
30 Sep 2026
Sekoia Elevate goes GA — agentic SOC verdicts in 99 seconds
Sekoia said Wednesday its Elevate agentic AI layer is generally available, with agents investigating customer security data and returning an audit-ready verdict in 99 seconds on average.
SOC tools spent two decades making better alerts while people still do the investigation. Elevate’s bet is that agents pull the logs, the threat intelligence, and the runbooks in under two minutes and leave a paper trail a person can challenge, so the queue shrinks without a black-box rubber stamp.
On Wednesday, 30 September 2026, Sekoia announced that Sekoia Elevate is generally available. Generally available means a customer can take the product in the ordinary release. Sekoia calls itself the European agentic cybersecurity company. Agentic, here, means the software carries out the investigation steps, rather than only writing a summary when a person asks. Elevate is the agentic AI layer of its autonomous SOC platform. A SOC is a security operations center, the team that watches alerts. GlobeNewswire carried the release at 8:00 a.m. Eastern. The dateline is Paris, France. The subhead says that after more than 425,000 autonomous investigations in Early Access, Elevate turns alerts into audit-ready verdicts that analysts can inspect, challenge, and govern. Those lines are Sekoia’s.
Elevate’s AI agents investigate an alert from end to end, using the customer’s own security data. They return an audit-ready verdict in 99 seconds on average. A verdict is the agent’s conclusion on that alert. Audit-ready means the conclusion comes with a record a reviewer can check later. Ninety-nine seconds is one minute and thirty-nine seconds. The record covers every query the agent ran and every piece of evidence it used. Sekoia says that with Elevate, the alert is no longer a request for human work. Machines do the investigative work at speed, and the security team keeps governance and the final decision. Those lines are Sekoia’s.
Sekoia says security tools spent twenty years producing better alerts, and SOC teams grew in order to process them. As telemetry expands, and as attackers adopt AI, that model no longer scales. Telemetry is the stream of logs and signals those tools already collect. For each case, Elevate’s agents gather and correlate raw logs, detections, threat intelligence, runbooks, and response context. A runbook is the written procedure an analyst would otherwise follow by hand. Sekoia calls that the manual groundwork that absorbs analyst time. The company says teams can then apply their expertise where it protects the business, without giving up control. Those lines are Sekoia’s.
The general release follows an Early Access program in real production environments. Early Access is the period before the ordinary release, with the product already running on customers’ live systems. During that phase, Sekoia says Elevate was deployed to more than 2,000 customers and hundreds of SOC analysts, and that it completed more than 425,000 autonomous investigations, correlating evidence across the connected data sources. More than 425,000 is the count of investigations the company reports for that program. It is not a count of confirmed attacks. Those lines are Sekoia’s.
Sekoia says leading managed security service providers in Europe and the United States report up to a fivefold reduction in overall investigation time, along with deeper and more consistent threat analysis. A managed security service provider, which the release shortens to MSSP, is a company that watches alerts for other companies. Fivefold means the investigation takes about one fifth as long, in the best case those partners report. “Up to” is the ceiling in that report, not a typical result the release prints for every customer. The figure is what those partners told Sekoia. The release does not print the before-and-after times, and it does not name the providers.
Sekoia says transparency is built into every investigation. Elevate records the queries its agents run and the evidence behind each finding, so an analyst can see how a verdict was reached and where more review may be needed. Analysts can review, correct, or override any conclusion, and every change is logged for incident review and for audit. Each investigation a person validates or corrects also adds context the next investigation can use. Those lines are Sekoia’s.
Sekoia says autonomous cyber defense needs a system, not only a model. Elevate draws on work the company says it has built for years: its own threat intelligence, a security data infrastructure, deep integrations, and investigation workflows across thousands of production environments. The platform is model-agnostic. That means it is not locked to one AI model. Sekoia says it chooses a model for each task. The platform is also open by design, so it works across the security tools the customer already runs. Those lines are Sekoia’s.
Freddy Milesi, chief executive of Sekoia, said: “The alert economy is ending.” He said the model alone is not the moat. A moat, in that sentence, is the advantage a rival cannot easily copy. He said what makes an agent effective in a SOC is the system around it: threat intelligence, customer context, memory, and the ability to act. He said Elevate is that system in production, delivering autonomous cyber defense independent of any single stack or model. A stack, here, is the set of security tools a company already uses. That quotation is his, on the wire.
Georges Bossert, chief technology and product officer at Sekoia, said: “Elevate shifts the analyst’s role from data miner to decision-maker.” A data miner, in that sentence, is the person who still has to dig the logs out by hand. He said the agents do the exhaustive groundwork from raw data and explain every step, so teams can focus on the decisions that protect the business, without giving up control. That quotation is his, on the wire.
The about box describes the company. It is not a customer list for this launch. It says the platform connects threat intelligence, customer context, investigation memory, AI models, security capabilities, and response actions, so machines investigate and act at scale while security teams set intent, policy, and control. It says the platform works across any security stack, any model, and any deployment environment. It says Sekoia serves small and midsize businesses that an MSSP supports, and Fortune 2000 enterprises. Fortune 2000, in that sentence, is the company’s phrase for large firms. The GlobeNewswire company profile lists software as the industry, Freddy Milesi as chief executive, and the employee range as 50 to 999. The press contact is Arnaud Dechoux at media@sekoia.com. The wire points readers to sekoia.com/platform/elevate. The release does not print a price or a funding amount, and it does not name a customer for the general-availability launch.
In plain terms, Sekoia said on Wednesday that Elevate is now on general release. The agents are supposed to investigate an alert from the customer’s own security data and return a verdict in 99 seconds on average, with a record of every query and every piece of evidence. During early access the company says the product ran for more than 2,000 customers and hundreds of analysts, and completed more than 425,000 investigations. A person can review, correct, or override a conclusion, and the change is logged. The fivefold cut in investigation time is what leading MSSPs in Europe and the United States report to Sekoia. The release does not name them.
The picture is Sekoia’s Elevate verdict card from the product page. The alert is named FromBase64String Command Line. A circle on the card reads 80. The release does not say what 80 measures. The clock on the card reads 14:32:01, and the alert id reads ALNV6X1CYs9. A tag reads Sigma. Sigma is a shared way of writing a detection rule, so the same rule can run in more than one product. Under Verdict, a red tag reads true positive and risky activity, and a blue tag reads Confidence 92 percent. The written reasoning says rundll32.exe was started by a user who is not an administrator, in an interactive session. rundll32.exe is a Windows program that can run code stored in a library file. The note says the Base64 payload decodes to the harmless string “worm.” Base64 is a way of writing that payload as ordinary letters and numbers. The note says the agent saw no outbound traffic, no privilege escalation, and no high-value asset involved. Privilege escalation means gaining a higher level of access than the account already has. The note closes by saying the telemetry looks benign, so the alert is a false positive. The tags call the same alert a true positive. It is a product-page card. The clock is a time of day. The card does not print a calendar date.
RELATED
Sources
- GlobeNewswire — Sekoia Elevate general availability, 30 Sep 2026
globenewswire.com
- Sekoia — Elevate product page
sekoia.io