Torq is the AI SOC platform that combines agentic insights and automation so that enterprises can triage, investigate, and respond to actual risks, faster. Torq streamlines every step from alert through resolution. The platform analyzes your risk context to identify your biggest threats. Working alongside your SecOps staff, the Torq platform integrates with your security stack to facilitate containment and remediation workflows.
Torq is the AI SOC platform that combines agentic insights and automation so that enterprises can triage, investigate, and respond to actual risks, faster. Torq streamlines every step from alert through resolution, expanding capacity and throughput. First, Torq ingests and normalizes telemetry from across your security stack, preparing the data for agentic reasoning at scale. Auto Triage filters out noise and prioritizes actual threats. Next, cases are automatically opened and assigned to highly specialized AI agents designed for investigation and response. Using tools and actions you specify, they gather evidence, assemble timelines, and transparently record decisions and authorized actions. Your team is in complete control. With Torq, your SOC delivers more results, more efficiently, from triage through remediation.
Highlights
Eliminates alert fatigue - Torq's AI SOC platform integrates with AWS security tools to provide a unified view of security cases that prioritizes urgent threats to help decrease mean-time-to-response (MTTR).
Ends tech sprawl - Torq's AI SOC platform addresses tech sprawl with integrations across the entire security stack. Now security teams can overcome the challenges posed by complex multi-cloud environments and evolving security threats.
Addresses talent shortage- Torq's AI SOC platform capabilities enable security teams to achieve more with fewer resources, reducing the need for manual tasks. Pre-built integrations with AWS services automate complex processes, empowering less experienced analysts, and improving overall productivity.
Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You buy the Torq AI SOC Platform through a contract that bills by units. Three plan levels are available: Torq Essential, Torq Enterprise, and Torq Elite. These form a tiered structure, letting you pick the level that matches your security operations needs. Within each plan, you choose the number of units, so the total cost scales with the quantity you commit to. All three plans use the same unit-based billing model and share the same term. The plan you select determines the scope of platform capabilities included.
Top-of-mind questions for buyers
What differs between the Torq Essential, Enterprise, and Elite plans?
All three plans bill by units under the same contract term. The plan you pick sets the scope of platform capabilities you can access. Higher plans expand what is included. To confirm which specific features fall under each plan level, contact the vendor, since the pricing table does not detail per-plan feature splits.
What does one unit represent for billing on any plan?
The plans bill by units, and you choose the quantity you commit to. The available data does not define what a single unit maps to, such as an agent, workspace, case, or seat. Contact the vendor to confirm the exact unit definition before committing to a quantity.
How does my total cost scale as I add units?
You select the number of units within your chosen plan, and the total scales with that committed quantity. Cost is driven by two factors together: the plan level you pick and the unit count under it. Adding units raises the total; the plan level sets the capability scope.
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
https://support.torq.iosupport@torq.io.
By purchasing, deploying, accessing, or using this product, you agree to comply with the AWS Marketplace Standard EULA, and the terms of applicable open source software licenses bundled with the product. In addition, if you elect to use any artificial intelligence (AI) features made available by Torq as part of the product, the Torq AI Terms shall govern your use thereof.
Pursuant with the Data Processing Addendum, you authorize the engagement of the sub processors listed at: https://torq.io/legal/subprocessors/, as may be updated by Torq from time to time.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Auto Triage filters out noise and prioritizes actual threats from ingested security telemetry
Telemetry Ingestion and Normalization
Ingests and normalizes telemetry from across the security stack to prepare data for agentic reasoning at scale
Agentic Investigation and Response
Specialized AI agents designed for investigation and response that gather evidence, assemble timelines, and record decisions and authorized actions
Security Stack Integration
Pre-built integrations across the entire security stack including AWS security tools to provide unified view of security cases
Automated Case Management
Automatically opens and assigns cases to AI agents for investigation and response workflows from alert through resolution
Multi-Source Threat Data Integration
Correlates security events from Trellix Security Platform and over 500 third-party tools including 13 AWS integrations to create unified threat visibility across the security stack.
AI-Driven Alert Triage and Prioritization
Applies artificial intelligence-driven analytics to perform 100% alert triage, prioritize threats, and provide GenAI-powered insights for threat investigation and remediation guidance.
No-Code Automation for Investigation and Response
Provides UI-driven, point-and-click automation capabilities to offload repetitive security operations tasks and accelerate investigation and response workflows.
Pre-Built Analytics and Correlation Rules
Ingests data from multiple sources and correlates events using pre-built analytics and rules to reconstruct complete attack narratives and reduce manual investigation pivots.
Multi-Deployment Architecture Support
Supports cloud, hybrid, and air-gapped deployment models with an open integration ecosystem for flexible security infrastructure configurations.
Alert Prioritization Engine
Patented Dynamic Risk Scoring alert engine for precise threat identification and response prioritization
Security Monitoring Coverage
24x7x365 monitoring and threat response across AWS environments, Splunk, and foundational SOC tools
Automation has transformed incident triage and investigation while freeing analysts for deeper work
Reviewed on Aug 17, 2026
Review provided by PeerSpot
What is our primary use case?
My main use case for Torq is the automation of cyber security processes through a SOAR platform and APIs.
A main example of how I use Torq for automation would be a classic one: opening of a security incident in an ITSM, bidirectional synchronization, enrichment, and auto-remediation based on closure of the incident. Everything is automated.
I use Torq for automation of triage, investigation, and remediation actions across multiple attack surfaces such as endpoint, identity, cloud, or IT. It automates the investigation with enrichment such as logs. I do not dive deeper into remediation actions, but they are present, and it automates triage, for example, for phishing incidents. It helps tremendously to have those kinds of data. Its abilities compared to other tools were evaluated through an RFP where we compared multiple tools, and Torq was literally the one, the outsider that stood out, and we chose it. As a technical team, we chose Torq compared to the one that we were using before. We did not start from scratch, as we already had a baseline, and we were searching for a tool that would bring something new to the table with the already existing technical tools that we had, but would bring new innovation and new capabilities. That was the objective, and Torq answered that.
What is most valuable?
One of the best features of Torq, I would highlight two main ones. The first one is the capability of transforming an action that you develop yourself, such as an HTTP request that you develop yourself, and make it available as a custom action to all of the other members of the team that you have, which in a sense increases the scalability of the tool and lets the tool be available for people that don't really know the specifics of APIs, HTTP requests, and just know how to click and drop some actions and want to do their small playbooks. Torq is, in a sense, a tool that is ever-evolving based on the usage that you do with it.
The second one is the look and feel is quite good, and it would be all the AI initiatives that are inside the tool. I can feel that Torq and the company that is behind it are pushing forward what SOAR is, not letting it stale in its current state, and they're pushing it further to make SOAR a new tool in itself by leveraging AI, making it the center of what a SOC is and what incident response is.
The custom action feature in Torq has helped my team tremendously. For example, SharePoint HTTP requests were quite difficult in one of our scenarios. You only have to do the job once of scraping the documentation, understanding how it works, developing the HTTP request by yourself, and then you can save them, put a meaningful description, and add some dynamic fields that the next person that will use that will find much easier than understanding how the logic is and how the documentation is. For the SharePoint example, it has helped tremendously to deliver automation quickly around SharePoint, CSV file upload, and other related tasks.
Torq has impacted my organization positively by allowing us to earn time and invest resources in other projects that are more meaningful and more interesting, pushing deeper into what a SOC is, and building our processes. Torq is a good way to reinvest time in something more interesting, whether for the humans, for the analysts, or for the company in a more secure way. This is what automation brings: interesting subject matter, new capabilities, and more time, fundamentally.
It is quite difficult to quantify, but a good example would be a playbook that is automatically analyzing a phishing incident developed with Torq. It frees up approximately 200 or 250 incidents per week or per month. You take one incident, which took about five minutes to ten minutes, and multiply that across all incidents. The human cost is also significant, such as the fatigue of doing always the same incident, always the same things. This is not easily measurable, but I think it is important to highlight that as it may sometimes be the best resource, the best gain that Torq can bring to the table.
What needs improvement?
There are some bugs in Torq, of course. They can be present in data transformation, some UI debugging, and other areas that can be improved. There are some ideas, and Torq always takes them into consideration. Unfortunately, they are currently focused too much on AI and how the tool is evolving. I can understand because this is how they can keep their head above the water and ahead of all the other tools. This is how they can be this disruptive and interesting for companies. However, it is also important to have some good bases, some solid baselines. There are some issues and bugs that I think need to be fixed, but they are currently not focused on it. The tool is working overall. It is doing what we need. No tool can be perfect, and there is room for improvement, but Torq is already quite far advanced compared to others in the market.
One of the things that I think would be the most interesting for Torq is the ability, when you are debugging, when you have a crash in a playbook, to rerun the playbook from the step that has crashed. This is not implemented, and it is painful to relaunch a playbook manually and do everything when you have actions inside a playbook that have impact. For example, if you reset the token of a user and then the playbook crashes, and it was supposed to send a notification in Teams or add the user to a specific table, just to have the information, you want to have this information, but you don't want to relaunch the whole playbook because it will reset the token of the user again. This is an example where it is quite important, but the feature is lacking.
For how long have I used the solution?
I have been using Torq for approximately one year to a year and a half.
What do I think about the stability of the solution?
Torq is stable.
What do I think about the scalability of the solution?
The scalability of Torq is quite good. The customer support is quite responsive and helpful. Most cases are handled in less than a week.
How are customer service and support?
I would rate the customer support a four. They are present and help a lot.
Which solution did I use previously and why did I switch?
I previously used Logic App from Microsoft. The two main pain points were the number of connectors available with built-in actions. We needed to redevelop every HTTP request every time that we started to create a new playbook. Scalability was not present in that case. Additionally, the tool was quite stale. It did not move a lot in the last year. It has started to move a bit now, but when we were doing the RFP and thinking of changing, we wanted a tool that has a roadmap, innovation, and people that were working on it.
What's my experience with pricing, setup cost, and licensing?
Pricing is pretty straightforward and adaptable based on what you need and what you want to use. The pricing is based on the number of playbooks that you have, which makes it interesting based on how you design your SOC's architecture and makes you spend more time on how you want to design your automation SOCs.
What other advice do I have?
Regarding someone thinking about using Torq, I recommend looking into their provided academy to start working with the tool and understand how JQ works, how the sprig function works, and not diving directly into automation without being sure that your processes and what you want to automate have already been tested out and are a good return on investment for the time that your SOAR team will spend on it. I would rate this review as an 8 out of 10.
JamesWan
Automation has transformed incident response workflows and still needs a more mature visual interface
Reviewed on Aug 09, 2026
Review provided by PeerSpot
What is our primary use case?
My main use case for Torq is enterprise automation, focusing on the cybersecurity application to support security automation and orchestration as well as case management.
For example, we have Splunk which aggregates the logs and generates high-fidelity alerts. With Torq automation, we automate the process to poll for the alerts, enrich all the alerts, and build workflows for the security teams, including security operations, the SOC, and incident response, to quickly investigate the alerts. The automation then determines the maliciousness of the alerts and progresses through all other stages of the case life cycle.
At this point, we primarily focus on cybersecurity for incident response as well as internal insider risk automation, which is our main use case for Torq.
What is most valuable?
The best feature of Torq is the ease of developing workflows. It has templates, and visually, it is very easy to build the steps, called automation steps. It is easy to debug, as you can see the input and output, making it very clear where issues occur, allowing for quick fixes. This is the best feature I see compared to command line options.
The impact of Torq on my team's efficiency is significant because with compiled code, you go through the whole cycle, and it takes a long time to figure out bugs. With Torq automation, every step is a container, clearly defining the input and output, which significantly speeds up the debugging process. It helps us produce workflows quickly, and we can also quickly respond to issues and fix them.
Additionally, Torq integrates with many other technologies very easily, making integration reusable.
What needs improvement?
Regarding improvements for Torq, there is definitely work still to be done to mature it. The biggest thing I think is the GUI. If you want to build a full-fledged workflow with the visual interface, it is not as fully functional as other counterparts. Currently, if you want to build a screen and then have a pop-up and then go back, it is not possible. It is just one way instead of having a mature UI component. Some work needs to be done to make UI development easier and more mature.
For documentation, I think Torq has good documentation, but it occasionally needs updates, as some parts are outdated. In general, their documentation is sufficient. For integration, it is not always smooth, but generally, it goes well. However, we did encounter some problems with custom steps, which definitely affected our progress, and the speed of bug fixes is also a bit slower than expected.
For how long have I used the solution?
I have been using Torq for more than a year.
What do I think about the stability of the solution?
Torq is relatively stable, though not always, but stable enough.
What do I think about the scalability of the solution?
So far, Torq's scalability appears good, but we still need to see how it holds up over time.
How are customer service and support?
The customer support for Torq is a little above average, though not super excellent.
Which solution did I use previously and why did I switch?
Previously, we were using IBM QRadar, which is a legacy three-tier on-premises solution. We switched to the cloud-based automation system that also has AI capabilities, as it offers a new generation tool that leverages AI.
The specific challenges in our SOC that led us to consider changes before implementing Torq included the legacy SOAR product from IBM, which is very hard to maintain and troubleshoot. People felt that an AI-enabled new product would be better.
Before choosing Torq, we evaluated Swimlane as well.
How was the initial setup?
We just started to operationalize Torq, and we have just gone into production. It is definitely well-received by the security operation team, who appreciate the neat GUI and what they see. I believe they think it is better than the legacy SOAR product we had.
What was our ROI?
We have seen a return on investment regarding time saved. It used to take us weeks to develop a workflow, but now it can be done in days or even hours. We have a two-person team, and we are accomplishing the workload of five people.
It took about half a year to realize value with Torq.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup costs, and licensing is that it could be clearer, especially related to the AI aspects, which seem a bit fuzzy. The licensing and cost for the AI agent are not easy to understand, and I hope it becomes clearer once we start to use it more actively.
What other advice do I have?
In this early stage, they are able to capture the metrics they want, such as MTTD and MTTR. It is very clear from the case life cycle to have those metrics, and they like what they see.
SOC has good potential, and for integration, we still need to see how HyperSOC can manage multiple point solutions. We have a very complex environment, but I think we are moving in a good direction as we have started to integrate with Defender and other technologies like Splunk.
Torq has definitely changed the day-to-day experience for our security analysts, as they feel more excited and feel that Torq interface and workflow allow them to build things themselves. They think it is a better product than the legacy product.
We have started to build workflows in Torq to triage, analyze, and contain incidents, including enrichment and integration of intelligence into the workflow. I find it a very good framework for integration compared to completely in-house built tools, as it is easier to maintain due to its vendor components and appears scalable.
What matters most to our leadership team is risk reduction through automation and using the automation system to amplify efficiency, allowing us to do more with fewer people, along with leveraging some AI agent capabilities. Torq has helped us show real SOC impact in this regard.
Regarding Torq's AI capabilities, I note they do have guardrails. I have not fully explored its AI capabilities, except for playing around with Socrate, which appears to have a triage agent. I still need more time to explore it, but the potential is there. Socrate can automatically summarize the case information; we just need more time to actually use it.
So far, the AI agent from Socrate seems good enough in terms of accuracy and reliability of output. It is a generalized AI agent, and for other capabilities, we have not tried them, so I cannot comment.
We have not started to use Torq's agentic AI capabilities yet, but we are definitely looking into it, hoping it will provide additional resources for our operations.
My advice for others looking into using Torq is that those who are capable of developing will be able to utilize its features to leverage Torq platform effectively. I would rate this product a 7.5 out of 10.
Gurjap Kaur
Automation and ai integration have transformed incident response and reduced alert fatigue
Reviewed on Jul 25, 2026
Review from a verified AWS customer
What is our primary use case?
My main use case for Torq is reviewing the incidents and responding to them. After that, I investigate them and take appropriate actions.
For example, a user has logged in from a blacklisted country and it triggers an alert. I investigate the alert and contact the user through Torq.
Another use case is when an IP from my client side has tried to connect to an external IP which is malicious. It may also trigger an alert, and if at the firewall it's not blocked, the action is not blocked. So that may trigger an alert and I will have to do further investigation and complete the required action.
What is most valuable?
Torq offers the best feature through integration with AI. I can use AI alongside Torq.
AI helps me add work notes, resolve notes, and also assists in the investigation and checking of IPs, IP reputation, and more. AI helps me accomplish all of these things.
Torq has minimized the alert fatigue and also reduced the time I need to work on the alerts. Runbooks are present for each use case that helps eliminate other tasks such as going through all of the alerts manually.
The automation Torq provided for some use cases removed the false positives, which saved me time. The number of alerts is reduced after fine-tuning the false positives.
Torq has changed my approach in many ways. It reduced the manual tasks and also helped me in resolving high volume alerts. I also work on the malware alerts more efficiently through Torq.
Torq's ability to solve an operational security issue is commendable. It meets all the compliances and also helps me resolve threats. I also use runbooks to contain malware.
What needs improvement?
Torq can be improved by adding some more features, such as adding more automation and providing a no-code option so I don't have to code for everything.
Torq could add API dependency and also on-premise connectivity. If on-premise connectivity is available, organizations wanting to work on Torq could implement it that way.
For how long have I used the solution?
I have been using Torq for three months now.
What do I think about the stability of the solution?
Torq is very stable.
What do I think about the scalability of the solution?
Regarding the scalability of Torq, I need to consider the elasticity as well. Its scalability is good because it has a cloud-native architecture and it expands dynamically to handle thousands of alerts at the same time.
How are customer service and support?
I haven't had any issues using Torq so far, so I haven't contacted customer support. That is why I cannot comment on that.
Which solution did I use previously and why did I switch?
I used Splunk and I wanted to work on a different tool with more enhanced features. That is why I switched to Torq.
What was our ROI?
The standardized processes helped me guarantee identical incident response every time.
Torq fortified my workflows and secured my cloud infrastructure.
What's my experience with pricing, setup cost, and licensing?
I am the end user. I don't have knowledge about pricing, setup cost, or licensing.
Which other solutions did I evaluate?
I also evaluated Azure Sentinel and QRadar. Those are the two options I evaluated before choosing Torq.
What other advice do I have?
I would definitely recommend others to use Torq as it is an all-rounder tool which even integrates AI. As we all know, it is the era of AI users, so we have to integrate AI into every tool. Torq is best suited for all the SOC analysts.
Torq is a very scalable, elastic tool and also throttles integration of the tools, drops events, and creates message processing backlogs. It also shares back-end resources, so it is a good tool overall. I give Torq a rating of eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Sonu Prasad
Automation has transformed incident investigations and now simplifies alert triage and response
Reviewed on Jul 06, 2026
Review from a verified AWS customer
What is our primary use case?
My main use case for Torq is to automate security incidents. By using Socrates CI, I am able to automate the investigation steps with the runbook and integrate other devices to forward their logs, customizing recording coordinates and parsing with jq.
A recent scenario where I used Torq involved integrating Elasticsearch with Torq to forward the entire log from Elasticsearch to Torq, where I wrote a runbook for the investigation. For example, there is an RDP to the internet use case requiring ten to fifteen steps to investigate the incident. With Torq and Socrates, I automate everything to reach the final outcome.
I have used Torq to automate triage, investigations, and remediation actions across multiple attack surfaces. It performs better than other tools because of its extensive integration capabilities and customizable features, allowing me to tailor responses according to my needs.
I primarily utilize Torq for investigation and alert automation, and I do not have any other business relationships with the vendor.
What is most valuable?
I find Torq very helpful from an automation point of view, with customizable suite features that allow me to customize according to my needs. Initially, developing workflows was complex due to the numerous customization options available, but with Torq's support, I can successfully do that. I also utilize the available templates in Torq as a guideline for developing workflows based on these templates.
Torq offers features like the shocker rates, allowing me to give prompts to the procreate, which investigates each alert according to my defined handbook—a feature I really appreciate. Additionally, I can integrate any third-party tool to Torq using the webhook connector and Torq's default connectors, which is another excellent feature I appreciate.
The Socrates feature is a basic AI model that I develop according to my needs and offer some context in the Socrates tool. I write runbooks and provide prompts to automate the investigation steps using Socrates, which connects every tool and software to enrich the data I need. This feature significantly aids my daily activities, especially since it automates many tasks previously performed by manual analysts. Currently, I am using the WayBook connector and Torq's default connector to integrate third-party tools with Torq, along with various tools like Elasticsearch.
I appreciate Torq's GUI interface, which is easy for every analyst to understand. Additionally, the dashboard features enable monitoring spikes, device integrations, and device statuses according to my needs, allowing me to develop comprehensive visualizations for alerts. Recently introduced migration features in the GUI add value by showing connected tools to my endpoints and assisting my investigation processes, which I find beneficial.
What needs improvement?
To improve Torq, I suggest that known alerts and attacks in the market should lead to developed use cases and workflows. Implementing these would help map known traits automatically when integrating third-party tools and require minimal credential configurations. Having examples of steps to investigate specific alerts would assist in developing other cases effectively.
Torq provides comprehensive support, and I find their documentation useful for addressing challenges in my workflows. Walking through the documentation available on Torq's website gives me clarity on solving issues. If Torq could enhance its AI features, it would benefit customers significantly by making the platform even more user-friendly.
For how long have I used the solution?
I have been using Torq for the last one to two years.
What do I think about the stability of the solution?
Torq is stable and functions reliably within my operations.
What do I think about the scalability of the solution?
Torq's scalability is highly effective, allowing me to customize features according to my specific requirements.
How are customer service and support?
Torq provides comprehensive support, and I find their documentation useful for addressing challenges in my workflows. Walking through the documentation available on Torq's website gives me clarity on solving issues. If Torq could enhance its AI features, it would benefit customers significantly by making the platform even more user-friendly.
Customer support is very good, available twenty-four seven, offering quick resolutions through group chats or calls.
Which solution did I use previously and why did I switch?
My experience managing various point solutions was complicated compared to using Torq's unified platform approach for AI SOC automation and case management.
Before Torq, using separate security platforms posed challenges in enabling log forwarding and investigating alerts efficiently with manual documentation. With Torq, I automate actions while achieving SLA compliance and streamline alert investigation processes much better.
What was our ROI?
I started realizing value with Torq right away; the benefits became apparent immediately as I transitioned to automation.
I have seen a return on investment with Torq, as the automation reduces the number of employees needed and significantly saves both time and resources.
Which other solutions did I evaluate?
I did not evaluate other options before choosing Torq, as my focus remains on employing Torq as my solution.
What other advice do I have?
I would rate Torq a perfect ten on a scale of one to ten.
I chose ten because Torq meets all my expectations, providing support for any challenges I face during workflow, integration, and runbook development. They also have comprehensive documentation for knowledge sharing, along with Torq Academy, which offers multiple certifications to help users understand how Torq features work, especially the SOC analyst certification for beginners.
While comparing various AI outputs, I find that accuracy is not always one hundred percent, but it reaches about eighty percent with precise prompts. Accuracy depends significantly on the clarity of prompts given to Torq's AI, with good prompts yielding better responses.
The effect of using Torq's Agentic AI on stress levels and focus is positive, as it automates procedures, allowing staff to follow predefined protocols without additional manual effort.
Metrics that matter most to my leadership team include investigating every alert and resolving issues as per defined parameters. Automation from Torq helps us show real SOC impact through efficient handling and timely responses.
Before using Torq, I relied on manual investigation steps detailed in my playbook for alerts. Now, with Torq, I automate procedures through a defined software model, allowing runbooks to handle alerts effectively. When an alert is triggered in Elasticsearch, it forwards to Torq, which follows the runbooks I have set up for each alert. If additional actions are required, it sends alerts and notifications, categorizing legitimate alerts and closing them automatically at both Torq and Elasticsearch levels.
I can monitor alert severity and manage how many alerts I have based on this metric, which is a positive impact since investigating alerts efficiently was challenging during manual processes. I can now see how many alerts are pending and their severity levels, contributing to meeting my SLA and TRA requirements.
Torq significantly changes day-to-day experiences for security analysts by automating alert handling and reducing overall workload, thus improving job satisfaction and operational efficiency.
Torq's Agentic AI significantly increases the alert handling capacity for my SecOps staff, streamlining their responsibilities and ensuring they manage alerts effectively. I would rate this product ten out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Maiko Svanidze
AI-driven automation has transformed incident response speed and boosted analyst confidence
Reviewed on Jun 30, 2026
Review from a verified AWS customer
What is our primary use case?
For Torq, first of all, it's a hyperautomation and AI assistant usage. Our EDR SentinelOne is integrated in Torq and besides the vendor itself having hyperautomation abilities, Torq helps me to analyze incidents and to respond to incidents more quickly and more efficiently.
Torq's AI SOC automation case management is much faster and more efficient compared to the manual tools I have used before. Torq is an ideal assistant for AI SOC in automation challenges.
Torq changed the day-to-day experience for my security analysts. They are more confident and can test more approaches in the security operation center every day as workflows and routine.
What is most valuable?
I rely on Torq's AI assistant in most of my incident response and in building right and less complex workflows for automation.
Torq helped me also in some infrastructure and ticketing challenges, for example, to organize the ticketing system in our company, but I am still in a process of learning about Torq and realizing different scenarios using Torq.
The most valuable feature of Torq is hyperautomation and AI assistant because the quality of speed and recommendation from the AI assistant is really high. Another outstanding feature is that you don't need to write code. There is a library of prepared scripts or JSON scripts which can be right and adapted. You can face quite complex challenges without a programming background and can successfully solve these issues and challenges.
Torq's no-code library helps me to be more efficient and respond to incidents more flexibly. The support of the AI assistant makes my actions more efficient and quicker.
What needs improvement?
The only thing is more out-of-the-box integrations. Torq already has a lot of supported integrations and adding new ones is not difficult, but for some customers, it's easier to have a plug and play interface to start onboarding.
We didn't evaluate other options because we tested Torq and we liked it.
At this stage, I have no additional suggestions. I will update my review several months later and maybe then I will have some suggestions to prove and to what in addition I would like to see in the solution.
I can't evaluate Torq's agentic AI, but I think in my next review, I can provide more information.
For how long have I used the solution?
I have been using Torq for the last six months.
What do I think about the stability of the solution?
I haven't experienced any downtime or technical issues while running the platform.
What do I think about the scalability of the solution?
Torq can handle growth and increase easily without any downtime or lack of service.
How are customer service and support?
Customer support is responsive and helpful, but most of my questions were more how-to questions.
Which solution did I use previously and why did I switch?
I used online SIEMs with integrated SOARs, not online but on-premises, and we switched because it was too slow and too inefficient to use.
How was the initial setup?
From my point of view, Torq has excellent documentation and a support portal. You can find literally everything on the support portal. There are visual manuals and quite simple instructions for onboarding and for every use case you can imagine in your infrastructure.
My advice would be to test Torq in your environment, ask as many questions as possible during POC and refer to documentation in cases you feel not confident about your new solution.
What about the implementation team?
At this stage, we are just customers of Torq.
What was our ROI?
Regarding Torq's pricing and license costs, as long as our existing team started to work more efficiently and quicker, I think we have quite a return of investment and we suppose to add more security management center tools. The return of investment is also the money we saved not adding another security tool. For me and for our security stack, it's about 30% return on investment.
What's my experience with pricing, setup cost, and licensing?
Torq is a standalone solution from Torq providers.
Which other solutions did I evaluate?
We didn't evaluate other options because we tested Torq and we liked it.
What other advice do I have?
I think I have told everything about Torq that I can share at this stage, but I am still in the process of learning the platform and I still think that there are many more features which can be adapted and can be used inside the company.
According to positive outcomes, Torq reduced manual work and made incident response more efficient. From Torq workflows, I learn much more about my company ecosystem. This also reflects on the defensive side of the company. I see the gaps that I had according to incidents and I can fix and address the gaps relying on knowledge I get from automation results.
I think the speed of work increased minimum by 50%, but I think with more automation and more optimization, we can make this result much better.
The easiness of integration, good quality of support and good quality of documentation make this product easy to work with. From what I see, the vendor itself is oriented on improvement, which means that they will not stop at the level they reached by now.
I am quite confident in Torq because I have checked, for example, compliance to ISO 27001 and this is the most relevant standard here in Georgia. I trust in Torq and I trust in the security compliance the platform provides.
Torq's AI recommendations are consistently helpful. There was no case when the system provided me with a false recommendation or inaccurate response.
Alert fatigue is something I would like Torq to help me address.
My overall rating for this review is 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?