Torq AI SOC Platform logo

    Torq AI SOC Platform

    Sold by
    Torq is the AI SOC platform that combines agentic insights and automation so that enterprises can triage, investigate, and respond to actual risks, faster. Torq streamlines every step from alert through resolution. The platform analyzes your risk context to identify your biggest threats. Working alongside your SecOps staff, the Torq platform integrates with your security stack to facilitate containment and remediation workflows.

    Ratings and reviews

    4.7
    168 ratings
    3 star
    2 star
    1 star
    89%
    11%
    0%
    0%
    0%
    5 AWS reviews
    |
    163 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (168)
    Alexandre Becquart

    Automation has transformed incident triage and investigation while freeing analysts for deeper work

    Reviewed on Aug 17, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Torq is the automation of cyber security processes through a SOAR platform and APIs.

    A main example of how I use Torq for automation would be a classic one: opening of a security incident in an ITSM, bidirectional synchronization, enrichment, and auto-remediation based on closure of the incident. Everything is automated.

    I use Torq for automation of triage, investigation, and remediation actions across multiple attack surfaces such as endpoint, identity, cloud, or IT. It automates the investigation with enrichment such as logs. I do not dive deeper into remediation actions, but they are present, and it automates triage, for example, for phishing incidents. It helps tremendously to have those kinds of data. Its abilities compared to other tools were evaluated through an RFP where we compared multiple tools, and Torq was literally the one, the outsider that stood out, and we chose it. As a technical team, we chose Torq compared to the one that we were using before. We did not start from scratch, as we already had a baseline, and we were searching for a tool that would bring something new to the table with the already existing technical tools that we had, but would bring new innovation and new capabilities. That was the objective, and Torq answered that.

    What is most valuable?

    One of the best features of Torq, I would highlight two main ones. The first one is the capability of transforming an action that you develop yourself, such as an HTTP request that you develop yourself, and make it available as a custom action to all of the other members of the team that you have, which in a sense increases the scalability of the tool and lets the tool be available for people that don't really know the specifics of APIs, HTTP requests, and just know how to click and drop some actions and want to do their small playbooks. Torq is, in a sense, a tool that is ever-evolving based on the usage that you do with it.

    The second one is the look and feel is quite good, and it would be all the AI initiatives that are inside the tool. I can feel that Torq and the company that is behind it are pushing forward what SOAR is, not letting it stale in its current state, and they're pushing it further to make SOAR a new tool in itself by leveraging AI, making it the center of what a SOC is and what incident response is.

    The custom action feature in Torq has helped my team tremendously. For example, SharePoint HTTP requests were quite difficult in one of our scenarios. You only have to do the job once of scraping the documentation, understanding how it works, developing the HTTP request by yourself, and then you can save them, put a meaningful description, and add some dynamic fields that the next person that will use that will find much easier than understanding how the logic is and how the documentation is. For the SharePoint example, it has helped tremendously to deliver automation quickly around SharePoint, CSV file upload, and other related tasks.

    Torq has impacted my organization positively by allowing us to earn time and invest resources in other projects that are more meaningful and more interesting, pushing deeper into what a SOC is, and building our processes. Torq is a good way to reinvest time in something more interesting, whether for the humans, for the analysts, or for the company in a more secure way. This is what automation brings: interesting subject matter, new capabilities, and more time, fundamentally.

    It is quite difficult to quantify, but a good example would be a playbook that is automatically analyzing a phishing incident developed with Torq. It frees up approximately 200 or 250 incidents per week or per month. You take one incident, which took about five minutes to ten minutes, and multiply that across all incidents. The human cost is also significant, such as the fatigue of doing always the same incident, always the same things. This is not easily measurable, but I think it is important to highlight that as it may sometimes be the best resource, the best gain that Torq can bring to the table.

    What needs improvement?

    There are some bugs in Torq, of course. They can be present in data transformation, some UI debugging, and other areas that can be improved. There are some ideas, and Torq always takes them into consideration. Unfortunately, they are currently focused too much on AI and how the tool is evolving. I can understand because this is how they can keep their head above the water and ahead of all the other tools. This is how they can be this disruptive and interesting for companies. However, it is also important to have some good bases, some solid baselines. There are some issues and bugs that I think need to be fixed, but they are currently not focused on it. The tool is working overall. It is doing what we need. No tool can be perfect, and there is room for improvement, but Torq is already quite far advanced compared to others in the market.

    One of the things that I think would be the most interesting for Torq is the ability, when you are debugging, when you have a crash in a playbook, to rerun the playbook from the step that has crashed. This is not implemented, and it is painful to relaunch a playbook manually and do everything when you have actions inside a playbook that have impact. For example, if you reset the token of a user and then the playbook crashes, and it was supposed to send a notification in Teams or add the user to a specific table, just to have the information, you want to have this information, but you don't want to relaunch the whole playbook because it will reset the token of the user again. This is an example where it is quite important, but the feature is lacking.

    For how long have I used the solution?

    I have been using Torq for approximately one year to a year and a half.

    What do I think about the stability of the solution?

    Torq is stable.

    What do I think about the scalability of the solution?

    The scalability of Torq is quite good. The customer support is quite responsive and helpful. Most cases are handled in less than a week.

    How are customer service and support?

    I would rate the customer support a four. They are present and help a lot.

    Which solution did I use previously and why did I switch?

    I previously used Logic App from Microsoft. The two main pain points were the number of connectors available with built-in actions. We needed to redevelop every HTTP request every time that we started to create a new playbook. Scalability was not present in that case. Additionally, the tool was quite stale. It did not move a lot in the last year. It has started to move a bit now, but when we were doing the RFP and thinking of changing, we wanted a tool that has a roadmap, innovation, and people that were working on it.

    What's my experience with pricing, setup cost, and licensing?

    Pricing is pretty straightforward and adaptable based on what you need and what you want to use. The pricing is based on the number of playbooks that you have, which makes it interesting based on how you design your SOC's architecture and makes you spend more time on how you want to design your automation SOCs.

    What other advice do I have?

    Regarding someone thinking about using Torq, I recommend looking into their provided academy to start working with the tool and understand how JQ works, how the sprig function works, and not diving directly into automation without being sure that your processes and what you want to automate have already been tested out and are a good return on investment for the time that your SOAR team will spend on it. I would rate this review as an 8 out of 10.

    JamesWan

    Automation has transformed incident response workflows and still needs a more mature visual interface

    Reviewed on Aug 09, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Torq is enterprise automation, focusing on the cybersecurity application to support security automation and orchestration as well as case management.

    For example, we have Splunk which aggregates the logs and generates high-fidelity alerts. With Torq automation, we automate the process to poll for the alerts, enrich all the alerts, and build workflows for the security teams, including security operations, the SOC, and incident response, to quickly investigate the alerts. The automation then determines the maliciousness of the alerts and progresses through all other stages of the case life cycle.

    At this point, we primarily focus on cybersecurity for incident response as well as internal insider risk automation, which is our main use case for Torq.

    What is most valuable?

    The best feature of Torq is the ease of developing workflows. It has templates, and visually, it is very easy to build the steps, called automation steps. It is easy to debug, as you can see the input and output, making it very clear where issues occur, allowing for quick fixes. This is the best feature I see compared to command line options.

    The impact of Torq on my team's efficiency is significant because with compiled code, you go through the whole cycle, and it takes a long time to figure out bugs. With Torq automation, every step is a container, clearly defining the input and output, which significantly speeds up the debugging process. It helps us produce workflows quickly, and we can also quickly respond to issues and fix them.

    Additionally, Torq integrates with many other technologies very easily, making integration reusable.

    What needs improvement?

    Regarding improvements for Torq, there is definitely work still to be done to mature it. The biggest thing I think is the GUI. If you want to build a full-fledged workflow with the visual interface, it is not as fully functional as other counterparts. Currently, if you want to build a screen and then have a pop-up and then go back, it is not possible. It is just one way instead of having a mature UI component. Some work needs to be done to make UI development easier and more mature.

    For documentation, I think Torq has good documentation, but it occasionally needs updates, as some parts are outdated. In general, their documentation is sufficient. For integration, it is not always smooth, but generally, it goes well. However, we did encounter some problems with custom steps, which definitely affected our progress, and the speed of bug fixes is also a bit slower than expected.

    For how long have I used the solution?

    I have been using Torq for more than a year.

    What do I think about the stability of the solution?

    Torq is relatively stable, though not always, but stable enough.

    What do I think about the scalability of the solution?

    So far, Torq's scalability appears good, but we still need to see how it holds up over time.

    How are customer service and support?

    The customer support for Torq is a little above average, though not super excellent.

    Which solution did I use previously and why did I switch?

    Previously, we were using IBM QRadar, which is a legacy three-tier on-premises solution. We switched to the cloud-based automation system that also has AI capabilities, as it offers a new generation tool that leverages AI.

    The specific challenges in our SOC that led us to consider changes before implementing Torq included the legacy SOAR product from IBM, which is very hard to maintain and troubleshoot. People felt that an AI-enabled new product would be better.

    Before choosing Torq, we evaluated Swimlane as well.

    How was the initial setup?

    We just started to operationalize Torq, and we have just gone into production. It is definitely well-received by the security operation team, who appreciate the neat GUI and what they see. I believe they think it is better than the legacy SOAR product we had.

    What was our ROI?

    We have seen a return on investment regarding time saved. It used to take us weeks to develop a workflow, but now it can be done in days or even hours. We have a two-person team, and we are accomplishing the workload of five people.

    It took about half a year to realize value with Torq.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup costs, and licensing is that it could be clearer, especially related to the AI aspects, which seem a bit fuzzy. The licensing and cost for the AI agent are not easy to understand, and I hope it becomes clearer once we start to use it more actively.

    What other advice do I have?

    In this early stage, they are able to capture the metrics they want, such as MTTD and MTTR. It is very clear from the case life cycle to have those metrics, and they like what they see.

    SOC has good potential, and for integration, we still need to see how HyperSOC can manage multiple point solutions. We have a very complex environment, but I think we are moving in a good direction as we have started to integrate with Defender and other technologies like Splunk.

    Torq has definitely changed the day-to-day experience for our security analysts, as they feel more excited and feel that Torq interface and workflow allow them to build things themselves. They think it is a better product than the legacy product.

    We have started to build workflows in Torq to triage, analyze, and contain incidents, including enrichment and integration of intelligence into the workflow. I find it a very good framework for integration compared to completely in-house built tools, as it is easier to maintain due to its vendor components and appears scalable.

    What matters most to our leadership team is risk reduction through automation and using the automation system to amplify efficiency, allowing us to do more with fewer people, along with leveraging some AI agent capabilities. Torq has helped us show real SOC impact in this regard.

    Regarding Torq's AI capabilities, I note they do have guardrails. I have not fully explored its AI capabilities, except for playing around with Socrate, which appears to have a triage agent. I still need more time to explore it, but the potential is there. Socrate can automatically summarize the case information; we just need more time to actually use it.

    So far, the AI agent from Socrate seems good enough in terms of accuracy and reliability of output. It is a generalized AI agent, and for other capabilities, we have not tried them, so I cannot comment.

    We have not started to use Torq's agentic AI capabilities yet, but we are definitely looking into it, hoping it will provide additional resources for our operations.

    My advice for others looking into using Torq is that those who are capable of developing will be able to utilize its features to leverage Torq platform effectively. I would rate this product a 7.5 out of 10.

    Gurjap Kaur

    Automation and ai integration have transformed incident response and reduced alert fatigue

    Reviewed on Jul 25, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Torq is reviewing the incidents and responding to them. After that, I investigate them and take appropriate actions.

    For example, a user has logged in from a blacklisted country and it triggers an alert. I investigate the alert and contact the user through Torq.

    Another use case is when an IP from my client side has tried to connect to an external IP which is malicious. It may also trigger an alert, and if at the firewall it's not blocked, the action is not blocked. So that may trigger an alert and I will have to do further investigation and complete the required action.

    What is most valuable?

    Torq offers the best feature through integration with AI. I can use AI alongside Torq.

    AI helps me add work notes, resolve notes, and also assists in the investigation and checking of IPs, IP reputation, and more. AI helps me accomplish all of these things.

    Torq has minimized the alert fatigue and also reduced the time I need to work on the alerts. Runbooks are present for each use case that helps eliminate other tasks such as going through all of the alerts manually.

    The automation Torq provided for some use cases removed the false positives, which saved me time. The number of alerts is reduced after fine-tuning the false positives.

    Torq has changed my approach in many ways. It reduced the manual tasks and also helped me in resolving high volume alerts. I also work on the malware alerts more efficiently through Torq.

    Torq's ability to solve an operational security issue is commendable. It meets all the compliances and also helps me resolve threats. I also use runbooks to contain malware.

    What needs improvement?

    Torq can be improved by adding some more features, such as adding more automation and providing a no-code option so I don't have to code for everything.

    Torq could add API dependency and also on-premise connectivity. If on-premise connectivity is available, organizations wanting to work on Torq could implement it that way.

    For how long have I used the solution?

    I have been using Torq for three months now.

    What do I think about the stability of the solution?

    Torq is very stable.

    What do I think about the scalability of the solution?

    Regarding the scalability of Torq, I need to consider the elasticity as well. Its scalability is good because it has a cloud-native architecture and it expands dynamically to handle thousands of alerts at the same time.

    How are customer service and support?

    I haven't had any issues using Torq so far, so I haven't contacted customer support. That is why I cannot comment on that.

    Which solution did I use previously and why did I switch?

    I used Splunk and I wanted to work on a different tool with more enhanced features. That is why I switched to Torq.

    What was our ROI?

    The standardized processes helped me guarantee identical incident response every time.

    Torq fortified my workflows and secured my cloud infrastructure.

    What's my experience with pricing, setup cost, and licensing?

    I am the end user. I don't have knowledge about pricing, setup cost, or licensing.

    Which other solutions did I evaluate?

    I also evaluated Azure Sentinel and QRadar. Those are the two options I evaluated before choosing Torq.

    What other advice do I have?

    I would definitely recommend others to use Torq as it is an all-rounder tool which even integrates AI. As we all know, it is the era of AI users, so we have to integrate AI into every tool. Torq is best suited for all the SOC analysts.

    Torq is a very scalable, elastic tool and also throttles integration of the tools, drops events, and creates message processing backlogs. It also shares back-end resources, so it is a good tool overall. I give Torq a rating of eight out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Sonu Prasad

    Automation has transformed incident investigations and now simplifies alert triage and response

    Reviewed on Jul 06, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Torq is to automate security incidents. By using Socrates CI, I am able to automate the investigation steps with the runbook and integrate other devices to forward their logs, customizing recording coordinates and parsing with jq.

    A recent scenario where I used Torq involved integrating Elasticsearch with Torq to forward the entire log from Elasticsearch to Torq, where I wrote a runbook for the investigation. For example, there is an RDP to the internet use case requiring ten to fifteen steps to investigate the incident. With Torq and Socrates, I automate everything to reach the final outcome.

    I have used Torq to automate triage, investigations, and remediation actions across multiple attack surfaces. It performs better than other tools because of its extensive integration capabilities and customizable features, allowing me to tailor responses according to my needs.

    I primarily utilize Torq for investigation and alert automation, and I do not have any other business relationships with the vendor.

    What is most valuable?

    I find Torq very helpful from an automation point of view, with customizable suite features that allow me to customize according to my needs. Initially, developing workflows was complex due to the numerous customization options available, but with Torq's support, I can successfully do that. I also utilize the available templates in Torq as a guideline for developing workflows based on these templates.

    Torq offers features like the shocker rates, allowing me to give prompts to the procreate, which investigates each alert according to my defined handbook—a feature I really appreciate. Additionally, I can integrate any third-party tool to Torq using the webhook connector and Torq's default connectors, which is another excellent feature I appreciate.

    The Socrates feature is a basic AI model that I develop according to my needs and offer some context in the Socrates tool. I write runbooks and provide prompts to automate the investigation steps using Socrates, which connects every tool and software to enrich the data I need. This feature significantly aids my daily activities, especially since it automates many tasks previously performed by manual analysts. Currently, I am using the WayBook connector and Torq's default connector to integrate third-party tools with Torq, along with various tools like Elasticsearch.

    I appreciate Torq's GUI interface, which is easy for every analyst to understand. Additionally, the dashboard features enable monitoring spikes, device integrations, and device statuses according to my needs, allowing me to develop comprehensive visualizations for alerts. Recently introduced migration features in the GUI add value by showing connected tools to my endpoints and assisting my investigation processes, which I find beneficial.

    What needs improvement?

    To improve Torq, I suggest that known alerts and attacks in the market should lead to developed use cases and workflows. Implementing these would help map known traits automatically when integrating third-party tools and require minimal credential configurations. Having examples of steps to investigate specific alerts would assist in developing other cases effectively.

    Torq provides comprehensive support, and I find their documentation useful for addressing challenges in my workflows. Walking through the documentation available on Torq's website gives me clarity on solving issues. If Torq could enhance its AI features, it would benefit customers significantly by making the platform even more user-friendly.

    For how long have I used the solution?

    I have been using Torq for the last one to two years.

    What do I think about the stability of the solution?

    Torq is stable and functions reliably within my operations.

    What do I think about the scalability of the solution?

    Torq's scalability is highly effective, allowing me to customize features according to my specific requirements.

    How are customer service and support?

    Torq provides comprehensive support, and I find their documentation useful for addressing challenges in my workflows. Walking through the documentation available on Torq's website gives me clarity on solving issues. If Torq could enhance its AI features, it would benefit customers significantly by making the platform even more user-friendly.

    Customer support is very good, available twenty-four seven, offering quick resolutions through group chats or calls.

    Which solution did I use previously and why did I switch?

    My experience managing various point solutions was complicated compared to using Torq's unified platform approach for AI SOC automation and case management.

    Before Torq, using separate security platforms posed challenges in enabling log forwarding and investigating alerts efficiently with manual documentation. With Torq, I automate actions while achieving SLA compliance and streamline alert investigation processes much better.

    What was our ROI?

    I started realizing value with Torq right away; the benefits became apparent immediately as I transitioned to automation.

    I have seen a return on investment with Torq, as the automation reduces the number of employees needed and significantly saves both time and resources.

    Which other solutions did I evaluate?

    I did not evaluate other options before choosing Torq, as my focus remains on employing Torq as my solution.

    What other advice do I have?

    I would rate Torq a perfect ten on a scale of one to ten.

    I chose ten because Torq meets all my expectations, providing support for any challenges I face during workflow, integration, and runbook development. They also have comprehensive documentation for knowledge sharing, along with Torq Academy, which offers multiple certifications to help users understand how Torq features work, especially the SOC analyst certification for beginners.

    While comparing various AI outputs, I find that accuracy is not always one hundred percent, but it reaches about eighty percent with precise prompts. Accuracy depends significantly on the clarity of prompts given to Torq's AI, with good prompts yielding better responses.

    The effect of using Torq's Agentic AI on stress levels and focus is positive, as it automates procedures, allowing staff to follow predefined protocols without additional manual effort.

    Metrics that matter most to my leadership team include investigating every alert and resolving issues as per defined parameters. Automation from Torq helps us show real SOC impact through efficient handling and timely responses.

    Before using Torq, I relied on manual investigation steps detailed in my playbook for alerts. Now, with Torq, I automate procedures through a defined software model, allowing runbooks to handle alerts effectively. When an alert is triggered in Elasticsearch, it forwards to Torq, which follows the runbooks I have set up for each alert. If additional actions are required, it sends alerts and notifications, categorizing legitimate alerts and closing them automatically at both Torq and Elasticsearch levels.

    I can monitor alert severity and manage how many alerts I have based on this metric, which is a positive impact since investigating alerts efficiently was challenging during manual processes. I can now see how many alerts are pending and their severity levels, contributing to meeting my SLA and TRA requirements.

    Torq significantly changes day-to-day experiences for security analysts by automating alert handling and reducing overall workload, thus improving job satisfaction and operational efficiency.

    Torq's Agentic AI significantly increases the alert handling capacity for my SecOps staff, streamlining their responsibilities and ensuring they manage alerts effectively. I would rate this product ten out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Maiko Svanidze

    AI-driven automation has transformed incident response speed and boosted analyst confidence

    Reviewed on Jun 30, 2026
    Review from a verified AWS customer

    What is our primary use case?

    For Torq, first of all, it's a hyperautomation and AI assistant usage. Our EDR SentinelOne is integrated in Torq and besides the vendor itself having hyperautomation abilities, Torq helps me to analyze incidents and to respond to incidents more quickly and more efficiently.

    Torq's AI SOC automation case management is much faster and more efficient compared to the manual tools I have used before. Torq is an ideal assistant for AI SOC in automation challenges.

    Torq changed the day-to-day experience for my security analysts. They are more confident and can test more approaches in the security operation center every day as workflows and routine.

    What is most valuable?

    I rely on Torq's AI assistant in most of my incident response and in building right and less complex workflows for automation.

    Torq helped me also in some infrastructure and ticketing challenges, for example, to organize the ticketing system in our company, but I am still in a process of learning about Torq and realizing different scenarios using Torq.

    The most valuable feature of Torq is hyperautomation and AI assistant because the quality of speed and recommendation from the AI assistant is really high. Another outstanding feature is that you don't need to write code. There is a library of prepared scripts or JSON scripts which can be right and adapted. You can face quite complex challenges without a programming background and can successfully solve these issues and challenges.

    Torq's no-code library helps me to be more efficient and respond to incidents more flexibly. The support of the AI assistant makes my actions more efficient and quicker.

    What needs improvement?

    The only thing is more out-of-the-box integrations. Torq already has a lot of supported integrations and adding new ones is not difficult, but for some customers, it's easier to have a plug and play interface to start onboarding.

    We didn't evaluate other options because we tested Torq and we liked it.

    At this stage, I have no additional suggestions. I will update my review several months later and maybe then I will have some suggestions to prove and to what in addition I would like to see in the solution.

    I can't evaluate Torq's agentic AI, but I think in my next review, I can provide more information.

    For how long have I used the solution?

    I have been using Torq for the last six months.

    What do I think about the stability of the solution?

    I haven't experienced any downtime or technical issues while running the platform.

    What do I think about the scalability of the solution?

    Torq can handle growth and increase easily without any downtime or lack of service.

    How are customer service and support?

    Customer support is responsive and helpful, but most of my questions were more how-to questions.

    Which solution did I use previously and why did I switch?

    I used online SIEMs with integrated SOARs, not online but on-premises, and we switched because it was too slow and too inefficient to use.

    How was the initial setup?

    From my point of view, Torq has excellent documentation and a support portal. You can find literally everything on the support portal. There are visual manuals and quite simple instructions for onboarding and for every use case you can imagine in your infrastructure.

    My advice would be to test Torq in your environment, ask as many questions as possible during POC and refer to documentation in cases you feel not confident about your new solution.

    What about the implementation team?

    At this stage, we are just customers of Torq.

    What was our ROI?

    Regarding Torq's pricing and license costs, as long as our existing team started to work more efficiently and quicker, I think we have quite a return of investment and we suppose to add more security management center tools. The return of investment is also the money we saved not adding another security tool. For me and for our security stack, it's about 30% return on investment.

    What's my experience with pricing, setup cost, and licensing?

    Torq is a standalone solution from Torq providers.

    Which other solutions did I evaluate?

    We didn't evaluate other options because we tested Torq and we liked it.

    What other advice do I have?

    I think I have told everything about Torq that I can share at this stage, but I am still in the process of learning the platform and I still think that there are many more features which can be adapted and can be used inside the company.

    According to positive outcomes, Torq reduced manual work and made incident response more efficient. From Torq workflows, I learn much more about my company ecosystem. This also reflects on the defensive side of the company. I see the gaps that I had according to incidents and I can fix and address the gaps relying on knowledge I get from automation results.

    I think the speed of work increased minimum by 50%, but I think with more automation and more optimization, we can make this result much better.

    The easiness of integration, good quality of support and good quality of documentation make this product easy to work with. From what I see, the vendor itself is oriented on improvement, which means that they will not stop at the level they reached by now.

    I am quite confident in Torq because I have checked, for example, compliance to ISO 27001 and this is the most relevant standard here in Georgia. I trust in Torq and I trust in the security compliance the platform provides.

    Torq's AI recommendations are consistently helpful. There was no case when the system provided me with a false recommendation or inaccurate response.

    Alert fatigue is something I would like Torq to help me address.

    My overall rating for this review is 10.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    reviewer2866401

    Automation has streamlined incident handling and AI now summarizes and responds to threats

    Reviewed on Jun 30, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Torq is to handle the correct cases using it as a SOAR platform. We have created a work plan and we've used Torq as a SOAR platform to handle the incidents from start to closure.

    What is most valuable?

    In my opinion, the best features Torq offers are ease of navigation and good AI usage as Socrates. There are different stages of the incident when it comes into the queue, and we could easily navigate to the sections that we would want to update and work on. That is how it brings a lot of customization to the incidents navigation and all other stages of the incident. The good usage of AI is regarding Socrates, the AI that summarizes and can respond to the threats or the incidents on its own when it's assigned to the incident. Those are two of the strongest points of Torq.

    Torq is good in the reporting structure and showing metrics to the leadership. I think Torq plays a good role in that sense.

    What needs improvement?

    Torq can probably use more ML and look at what can be closed and what cannot be closed in terms of data classification. In terms of auto closure of incidents, it can do better when it uses ML. I choose that number because it's a great SOAR tool. It's not one of those existing SOAR platforms or just a pure SOAR. It has good incident handling, good UI, and a good user-friendly environment, but it can also improve its automation workbooks, work plans, and usage of ML to better cater to the market or consumers.

    For how long have I used the solution?

    I have used Torq for five months.

    What do I think about the stability of the solution?

    I did not see it buffer, take a lot of time to load, or be unresponsive. I haven't seen those issues in Torq. I think that's a good experience.

    What do I think about the scalability of the solution?

    If scalability is rated out of ten, I would rate it seven out of ten.

    Which solution did I use previously and why did I switch?

    It was Demisto XSOAR, and we shifted because we needed a more user-friendly SOAR platform.

    How was the initial setup?

    I would just make sure to replace the old or the previous solution with Torq point by point. If that is good, I think everything else will be taken care of.

    What about the implementation team?

    We were just consumers.

    What was our ROI?

    I can share the time saved from my work alone and cannot disclose or specify any other employees. I saved nearly roughly about ten hours of my time while I was working in Torq because it's much better than the previous tool.

    Which other solutions did I evaluate?

    I have heard Hyper Automate is pretty user-friendly and has less coding compared to other leaders in the market or other players in the market. Its drag and drop tasks or work plan building is what I heard.

    What other advice do I have?

    We have seen fewer failures of automations from the time Torq came into the picture. We've had a more streamlined process of handling incidents, and at the same time, we've learned to embed the AI into our incident types, and that is how it has helped us in the automation. I think Torq can really integrate other tools within the case management platform, and it can make the work a little more efficient. I would rate this review eight out of ten.

    reviewer2846346

    Automation has transformed phishing response and routine workflows while AI now accelerates case handling

    Reviewed on May 26, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Torq is automation, specifically automating processes that the business considers redundant, mundane, and busy work items, along with other significant automation opportunities like phishing cases, typosquatting, leaked credentials, and double-checking, so there are numerous different use cases.

    One specific example of an automation I have set up with Torq is phishing analysis. Torq workflow that handles phishing cases essentially closes out 60%, meaning only 40% of all phishing cases that come to our team need to be reviewed because the automation can close out the other 60%. If my team had to look at every single email, it would consume a lot of time, so it saves a lot of time.

    What is most valuable?

    Torq's best features include the AI components within the platform, specifically the ability to have an AI helping assistant while you are working in the platform itself, which is extremely convenient. You can ask it any type of question and it gives me an answer that I can work with or is the actual answer because it has Torq's back-end knowledge to answer Torq-specific questions. Another great feature is the Python script AI assistant, which has been really helpful because you can prompt it and it does it for you, as well as other micro-steps like Transform operators and the ability to run easy JQ commands to pull or separate specific data.

    Torq's integrations are extremely easy, so any product you have in your tech stack is easily integratable; it takes a few steps, plug it in, and you are ready to go.

    Torq has positively impacted our organization by saving a ton of time, especially on the GRC side of the business where we automate many emailing processes, such as sending out phishing tests to our employees. If they fail by clicking on the link, we notify all of them, so we have definitely seen a huge efficiency boost. We are targeting $600,000 saved this year in 2026, which is a substantial amount of money.

    What needs improvement?

    I wish Torq's AI assistant for building templated workflows from scratch worked better; when you start with a blank slate, asking AI to help you build or template the workflow out does not go well. Almost every single time I have tried to use it, I have had to delete it and start from scratch, so that would be the only piece of Torq I would mention. Additionally, I think it would be nice to have a direct connection between case management and automation instead of having to build out workflows to manage cases.

    For how long have I used the solution?

    I have been using Torq since we moved into production ready as of last November, so it has been about six or seven months.

    How are customer service and support?

    I have not run into any issues with customer support from Torq, which has been astronomically amazing. I have a great relationship with my CSM and my technical enablement engineer, so it has been really easy working in Torq and building, which is why it cannot be anything lower than that.

    Which solution did I use previously and why did I switch?

    We came from XSOAR, which I consider a very archaic platform, and Torq has exceeded expectations by delivering workflows in a timely and lower effort manner than XSOAR. XSOAR would have been a two; Torq is definitely a nine and a half, almost a ten. It meets all my needs, and I have not run into any issues.

    Torq challenges we faced in our SOC that led to considering changes before implementing Torq were primarily due to the automation industry changing. Palo Alto's XSOAR simply did not meet our needs, and with our contract coming up, we performed an industry review and compared Torq with Tines and others. Ultimately, Torq proved to be superior with a much easier to interact with playbook builder compared to Tines, which felt complicated and convoluted.

    We previously used Palo Alto XSOAR because it was slow, and our contract was up.

    What was our ROI?

    Torq calculation for the $600,000 in savings is very specific and based on the team's time. For example, we calculate that handling phishing cases takes about five minutes per case, but if Torq auto-closes it, we save more money because our analysts do not have to take time out of their day to review it. We do a per-minute price cost based on yearly salaries of whichever department we save time for, multiplying that by how long it would take to handle the specific use case, and then total it into an ROI table that we are holding in the workspace variables.

    We have seen a return on investment, targeting a $600,000 ROI for the year. So far, from the start of our usage, we have saved around $200,000 to date. We aim not to eliminate jobs but to reduce mundane tasks through automation.

    What's my experience with pricing, setup cost, and licensing?

    My experience with Torq's pricing, setup cost, and licensing was good, but I did not deal with that too much; that was handled by my boss, and Torq's pricing came in very comparable to the other products we were looking at.

    What other advice do I have?

    I have not looked into Torq's AI capabilities regarding governance and security too much, so I do not have much to say on that.

    Regarding Torq's AI capabilities, I trust more or less the accuracy and reliability of output. I have not done a whole lot with AI beyond using the AI chat agent and the AI script builders, but we are building out a HyperAgent for active threat hunting in our environment. This process involves pulling feeds using a Python script, which extracts artifacts from individual pages or feeds and injects them into the HyperAgent, allowing the HyperAgent to scan and identify if we are impacted by the feed, and then build a report or storyboard for us. I have not seen anything that indicates inaccuracy, so I trust the produced outputs so far.

    Torq is deployed in our organization as a private cloud; we are not on-prem, and we utilize Torq's back-end or cloud instances.

    Torq has changed the day-to-day experience for my security analysts, both in terms of workload and morale, by making the process easier.

    Torq biggest feedback from my teammates is that going through each case is much easier because the case management layout in Torq is structured with a multi-pane window. You have all cases in the background, and when you pull up a case, it displays on the side for quick review and closure, so you are not opening up numerous tabs for each individual case. This makes life a lot easier, and my analysts really appreciate the UI aspects of Torq.

    Torq value is realized instantaneously; the moment I started building and shipping out workflows from XSOAR, it became easier post go-live since I already knew how to build. Thus, the transition from XSOAR to Torq provided instant gratification.

    We do not use Torq's Agentic AI at this moment in time.

    There have not been any changes in the stress levels and focus of our SecOps staff due to using Torq's AI since our analysts engage the AI component of Torq very little. Torq's AI main usage is found on the back end by developers, including myself.

    I would rate this review as a nine overall.

    Hiten Nandasana

    Automation platform has transformed user onboarding and manages daily workflows efficiently

    Reviewed on May 18, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Initially, we were using Slack for small automations, such as creating pipelines or shutting down servers. For example, I could shut down one of our Angular services on one of our servers through a slash command in Slack. To automate this process, we migrated everything from Slack to Torq. Currently, we are in the migration phase, with most of it completed, though some portions are still pending.

    We use Torq for identity management. For identity purposes, we create user accounts and have a workflow that creates a user account, adds that user into Slack, and grants Git access. This workflow handles user additions, deletions, and modifications related to identity, and it is working very well.

    We are not using Torq extensively for security purposes, as we have limited use cases for security. However, we are using it for day-to-day activities and general automations, which are also working well.

    What is most valuable?

    Feature-wise, I appreciate the Torq UI because of its drag-and-drop functionality. Everything is drag-and-drop, and I can accomplish whatever I want to do directly without writing any code. In Slack, there are many things that require writing code and familiarity with automation tools, but Torq is no-code. This is very good compared to all other solutions I have seen.

    The workload has been reduced quite a bit. Initially, onboarding a new user would take four or five hours for one person to create a user account everywhere, remember everything, and follow Confluence documentation. After implementing Torq, we only need to provide the name, user ID, and email, submit it, and then it creates everything. Almost four or five hours of work is now completed in four or five minutes. This represents a very good time saving.

    What needs improvement?

    I do not dislike anything about Torq because it has satisfied all of our use cases and requirements. We contacted support as well, and support is very good. I believe everything is good now. However, one thing I can mention is that if Torq provided more templates on the development side, that would be beneficial.

    As of now, Torq satisfies our use cases. A template would be helpful for someone who does not know anything about Torq and is starting to use it for the first time. After conducting a POC on Torq, I can implement solutions without needing templates as much, but templates would serve as a reference for new users. For example, templates would show what is possible with Torq. We faced this issue when we were new to Torq. We were considering use cases but wondering whether they were possible with Torq. At that time, we asked support if it was possible, and they explained how to implement it. If there were default templates available, we could see the templates and understand what is possible and doable with Torq.

    For how long have I used the solution?

    I have used Torq for about one and a half year.

    What do I think about the stability of the solution?

    I have not faced any issues until now. Torq is working very well without any problems and no downtime. Whenever I access the Torq URL, it is working. This is very good.

    There is no downtime at all. We have been using Torq for one and a half years, but we have experienced no downtime.

    What do I think about the scalability of the solution?

    Torq is very scalable. Whenever we require any new use cases, we simply need to create a new workflow. If we need to update something, we can update the workflow as well. Torq is fully scalable.

    How are customer service and support?

    The support team is very quick. Within 24 hours, they will send an email or come on a call if something is critical. Support is provided within 24 hours.

    Which solution did I use previously and why did I switch?

    We used Slack previously. I do not have experience with other tools. We used only Slack. However, Slack is used primarily for chatting and communication purposes in all organizations. While Slack is not similar to Torq, we were able to accomplish our automation through it somehow.

    How was the initial setup?

    The initial deployment was very easy. I did not face any issues. We purchased a SaaS product that is cloud-based, so there were no issues at all. The process was very straightforward with simple steps.

    What about the implementation team?

    At least one or two people are needed. One to two people are enough for this. It is a one-time setup where we create workflows based on our use cases. However, if we want to add more workflows, we need some support. For that purpose, one or two people who know Torq are more than enough.

    What was our ROI?

    After we created a workflow and tested it, we started using it, and the return was immediate. After creating the workflow, we were immediately getting results.

    What's my experience with pricing, setup cost, and licensing?

    The pricing is cheap. Although I did not purchase the product myself, my manager and others were discussing it. This is a very cheap product, and it is very helpful.

    What other advice do I have?

    I have been working for five years with experience in the IT field. Torq is very good. It manages everything. I would rate this product 10 out of 10.

    Abdullah Zubair

    Modern automation has transformed alert triage and now unifies incident handling for analysts

    Reviewed on May 18, 2026
    Review provided by PeerSpot

    What is our primary use case?

    As MSSPs, we serve our customers using Torq, and I work as a consultant in an MSSP that uses Torq as our main SOAR platform for our SOC.

    Our usual use cases for Torq involve a variable amount of scenarios. We use it for fast automation building, as the automation building capability in Torq is low-code and quick with less scripting involved. This enables faster Tier 1 SOC automation, so all Level 1 analyst work is eliminated with Torq.

    Our other use case centers on its cloud-native architecture. Torq makes use of API-first integrations and event-driven workflows with AI-assisted triage and response capabilities. It can be integrated with different multi-cloud vendors as well as other SaaS stacks, other MDR, and MSSP operations. Integration with cloud technologies is very straightforward.

    Regarding Torq's automation of triage, investigation, and remediation actions across multiple attack surfaces, the data ingestion pipeline and workflow are excellent. Torq ingests alerts from a SIEM, EDR, CSPM, IAM, email, ASM, and other sources. It then performs normalization and enrichment. The third phase involves correlation across services, correlating data between different platforms when alerts arrive from endpoints, identity, cloud, network, or other sources. After correlation, the AI rule-based triage determines whether an alert is a false positive, a real attack, or its priority level. This is managed by the AI Agentic software within Torq. The automated response playbook then comes into play for remediation. If a playbook has been configured, it may disable a user, isolate a host, revoke a token, or patch a cloud issue based on what the AI detected. The final stage involves ticketing and validation. Torq audits everything, generates a ticket regarding whether the task has been completed, and includes a validation point that ensures all completed work has been confirmed or validated for completeness.

    What is most valuable?

    The valuable and important aspects I find about Torq include how it was deployed in our environment and integrated with every other technology within our SOC, which was a straightforward task with minimal hassle. The documentation from Torq was thorough, and we were able to integrate other technologies well.

    Torq's UI interface is easy to understand and digest. It is visually appealing and information flows consistently, making it easy to grasp whether you are looking at it for the first time or have been working on it for a month or two. The interface is logical in terms of page navigation and how settings are organized by category, all sensibly categorized.

    In terms of how Torq has changed the day-to-day experience for my security analysts regarding their workload and job satisfaction, the analysts feel more confident. They believe Torq has all the elements that increase their confidence in how technology should look and integrate with every other piece of technology within our SOC. Under one SOC tool in Torq, analysts get to know everything within the context of an alert or incident they are working on. Torq also provides analysts with a comprehensive viewpoint where they can see all alerts coming from various software, technologies, and alerting systems for a certain customer. This ability to view the whole picture within Torq is one of the major breakthroughs and best offerings of Torq.

    What needs improvement?

    Torq does extensive marketing saying that SOAR is dead and markets itself as an all-in-one solution, but this is not actually true. Torq is a SOAR platform. Branding that suggests SOAR is dead might not be the best approach. Similarly, marketing Torq as an AI SOC replacing SOAR is part of the overall branding strategy, but Torq should position itself as a SOAR platform because that is what it is. If Torq brands itself as an AI SOC or something else, there might be different outcomes in the long run.

    The AI value depends on maturity. Real value depends heavily on telemetry, integration depth, and workflow design, all of which rely on how mature customers are in their SOC department. There is a dependency in this relationship. Enterprise complexity still exists as well. Although Torq is easier than older SOAR tools, large deployments can still become operationally complex, integration-heavy, and governance-sensitive. Many organizations apply extensive governance for security, and Torq does not always comply with all the policies that certain enterprises require.

    For how long have I used the solution?

    I have been working with Torq for almost four months.

    What do I think about the stability of the solution?

    Torq is quite stable and reliable with consistent performance. I have not encountered any bugs or errors.

    What do I think about the scalability of the solution?

    Torq is quite scalable and can scale to accommodate whatever amount of customers you onboard or whatever volume of incidents or alerts are generated daily.

    How are customer service and support?

    We do not often communicate with Torq's technical support. We had to contact them during initial installation, but we have not needed to since. My impression of their technical support during the initial setup was that they were helpful, responded within a reasonable timeframe, and provided exactly what we needed.

    Which solution did I use previously and why did I switch?

    Before using Torq, we were using Google Simplify, a SOAR platform by Google, which we used for about four or five years. Before that, we were not using any SOAR solution.

    How was the initial setup?

    I participated in the initial setup of Torq, which was not complex. Everything was straightforward with minimal hassle. All customization had to be done through APIs, which is always the best approach. There were not many issues during the initial deployment.

    What was our ROI?

    We are still in the process of realizing value with Torq. Since we transitioned from another SOAR just a few months ago, we have not conducted any system review or performance review. After a six-month or twelve-month period, we will likely conduct a performance review. For now, we are still assessing how much efficiency improvement we have achieved with Torq enablement. Generally speaking, the analysts are very pleased with it, and the integration of how Torq connects is working well.

    Which other solutions did I evaluate?

    Before choosing Torq, we evaluated other vendors including Tines, Splunk SOAR, Microsoft Sentinel Automation, and Palo Alto Cortex XSOAR. We ultimately decided on Torq.

    We dismissed other options in favor of Torq for a variety of reasons. Our solution architect team conducted extensive analysis to determine which platform would move forward, alongside company negotiations and the support we were receiving from Torq. The decision was not based on just one or two factors, but rather on an in-depth analysis.

    What other advice do I have?

    Comparing Torq's unified platform approach to AI SOC automation and case management with my experience managing multiple point solutions across my security stack, I find that Torq is modern because many other platforms lack this quality. When I say modern, I mean it encompasses everything—the UI interface, integrations, the ability to use AI, and the ability to navigate through cases. Other platforms that are not as modern lack in one or two departments. With Torq, case handling and how a case moves from instantiation through analyst work to resolution or closure—all these stages are managed in a way that is somewhat similar to how other platforms handle them, but it is more modern and represents how technology should look in 2026. The UI interface is quite good, which makes a significant difference in how you view the technology. While it is not a very big leap in terms of case handling compared to other platforms, it still represents an improvement when compared with other multi-integration or multi-connecting platforms.

    Regarding the pricing and licensing of Torq, I cannot comment extensively because pricing has been controlled by our product manager. The relativeness between what pricing we received from the previous SOAR and our current Torq pricing is something that should be asked from a product manager, as we as architects and engineers do not handle the sales aspect of the technology. The pricing appears to be user-based rather than database-based, meaning it is based on the number of analysts working on the platform, whether that is fifty, twenty, or thirty, which represents good value.

    I would rate this review eight out of ten.

    AdityaDesai

    Automation has streamlined multi-tenant SOC workflows and improves alert handling efficiency

    Reviewed on May 15, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My usual use cases for Torq involved more than 70 customers. We were an MSSP back then, and there were all sizes of customers with different industry verticals. Since our company was a Microsoft shop, we had a lot of Microsoft solutions integrating with Torq. We had an in-house Security Operations Center that worked 24/7. Torq was utilized in an MSSP model wherein we had different client workspaces, a pro-arc, and a parent workspace. From alert ingestion, incident investigation, triage investigation, to response, we were using Torq. We also built a lot of workflows within Torq that handled malware analysis, email phishing analysis, and identity access management analysis, such as alerts from identity and access management. Additionally, we developed a vulnerability prioritization solution for our clients, which went to market, and many clients appreciated this solution as it provided significant insights into vulnerabilities relevant for them, driven by threat intelligence.

    My experience with Torq's Identiq AI regarding increasing alert handling capacity for our SecOps staff involves using Socrates, the AI orchestrator in Torq. Unfortunately, when I was working with Torq, I did not get hands-on experience with their Identiq AI capabilities because it was not available at that time. However, I utilized Socrates orchestrators within the platform that did help reduce some of the workload for our SOC analysts, but it was very premature back then. They later introduced a lot of features after we started implementing, which really helped. It is effective in handling alerts as long as you provide summarized data; otherwise, it could blow out of context and hallucinate.

    When I used Torq, it was indeed in the early stages of AI capabilities. Only a few customers were allowed to use it, and we were among them. It functioned well as long as we summarized the data properly. If you input garbage, you would get garbage out. Thus, we had to do significant fine-tuning regarding what data context we provided to the AI orchestrator to get meaningful results from a case or alert. There are features allowing us to dump plain JSON logs into case management, but that would not help much because the data context would be too large. They also have a certain token size limit, meaning we would only get meaningful results if we stayed within that limit. Hence, context is crucial, and they can improve on developing tools to enrich case data, providing meaningful context to the AI orchestrator.

    In terms of Torq's unified platform approach to AI SOC automation and case management compared to managing multiple point solutions across my security stack, I find it case-centric. They have many triggers that execute workflows based on specific changes in the cases. Each time there is a change an analyst makes in case management, it triggers a workflow. It is a case-centric platform, and when discussing a unified view, it is essentially about integrating various security solutions using API and some authentication, bringing in the data and allowing the workflows to do the work. Now, every time we need to use Torq, whether for reporting or workflow execution, we have to go through a case; otherwise, it is more isolated, requiring some interactive tasks to manage the inputs and execute the workflow.

    I have used Torq to automate triage, investigation, and remediation actions across multiple attack surfaces, including endpoint, identity, cloud, and IT. They provide good connector actions for various remediations like isolating or quarantining devices or blocking IPs. As long as the third-party API supports those actions, Torq can effectively deliver these connector actions. In cases where Torq lacks connector actions, there are HTTP steps and actions we can configure to hit the API endpoint and perform response actions.

    Torq is deployed only in the cloud in our organization, whereas Swimlane offers flexibility for customers to choose between on-premises or cloud deployments. We are using Azure as our specific cloud platform.

    What is most valuable?

    What I liked the most about Torq is the actual workflow builder. It is really great because they offer a lot of features and convenience features that are useful for any automation engineer. We can drag and drop and copy-paste. It does not provide much flexibility compared to Swimlane, but it does offer a very convenient user interface that can speed up the workflow building process.

    In terms of Torq's unified platform approach to AI SOC automation and case management compared to managing multiple point solutions across my security stack, I find it case-centric. They have many triggers that execute workflows based on specific changes in the cases. Each time there is a change an analyst makes in case management, it triggers a workflow. It is a case-centric platform, and when discussing a unified view, it is essentially about integrating various security solutions using API and some authentication, bringing in the data and allowing the workflows to do the work.

    I have used Torq to automate triage, investigation, and remediation actions across multiple attack surfaces, including endpoint, identity, cloud, and IT. They provide good connector actions for various remediations like isolating or quarantining devices or blocking IPs. As long as the third-party API supports those actions, Torq can effectively deliver these connector actions. In cases where Torq lacks connector actions, there are HTTP steps and actions we can configure to hit the API endpoint and perform response actions.

    What needs improvement?

    Although the reporting within Torq is not that great, we did ask for many features regarding reporting in Torq, but due to some platform constraints, they could not make the whole dataset available for us to be used in reporting. Except for that, we used some basic reporting.

    When I used Torq, it was indeed in the early stages of AI capabilities. Only a few customers were allowed to use it, and we were among them. It functioned well as long as we summarized the data properly. If you input garbage, you would get garbage out. Thus, we had to do significant fine-tuning regarding what data context we provided to the AI orchestrator to get meaningful results.

    In terms of Torq's unified platform approach to AI SOC automation and case management compared to managing multiple point solutions across my security stack, I find it case-centric. The unified view in case management is good since it provides clarity, although there are limitations regarding how many items in case management can be modified at once. Bulk operations are very limited, potentially due to their back-end database or data retrieval processes that can be improved.

    Regarding improvements for Torq, when we were onboarded, there were aspects we were uncertain about, such as the number of cases that could be generated, what data we could bring in, how many clients we could onboard, and similar concerns. Initially, we also lacked clarity about the number of playbooks or workflows we could build. Different triggers like system triggers, case-based triggers, and others can be employed without restrictions, but when it comes to on-demand and scheduled jobs, there is a limitation based on the subscription and pricing tier that notably caps the number of workflows we can create. No bulk editing across cases was one issue, along with limited filtering related to single grouping constraints. Additionally, the out-of-the-box case templates provided require substantial modifications before they become usable. There is also a feature in the cases for notes that cannot be searched. They are only visible through the UI, which is another area for improvement.

    The workflow and execution-based charges seem misleading as this was not discussed initially. I am not sure if new customers are made aware of this. It seems that workflows revolving around cases hinder functionality outside of case management, as we have many use cases needing on-demand triggers and schedules for functions like reporting or polling devices. Creating additional workflows to achieve basic functionalities raises costs significantly, which disadvantages customers. While they facilitate optimization and scaling, the support received tends to be very basic. Improvements can be made in that area as well.

    For how long have I used the solution?

    I have used Torq for over a year.

    What do I think about the stability of the solution?

    Torq is generally really stable and reliable, maintaining an uptime of almost 99.9%. This is a significant improvement compared to D3 Security, which we used previously. There were minor intermittent issues we faced where the platform was not reachable, and certain UI features became unresponsive, but these problems were resolved fairly quickly, within about 10 to 15 minutes. Such downtime did not greatly impact operations because the back-end workflows were functioning correctly, allowing ingestion and API actions to remain unaffected.

    What do I think about the scalability of the solution?

    Regarding the scalability of Torq, it is good. It is not very poor, but conditions apply. If a very large workflow processes excessive data, the browser can sometimes crash.

    We did address this issue with the Torq team when they suggested modularizing our workflows to handle this better. They recommended breaking down larger workflows into smaller components. However, their support or advice was not available when we were architecting the entire solution for our security operations center. Despite numerous review meetings, the guidance was absent at that time, and only after we started encountering slowness and crashes did they suggest the modularization approach. We made significant efforts to modularize as best as we could, but even so, some slowness persisted. If the workflow handles less data and remains small, it operates well. However, with a lot of incoming data managed within a single workflow, it can crash and become slow.

    How are customer service and support?

    I would rate their technical support and customer service as an eight, perhaps seven or eight.

    Their response time is quite quick. Any tickets raised in the portal receive prompt follow-up. However, they often request access to the platform to perform necessary actions, and I typically grant this access by default. Having worked with them for over a year, I am well-acquainted with their procedures, yet there are instances where they ask again for access, which can delay resolution. When it comes to requests for new features, they often place our needs on a pipeline to evaluate demand across customers. Although I understand their development procedures, I believe if a feature is deemed critical by a customer, they should establish a timeline for potential delivery rather than simply putting it on a list without a timeline.

    Which solution did I use previously and why did I switch?

    Before Torq, specific challenges in my SOC involved using another platform called D3 Security, which claimed to be a cloud-based solution, but it was essentially running on a VM in the cloud. Every time they performed an update, push, or maintenance, the system would be down for hours or a certain time period. We saw downtimes up to an hour with that platform previously. Although the situation may be different now, what I experienced in 2022 and 2023 made it clear that scheduled maintenance, updates, and upgrades required downtime, which was not seamless. We had a high-performance security operations center working 24/7, so we needed a platform that would provide better uptime, not behave like a legacy solution. Torq addressed this. Updates were seamless, and while there were issues and downtimes, they were not as severe as with the previous solution due to Torq's different architecture and update handling. The serverless nature of Torq provided options for updating actions or steps in workflows on the screen, allowing us to decide whether to upgrade to the newest version or stick with the current one, empowering us with flexibility and decision-making freedom to test before upgrading, which was not the case with D3 Security.

    How was the initial setup?

    The initial setup of Torq is pretty straightforward. It is not complex, and I find it relatively easy, although a learning curve exists, which is not too challenging.

    What was our ROI?

    I think it takes around three months to realize value with Torq. Implementation alone takes about one month. They have an excellent support and customer success team that assists significantly during this time. It took roughly one month to complete the end-to-end implementation, and to stabilize everything, we faced a lot of errors since we configured most of it, which required about two months for stabilization. Overall, I believe you need around four to five months to see a return on investment.

    Which other solutions did I evaluate?

    Before Torq, I was using D3 Security, which had a legacy architecture with standalone servers in the cloud. This setup truly hindered our ability to work seamlessly within our security operations center, where we needed nearly 24/7 uptime. Although they promised a certain SLA, they did not meet our expectations, leading us to seek a more modernized solution like Torq, Tines, or Swimlane.

    We did evaluate other options, conducting proof of concepts with Torq, Tines, and Swimlane, but we ultimately proceeded with Torq.

    What other advice do I have?

    These abilities compare to other tools I looked at as being quite standard. It is not something exceptional, as I mentioned. The overall performance depends significantly on how one builds the workflow since it is a SOAR platform. The customer bears the majority of the workload in developing workflows and playbooks to customize according to their needs. In a typical SOC scenario, we would want confirmation that an alert is a definite true positive before taking specific actions based on approvals. Torq provides end-to-end features allowing us to determine if it is a true positive. Additionally, there are communication connectors to notify our clients, "Hey, this looks fishy. We want to block this user." We can send a link within that communication, and once they click, we receive a response back confirming it is approved. There is also an escalation procedure built within the platform to assign cases to different tier analysts, and based on that, they can take response actions. Overall, I believe it is a convenient setup, yet ultimately, it is up to the customers to build it as they see fit. I would rate Torq overall at around an eight, based on all aspects I have worked with.