Listing Thumbnail

    Torq AI SOC Platform

     Info
    Sold by: Torq 
    Deployed on AWS
    Torq is the AI SOC platform that combines agentic insights and automation so that enterprises can triage, investigate, and respond to actual risks, faster. Torq streamlines every step from alert through resolution. The platform analyzes your risk context to identify your biggest threats. Working alongside your SecOps staff, the Torq platform integrates with your security stack to facilitate containment and remediation workflows.
    4.7

    Overview

    Play video

    Torq is the AI SOC platform that combines agentic insights and automation so that enterprises can triage, investigate, and respond to actual risks, faster. Torq streamlines every step from alert through resolution, expanding capacity and throughput. First, Torq ingests and normalizes telemetry from across your security stack, preparing the data for agentic reasoning at scale. Auto Triage filters out noise and prioritizes actual threats. Next, cases are automatically opened and assigned to highly specialized AI agents designed for investigation and response. Using tools and actions you specify, they gather evidence, assemble timelines, and transparently record decisions and authorized actions. Your team is in complete control. With Torq, your SOC delivers more results, more efficiently, from triage through remediation.

    Highlights

    • Eliminates alert fatigue - Torq's AI SOC platform integrates with AWS security tools to provide a unified view of security cases that prioritizes urgent threats to help decrease mean-time-to-response (MTTR).
    • Ends tech sprawl - Torq's AI SOC platform addresses tech sprawl with integrations across the entire security stack. Now security teams can overcome the challenges posed by complex multi-cloud environments and evolving security threats.
    • Addresses talent shortage- Torq's AI SOC platform capabilities enable security teams to achieve more with fewer resources, reducing the need for manual tasks. Pre-built integrations with AWS services automate complex processes, empowering less experienced analysts, and improving overall productivity.

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Torq AI SOC Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (3)

     Info
    Dimension
    Description
    Cost/12 months
    Torq Essential
    Essential Plan
    $450,000.00
    Torq Enterprise
    Enterprise Plan
    $450,000.00
    Torq Elite
    Elite Plan
    $450,000.00

    AI Insights

     Info

    Dimensions summary

    You buy the Torq AI SOC Platform through a contract that bills by units. Three plan levels are available: Torq Essential, Torq Enterprise, and Torq Elite. These form a tiered structure, letting you pick the level that matches your security operations needs. Within each plan, you choose the number of units, so the total cost scales with the quantity you commit to. All three plans use the same unit-based billing model and share the same term. The plan you select determines the scope of platform capabilities included.

    Top-of-mind questions for buyers

    All three plans bill by units under the same contract term. The plan you pick sets the scope of platform capabilities you can access. Higher plans expand what is included. To confirm which specific features fall under each plan level, contact the vendor, since the pricing table does not detail per-plan feature splits.
    The plans bill by units, and you choose the quantity you commit to. The available data does not define what a single unit maps to, such as an agent, workspace, case, or seat. Contact the vendor to confirm the exact unit definition before committing to a quantity.
    You select the number of units within your chosen plan, and the total scales with that committed quantity. Cost is driven by two factors together: the plan level you pick and the unit count under it. Adding units raises the total; the plan level sets the capability scope.
    torq.io
    Helpful?

    Vendor refund policy

    Please contact us at sales@torq.io 

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Support

    Vendor support

    https://support.torq.io  support@torq.io . By purchasing, deploying, accessing, or using this product, you agree to comply with the AWS Marketplace Standard EULA, and the terms of applicable open source software licenses bundled with the product. In addition, if you elect to use any artificial intelligence (AI) features made available by Torq as part of the product, the Torq AI Terms shall govern your use thereof. Pursuant with the Data Processing Addendum, you authorize the engagement of the sub processors listed at: https://torq.io/legal/subprocessors/ , as may be updated by Torq from time to time.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Alert Triage and Noise Filtering
    Auto Triage filters out noise and prioritizes actual threats based on risk context analysis
    Telemetry Ingestion and Normalization
    Ingests and normalizes telemetry from across security stack to prepare data for agentic reasoning at scale
    Specialized AI Agent Investigation
    Deploys highly specialized AI agents designed for investigation and response that gather evidence, assemble timelines, and record decisions transparently
    Security Stack Integration
    Integrates with AWS security tools and across the entire security stack to provide unified view of security cases
    Automated Containment and Remediation Workflows
    Facilitates automated containment and remediation workflows with tools and actions specified by security teams
    Multi-Source Threat Data Integration
    Correlates and ingests security data from Trellix Security Platform and over 500 third-party tools including 13 AWS integrations to create unified threat visibility across the security stack.
    AI-Driven Detection and Alert Triage
    Applies artificial intelligence-driven analytics and automated alert triage to prioritize threats and provide GenAI-powered insights for threat investigation and remediation guidance.
    No-Code Automation for Investigation and Response
    Provides UI-driven, point-and-click automation capabilities to offload repetitive security operations tasks and accelerate investigation and response workflows.
    Pre-Built Analytics and Correlation Rules
    Utilizes pre-built analytics and correlation rules to rapidly correlate multi-vector threat detections and reconstruct complete attack narratives from ingested security events.
    Hybrid and Air-Gapped Deployment Support
    Supports deployment across cloud, hybrid, and air-gapped environments with flexible integration architecture for diverse infrastructure configurations.
    Alert Prioritization Engine
    Patented Dynamic Risk Scoring alert engine for precise threat identification and response prioritization
    Security Monitoring Coverage
    24x7x365 monitoring and managed detection & response across multiple security domains including endpoint detection, vulnerability management, and firewall management
    SOC Technology Integration
    Curated integration with industry-leading SOC technologies including AWS and Splunk tools through the Deepwatch Security Center
    Security Posture Assessment
    Proprietary Security Index providing quantitative analysis and industry benchmarking for security program maturity evaluation
    Threat Hunting Capability
    Proactive threat hunting services to identify and remediate security threats across the attack surface

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.7
    170 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    88%
    12%
    0%
    0%
    0%
    5 AWS reviews
    |
    165 external reviews
    External reviews are from G2  and PeerSpot .
    Consulting

    Agentic Hyperautomation That Slashes Alert Fatigue—No Fragile Code Needed

    Reviewed on Sep 02, 2026
    Review provided by G2
    What do you like best about the product?
    Its agentic hyperautomation actually slashes alert fatigue by handling repetitive triaging instantly, without forcing security teams to write endless, fragile code.
    What do you dislike about the product?
    Despite its hyperautomation, Torq requires a steep initial learning curve, complex pricing with high enterprise entry costs, and debugging nested workflow errors can quickly turn into a headache.
    What problems is the product solving and how is that benefiting you?
    It cuts through endless alert noise and tool sprawl by auto-triaging routine threats, giving analysts their time back to focus on real threat hunting.
    Arnab S.

    Enables IT to Handle Triggers and Alerts with Ease

    Reviewed on Aug 27, 2026
    Review provided by G2
    What do you like best about the product?
    How it can enable IT to deal with lot of triggers and alerts
    What do you dislike about the product?
    Complex license process navigation takes learning curve
    What problems is the product solving and how is that benefiting you?
    To deal with big Enterprise which is tech enables leading to IT disruptions
    Alexandre Becquart

    Automation has transformed incident triage and investigation while freeing analysts for deeper work

    Reviewed on Aug 17, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Torq is the automation of cyber security processes through a SOAR platform and APIs.

    A main example of how I use Torq for automation would be a classic one: opening of a security incident in an ITSM, bidirectional synchronization, enrichment, and auto-remediation based on closure of the incident. Everything is automated.

    I use Torq for automation of triage, investigation, and remediation actions across multiple attack surfaces such as endpoint, identity, cloud, or IT. It automates the investigation with enrichment such as logs. I do not dive deeper into remediation actions, but they are present, and it automates triage, for example, for phishing incidents. It helps tremendously to have those kinds of data. Its abilities compared to other tools were evaluated through an RFP where we compared multiple tools, and Torq was literally the one, the outsider that stood out, and we chose it. As a technical team, we chose Torq compared to the one that we were using before. We did not start from scratch, as we already had a baseline, and we were searching for a tool that would bring something new to the table with the already existing technical tools that we had, but would bring new innovation and new capabilities. That was the objective, and Torq answered that.

    What is most valuable?

    One of the best features of Torq, I would highlight two main ones. The first one is the capability of transforming an action that you develop yourself, such as an HTTP request that you develop yourself, and make it available as a custom action to all of the other members of the team that you have, which in a sense increases the scalability of the tool and lets the tool be available for people that don't really know the specifics of APIs, HTTP requests, and just know how to click and drop some actions and want to do their small playbooks. Torq is, in a sense, a tool that is ever-evolving based on the usage that you do with it.

    The second one is the look and feel is quite good, and it would be all the AI initiatives that are inside the tool. I can feel that Torq and the company that is behind it are pushing forward what SOAR is, not letting it stale in its current state, and they're pushing it further to make SOAR a new tool in itself by leveraging AI, making it the center of what a SOC is and what incident response is.

    The custom action feature in Torq has helped my team tremendously. For example, SharePoint HTTP requests were quite difficult in one of our scenarios. You only have to do the job once of scraping the documentation, understanding how it works, developing the HTTP request by yourself, and then you can save them, put a meaningful description, and add some dynamic fields that the next person that will use that will find much easier than understanding how the logic is and how the documentation is. For the SharePoint example, it has helped tremendously to deliver automation quickly around SharePoint, CSV file upload, and other related tasks.

    Torq has impacted my organization positively by allowing us to earn time and invest resources in other projects that are more meaningful and more interesting, pushing deeper into what a SOC is, and building our processes. Torq is a good way to reinvest time in something more interesting, whether for the humans, for the analysts, or for the company in a more secure way. This is what automation brings: interesting subject matter, new capabilities, and more time, fundamentally.

    It is quite difficult to quantify, but a good example would be a playbook that is automatically analyzing a phishing incident developed with Torq. It frees up approximately 200 or 250 incidents per week or per month. You take one incident, which took about five minutes to ten minutes, and multiply that across all incidents. The human cost is also significant, such as the fatigue of doing always the same incident, always the same things. This is not easily measurable, but I think it is important to highlight that as it may sometimes be the best resource, the best gain that Torq can bring to the table.

    What needs improvement?

    There are some bugs in Torq, of course. They can be present in data transformation, some UI debugging, and other areas that can be improved. There are some ideas, and Torq always takes them into consideration. Unfortunately, they are currently focused too much on AI and how the tool is evolving. I can understand because this is how they can keep their head above the water and ahead of all the other tools. This is how they can be this disruptive and interesting for companies. However, it is also important to have some good bases, some solid baselines. There are some issues and bugs that I think need to be fixed, but they are currently not focused on it. The tool is working overall. It is doing what we need. No tool can be perfect, and there is room for improvement, but Torq is already quite far advanced compared to others in the market.

    One of the things that I think would be the most interesting for Torq is the ability, when you are debugging, when you have a crash in a playbook, to rerun the playbook from the step that has crashed. This is not implemented, and it is painful to relaunch a playbook manually and do everything when you have actions inside a playbook that have impact. For example, if you reset the token of a user and then the playbook crashes, and it was supposed to send a notification in Teams or add the user to a specific table, just to have the information, you want to have this information, but you don't want to relaunch the whole playbook because it will reset the token of the user again. This is an example where it is quite important, but the feature is lacking.

    For how long have I used the solution?

    I have been using Torq for approximately one year to a year and a half.

    What do I think about the stability of the solution?

    Torq is stable.

    What do I think about the scalability of the solution?

    The scalability of Torq is quite good. The customer support is quite responsive and helpful. Most cases are handled in less than a week.

    How are customer service and support?

    I would rate the customer support a four. They are present and help a lot.

    Which solution did I use previously and why did I switch?

    I previously used Logic App from Microsoft. The two main pain points were the number of connectors available with built-in actions. We needed to redevelop every HTTP request every time that we started to create a new playbook. Scalability was not present in that case. Additionally, the tool was quite stale. It did not move a lot in the last year. It has started to move a bit now, but when we were doing the RFP and thinking of changing, we wanted a tool that has a roadmap, innovation, and people that were working on it.

    What's my experience with pricing, setup cost, and licensing?

    Pricing is pretty straightforward and adaptable based on what you need and what you want to use. The pricing is based on the number of playbooks that you have, which makes it interesting based on how you design your SOC's architecture and makes you spend more time on how you want to design your automation SOCs.

    What other advice do I have?

    Regarding someone thinking about using Torq, I recommend looking into their provided academy to start working with the tool and understand how JQ works, how the sprig function works, and not diving directly into automation without being sure that your processes and what you want to automate have already been tested out and are a good return on investment for the time that your SOAR team will spend on it. I would rate this review as an 8 out of 10.

    JamesWan

    Automation has transformed incident response workflows and still needs a more mature visual interface

    Reviewed on Aug 09, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Torq is enterprise automation, focusing on the cybersecurity application to support security automation and orchestration as well as case management.

    For example, we have Splunk which aggregates the logs and generates high-fidelity alerts. With Torq automation, we automate the process to poll for the alerts, enrich all the alerts, and build workflows for the security teams, including security operations, the SOC, and incident response, to quickly investigate the alerts. The automation then determines the maliciousness of the alerts and progresses through all other stages of the case life cycle.

    At this point, we primarily focus on cybersecurity for incident response as well as internal insider risk automation, which is our main use case for Torq.

    What is most valuable?

    The best feature of Torq is the ease of developing workflows. It has templates, and visually, it is very easy to build the steps, called automation steps. It is easy to debug, as you can see the input and output, making it very clear where issues occur, allowing for quick fixes. This is the best feature I see compared to command line options.

    The impact of Torq on my team's efficiency is significant because with compiled code, you go through the whole cycle, and it takes a long time to figure out bugs. With Torq automation, every step is a container, clearly defining the input and output, which significantly speeds up the debugging process. It helps us produce workflows quickly, and we can also quickly respond to issues and fix them.

    Additionally, Torq integrates with many other technologies very easily, making integration reusable.

    What needs improvement?

    Regarding improvements for Torq, there is definitely work still to be done to mature it. The biggest thing I think is the GUI. If you want to build a full-fledged workflow with the visual interface, it is not as fully functional as other counterparts. Currently, if you want to build a screen and then have a pop-up and then go back, it is not possible. It is just one way instead of having a mature UI component. Some work needs to be done to make UI development easier and more mature.

    For documentation, I think Torq has good documentation, but it occasionally needs updates, as some parts are outdated. In general, their documentation is sufficient. For integration, it is not always smooth, but generally, it goes well. However, we did encounter some problems with custom steps, which definitely affected our progress, and the speed of bug fixes is also a bit slower than expected.

    For how long have I used the solution?

    I have been using Torq for more than a year.

    What do I think about the stability of the solution?

    Torq is relatively stable, though not always, but stable enough.

    What do I think about the scalability of the solution?

    So far, Torq's scalability appears good, but we still need to see how it holds up over time.

    How are customer service and support?

    The customer support for Torq is a little above average, though not super excellent.

    Which solution did I use previously and why did I switch?

    Previously, we were using IBM QRadar, which is a legacy three-tier on-premises solution. We switched to the cloud-based automation system that also has AI capabilities, as it offers a new generation tool that leverages AI.

    The specific challenges in our SOC that led us to consider changes before implementing Torq included the legacy SOAR product from IBM, which is very hard to maintain and troubleshoot. People felt that an AI-enabled new product would be better.

    Before choosing Torq, we evaluated Swimlane as well.

    How was the initial setup?

    We just started to operationalize Torq, and we have just gone into production. It is definitely well-received by the security operation team, who appreciate the neat GUI and what they see. I believe they think it is better than the legacy SOAR product we had.

    What was our ROI?

    We have seen a return on investment regarding time saved. It used to take us weeks to develop a workflow, but now it can be done in days or even hours. We have a two-person team, and we are accomplishing the workload of five people.

    It took about half a year to realize value with Torq.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup costs, and licensing is that it could be clearer, especially related to the AI aspects, which seem a bit fuzzy. The licensing and cost for the AI agent are not easy to understand, and I hope it becomes clearer once we start to use it more actively.

    What other advice do I have?

    In this early stage, they are able to capture the metrics they want, such as MTTD and MTTR. It is very clear from the case life cycle to have those metrics, and they like what they see.

    SOC has good potential, and for integration, we still need to see how HyperSOC can manage multiple point solutions. We have a very complex environment, but I think we are moving in a good direction as we have started to integrate with Defender and other technologies like Splunk.

    Torq has definitely changed the day-to-day experience for our security analysts, as they feel more excited and feel that Torq interface and workflow allow them to build things themselves. They think it is a better product than the legacy product.

    We have started to build workflows in Torq to triage, analyze, and contain incidents, including enrichment and integration of intelligence into the workflow. I find it a very good framework for integration compared to completely in-house built tools, as it is easier to maintain due to its vendor components and appears scalable.

    What matters most to our leadership team is risk reduction through automation and using the automation system to amplify efficiency, allowing us to do more with fewer people, along with leveraging some AI agent capabilities. Torq has helped us show real SOC impact in this regard.

    Regarding Torq's AI capabilities, I note they do have guardrails. I have not fully explored its AI capabilities, except for playing around with Socrate, which appears to have a triage agent. I still need more time to explore it, but the potential is there. Socrate can automatically summarize the case information; we just need more time to actually use it.

    So far, the AI agent from Socrate seems good enough in terms of accuracy and reliability of output. It is a generalized AI agent, and for other capabilities, we have not tried them, so I cannot comment.

    We have not started to use Torq's agentic AI capabilities yet, but we are definitely looking into it, hoping it will provide additional resources for our operations.

    My advice for others looking into using Torq is that those who are capable of developing will be able to utilize its features to leverage Torq platform effectively. I would rate this product a 7.5 out of 10.

    Gurjap Kaur

    Automation and ai integration have transformed incident response and reduced alert fatigue

    Reviewed on Jul 25, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Torq is reviewing the incidents and responding to them. After that, I investigate them and take appropriate actions.

    For example, a user has logged in from a blacklisted country and it triggers an alert. I investigate the alert and contact the user through Torq.

    Another use case is when an IP from my client side has tried to connect to an external IP which is malicious. It may also trigger an alert, and if at the firewall it's not blocked, the action is not blocked. So that may trigger an alert and I will have to do further investigation and complete the required action.

    What is most valuable?

    Torq offers the best feature through integration with AI. I can use AI alongside Torq.

    AI helps me add work notes, resolve notes, and also assists in the investigation and checking of IPs, IP reputation, and more. AI helps me accomplish all of these things.

    Torq has minimized the alert fatigue and also reduced the time I need to work on the alerts. Runbooks are present for each use case that helps eliminate other tasks such as going through all of the alerts manually.

    The automation Torq provided for some use cases removed the false positives, which saved me time. The number of alerts is reduced after fine-tuning the false positives.

    Torq has changed my approach in many ways. It reduced the manual tasks and also helped me in resolving high volume alerts. I also work on the malware alerts more efficiently through Torq.

    Torq's ability to solve an operational security issue is commendable. It meets all the compliances and also helps me resolve threats. I also use runbooks to contain malware.

    What needs improvement?

    Torq can be improved by adding some more features, such as adding more automation and providing a no-code option so I don't have to code for everything.

    Torq could add API dependency and also on-premise connectivity. If on-premise connectivity is available, organizations wanting to work on Torq could implement it that way.

    For how long have I used the solution?

    I have been using Torq for three months now.

    What do I think about the stability of the solution?

    Torq is very stable.

    What do I think about the scalability of the solution?

    Regarding the scalability of Torq, I need to consider the elasticity as well. Its scalability is good because it has a cloud-native architecture and it expands dynamically to handle thousands of alerts at the same time.

    How are customer service and support?

    I haven't had any issues using Torq so far, so I haven't contacted customer support. That is why I cannot comment on that.

    Which solution did I use previously and why did I switch?

    I used Splunk and I wanted to work on a different tool with more enhanced features. That is why I switched to Torq.

    What was our ROI?

    The standardized processes helped me guarantee identical incident response every time.

    Torq fortified my workflows and secured my cloud infrastructure.

    What's my experience with pricing, setup cost, and licensing?

    I am the end user. I don't have knowledge about pricing, setup cost, or licensing.

    Which other solutions did I evaluate?

    I also evaluated Azure Sentinel and QRadar. Those are the two options I evaluated before choosing Torq.

    What other advice do I have?

    I would definitely recommend others to use Torq as it is an all-rounder tool which even integrates AI. As we all know, it is the era of AI users, so we have to integrate AI into every tool. Torq is best suited for all the SOC analysts.

    Torq is a very scalable, elastic tool and also throttles integration of the tools, drops events, and creates message processing backlogs. It also shares back-end resources, so it is a good tool overall. I give Torq a rating of eight out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    View all reviews