. All of our security operations team got into Torq and started working on workflows in parallel, which made the entire onboarding process really easier. Something that should have taken half a year took two to three months, and then we finished everything and migrated everything.
What about the implementation team?
Only our teams implemented Torq.
What was our ROI?
The main thing that I got when we started working with Torq is time. I used to have much more time to review alerts, and most of the alerts were manually closed rather than automatically closed. I had most of my day investigating alerts and solving them. A huge part of them are false positives and things that are legitimate and just need a quick check or sending a message.
Since we started working with Torq, I am handling much fewer alerts. It is becoming really easy for me to handle an alert. I have all the information that I need. I do not need to connect to different vendors to receive this information. The main thing I got from Torq is time, and this free time helps me to build another automated system, learn, and there is no need to explain what time is and how important it is.
I used to spend something like three to four hours each day working on cases. Now when we are working in Torq, in the first hour and a half to two hours, I am solving all the cases and the open cases, and I am free to do whatever I need.
What's my experience with pricing, setup cost, and licensing?
Unfortunately, I am not aware of the pricing itself. This is something that my manager would be able to answer, but I am not aware of the price.
What other advice do I have?
I would definitely recommend Torq. I have no doubt, really. When we looked for another vendor, Torq really answered all our questions. It really helps us to receive the best solution for our SOAR.
We already connected Torq with our EDR, SIM logs, and DLP systems. When we connected it, the whole idea of Torq was collecting all the data to a specific place. We created alerts in the SIM and then automatically sent them to Torq. We do not handle the alerts in the SIM, only on Torq. When we collected the data from all the vendors, it is really easy when everything is in one place. We have everything in Torq, and then we do not need to connect to each system to review all the data.
I believe we looked for a maturity that they did not have at first, but right now I can see and tell that they have this maturity, and we are going to use the Agentic AI. It used to be like a six, and right now it seems like an eight, maybe nine even when we review it. I would rate this review an eight overall.